2016/04/15 04:43:10
SuperG
http://www.theregister.co.uk/2016/04/14/uninstall_quicktime_for_windows/
 
RIP QuickTime for Windows. Apple is "deprecating support" for the application, and will no longer patch security flaws in the software.
The iGiant is also quietly advising users to uninstall the media player from their Windows machines to avoid being hacked.
Word of the end of support comes from infosec biz Trend Micro. It discovered two critical flaws in the Windows build of QuickTime and reported them to Apple. In response, Trend told The Register, the iPhone maker said it won't fix the bugs, and is cutting the application loose.
Both of the vulnerabilities – ZDI-16-241 and ZDI-16-242 – are heap-corruption-based remote code execution vulnerabilities.
An attacker can exploit these flaws to hijack a victim's PC and infect it with malware, simply by tricking them into opening a malicious file or web download. Apple's response: uninstall QuickTime for Windows.
"We're not aware of any active attacks against these vulnerabilities currently. But the only way to protect your Windows systems from potential attacks against these or other vulnerabilities in Apple QuickTime now is to uninstall it," said Christopher Budd, global threat communications manager at Trend Micro, on Thursday.
"In this regard, QuickTime for Windows now joins Microsoft Windows XP and Oracle Java 6 as software that is no longer being updated to fix vulnerabilities, and subject to ever-increasing risk as more and more unpatched vulnerabilities are found affecting it."
The flaws were reported to Apple on November 11, 2015, and acknowledged the same day by Cupertino. The following March, Apple told Trend Micro that "the product would be deprecated on Windows and the vendor would publish removal instructions for users."
Bizarrely, Apple doesn't seem to have mentioned the change of heart over QuickTime to anyone else. The iOS goliath last updated QuickTime for Windows in January, and there appears to have been no general warning to users that support is being dropped. For what it's worth, QuickTime has never played nice with Windows 8 or 10, and its web plugin was disabled by default in that January update.
Given the short lead time between vulnerabilities being announced and malware writers exploiting them, Trend's disclosures today could turn into a serious security headache. QuickTime has been available for Windows for over 20 years and there's a considerable installed base of users out there, all of whom are now at risk.
Apple does not respond to The Register's requests for comment. Microsoft "politely" declined to comment. ®
2016/04/15 08:26:12
Mesh
I've generally been avoiding installing Quicktime, and I think IK (or some other company) always asks to install QT with their Auth. Mgr./installer. I personally never had a real need for QT, so the loss is not really a biggie in my book.  
2016/04/15 08:58:55
SmokeyJ628
Good riddance.  I've always hated QT.
2016/04/15 09:32:12
pentimentosound
I'm pretty sure, the IK stuff uses(used?) it. I wonder what my options are now?
Thanks for the headsup. I suppose I should uninstall it, but I'd like to have some more info, first.
Michael
2016/04/15 10:38:30
bitflipper
SmokeyJ628
Good riddance.  I've always hated QT.



Ditto. It was a kludge on Windows from the get-go. It wanted to associate itself with every known audio or video filename extension. It installed a background service that started every time you booted. It popped up ads wanting you to buy the "pro" version. It was unnecessarily difficult to uninstall. Apple made deals with Hollywood to release movie trailers only in QT format, so more users would be enticed to install it. Even some video games required it, for no good reason other than the developers were probably bribed by Apple. And Apple never seemed to have any interest in making it work well on Windows.
 
Unfortunately, many of the underhanded strategies for spreading it and locking it into your computer's ecosystem remain, in the form of iTunes.
2016/04/15 10:45:46
bapu
iQuit.
2016/04/15 12:09:18
jbow
Uninstalled... thanks!
 
J
2016/04/15 12:12:03
jbow
pentimentosound
I'm pretty sure, the IK stuff uses(used?) it. I wonder what my options are now?
Thanks for the headsup. I suppose I should uninstall it, but I'd like to have some more info, first.
Michael


IK will need to make some changes, huh?  FWIW, I checked and the CS opens and Amplitude 4 opens, I didn't try to use them but the GUI looked right.
 
J
2016/04/15 12:16:54
bapu
If I uninstall QuickTime will it now be safe to click on any link in any email even from the Hamster Groomers Forum?
2016/04/15 12:56:36
TheMaartian
Crapola. The only reason I reinstalled it in Win10 was for Rhyme Genie and TuneSmith (used for quick idea recording). Uninstalling. 
© 2025 APG vNext Commercial Version 5.1

Use My Existing Forum Account

Use My Social Media Account