On CBS.com: Share YOUR travel photos at Amazing Race
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Sep 22, 2004 11:17:00 PM

A sample program hit the Internet on Wednesday, showing by example how malicious coders could compromise Windows computers by using a flaw in the handling of a widespread graphics format by Microsoft's software.

Security professionals expect the release of the program to herald a new round of attacks by viruses and Trojan horses incorporating the code to circumvent security on Windows computers that have not been updated. The flaw, in the way Microsoft's software processes JPEG graphics, could allow a program to take control of a victim's computer when the user opens a JPEG file.

"Within days, you'll likely see (attacks) using this code as a basis," said Vincent Weafer, senior director of security response for antivirus-software company Symantec. "This is dangerous in a sense that everyone processes JPEG files to some degree."

The program is the latest example of "exploit code," a sample that shows others how to create attack programs that can take advantage of a particular flaw. Such code preceded the Sasser worm by two days and the MSBlast worm by nine days.

The critical flaw the program exploits has to do with how Microsoft's operating systems and other software process the widely used JPEG image format. Because the software giant's Internet Explorer browser is vulnerable, Windows users could fall prey to an attack just by visiting a Web site that has JPEG images.

The flaw affects various versions of at least a dozen Microsoft software applications and operating systems, including Windows XP, Windows Server 2003, Office XP, Office 2003, Internet Explorer 6 Service Pack 1, Project, Visio, Picture It and Digital Image Pro. The software giant has a full list of the applications in the advisory on its Web site. Windows XP Service Pack 2, which is still being distributed to many customers' computers, is not vulnerable to the flaw.

Users can download the patches from Microsoft's Windows Update and Office Update servers. In addition, the software giant has made available online programs that scan for vulnerable software and patch it.

Symantec and other antivirus companies have released updates for their software to detect graphics being used in attempts to exploit the flaw.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 46 Talkback(s)
Really Useful links! Thanks.
At last, a user who posts something more than just rantings about a fait accompli. The debate WIN/OSS will rage long and acidly long after the issue of GDI+ is dead and buried. The issue IMHO is not... (Read the rest)
Posted by: GrahamA Posted on: 09/29/04 You are currently: a Guest | | Terms of Use
Ouch...  Linux User 147560 | 09/22/04
Umm.. what does closed source have to do with it?  d_jedi | 09/22/04
How so?  No_Ax_to_Grind | 09/22/04
open source would let you UNINSTALL  V Sanders | 09/22/04
Maybe...  Linux User 147560 | 09/22/04
It's All Over  Jeff Spicoli | 09/22/04
Open source has bugs too.  mobrien_12@... | 09/22/04
How prevailant is png  Linux User 147560 | 09/22/04
Don't see the point.  mobrien_12@... | 09/22/04
Must be the top of your head . . .  Roger Ramjet | 09/23/04
Root is not protection  amicus_curious | 09/23/04
Don't Hate  Roger Ramjet | 09/23/04
round and round  linuxoverwindows | 09/23/04
RE: roundand round  phobos | 09/23/04
People's expectation are that it work  voska | 09/23/04
Apples and oranges  d_jedi | 09/23/04
A challenge!  Roger Ramjet | 09/23/04
Re: A challenge (and fix the f*ing talkbacks, ZDNet!! )  d_jedi | 09/23/04
Excellent Response  AmusedAtItAll | 09/23/04
Not just that . . .  Roger Ramjet | 09/23/04
But..  d_jedi | 09/23/04
I like...  doe_z | 09/23/04
A little birdy told me...  John Le'Brecage | 09/22/04
Shock and Awe  Roger Ramjet | 09/23/04
Exactly...  John Le'Brecage | 09/23/04
Whatever happened to investigative journalism?  Omch'Ar | 09/23/04
The Porn industry  Seeker1 | 09/23/04
Dan Rather thinks  Seeker1 | 09/23/04
Not really..  Patrick Jones | 09/23/04
Windows update won't fix this hole  an27182818 | 09/23/04
Windows Update won't fix this hole, Part II  boomslang_z | 09/23/04
What MS need to do...  ryusen | 09/23/04
The person(s) responsible for this should be...  BitTwiddler | 09/23/04
Law and Order  StorageGuru | 09/23/04
true  linuxoverwindows | 09/23/04
I agree!  StorageGuru | 09/23/04
MP#, part 2  Yagotta B. Kidding | 09/23/04
Not Quite true . . .  Roger Ramjet | 09/23/04
Waiting for em to port it to Linux  FilledOut | 09/23/04
Where is AX  sa_z | 09/23/04
wow - scary  V Sanders | 09/23/04
Give Credit.....  DragonBRockin | 09/23/04
Don't wait, install firefox  kevin.dell@... | 09/24/04
agreed.  stevo32 | 09/28/04
SANS GDI+ Third Party Vulnerability Scanner  boomslang_z | 09/27/04
Really Useful links! Thanks.  GrahamA | 09/29/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc