First Aid for the QuickTime Security Flaw

Our colleagues at Slashcam kindly took the trouble to address the most pressing questions about the QuickTime security flaw. An excerpt.

Archive notice: This article was originally published on May 24, 2016. Links and embedded videos are preserved as part of the historical record.

How would a possible attack via the QuickTime security flaw work?

(…) Various programs (including Premiere, After Effects, Avid, Edius, Vegas, Resolve – but also web browsers with the QT plug-in installed) access the QT library to open, play and save certain video and audio formats. Without QT installed, many of these formats are not even recognised. Exactly which ones depends on the software.

None of these programs reads ProRes without QT, and Resolve cannot even read and write Mp4/H.264 without QT. When these programs access QT while opening and playing, QT effectively takes command: in fact, it is not Premiere or Avid but the QT library that plays the corresponding format explained.

Video files played by QT can be prepared with a few manipulated bits so that they throw QT off track when opened or played. QT can then become so confused that it executes program code that may be patched into the video file itself. This program code can, for example, be malware that first searches all .mov files on the computer in order to patch its own malicious code into them and then encrypts data on the computer as ransomware. (…)

What to do? Security advice for users of Windows video software that uses QuickTime

  1. Uninstall QuickTime as a trial and see what still works with the software in use and what does not. If you have a workflow in which QuickTime is dispensable (for example, if you import CinemaDNG and export DnxHR in an MXF container, and can handle mp4 encoding with an external encoder that does not depend on QuickTime), that is the best solution.
  2. If 1.) is not feasible, reinstall QuickTime without the browser plug-in, then delete the Player app’s program file.
  3. As a rule, avoid downloading .mov files (and possibly other file types played through QuickTime in the NLE). These include, for example, freely downloadable camera test footage, downloadable grain and effects overlays and, when in doubt, stock footage (for example from archive.org) in the risky file formats.
  4. Install antivirus software on your computer that detects the QuickTime flaw (currently Trend Micro). Scan all video files currently stored on the computer.
  5. .mov files (and other video formats played through QuickTime) from your own cameras are generally unproblematic. However, the memory cards should not have been opened/copied on third-party computers, but should go directly from the camera to the editing computer wherever possible. Alternatively: activate the memory cards’ hardware write protection immediately after removing them from the camera. Otherwise: run the memory cards through the virus scanner once after opening them on the computer.
  6. For anyone who works a lot with files supplied by third parties: first open files on a separate offline computer, scan them for malware with a suitable scanner and, if necessary, transcode them into non-vulnerable formats (e.g. DNxHDDNxHD explained in the glossary in an MXF container). If you always transcode anyway, an alternative operating system such as Linux (with ffmpeg) or Mac OS X is a good option.
  7. Keep the editing computer offline wherever possible (or go online as little as possible – for example, only when Adobe CC requests a licence check).

For the full article, visit www.slashcam.de