Important: Uninstall QuickTime for Windows
Summary
This blog post, "Important: Uninstall QuickTime for Windows", is a blueAPACHE article from 2016 covering security. Apple’s QuickTime used to be a common install for many Windows users – thanks mostly to iTunes – but it has been a long time since it was a prerequisite for playing video and audio files on Windows-based computers. It is written for readers evaluating emPOWER Security. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.
Key facts
| Label | Value |
|---|---|
| Publication year | 2016 |
| Topic | Important: Uninstall QuickTime for Windows |
| Services referenced | emPOWER Security |
| Named products or vendors | Microsoft, Windows |
Article
Apple’s QuickTime used to be a common install for many Windows users – thanks mostly to iTunes – but it has been a long time since it was a prerequisite for playing video and audio files on Windows-based computers. In recent days, Trend Micro discovered two critical flaws in the Windows build of QuickTime and reported them to Apple. Apple responded to Trend Micro explaining that they won’t be fixing the bugs, said they were no longer supporting it, and recommended uninstalling QuickTime for Windows. Christopher Budd from Trend Micro stated “Apple is deprecating QuickTime for Microsoft Windows. They will no longer be issuing security updates for the product on the Windows Platform and recommend users uninstall it. Note that this does not apply to QuickTime on Mac OSX.” Apple began winding down support for QuickTime 7 on Windows in 2013 when the stopped offering tools to third-party developers. The last update for Windows was some nine months ago, and in January this year, they removed QuickTime browser plug-ins on Windows. However, there appears to have been no general warning to users that support is being dropped. The vulnerabilities identified – ZDI-16-241 and ZDI-16-242 – are heap-corruption-based remote code execution vulnerabilities. They allow a hacker to hijack a victim’s computer and infect it with malware, simply by tricking them into opening a malicious file or web download. Budd explained that they were not aware of any attacks that had taken advantage of the QuickTime weaknesses, but the best defence was to follows Apple’s own advice and uninstall the programs from Windows-powered machines. The US Computer Security Readiness Team (CERT) – part of the US Department of Homeland Security – agrees. Following Trend Micro’s findings, CERT issued an alert advising Windows users to immediately uninstall QuickTime. Organisations can mitigate the risks associated with obsolete software by implementing a Standard Operating Environment (SOE) across the organisation. SOE is a standard implementation of an operating system and its associated software. Combined with the correct policies, employees can be restricted in what they can, and can not, install. You can find information on how to uninstall QuickTime for Windows from the Apple website at https://support.apple.com/HT205771. For more information, contact the blueAPACHE account team.
Related
Frequently asked questions
Which two vulnerabilities did Trend Micro discover in QuickTime for Windows, per this article?
ZDI-16-241 and ZDI-16-242, described as heap-corruption-based remote code execution vulnerabilities that could let a hacker hijack a victim's computer via a malicious file or web download.
Who from Trend Micro is quoted explaining Apple's decision, and what did they say?
Christopher Budd, who stated Apple is deprecating QuickTime for Microsoft Windows, will no longer issue security updates for it on Windows, and recommends users uninstall it (this does not apply to QuickTime on Mac OSX).
When did Apple begin winding down support for QuickTime 7 on Windows, according to the article?
In 2013, when Apple stopped offering tools to third-party developers; the last Windows update was about nine months before this article, and QuickTime browser plug-ins on Windows were removed in January of the article's year.
Which US agency issued an alert advising Windows users to uninstall QuickTime, per this article?
US-CERT (the US Computer Security Readiness Team), part of the US Department of Homeland Security, following Trend Micro's findings.
Were there any known attacks exploiting the QuickTime vulnerabilities at the time of this article?
No, Budd said Trend Micro was not aware of any attacks taking advantage of the QuickTime weaknesses, but recommended uninstalling as the best defence regardless.
What mitigation strategy does the article recommend for organisations dealing with obsolete software generally?
Implementing a Standard Operating Environment (SOE) across the organisation, combined with policies restricting what employees can and cannot install.
Where does the article direct readers to find instructions for uninstalling QuickTime for Windows?
The Apple support website at support.apple.com/HT205771.
What was QuickTime for Windows historically bundled with, according to the article?
iTunes, described as the main reason QuickTime used to be a common install for Windows users, despite no longer being a prerequisite for playing video and audio files.
Source
- origin post (2016)
Knowledge Base
Why does blueAPACHE's blog recommend uninstalling QuickTime for Windows?
Trend Micro discovered two critical flaws in the Windows build of QuickTime and reported them to Apple. Apple responded that it would not fix the bugs, stated it was no longer supporting QuickTime for Windows, and recommended uninstalling it.
What did Christopher Budd of Trend Micro say about QuickTime on Windows versus Mac OSX?
Christopher Budd stated that Apple is deprecating QuickTime for Microsoft Windows and will no longer issue security updates for it on the Windows platform, recommending users uninstall it, but clarified this does not apply to QuickTime on Mac OSX.
What are the two vulnerabilities identified in QuickTime for Windows?
The vulnerabilities are identified as ZDI-16-241 and ZDI-16-242, which are heap-corruption-based remote code execution vulnerabilities that allow a hacker to hijack a victim's computer and infect it with malware simply by tricking them into opening a malicious file or web download.
Had there been any known attacks exploiting the QuickTime vulnerabilities at the time of the article?
Budd explained that Trend Micro was not aware of any attacks that had taken advantage of the QuickTime weaknesses, but stated the best defence was to follow Apple's advice and uninstall the program from Windows-powered machines.
How did Apple begin winding down support for QuickTime 7 on Windows?
Apple began winding down support for QuickTime 7 on Windows in 2013 when it stopped offering tools to third-party developers. The last update for Windows was some nine months prior to the article, and in January of that year Apple removed QuickTime browser plug-ins on Windows. The article notes there appears to have been no general warning to users that support was being dropped.
Did any US government body issue an alert about QuickTime for Windows?
Yes, the US Computer Security Readiness Team (CERT), part of the US Department of Homeland Security, issued an alert following Trend Micro's findings, advising Windows users to immediately uninstall QuickTime.
How can organisations mitigate risks from obsolete software like QuickTime for Windows?
The article states organisations can mitigate the risks associated with obsolete software by implementing a Standard Operating Environment (SOE) across the organisation, which is a standard implementation of an operating system and its associated software. Combined with the correct policies, employees can be restricted in what they can and cannot install.
Where can users find instructions to uninstall QuickTime for Windows?
The article directs users to Apple's website at https://support.apple.com/HT205771 for information on how to uninstall QuickTime for Windows.
Who should be contacted for more information about this QuickTime issue?
The article advises contacting the blueAPACHE account team for more information.
When was this blueAPACHE blog post about uninstalling QuickTime for Windows published?
The blog post was written by blueAPACHE and dated April 19, 2016, with a read time of 2 minutes.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c03b153d68a8eeb8f33_Quicktime.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.
-
https://www.facebook.com/tr?id=541021476571056&ev=PageView&noscript=1
(no alt text)