Quantcast
0
0

Researcher Finds New Flaw in QuickTime for Windows

Jeremy Kirk, IDG News Service

Monday, April 28, 2008 5:00 AM PDT

A security think tank says it has found a vulnerability in Apple's QuickTime multimedia player that can be exploited remotely to compromise Windows Vista PCs upgraded to Service Pack 1, as well as XP SP2.

From the scant details published on the GNUCitizen's blog, the exploit involves a maliciously crafted media file. When a user opens the file, which can be hosted on a Web site, the vulnerability in QuickTime allows the hacker to take complete control of the machine, according to Petko D. Petkov, known to the hacking community as "pdp."

Petkov doesn't think users are in danger of being attacked as of yet.

"I highly doubt that anyone knows how to exploit this vulnerability," Petkov said. "I haven't shared the details with anyone, and the actual vulnerability is different enough to be rather challenging for even some of the most gifted hackers out there."

In a video with a thumping techno beat, Petkov shows a QuickTime file sitting on the desktop of a PC running XP SP2. If a user opens the malicious file, Petkov then has control of the PC, demonstrated by the way the applications Paint, Calculator and Notepad are seen launching, apparently without further user intervention. The demonstration is repeated on a PC running Windows Vista inside a virtual machine.

Attacking vulnerabilities in applications is becoming increasingly favored by hackers, as finding problems in operating systems becomes increasingly harder, said Alan Paller, director of research for the SANS Institute, last week at the Infosec conference in London.

Petkov said Monday that he has notified Apple of the problem.

The company did not respond to a request for comment.

QuickTime has proved to be one of the more porous applications. Apple, which doesn't have a regular patching schedule like Microsoft, patched the application for at least the sixth time earlier this month, fixing 11 vulnerabilities.

Advertisement: Learn about storing and securing your data before disaster strikes. 

Community Comments
Recommend this story?

PC World's Marketplace

PC World's Free Whitepapers

Security News
More

Latest Expert Blogs

All Blogs
Featured Resources

Premier Content From Our Sponsors

Featured Whitepapers

White papers, case studies and product info from top brands

  • The 5 Reasons to Worry about Your DNS DNS servers are one of the most critical, yet vulnerable, network infrastructure applications. Because of their exposure to the Internet, they are among the most vulnerable computers that an organization deploys. This whitepaper explains the top fi...
Featured Webcasts

Watch webcast presentations and videos from industry thought leaders on today's most important business and technology topics. For free.