April 15, 2016 By Larry Loeb 2 min read

Trend Micro issued a warning for all Windows users of QuickTime urging them to uninstall the Apple software. Along with this warning, it described two zero-day vulnerabilities in the software that will go unpatched.

A third party announcing what Apple’s intentions are for a major hunk of the company’s software is highly unusual. As of this writing, there has been no official word from Apple concerning this. But a clue can be gleaned from the instructions for uninstalling QuickTime for Windows.

“Most recent media-related programs for Windows — including iTunes 10.5 or later — no longer use QuickTime to play modern media formats,” Apple wrote. “These programs either play the media directly or use the media support built into Windows.” It seems that Apple feels QuickTime is no longer needed, and as a result, it won’t continue to support or update the application.

Zero-Day Vulnerabilities in QuickTime for Windows

But there’s more: Trend Micro also announced newly discovered zero-day vulnerabilities in the media player. Zero-Day Initiative detailed the two issues, ZDI-16-241 and ZDI-16-242, affecting QuickTime for Windows, and Trend Micro claimed that its own products have been protecting against these exploits since November 2015.

So why go public now? “These advisories are being released in accordance with the Zero Day Initiative’s Disclosure Policy for when a vendor does not issue a security patch for a disclosed vulnerability,” the security firm stated on its blog. “And because Apple is no longer providing security updates for QuickTime on Windows, these vulnerabilities are never going to be patched.”

Trend Micro said it is “not aware of any active attacks against these vulnerabilities currently.” Still, it clarified that the only way to ensure security is to uninstall the program before cybercriminals find a way to exploit the permanent vulnerabilities.

QuickTime for Windows follows other software such as Microsoft Windows XP and Oracle Java 6, which are no longer being updated to fix vulnerabilities. That makes them subject to ever-increasing risk as more and more unpatched vulnerabilities are found and cybercriminals attempt to exploit them.

CERT Weighs In

The U.S. Computer Emergency Readiness Team (US-CERT) amplified the warning about the vulnerability in its own alert. The organization said the impact is potentially damaging to users and their organizations.

“Computer systems running unsupported software are exposed to elevated cybersecurity dangers, such as increased risks of malicious attacks or electronic data loss,” US-CERT said. “Exploitation of QuickTime for Windows vulnerabilities could allow remote attackers to take control of affected systems.”

The only thing that users can responsibly do is uninstall QuickTime for Windows — immediately.

More from

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

DOD establishes Office of the Assistant Secretary of Defense for Cyber Policy

2 min read - The federal government recently took a new step toward prioritizing cybersecurity and demonstrating its commitment to reducing risk. On March 20, 2024, the Pentagon formally established the new Office of the Assistant Secretary of Defense for Cyber Policy to supervise cyber policy for the Department of Defense. The next day, President Joe Biden announced Michael Sulmeyer as his nominee for the role.“In standing up this office, the Department is giving cyber the focus and attention that Congress intended,” said Acting…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today