Apple QuickTime EOL for Windows – Zero day vulnerabilties exist- Please remove Windows installations

According to US-CERT , Apple will no longer be providing security updates for QuickTime for Windows, leaving this software vulnerable to exploitation.

The Zero Day Initiative has issued advisories for two vulnerabilities found in QuickTime for Windows.

Computers running QuickTime for Windows will continue to work after support ends. However, using unsupported software may increase the risks from viruses and other security threats. Potential negative consequences include loss of confidentiality, integrity, or availability of data, as well as damage to system resources or business assets. The only mitigation available is to uninstall QuickTime for Windows.

More information can be found here.

Please remove any installation of Apple QuickTime on Windows. An IEM fixlet is available to remove QuickTime.

Select the fixlet titled: DOI-Wide: Uninstall QuickTime for Windowsquicktime_unistall

More information about deploying IEM fixlets can be found here.

If you are using Windows 7sp1, there maybe some mp4 files that do not work in media player without additional codecs.

You can install the K-Lite Codex Pack to fix this issue.

K-Lite Codec Pack

An SCCM package for K-Lite will be available shortly.

Adobe Creative Suite/Creative Cloud still has some dependencies with QuickTime. These include the Apple ProRes Codec (K-Lite has a Pro-Res codec but it has not been test to see if it works in Adobe Products). Also, other QuickTime formats which would be affected by the uninstallation of QuickTime include Animation (import and export), DNxHD/HR (export) as would workflows where growing QuickTime files are being used (although we strongly advise using MXF for this wherever possible). Adobe is working to remove these dependencies. Adobe Blog

 

Apple has announced their end of support for QuickTime on Windows: https://support.apple.com/kb/DL837?locale=en_US

 

Comments are closed.