Microsoft DirectX DirectShow Length Record Remote Code Execution Vulnerability
BID:35616
Info
Microsoft DirectX DirectShow Length Record Remote Code Execution Vulnerability
| Bugtraq ID: | 35616 |
| Class: | Unknown |
| CVE: |
CVE-2009-1539 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2009 12:00AM |
| Updated: | Aug 21 2009 03:56PM |
| Credit: | TippingPoint and the Zero Day Initiative, Thomas Garnier of SkyRecon, and Yamata Li of Palo Alto Networks |
| Vulnerable: |
Nortel Networks Symposium TAPI Service Provider Nortel Networks Self-Service WVADS 0 Nortel Networks Self-Service VoiceXML 0 Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service MPS 100 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self-Service CCXML 0 Nortel Networks Self-Service - Peri Application Rel 3.0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Self-Service 0 Nortel Networks Contact Center Web Client Nortel Networks Contact Center NCC 0 Nortel Networks Contact Center Multimedia Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Manager Nortel Networks Contact Center Express Nortel Networks Contact Center Administration CCMA 6.0 Nortel Networks Contact Center Administration 0 Nortel Networks Contact Center - TAPI Server 0 Nortel Networks Contact Center - TAPI Desktop 0 Nortel Networks Contact Center - Symposium Agent 0 Nortel Networks Contact Center - Quality Monitoring 0 Nortel Networks Contact Center - Contact Recording 0 Nortel Networks Contact Center - CCT 5 Nortel Networks Contact Center - CCT 0 Nortel Networks Contact Center - Agent Desktop Display 0 Nortel Networks Contact Center Nortel Networks CallPilot 703t Nortel Networks CallPilot 600r Nortel Networks CallPilot 202i Nortel Networks CallPilot 201i Nortel Networks CallPilot 1005r Microsoft DirectX 9.0b Microsoft DirectX 9.0 c Microsoft DirectX 9.0 a Microsoft DirectX 9.0 Microsoft DirectX 8.1 b Microsoft DirectX 8.1 a Microsoft DirectX 8.1 Microsoft DirectX 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft DirectX DirectShow Length Record Remote Code Execution Vulnerability
Microsoft DirectX is prone to a remote code-execution vulnerability that resides in the DirectShow component.
Successful exploits allow remote attackers to execute arbitrary code in the context of the user running the application that uses DirectX. Failed exploit attempts will result in a denial-of-service condition.
Microsoft DirectX is prone to a remote code-execution vulnerability that resides in the DirectShow component.
Successful exploits allow remote attackers to execute arbitrary code in the context of the user running the application that uses DirectX. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft DirectX DirectShow Length Record Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft DirectX DirectShow Length Record Remote Code Execution Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Microsoft DirectX 8.1
Microsoft DirectX 9.0
Microsoft DirectX 7.0
Solution:
The vendor has released an update. Please see the references for details.
Microsoft DirectX 8.1
-
Microsoft Security Update for DirectX 8 for Windows 2000 (KB971633)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ce297c3e-8122 -4276-a9c2-d1a404f8028d
Microsoft DirectX 9.0
-
Microsoft Security Update for DirectX 9 for Windows 2000 (KB971633)
http://www.microsoft.com/downloads/details.aspx?FamilyId=862db2ad-3c1f -4a26-af70-d8c4f5a69dda -
Microsoft Security Update for Windows Server 2003 (KB971633)
http://www.microsoft.com/downloads/details.aspx?FamilyId=571d57c5-1ef8 -4dc4-a1e5-2211a805f0cc -
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB971633)
http://www.microsoft.com/downloads/details.aspx?FamilyId=48282a89-f849 -405a-a31e-2676f45b5042 -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB971633)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1779cbc0-0c29 -4fac-a3a6-8b335ffcb98e -
Microsoft Security Update for Windows XP (KB971633)
http://www.microsoft.com/downloads/details.aspx?FamilyId=09d585cb-481d -4767-875e-9c6ebe456b80 -
Microsoft Security Update for Windows XP x64 Edition (KB971633)
http://www.microsoft.com/downloads/details.aspx?FamilyId=f8cd4803-82da -467c-8cb1-520f5a6021d4
Microsoft DirectX 7.0
-
Microsoft Security Update for Windows 2000 (KB971633)
http://www.microsoft.com/downloads/details.aspx?FamilyId=e3e54348-6548 -4162-b4c0-9910ec6e18b3
References
Microsoft DirectX DirectShow Length Record Remote Code Execution Vulnerability
References:
References:
- Microsoft DirectShow Quicktime Atom Parsing Memory Corruption Vulnerability (Zero Day Initiative )
- Microsoft DirectX Homepage (Microsoft)
- TippingPoint Security Advisory TPTI-09-05 (3com)
- TPTI-09-05: Microsoft DirectShow QuickTime Atom Parsing Memory Corruption Vulne (dvlabs
) - ZDI-09-045: Microsoft DirectShow Quicktime Atom Parsing Memory Corruption Vulne (ZDI Disclosures
) - Microsoft Security Bulletin MS09-028 (Microsoft)
- Nortel Response to Microsoft Security Bulletin MS09-028 (Nortel Networks)