Microsoft Fixes 9 Flaws in Monthly Patch Release
Microsoft released six security bulletins for Patch Tuesday on July 14, including fixes for vulnerabilities affecting DirectShow and the Video ActiveX Control that have been targeted by attackers.
The bulletins address a total of nine vulnerabilities. Three of the bulletins—the ones affecting DirectShow and the Video ActiveX Control and a third addressing issues in the Embedded OpenType Font Engine—are rated critical and deal with flaws with the highest possible rating on Microsoft's exploitability index, meaning consistent exploit code is likely.
There are three vulnerabilities in DirectShow addressed this month, with the one under attack residing in the QuickTime Movie Parser Filter. An attacker could exploit the vulnerability by tricking a user into opening a specially crafted QuickTime file or receiving specially crafted streaming content from a Website or application. The other two bugs are pointer and size validation vulnerabilities.