Launch Printer Friendly Page Security TechCenter > Security Bulletins > Microsoft Security Bulletin MS03-030

Microsoft Security Bulletin MS03-030

Unchecked Buffer in DirectX Could Enable System Compromise (819696)

Originally posted: July 23, 2003
Updated: June 16, 2004

Summary

Who should read this bulletin:
Customers using Microsoft® Windows®

Impact of vulnerability:
Allow an attacker to execute code on a user's system

Maximum Severity Rating:
Critical

Recommendation:
Customers should apply the security patch immediately

Affected Software:

  • Microsoft DirectX® 5.2 on Windows 98
  • Microsoft DirectX 6.1 on Windows 98 SE
  • Microsoft DirectX 7.1 on Windows Millennium Edition
  • Microsoft DirectX 7.0 on Windows 2000
  • Microsoft DirectX 8.0, 8.0a, 8.1, 8.1a, and 8.1b when installed on Windows 98, Windows 98 SE, Windows Millennium Edition or Windows 2000
  • Microsoft DirectX 8.1 on Windows XP or Windows Server 2003
  • Microsoft DirectX 9.0a when installed on Windows 98, Windows 98 SE, Windows Millennium Edition (Windows Me), Windows 2000, Windows XP, or Windows Server 2003
  • Microsoft Windows NT 4.0 with either Windows Media Player 6.4 or Internet Explorer 6 Service Pack 1 installed
  • Microsoft Windows NT 4.0, Terminal Server Edition with either Windows Media Player 6.4 or Internet Explorer 6 Service Pack 1 installed

An End User version of the bulletin is available at:
http://www.microsoft.com/athome/security/update/bulletins/default.mspx.

General Information

Technical details

Frequently asked questions

Patch availability

Other information:

Acknowledgments

Microsoft thanks  eEye Digital Security for reporting this issue to us and working with us to help protect customers

Support:

  • Microsoft Knowledge Base article 819696 discusses this issue and will be available approximately 24 hours after the release of this bulletin. Knowledge Base articles can be found on the Microsoft Online Support Web site.
  • Technical support is available from Microsoft Product Support Services. There is no charge for support calls associated with security patches.

Security Resources: The Microsoft TechNet Security Web Site provides additional information about security in Microsoft products.

Disclaimer:

The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions:

  • V1.0 (July 23, 2003): Bulletin Created.
  • V1.1 (July 23, 2003): Fixed Download Link for Windows NT 4.
  • V1.2 (July 23, 2003): Updated Download Links in Patch Availability section.
  • V2.0 (August 20, 2003): Updated to include details of an additional patch for versions of DirectX.
  • V2.1 (August 20, 2003): Added clarification regarding additional patch in Technical description section.
  • V2.2 (June 16, 2004): Added clarification regarding file versions in Windows 2000 Service Pack 4 in the Patch Availability section.