April 15, 2016 By Larry Loeb 2 min read

Trend Micro issued a warning for all Windows users of QuickTime urging them to uninstall the Apple software. Along with this warning, it described two zero-day vulnerabilities in the software that will go unpatched.

A third party announcing what Apple’s intentions are for a major hunk of the company’s software is highly unusual. As of this writing, there has been no official word from Apple concerning this. But a clue can be gleaned from the instructions for uninstalling QuickTime for Windows.

“Most recent media-related programs for Windows — including iTunes 10.5 or later — no longer use QuickTime to play modern media formats,” Apple wrote. “These programs either play the media directly or use the media support built into Windows.” It seems that Apple feels QuickTime is no longer needed, and as a result, it won’t continue to support or update the application.

Zero-Day Vulnerabilities in QuickTime for Windows

But there’s more: Trend Micro also announced newly discovered zero-day vulnerabilities in the media player. Zero-Day Initiative detailed the two issues, ZDI-16-241 and ZDI-16-242, affecting QuickTime for Windows, and Trend Micro claimed that its own products have been protecting against these exploits since November 2015.

So why go public now? “These advisories are being released in accordance with the Zero Day Initiative’s Disclosure Policy for when a vendor does not issue a security patch for a disclosed vulnerability,” the security firm stated on its blog. “And because Apple is no longer providing security updates for QuickTime on Windows, these vulnerabilities are never going to be patched.”

Trend Micro said it is “not aware of any active attacks against these vulnerabilities currently.” Still, it clarified that the only way to ensure security is to uninstall the program before cybercriminals find a way to exploit the permanent vulnerabilities.

QuickTime for Windows follows other software such as Microsoft Windows XP and Oracle Java 6, which are no longer being updated to fix vulnerabilities. That makes them subject to ever-increasing risk as more and more unpatched vulnerabilities are found and cybercriminals attempt to exploit them.

CERT Weighs In

The U.S. Computer Emergency Readiness Team (US-CERT) amplified the warning about the vulnerability in its own alert. The organization said the impact is potentially damaging to users and their organizations.

“Computer systems running unsupported software are exposed to elevated cybersecurity dangers, such as increased risks of malicious attacks or electronic data loss,” US-CERT said. “Exploitation of QuickTime for Windows vulnerabilities could allow remote attackers to take control of affected systems.”

The only thing that users can responsibly do is uninstall QuickTime for Windows — immediately.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today