The Mac Observer

Windows QuickTime Zero-day Flaw Discovered

TMO Talk (0)

A new security flaw in QuickTime 7.3.1 for Windows surfaced on Thursday that apparently lets an attacker take control of remote PCs. The vulnerability was discovered by Italian security researcher Luigi Auriemma who posted proof-of-concept code for the exploit on the Internet, according to InformationWeek.

The alleged flaw takes advantage of a buffer overflow bug that lets an attacker send malicious code when QuickTime attempts to access a Real-Time Streaming Protocol link and port 554 on the server is closed.

Symantec Security Response claimed that the flaw appears to be legit. The companyis vice president of development, Alfred Huger, commented "The proof of concept code only managed to crash the product. But itis a safe assumption that if you can do that you may be able to execute remote code."

So far the flaw appears to impact only the Windows version of QuickTime, and to date there are no known instances of an actual attack based on the vulnerability. The likelihood that Windows users could see an actual attack based on Mr. Auriemmais sample code, however, is higher since he chose to publish his proof-of-concept before contacting Apple.

Post A Comment or Log-in. Need an account? Register here.
 

Recent Headlines - Updated February 13th

Mon, 6:26 PM
News - Apple Tops Harris Reputation Poll with Record Score
5:33 PM
Mac Geek Gab Podcast - MGG 381: Mac Internet Recovery, HTML on iPad, iDevice Syncing, More!
5:04 PM
Apple Stock Watch - Apple’s Stock Sets New Closing High of $502.60
1:50 PM
News - A Great 3-Minute Video Look at Macworld|iWorld 2012
12:41 PM
Deal Brothers - Mac mini 2.5GHz dual-core Intel Core i5:  $699
11:51 AM
Rumor - Pegatron Forced to Drop Zenbook Due to MacBook Air Similarities
11:00 AM
Apple Stock Watch - Apple’s Stock Breaks $500 Mark For First Time
10:20 AM
News - Apple Announces Foxconn Inspections
9:34 AM
iObserver - AT&T Begins Process Toward Offering Shared Data
9:15 AM
News - Apple Files Motion to Stop Galaxy Nexus Sales in U.S.
8:20 AM
News - Steve Jobs Given Trustees Award at the Grammys
Sat, 4:11 PM
MacOS KenDensed - MacOS KenDensed: iPad 3 Frenzy, Big-time Apple & Steve Jobs, G-Man
 

The Mac Observer Reader Specials

  • TypeStyler 11 is now in the Mac App Store!! -- Special Introductory Price of $59.95!! -- To Buy From The Mac App Store Click Here Now!! Or buy direct from Strider Software.
  • Mac RAM Upgrades: MacBook Pro 16GB kits $475, 8GB Kits for $119.99! iMac 16GB RAM Kits (4x 4GB) for $229.99! Mac Pro Memory 32GB Kit for $399.99, 64GB Kit for $889.99! Mac Hard Drives 2TB Seagate SATA II for $249.99! Click Here!
  • Poker Mac If you're using a Mac, then you've gotta check out Online Poker Mac. This mac poker and online casino mac site actually does the unthinkable, it actually rewards!

Apple Stock Quote (AAPL)

Loading...

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal