Microsoft: DRM Trojan hole is not a vulnerability

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Microsoft has denied that an anti-piracy "feature" in its Windows Media Player that allows a Trojan horse to run on a user's PC is a vulnerability.

Panda Software warned earlier this week that hackers are using the player's DRM tool to fool people into downloading spyware and viruses.

The Spanish security company said that virus writers had released licence-protected multimedia files containing Trojan horses (WmvDownloader.A and WmvDownloader.B) that can exploit the anti-piracy features in version 10 of the Media Player and Windows XP SP2.

Despite Panda's warning that the Trojan can download a cocktail of malware, Microsoft denies there is a flaw in its software.

"This Trojan appears to utilise a function of the Windows Media DRM designed to enable licence delivery scenarios as part of a social engineering attack," said Microsoft in an emailed statement.

"There is no way to automatically force the user to run the malicious software. This function is not a security vulnerability in Windows Media Player or DRM."

But Microsoft didn't say whether Windows XP SP2 fully protected users from unwanted downloads.

"Internet Explorer for Windows XP SP2 helps prevent downloads from automatically launching. Users who have installed Windows XP SP2 and turned on the pop-up blocker have an added layer of defence from this Trojan's attempt to deliver malicious software," said Microsoft.

The Redmond giant also said that people should go to the police if they think they have been attacked by such Trojans.

Microsoft also added that "customers in the United States who believe they have been attacked should contact their local FBI office or post their complaint on www.ifccfbi.gov. Customers outside the US should contact the national law enforcement agency in their country."

Talkback

Seems like they're burying their heads in the sand yet again. Whenever a flaw is found then Microsoft either wait ages before admitting it or deny it. How often do regular users need to access licences for music, when I used WMP I did it nearly everyday.

via Facebook 14 January, 2005 13:22
Reply

I don't think that law enforcement agencies (payed for with tax money) would welcome the day that everyone suspecting to be the victim of a trojan (or virus) attack comes to them and claim their time and resources (usually in short demand and needed for more urgent matters).

As such those law enforcement agencies should consider placing (some) responsibility on the vendors involved. And by doing so motivating such vendors to maximize their efforts in order to minimize demands on the resources of law enforcement agencies.

via Facebook 15 January, 2005 21:32
Reply

Microsoft probably has no incentive to fix this. As I understand it, the one and only security fix is called "upgrading to XP-SP2", and all earlier versions of I.E. are now official (as opposed to unofficial) security risks. This sounds like a perfect excuse for MS to ask everyone to migrate to XP - or else.

via Facebook 16 January, 2005 19:58
Reply

Time to Migrate!

Well, if you're running any version of windows <XP, I guess it's time to migrate.

Might as well look at the Mac and Linux if you're gonna have to migrate.

via Facebook 19 January, 2005 18:07
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Lonnie

those conformation letters are hard to figure out what is which letters it is a pain in the back side. Please make it more Ledge-able being better...

3 hours ago by Lonnie on Screenshots: Photoshop CS6 Beta
BrownieBoy

"cites" even. Ouch!

10 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
Horace Ontalhold

...... and PDP11s too

10 hours ago by Horace Ontalhold on Fusion-io lays minefield with a billion IOPS
BrownieBoy

I had a quick skim through the PDF. It seems to be that many of these so-called cost savings would be down to a hardware refresh. Although...

11 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
bobandroid

496,999 BT Fon Hotspots lovingly situated in your next door neighbours garden, no matter how you dress that up its still a pup... Not where I need...

13 hours ago by bobandroid on London Olympics: BT needs 25,000 more Wi-Fi hotspots
apexwm

Jack : I was hoping you could provide us a summary since you are familiar with this report. I am not yet sure how much of my time I'd like to...

15 hours ago by apexwm on Using Windows XP is a waste of money, says IDC
Smilig Eddie

2 – 4 more weeks of waiting: how many buyers are going to decide instead to see what the iPhone 5 offers? Consumer trust in the brand has also...

15 hours ago by Smilig Eddie on Samsung Galaxy 'S3' delayed by special paint
SRist

So it looks like this was a complete red herring - Adobe are allowing upgrades from Photoshop CS3, CS4 and CS5 at the same price. When did this...

16 hours ago by SRist on Photoshop users attack Adobe upgrade policy change
Jack Schofield

@apexwm Have you considered either (a) reading the story above or (b) reading the PDF? There are answers in both.

18 hours ago by Jack Schofield on Using Windows XP is a waste of money, says IDC
apexwm

I would love to hear why Microsoft believes that "upgrading from Windows XP to Windows 7 pays for itself in a year, in increased productivity and...

18 hours ago by apexwm on Using Windows XP is a waste of money, says IDC
debsmk

I have just changed mine to white they said 3 to 5 days

19 hours ago by debsmk on Samsung Galaxy 'S3' delayed by special paint
Atangana

I would like a job for me and do good to their tackiness vellent my help I will do my best to help you mercie for all

20 hours ago by Atangana on UK's 15-year-old World Excel champion offered £100k job
BrownieBoy

Well done to IDC for producing a report that says using XP is a waste of money. Only 11 years too late with it is all....

21 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
Jack Schofield

@Burn-IT ...which doesn't mean it isn't true ;-) I'll be interested if you can find any properly-researched, independent data from any of the...

22 hours ago by Jack Schofield on Using Windows XP is a waste of money, says IDC
Burn-IT

As said, sponsored by Microsoft........

23 hours ago by Burn-IT on Using Windows XP is a waste of money, says IDC
mrbigdong

@620W, I mine 1 BTC/daily for cost of 1.7eur, they naysayers regurgitate the rubbish they read as usual

23 hours ago by mrbigdong on A minor Bitcoin miner injury?
Mike Denton

If the link to the next section existed that would be awesome.... Guess I have to ask uncle google where it is

1 day ago by Mike Denton via Facebook on Security on the farm: Accounts and permissions
minzhu

Don't blame CEO, they want RIM win. RIM has strange culture and self distruct political environment. In RIM if a new hired person figure out...

1 day ago by minzhu on RIM CEO: Time to squash BlackBerry myths
Thomas Gellhaus

I've been very pleased with Mageia 2. My review went up on Sunday. My only issue is that my particular wireless printer hasn't been detected on...

1 day ago by Thomas Gellhaus via Facebook on Scorecard - Linux Mint 13 and Mageia 2
knapper

That we have :-) Retailers don't buy stuff to lie around in warehouses, particularly with fast moving technology products. If they didn't think...

2 days ago by knapper on Windows Phone, Android take bite out of BlackBerry