Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

March 9th, 2011, 13:06 GMT · By

Patch First Windows 7 SP1 RTM Vulnerability - DVR-MS Flaw

SHARE:

Adjust text size:


Windows 7
Enlarge picture
Customers already running the recently released Windows 7 Service Pack 1 (SP1) RTM will need to patch their copy of the operating system applying one of the security updates that Microsoft released this week.

The patch is included in Microsoft Security Bulletin MS11-015 which is designed to resolve two vulnerabilities, one in DirectShow and one in Windows Media Player and Windows Media Center.

It’s the DVR-MS Vulnerability - CVE-2011-0042 that is considered to be most severe, rated Critical by Microsoft, and also impacting Windows 7 SP1 RTM.

“A remote code execution vulnerability exists in the way that Windows Media Player and Windows Media Center handle .dvr-ms files. This vulnerability could allow an attacker to execute arbitrary code if the attacker convinces a user to open a specially crafted .dvr-ms file,” Microsoft warned.

“An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”

However, in order for an exploit to be successful, an attacker needs to first convince users to launch a malformed video Microsoft Digital Video Recording with one of the components of Windows that are impacted by the DVR-MS vulnerability.

Without victims launching a malicious file in either Windows Media Player or Windows Media Center, an attack cannot be successful.

I have included download links for the MS11-015 patch package for Windows 7 SP1 RTM at the bottom of this article.

However, users must be warned of the fact that additional copies of Windows are also affected by the Critical DVR-MS vulnerability, and that they need patching as well.

The security updates have already been released through Windows Update, but they can also be downloaded and installed manually via this link.

Also, early adopters still running Windows 7 SP1 Release Candidate (RC) should know that their copy of the platforms are also impacted by MS11-015 and that they also need to apply the patch.

Security Update for Windows 7 (KB2479943)

Security Update for Windows 7 for x64-based Systems (KB2479943)

Windows 7 Service Pack 1 (SP1) RTM Build 7601.17514.101119-1850 and Windows Server 2008 R2 Service Pack 1 (SP1) RTM are available for download here.

TELL US WHAT YOU THINK:

4,791 hits · 4 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


New Features for Windows Embedded Standard 2009

New Windows 7 SP1 RTM Wave Distributed via WSUS

Windows 7 SP1 RTM Blue Screens of Death Due to Language Packs

First Patch for Windows 7 SP1 RTM Will Fix Critical Vulnerability

Download Free Windows Virtual PC for Windows 7 SP1 Now with Updated Installer

READER COMMENTS:


Comment #1 by: saneman on 09 Mar 2011, 13:30 UTC reply to this comment

If the attacker convinces a user to open a specially crafted .dvr-ms file? What kind of idiot just opens these files up for remote users they don't know?

Comment #1.1 by: chancellor on 09 Mar 2011, 20:01 GMT

Specially crafted... more like sneakily crafted... you know "click here for details on getting a free Ipad 2 or Iphone 4". Many ways to craft things so as to entice (compel) someone to click on it ( and unbeknown, launch malicious code).


Comment #2 by: chancellor on 09 Mar 2011, 20:07 UTC reply to this comment

When my Win7 with SP1 installed took the MS update (KB2479943) it (the update) completely re-arranged my desktop icons AND put what appears to be registry key related alpha numerics beside my master utility icon. Has anyone else experienced something similar after taking the update?

Chance


Comment #3 by: Xsile on 09 Mar 2011, 21:29 UTC reply to this comment

This sp also targets any modification to WAT (windows activation technology) So beware all your pirates! Arrg Mate!

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM