IDNetters Forums

Technical News & Discussion => Windows News & Discussion => Topic started by: Gary on May 29, 2009, 08:11:55

Title: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Gary on May 29, 2009, 08:11:55
Quote "Microsoft has warned of a critical security bug in older versions of its Windows operating system that is already being exploited in the wild to remotely execute malware on vulnerable machines.The vulnerability in a Windows component known as DirectX is being targeted using booby-trapped QuickTime files, which when parsed can allow attackers to gain complete control of a computer. Because many browsers are designed to automatically play video, people can be compromised simply by visiting a site serving malicious files" Users of 2000, XP and Server 2003 versions of Windows are at risk of losing complete control of their machines. a fix for now is available here http://support.microsoft.com/kb/971778 using IE NOT Firefox. Full vulnerability details http://www.microsoft.com/technet/security/advisory/971778.mspx
Quote from of El Reg, full story here http://www.theregister.co.uk/2009/05/28/critical_microsoft_directx_vulnerability/
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 08:16:39
Thanks for that, Gary. :karmic: Sadly, it's returning 'file not found' atm. :(
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Gary on May 29, 2009, 08:18:20
Quote from: Rik on May 29, 2009, 08:16:39
Thanks for that, Gary. :karmic:
It seemed something very important for users of the forum as many still have XP, Rik.  :thnks: try using the El Reg story and following the link there, only works in IE it appears
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 08:19:35
Ah!, ;)
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Gary on May 29, 2009, 08:20:14
Quote from: Rik on May 29, 2009, 08:19:35
Ah!, ;)
You can get to it using FF but need IE for it to work  ::) Typical Ms it seems I have amended my first post to point that out  :thumb:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 08:20:57
Indeed. Turf wars and security shouldn't be mixed.
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 08:22:32
OK, from IE, I don't get the same error, instead it says it can't download the file. :sigh:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Gary on May 29, 2009, 08:23:26
Quote from: Rik on May 29, 2009, 08:20:57
Indeed. Turf wars and security shouldn't be mixed.
Agreed, especially such a dangerous one, it should be a universal browser patch.
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Gary on May 29, 2009, 08:24:36
Quote from: Rik on May 29, 2009, 08:22:32
OK, from IE, I don't get the same error, instead it says it can't download the file. :sigh:
Odd  :dunno: as I am using Vista it won't work for me, using FF I get to the fix me button but thats it. May be worth googling it Rik, or it may be pushed out as an out of cycle patch I guess It shows how to do it here via regedit though http://support.microsoft.com/kb/971778#FixedAlways
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 08:29:30
I was going for the RegEdit approach, Gary. :)
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Gary on May 29, 2009, 08:31:43
Quote from: Rik on May 29, 2009, 08:29:30
I was going for the RegEdit approach, Gary. :)
Best way, but not easy for non Tech types, great that Microsoft's fix it button does not work, rather Ironic really  :sigh:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 08:33:47
Certainly not iconic. ;D
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Ray on May 29, 2009, 08:40:41
Thanks, Gary, I've done it on my main machine and my server using the regedit approach now.  :thumb:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 08:41:17
Could you get the fix file, Ray?
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: JB on May 29, 2009, 08:42:19

I wonder if this also affects Quick Time Alternative ?

http://www.free-codecs.com/download/quicktime_alternative.htm
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Ray on May 29, 2009, 08:46:23
Quote from: Rik on May 29, 2009, 08:41:17
Could you get the fix file, Ray?

No, Rik, I couldn't, using IE the download window opened and just sat there without downloading anything.
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 09:19:03
Curious, with me it threw up an error dialogue that the file wasn't available.  :shake:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Gary on May 29, 2009, 09:22:42
Quote from: 6jb on May 29, 2009, 08:42:19
I wonder if this also affects Quick Time Alternative ?

http://www.free-codecs.com/download/quicktime_alternative.htm

It says "Vista, Windows Server 2008 and the beta version of Windows 7 are not affected, and neither is Apple's QuickTime player" so quick time alternative should be fine
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Gary on May 29, 2009, 09:24:19
Quote from: Rik on May 29, 2009, 08:33:47
Certainly not iconic. ;D
:lol:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: kinmel on May 29, 2009, 09:53:42
Microsoft Fix button works fine with Firefox in IE mode
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 09:55:14
Odd, I'm still getting the file not found error, Alan, even in IE.  :dunno:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: kinmel on May 29, 2009, 10:17:42
Quote from: Rik on May 29, 2009, 09:55:14
Odd, I'm still getting the file not found error, Alan, even in IE.  :dunno:

So am I now, sometimes it works and sometimes it doesn't,  perhaps the server is overloaded
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 10:24:21
More than likely. I've done it manually, it's such a quick fix.
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Sebby on May 29, 2009, 13:54:13
Thanks, Gary. Where do I download the Mac version?
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 14:35:44
:lol: :nana:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: quandam on May 29, 2009, 15:12:09
Gary & Rik

Thanks for the info. I am in your hands entirely here. I followed the link and clicked on 'Fix It' ( I'm on FF) and it all went through without a hitch, was I lucky or have I missed something? Hopefully not :fingers:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 15:13:44
I think you were lucky, Q, it seems to have been a bit hit and miss with the server, but if you got no error, you should be fine. :)
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: quandam on May 29, 2009, 15:16:46
Rik

I chose the 'work around' option, is that the correct choice?
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 15:19:26
Enable workaround/Fix it? It is. :)
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: quandam on May 29, 2009, 15:24:28
Much obliged :thumb:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 29, 2009, 15:27:24
NP. :)
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Gary on May 30, 2009, 07:23:14
Quote from: Sebby on May 29, 2009, 13:54:13
Thanks, Gary. Where do I download the Mac version?
I dont know, but I don't need the fix Sebby  :tongue: :nana: Think I'll slide a blu-ray film in my Laptops drive and have some light entertainment this morning  ;)
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Ray on May 30, 2009, 09:06:04
I've got this update trying to install under Windows update this morning only snag is the download size is 0kb and it just keeps popping up as an update is ready to install. I click on install and it says it's installed successfully, then comes up as available again.  :rant2:
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Ray on May 30, 2009, 09:14:56
Looks like the problem is with Windows update looking at my update history this update has been successfully installed and yet it is still been offered as available.  ???
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 30, 2009, 09:16:58
It's probably because it's outside the normal schedule, Ray.
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Ray on May 30, 2009, 09:35:17
Quote from: Rik on May 30, 2009, 09:16:58
It's probably because it's outside the normal schedule, Ray.

Could be, Rik, the only way I could get rid of the notification was by checking the 'don't notify me about this update again' box.
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Rik on May 30, 2009, 09:37:54
I usually use the "I'm not listening" box, Ray. ;D
Title: Re: Critical Windows vulnerability for users of 2000, XP and Server 2003
Post by: Gary on May 30, 2009, 14:28:33
Quote from: Sheltieuk on May 30, 2009, 09:35:17
Could be, Rik, the only way I could get rid of the notification was by checking the 'don't notify me about this update again' box.
you could undo the reg fix and download the update  ;)