Windows

    Security Fix for DirectX Media 6.0 on Windows NT 4.0 (KB819696)

    Select Language:
    This security patch fixes a MIDI file security issue in DirectX Media 6.0 on Windows NT 4.0. Internet Explorer 6 SP1 or Windows Media Player 6.4 install DirectX Media 6.0.
    • Version:

      -

      File Name:

      Q819696i.EXE

      Date Published:

      7/23/2003

      File Size:

      512 KB

      KB Articles: KB819696

        DirectX consists of a set of low-level Application Programming Interfaces (APIs) used by Windows programs for multimedia support. Within DirectX Media, the DirectShow technology performs client-side audio and video sourcing, manipulation and rendering.

        There are two buffer overruns with identical effects in the function used by DirectShow to check parameters in a Musical Instrument Digital Interface (MIDI) file. A security vulnerability results because it would be possible for a malicious user to attempt to exploit these flaws and execute code in the security context of the logged on user.

        An attacker could seek to exploit this vulnerability by creating a specially crafted MIDI file designed to exploit this vulnerability and then host it on a Web site or on a network share, or send it via an HTML email. In the case where the file was hosted on a web site or network share, the user would need to open the specially crafted file. If the file was embedded in a page, the vulnerability could be exploited when a user visited the Web page. In the HTML E-mail case, the vulnerability could be exploited when a user opened or previewed the HTML e-mail. A successful attack could have the effect of either causing DirectShow, or an application making use of DirectShow, to fail, or causing an attacker's code to run on the user's computer in the security context of the user.
    • Supported Operating System

      Windows NT

        • Windows NT 4.0 with Internet Explorer 6 Service Pack1 or Windows Media Player 6.4.
        1. Click the Download link to start the download, or choose a different language from the drop-down list and click Go.
        2. Do one of the following:
          • To start the installation immediately, click Open or Run this program from its current location.
          • To copy the download to your computer for installation at a later time, click Save or Save this program to disk.

    Popular downloads

      • 01

        DirectX End-User Runtime Web Installer

        The Microsoft DirectX® End-User Runtime provides updates to 9.0c and previous versions of DirectX — the core Windows® technology that drives high-speed multimedia and games on the PC.

      • 02

        Malicious Software Removal Tool

        This tool checks your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps to remove the infection if it is found. Microsoft will release an updated version of this tool on the second Tuesday of each month.

      • 03

        Microsoft Security Essentials

        Microsoft Security Essentials provides real-time protection for your home or small business PC that guards against viruses, spyware, and other malicious software.

      • 04

        Windows 7 Upgrade Advisor

        Download and run the Windows 7 Upgrade Advisor to see if your PC is ready for Windows 7. It scans your hardware, devices, and installed programs for known compatibility issues, gives you guidance on how to resolve potential issues found, and recommends what to do before you upgrade.

    Loading your results, please wait...

    Free PC updates

    • Security patches
    • Software updates
    • Service packs
    • Hardware drivers

    Microsoft Suggests

       Shop for a new Windows PC.
    Shop for a new Windows PC
    Browse our collection of laptops, tablets, and convertibles perfect for the new Windows.
    Shop now