Site Archives

Apple Quicktime Zero-Day Advisory

Posted on April 29th, 2008

GSA Reference Number: AD080429-01

Simply Put: The Apple QuickTime Media Player is vulnerable to a remote code execution vulnerability. This remote code execution vulnerability is a security flaw that could allow a malicious file to run other programs and applications on the user’s machine when they watch a QuickTime movie. If a user opens a malicious QuickTime file, it could take over the user’s machine. The QuickTime file could be located on a website, in an email attachment or on a CD or hard drive. No patch is available at this time.