Two Critical Vulnerabilities Affecting QuickTime for Windows Detected

by April 18, 2016 0 comments
Image Courtesy of Stuart Miles at freedigitalphotos.net

NEW DELHI, INDIA: Apple is pulling support for QuickTime for Windows on the heels of Trend Micro’s Zero Day Initiative’s discovery of two new, critical vulnerabilities affecting the software.

These are remote code execution vulnerabilities that could allow an attacker to gain control of the victim’s system. In an enterprise setting, this could mean opening the door for hackers to access larger, company-wide networks.

Apple is deprecating QuickTime for Microsoft Windows. They will no longer be issuing security updates for the product on the Windows Platform and recommend users uninstall it BUT this does not apply to QuickTime on Mac OSX.

Trend Micro’s Zero Day Initiative has just released two advisories ZDI-16-241 and ZDI-16-242 detailing two new, critical vulnerabilities affecting QuickTime for Windows. These advisories are being released in accordance with the Zero Day Initiative’s Disclosure Policy for when a vendor does not issue a security patch for a disclosed vulnerability. And because Apple is no longer providing security updates for QuickTime on Windows, these vulnerabilities are never going to be patched.

The only way to protect your Windows systems from potential attacks against these or other vulnerabilities in Apple QuickTime now is to uninstall it. In this regard, QuickTime for Windows now joins Microsoft Windows XP and Oracle Java 6 as software that is no longer being updated to fix vulnerabilities and subject to ever increasing risk as more and more unpatched vulnerabilities are found affecting it.

However, even with protections, ultimately the right answer is to follow Apple’s guidance and uninstall QuickTime for Windows. That is the only sure way to be protected against all current and future vulnerabilities in the product now that Apple is no longer providing security updates for it.

 

No Comments so far

Jump into a conversation

No Comments Yet!

You can be the one to start a conversation.

Your data will be safe!Your e-mail address will not be published. Also other data will not be shared with third person.