The problem affects the 'secdrv.sys' file, a component of the SafeDisc copy encryption developed by Macrovision and sold to game developers.
The DRM technology is bundled with Windows Server 2003, Windows XP and Windows Vista, but does not affect Windows Vista.
Danish security website Secunia rates the vulnerability as 'less critical', the second step on a five step severity scale. The risk to end users is limited because a successful exploit requires attackers to have an account on the targeted system.
Symantec first disclosed the issue on a company blog 20 days ago. Microsoft told the firm at the time that it was aware of the issue and was working on a fix.
Microsoft issued a security advisory on Monday in which it disclosed the ongoing attacks.
The company also linked to a patch that Macrovision has since issued, and said that Windows systems will be updated as part of the next Patch Tuesday update scheduled for 13 November.
Attackers target Windows DRM flaw
By
Tom Sanders
on Nov 8, 2007 6:27AM

Got a news tip for our journalists? Share it with us anonymously here.
Partner Content

Channel can help lead customers to boosting workplace wellbeing with professional headsets

Kaseya Dattocon APAC 2024 is Back

How NinjaOne Is Supporting The Channel As It Builds An Innovative Global Partner Program

Secure, integrated platforms enable MSPs to focus bringing powerful solutions to customers

Tech For Good program gives purpose and strong business outcomes
Sponsored Whitepapers
-1.jpg&w=100&c=1&s=0)
Stop Fraud Before It Starts: A Must-Read Guide for Safer Customer Communications

The Cybersecurity Playbook for Partners in Asia Pacific and Japan

Pulseway Essential Eight Framework

7 Best Practices For Implementing Human Risk Management

2025 State of Machine Identity Security Report