[an error occurred while processing this directive]
BBC News
watch One-Minute World News
Last Updated: Thursday, 24 July, 2003, 10:48 GMT 11:48 UK
'Critical' flaw found in Windows
Windows software
Various versions of Windows are affected
Microsoft has issued a warning about a critical security flaw that affects most versions of its Windows software.

The flaw involves DirectX, an extensive collection of programming add-ons for Windows used by computer games.

If exploited, the flaw could allow a malicious hacker to run their own specially crafted computer code to plant a virus or even take over a machine.

Microsoft has given the flaw its highest severity rating.

Music mayhem

The flaw affects a large number of the versions of Microsoft Windows in use.

Embarrassingly for Microsoft one of the products affected is Windows Server 2003.

This was supposed to be much more secure as it was one of the first products to go through Microsoft's improved systems for weeding out bugs and security problems.

On Windows Server 2003 the bug is only rated as "important" by Microsoft because the default settings would not allow such a program to be run.

VULNERABLE SOFTWARE
DirectX 5.2 on Windows 98
DirectX 6.1 on Windows 98 SE
DirectX 7.0a on Windows Me
DirectX 7.0 on Windows 2000
DirectX 8.1 on Windows XP
DirectX 8.1 on Windows Server 2003
DirectX 9.0a on Windows 2000
DirectX 9.0a on Windows XP
DirectX 9.0a on Windows Server 2003
DirectX 9.0a on Windows Me
NT 4.0 using Media Player 6.4 or Internet Explorer 6 Service Pack 1
NT 4.0 Terminal Server Edition using either Media Player 6.4 or Internet Explorer 6 Service Pack 1
The vulnerability comes about because of the way that a part of DirectX, called DirectShow, handles MIDI or music files.

MIDI, or Musical Instrument Digital Interface, defines a standardised way of swapping music information between computers, music keyboards and synthesisers.

The flaw, found by eEye Security, would allow a specially crafted MIDI instruction to swamp the cache, or buffer, in DirectX and allow a hidden program within it to run on the target machine.

Such buffer overflow bugs are quite a common way for malicious programs to infect a machine.

Microsoft has issued an alert about the flaw and a patch to close the loophole. It said that currently there were no known exploits of the bug.

The instruction could get into a computer by being put on a webpage.

It can also be put into an e-mail message that uses web formatting.

The DirectX flaw is the latest in a series of security problems that Microsoft has warned about over the last few weeks.




SEE ALSO:
Flaw exposes Microsoft ID service
09 May 03  |  Technology
Warning of serious Windows hole
21 Nov 02  |  Technology
New flaw puts Passport offline
05 Nov 01  |  Business
How far do you trust Microsoft?
13 Jun 03  |  Technology
Virus makes unwelcome return
05 Jun 03  |  Technology
E-mail virus uses Bill Gates
02 Jun 03  |  Technology
E-mail virus picks up speed
02 Jan 03  |  Technology


RELATED INTERNET LINKS:
The BBC is not responsible for the content of external internet sites


PRODUCTS AND SERVICES

News Front Page | Africa | Americas | Asia-Pacific | Europe | Middle East | South Asia
UK | Business | Entertainment | Science/Nature | Technology | Health
Have Your Say | In Pictures | Week at a Glance | Country Profiles | In Depth | Programmes
Americas Africa Europe Middle East South Asia Asia Pacific