You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
ms09-028
About this tag
MS09-028 is a Microsoft security bulletin addressing a vulnerability in Microsoft DirectShow that could allow remote code execution. The vulnerability, known as the DirectX NULL Byte Overwrite Vulnerability (CVE-2009-1537), was publicly reported and investigated by Microsoft. The security update resolves the issue by correcting the way DirectShow handles specially crafted QuickTime media files. Users are advised to apply the update from MS09-028 to protect their systems. This bulletin is part of Microsoft's ongoing efforts to address security flaws in Windows components and is relevant for users running affected versions of Windows.
Revision Note: V2.0 (July 14, 2009): Advisory updated to reflect publication of security bulletin.
Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-028 to address this issue. For more information about this issue...