On GameSpot: We try out down the PSP Go
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jan 10, 2006 1:39:00 AM

Just days after Microsoft rushed out a patch to fix a critical Windows flaw related to the processing of Windows Meta File images, two more problems with the component were flagged.

The newly disclosed issues could be a conduit for denial-of-service attacks, according to a description sent to the Bugtraq mailing list on Monday. A core function of the Windows operating system, explorer.exe, will crash a vulnerable Windows PC if a user views a specially crafted WMF image, according to the description. Explorer runs the Windows user interface, including the Start menu, taskbar, desktop and file manager.

Microsoft is aware of the problems, a representative for the software maker said in an e-mailed statement. The company had identified these issues before the report and is evaluating fixes for inclusion in the next service pack for the affected products, the representative said.

"Microsoft's initial investigation has found that these are not security vulnerabilities but rather performance issues that could cause an application to stop responding," the representative said.

Microsoft disputes that the flaws can cause Windows to stop responding, but said they may affect an application used to view a WMF image. Such applications include the Windows Picture and Fax Viewer.

"(The issues) may cause the WMF application to crash, in which case the user may restart the application and resume activity," the software maker said. The issues do not allow an attacker to commandeer a Windows system, Microsoft noted.

Word of the new problems comes just days after Microsoft rushed out a critical update for a vulnerability related to the rendering of WMF files. Cybercriminals were taking advantage of that flaw to attack Windows computers via malicious Web sites, Trojan horses and instant-messaging worms.

It is no surprise that more WMF flaws are being found, said Mike Murray, the director of vulnerability and exposure research at nCircle, a vulnerability management company in San Francisco. "When a part of Windows yields up a couple of vulnerabilities, it draws attention, and many malicious researchers start looking at that part more closely," he said.

Bugs affecting components of software typically come out in bunches, Murray said. "A few years ago it was IIS, then SQL Server, then RPC, now it's the Windows Graphics Engine," he said. IIS is Internet Information Services (the Web server part of Windows Server), SQL Server is Microsoft's database product, and RPC is the Remote Procedure Call component.

The newly reported Windows issues aren't as serious as the one Microsoft just patched--at least, not yet, Murray cautioned. "In the current release, they're only denial-of-service attacks. However, it's likely that they could be leveraged to be more severe. "If it's possible to write an exploit to take control of an attacked machine, we'll see one in the next week or two," he said.

Microsoft is not aware of any attacks that use the newly disclosed issues as a conduit, it said.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 36 Talkback(s)
MS fixing all flaws first
H--- no! Job security
State workers have it, why shouldn't MS. (Read the rest)
Posted by: jc@... Posted on: 01/11/06 You are currently: a Guest | | Terms of Use
Message has been deleted.  Jack-Booted EULA | 01/09/06
(NT) Three, now.  Jack-Booted EULA | 01/09/06
Today, 3,4 and 5.  Jack-Booted EULA | 01/10/06
(NT) Make that 4,5 and 6 :o)  Jack-Booted EULA | 01/10/06
heh  Jack-Booted EULA | 01/10/06
Message has been deleted.  Jedeye | 01/11/06
[article translation]  rick752 | 01/09/06
Rushed out  Boot_Agnostic | 01/10/06
Company continues to innovate...  Mike Cox | 01/10/06
Dude.........  Shelendrea | 01/10/06
6.2 Not developed enough!  The King's Servant | 01/10/06
My rep and I had a good chuckle  WiredGuy | 01/10/06
eXChange 2003 Innovation  Jedeye | 01/11/06
Doesn't seem to be that bad  voska | 01/10/06
Windows XP boots faster  duclod | 01/10/06
ROFL!! oh... must compose self...  el1jones | 01/10/06
Look at that...  Loverock Davidson | 01/10/06
Don't let it go to your head....  techboy_z | 01/10/06
ha ha  hipparchus2001 | 01/11/06
The OS boot time is one thing  voska | 01/11/06
Incorrect story title  Anti_Zealot | 01/10/06
LOL  Anti_Zealot | 01/10/06
So......  tslocum7 | 01/10/06
Malicious researchers??!!??  techboy_z | 01/10/06
Agreed  ghastly | 01/11/06
RE: Malicious researchers??!!?? by techboy  btljooz | 01/11/06
How do I tell the difference???  middle of nowhere | 01/10/06
RE: How do I tell the difference??? by middle of nowhere  btljooz | 01/11/06
This one doesn't involve bad hardware or  Boot_Agnostic | 01/10/06
hey, B_A, don't forget surreptitious ROOTKITS from  btljooz | 01/11/06
Can't forget about it  Boot_Agnostic | 01/11/06
Happy New Year!  michael_t | 01/10/06
Thanks Michael, Happy New Year to you too!  NonZealot | 01/10/06
If only their developers were as efficient as the PR wink  Gibberstein | 01/11/06
Well said, Gibberstein!!!  btljooz | 01/11/06
MS fixing all flaws first  jc@... | 01/11/06

What do you think?

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
advertisement

White Papers, Webcasts, and Downloads

Meet Doc