Executive Summary

Informations
Name TA16-105A First vendor Publication 2016-04-14
Vendor US-CERT Last vendor Modification 2016-04-14
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score Not Defined Attack Range Not Defined
Cvss Impact Score Not Defined Attack Complexity Not Defined
Cvss Expoit Score Not Defined Authentication Not Defined
Calculate full CVSS 2.0 Vectors scores

Detail

Overview

According to Trend Micro, Apple will no longer be providing security updates for QuickTime for Windows, leaving this software vulnerable to exploitation. [1]


Description


All software products have a lifecycle. Apple will no longer be providing security updates for QuickTime for Windows. [1]


The Zero Day Initiative has issued advisories for two vulnerabilities found in QuickTime for Windows. [2] [3]


Impact


Computer systems running unsupported software are exposed to elevated cybersecurity dangers, such as increased risks of malicious attacks or electronic data loss. Exploitation of QuickTime for Windows vulnerabilities could allow remote attackers to take control of affected systems.


Solution


Computers running QuickTime for Windows will continue to work after support ends. However, using unsupported software may increase the risks from viruses and other security threats. Potential negative consequences include loss of confidentiality, integrity, or availability of data, as well as damage to system resources or business assets. The only mitigation available is to uninstall QuickTime for Windows. Users can find instructions for uninstalling QuickTime for Windows on the Apple Uninstall QuickTime page. [4]


Original Source

Url : http://www.us-cert.gov/cas/techalerts/TA16-105A.html

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2016-04-16 13:27:08
  • Multiple Updates
2016-04-15 00:23:46
  • First insertion