On GameFAQs: The top 10 strangest game bosses
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Nov 29, 2005 10:53:00 PM

A correction was made to this story. Read below for details.

Computer code posted Tuesday can crash vulnerable Windows machines by exploiting a "critical" Windows flaw disclosed by Microsoft earlier this month.

The exploit code takes advantage of a flaw in the way Windows handles certain graphics files. Microsoft provided a patch in November with security bulletin MS05-053 and warned that the vulnerability could create an opening for spyware and Trojan horse attacks.

"Microsoft is aware that detailed exploit code has been published on the Internet for the vulnerability that is addressed by Microsoft security bulletin MS05-053," a company spokeswoman said Tuesday. Microsoft is not aware of any attacks that use the code, she said. The code was posted on various security Web sites.

"Initial investigation of this exploit code has verified that successful exploitation could lead to a denial-of-service attack...not remote code execution," the Microsoft spokeswoman said. With a denial-of-service attack a computer would crash, while remote code execution would mean the attacker has full control over a PC.

The MS05-053 update fixes bugs in the way Windows renders the Windows Metafile and Enhanced Metafile image formats. Microsoft tagged the patch "critical" for all its current operating system versions. The company said that to exploit the flaws, an attacker could craft an image and trick a Windows user into looking at it on a spoof Web site or in an HTML e-mail, for example.

The public release of the exploit code for the image handling flaw comes just days after computer code that takes advantage of another Windows flaw was posted to the Web. The public posting of exploit code could be a sign that an attack is coming, security experts have said.

Microsoft has urged all customers to apply the most recent security updates to protect their systems.

 

Correction: This story incorrectly stated the month Microsoft provided a patch for the imaging flaw. The patch was released in November.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 12 Talkback(s)
Please READ this:
http://news.zdnet.com/2100-1009_22-5897997.html

HELLOOOOO people!!!!!! Just READ the LINK wink... (Read the rest)
Posted by: btljooz Posted on: 11/30/05 You are currently: a Guest | | Terms of Use
Buuuuuuwaaaaahahahahah...  nix_os_fan | 11/29/05
Just keep Windows updated  dl@... | 11/29/05
It is not not possible to keep Windows updated  whisperycat | 11/30/05
I thought so: Why else would zd scream on the long time ago fixed Java  michael_t | 11/29/05
Let's compare 2 of your posts  NonZealot | 11/29/05
Was that java thingy a published exploit  Jack-Booted EULA | 11/29/05
As a an ancient wise chineese man said:  michael_t | 11/29/05
Code exploits Windows flaw in image file handling  Boot_Agnostic | 11/30/05
Don't surf with Windows  Chad_z | 11/30/05
When did you stop beating your wife?  NonZealot | 11/30/05
We have a winner...  jasonp@... | 11/30/05
Please READ this:  btljooz | 11/30/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc