Microsoft on Thursday said it is working on a security patch for a vulnerability in its DirectX streaming media technology in Windows that could allow someone to take complete control of a computer using a maliciously crafted QuickTime file.

  

Microsoft offers an easy way to enable a workaround for the latest security hole in DirectX.

(Credit: Microsoft)

The remote code execution vulnerability exists in the way Microsoft DirectShow, audio and video sourcing and rendering software, handles supported QuickTime format files, the company said.

“Microsoft is aware of limited, active attacks that use this exploit code,” Microsoft’s security advisory said. “If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”

Read the rest of this story