On TV.com: ANNA FARIS photos
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jul 12, 2005 9:30:00 PM

Hackers are actively exploiting two serious security vulnerabilities in Windows, Microsoft warned on Tuesday as it released "critical" alerts about the flaws.

One of the problems affects the Microsoft Color Management Module, a component of Windows that handles colors. The other relates to the JView Profiler, part of Microsoft's Java Virtual Machine. The vulnerabilities could be used to commandeer a PC, Microsoft said.

"Attackers are already using the JView Profiler flaw to download and install Trojan horses on victims' machines," said Dan Hubbard, senior director at Websense Security Labs. The Trojan horses would let the miscreants remotely control the hijacked PCs and make it part of a network of such computers known as a botnet, an increasing cyberthreat.

The Windows vulnerabilities are described in two bulletins issued as part of Microsoft's monthly patch cycle. A third alert deals with a bug affecting Word 2000 and Word 2002. The Word flaw could allow an attacker to take control of a vulnerable PC, the software maker said.

All three bulletins get Microsoft's highest security rating, but only the Windows flaws are actively being used to attack users, Microsoft said. The company is encouraging all customers to apply its updates. Security software vendor Symantec said in a statement that the JView Profiler and Color Managament Module issued that affect Windows are "the most serious" of Microsoft's three new security bulletins.

Modes of attack
An intruder could take advantage of the JView Profiler flaw by crafting a malicious Web page and persuading a user to visit the site, Microsoft said. The vulnerability has been publicly known since late last month, and Microsoft last week offered a fix for the problem, but did not send it out via its automatic patching services. The patch will now go out on Automatic Updates and on other services from Microsoft.

As for the Color Management Module vulnerability, people could fall victim to an attack by viewing a malicious image, said Stephen Toulouse, a security program manager at Microsoft.

"You could visit a Web page, and if you have not applied the update, malicious code could execute," Toulouse said. "You could click on a maliciously formed image attached to an e-mail, or you could just preview an image in an e-mail."

Because attackers have more than one way of enticing potential victims, Microsoft deemed the Color Management flaw critical, he noted.

Although the vulnerability was privately reported, Microsoft said, it is already being used in attempts to attack users.

"We have not seen a public posting detailing how to exploit the vulnerability," Toulouse said. "However we have been made aware that there are people attempting to exploit it."

Neel Mehta, a team lead at Internet Security Systems, said he expects a public exploit for the image problem within the week. "It is being analyzed by the underground. Exploitation of this issue will likely be widespread when a public exploit appears," he said.

The JView Profiler and the Color Management flaw affect all current Windows and Windows Server operating systems, including Windows XP with Service Pack 2 and Windows Server 2003 with Service Pack 1, the most recent versions that Microsoft has promoted as its most secure releases ever.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 63 Talkback(s)
Dumb Comments Isn't the Problem!
Windoze in any flavor is the problem along with the bad code that
is being put in the software.
P.S. Get a Mac!... (Read the rest)
Posted by: tystoy1 Posted on: 09/06/05 You are currently: a Guest | | Terms of Use
Windows is the flaw!  Reverend MacFellow | 07/12/05
yea jeezzzz,  JoeMama_z | 07/12/05
Hypocracy  Harry Bardal | 07/13/05
LOL  ThePro_z | 07/13/05
Consequences  Harry Bardal | 07/13/05
how many people....  JoeMama_z | 07/13/05
Grandma Will Be The Advocate  Harry Bardal | 07/13/05
140000 viruses....  stuart_at_oz | 07/13/05
more secure??  JoeMama_z | 07/13/05
Cheerleading  Harry Bardal | 07/13/05
well said!  An_Axe_to_Grind | 07/13/05
OS10 secure, why?  Crestview | 07/13/05
The Fear, Oh Lord, The Fear  Harry Bardal | 07/13/05
OS X Secure, Why you ask?  KannazkuiHikaru | 08/23/05
Dude, that one was too easy.  dstinson_z | 07/13/05
I just wanted to be first!  An_Axe_to_Grind | 07/13/05
Not for me.  Grayson Peddie | 07/12/05
False sense of security  Yagotta B. Kidding | 07/12/05
Spoken like a true serf [nt]  Omch'Ar | 07/12/05
Grayson.... ummmmm.....  DragonBRockin | 07/12/05
I ADMIT!!! I ADMIT!!!  Grayson Peddie | 07/13/05
So sad  AmusedAtItAll | 07/13/05
Oh...  Grayson Peddie | 07/13/05
Gee there's a mature response!  Linux User 147560 | 07/13/05
F*ck it off...  Grayson Peddie | 07/13/05
Wrong. And Obnoxious Too.  PMC-CON | 07/14/05
Well gee whiz.  Judas I. | 07/12/05
Ok here is some useful info for those of you too lazy to look for yourself.  JoeMama_z | 07/12/05
A simple statement.  Cardinal_Bill | 07/12/05
this is true...  JoeMama_z | 07/12/05
Design client OS for average users  jasonp@... | 07/13/05
but how...  JoeMama_z | 07/13/05
Yep.  Cardinal_Bill | 07/13/05
MSJVM  DanP. | 07/22/05
Yawn...wake me up when Micro$ux wakes up...  Colonel_Panic | 07/12/05
Windows freezes after WindowsUpdate if old ZoneAlarm installed  solprovider | 07/12/05
dood... if you're on win98se... you have other problems  Valis Keogh | 07/12/05
win98se  thomasgclough | 07/14/05
Penny Wise, Pound Foolish  PMC-CON | 07/14/05
Dumb Comments Isn't the Problem!  tystoy1 | 09/06/05
It's windows 98 for cryin' out loud!  Crestview | 07/13/05
There is no: "Microsoft's Java Virtual Machine"!!!  FirstNLastN | 07/12/05
Apparently YOU are the moron  ThePro_z | 07/13/05
News flash some banking apps use MS JVM  crocd | 07/13/05
Clue me in  whisperycat | 07/13/05
You've got it  ebrke | 07/13/05
Bravo!!!  Aguy_z | 07/13/05
Victim Mentality -- Web TV?  PMC-CON | 07/14/05
BUWAHAHAHAH!!!! MICROSOFT SUCKS ONCE AGAIN!!!  itanalyst | 07/13/05
Message has been deleted.  Da-Man | 07/13/05
Yes, I Did Come Up With It On My Own  itanalyst | 07/13/05
I see you are...  Colonel_Panic | 07/13/05
Yeah, but you don't have to send us anything...  John Zern | 07/13/05
And...  Grayson Peddie | 07/13/05
PCs falling victim to Windows Flaws  Otto_Delete | 07/13/05
ZD is amazing!  An_Axe_to_Grind | 07/13/05
install real java instead of M$ clone and solve problem. why does the  wessonjoe | 07/13/05
I'VE HAD IT...  LouF_59 | 07/13/05
Sorry, GBML ?  jacrav | 07/13/05
Ok, I give in  Crestview | 07/13/05
Honestly....  JoeMama_z | 07/13/05
Destructive Criticism  hawkzx11@... | 07/13/05
Buwahahahah  weenus500 | 07/13/05

What do you think?

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More