Microsoft to Plug DirectX And ActiveX Holes

Microsoft plans to swat two Windows bugs that have come under attack by hackers as part of the 14 July Patch Tuesday.

Among the collection of patches are fixes for the DirectX vulnerability that Microsoft first warned users about at the end of May. But also slated to be fixed is a vulnerability in the Video ActiveX Control that the company warned about 6 July.

“I want to provide some clarity on two of the pending Windows updates mentioned,” blogged Jerry Bryant, a Microsoft Security Response Centre (MSRC) team member.

“First, we will be addressing the issue discussed in Security Advisory 971778 concerning a vulnerability in DirectShow…Second, our engineering teams have been working around the clock to produce an update for the issue discussed in Security Advisory 972890 (vulnerability in the Microsoft Video ActiveX Control) and we believe that they will be able to release an update of appropriate quality for broad distribution that protects against the attacks we detailed in the advisory and in an MSRC blog post by Christopher Budd.”

While customers wait, they can enable the workaround for the Video ActiveX flaw by following the instructions here. Information on mitigations for the DirectX vulnerability, which lies in the QuickTime parser in Microsoft DirectShow, can be found here in the workarounds section of the advisory. Microsoft DirectX is a Windows feature used for streaming media to enable graphics and sound when playing games or watching video. DirectShow works within DirectX to provide client-side audio and video sourcing, manipulation and rendering.

All told, there are six bulletins scheduled for next week’s Patch Tuesday. In addition to the aforementioned bugs is a third bulletin for Windows that is rated “critical.” There are also three updates rated “important” for ISA (Internet Security and Acceleration) Server, Virtual PC and Virtual Server, and Microsoft Office Publisher.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Share
Published by
Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Northvolt Mulls US Bankruptcy Protection – Report

Troubled battery maker Northvolt reportedly considers Chapter 11 bankruptcy protection in the United States as…

11 hours ago

FTC Plans Investigation Into Microsoft Cloud Business – Report

Microsoft's cloud business practices are reportedly facing a potential anti-competitive investigation by the FTC

13 hours ago

Programmer Sentenced To Five Years In Prison For Bitcoin Laundering

Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…

14 hours ago

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

1 day ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

1 day ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

1 day ago