Saturday, June 6, 2009

Temporarily handling DirectShow 0Day Exploit

For those IE fans, Microsoft still not release their patch to fix the DirectShow 0Day vulnerability yet and you will lucky if they release the patch this month or next month. For temporarily to fix the problem, Microsoft release article in their website how to fix the Quicktime inside the registry. At here, It will be good practice if the you can consider following step by during some configuration inside the Security setting.

1. Open IE --> Tools --> Internet Options
2. Click Security tab, highlight Internet --> Click Custom Level
3. Disable "Run components not signed with Authenticode" and "Run components signed with Authenticode"

This kind of setting not fix the DirectShow vulnerability problem, at least it can prevent any successful attempt to manipulate the vulnerability.

0 comments: