DirectShow, ActiveX 0-days among planned Microsoft fixes

Microsoft is planning six patches next week, including fixes for two zero-day issues, one that was disclosed just this week.

The July Patch Tuesday release contains three updates addressing "critical" security vulnerabilities in Windows, according to an advance notification issued Thursday. Two of the bulletins address previously revealed issues that are being exploited in limited attacks: One is a vulnerability in DirectShow, the other is a bug in the Microsoft Video ActiveX control.

Many security experts predicted that websites hosting the exploit for the ActiveX flaw, which was revealed Monday, would only continue to grow, meaning Microsoft had to act quickly.

"Our engineering team has been working around the clock to produce an update for the issue...and we believe that they will be able to release an update of appropriate quality for broad distribution that protects against the attacks," wrote Jerry Bryant, a Microsoft security program manager, on the company's Security Response Center blog. "As you know, this information may change between now and next Tuesday."

The vulnerability impacts Windows XP and Server 2003 users and is particularly dangerous because users can be infected simply by visiting a website.

"It requires no user intervention at all," Dmitriy Ayrapetov, product line manager at internet security firm SonicWALL, told SCMagazineUS.com this week. "Anywhere you can click on a web page in Internet Explorer, that's where they're vulnerable."

He said he wouldn't be surprised if hijacked social networking sites, such as Facebook and Twitter, soon are used to spread the malware.

So far, most of the compromised websites being used to serve up the attack -- experts estimate the number is somewhere in the thousands -- are based in China, researchers said.

Right now, the goal of the malware writers largely is to install World of Warcraft password-stealing trojans on victim machines, Roger Thompson, chief research officer at ant-virus firm AVG, told SCMagazineUS.com this week. However, the payload could become more malicious, and he expects many more sites in the United States to be hacked and seeded with the exploit to launch drive-by downloads.

Until the fix is released, users should apply an available workaround, which is to set the kill bit for the affected ActiveX control.

In addition to the three "critical" patches, Microsoft on Tuesday plans to push out three "important" fixes, affecting Publisher, Internet Security and Acceleration Server and Virtual PC and Virtual Server, according to the notification.

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.