On CNET: Worst Nintendo Wii game ideas ever
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers, News.com
Posted on ZDNet News: Nov 8, 2005 7:44:00 PM

Three security flaws in the way Windows handles certain graphics files could create an opening for spyware and Trojan horse attacks, Microsoft has warned.

The vulnerabilities relate to how the operating system renders the Windows Metafile (WMF) and Enhanced Metafile (EMF) image formats, Microsoft said Tuesday in its MS05-053 security bulletin. Two of them could allow a remote intruder to gain complete control over a Windows PC, Microsoft warned in the bulletin, the sole one in its monthly patch cycle.

Microsoft has tagged the security bulletin "critical," its most serious rating. The software maker urges Windows users to install the security update that accompanied the alert as soon as possible to protect against any attacks via the security bugs.

To exploit the flaws, an attacker could craft a malicious image and trick a Windows user to look at it on a malicious Web site or in an HTML e-mail, for example, according to Microsoft. This type of vulnerability could be a conduit for the installation of spyware, Trojan horses, bots or other harmful programs on an unsuspecting user's machine.

While two of the vulnerabilities disclosed on Tuesday could allow an outsider to commandeer a Windows PC, the third is limited in scope and would crash only an application used to view a malformed file, Microsoft said.

Bugs in file format handling are increasingly being uncovered. That's because image formats are complicated, and applications have to support many image file types, experts said. Microsoft in August warned of a similar flaw, which is related to an error in the way Internet Explorer handles JPEG images.

"We will continue to see this type of vulnerabilities in every major application for the foreseeable future," said Neel Mehta, a team leader at Internet Security Systems. "It is not just images, but any type of complex file format. This is something that security researchers and hackers have realized to be a weak point in many applications."

Mehta doesn't expect the latest Windows flaws to be exploited in a widespread attack. "We're not bracing for any major worm or malware outbreak, but we do expect them to be used in targeted attacks," Mehta said. "There is user interaction required, there has to be someone sitting at the other end in order to be compromised."

Of the three vulnerabilities, the most serious affects all current Windows operating systems. The two other flaws are found in Windows 2000, Windows XP with Service Pack 1 and Windows Server 2003, but don't exist in Microsoft's latest desktop and server products, Windows XP with SP 2 and Windows Server 2003 with SP1, Microsoft said.

Microsoft is not aware of any malicious code that exploits the two flaws that could allow a PC to be fully compromised, the software maker said. However, code that exploits the third flaw and can crash an application running on Windows has been posted to the Internet, Microsoft said.

Microsoft released only one security bulletin on this November "Patch Tuesday." Mehta suggested that people take the time to catch up on patches. "Because it is quiet, it does give people an opportunity to catch up and make sure they are protected," he said. People who have signed up for Microsoft's update service should receive the patch download automatically.

  • Talkback
  • Most Recent of 91 Talkback(s)
Simple fix go to fire fox
If your sp f*cking concerned about this flaw just migrate to mozilla Fire Fox. There is you fix now stpop dissing microsoft.... (Read the rest)
Posted by: opensource-geek Posted on: 12/09/05 You are currently: Logged In | Log out
The real critical flaw ..... An_Axe_to_Grind   | 11/08/05
Microsoft Has an Image Problem schneb   | 11/09/05
No it's a talent problem ... An_Axe_to_Grind   | 11/09/05
That's why the irrelevant PhP vulnerability was pushed so hard michael_t   | 11/08/05
You do know the difference ... ShadeTree   | 11/08/05
he he he ... my good friend michael_t   | 11/08/05
Substitute "that" for "if" and... ShadeTree   | 11/08/05
Whoa nelly! Jeff Spicoli   | 11/08/05
Kudos Shady-greymater! Did think that all by yourself? That must took a michael_t   | 11/08/05
Message has been deleted. Jeff the god of biscuits   | 11/08/05
I though my big foot up michael_t   | 11/09/05
So let me get this straight. ShadeTree   | 11/09/05
Mike T Jeff the god of biscuits   | 11/09/05
Wait just a moment... yourkiddingright   | 11/09/05
Pretty simple actually IT Scion   | 11/09/05
Ok, so is this correct then... yourkiddingright   | 11/09/05
Sure IT Scion   | 11/09/05
Last time I checked the PhP flaw michael_t   | 11/09/05
Just like you IT Scion   | 11/09/05
You resort to semantics of the colloquial meaning of words michael_t   | 11/09/05
Wow.. IT Scion   | 11/10/05
nothing like fearing ever 'href' click nynetsec   | 11/08/05
Image-handling flaws put Windows PCs at risk Loverock Davidson   | 11/08/05
I thought so! stormdoor   | 11/08/05
I know so Loverock Davidson   | 11/08/05
If this were a flaw in linux... Sxooter_z   | 11/08/05
Captain Obvious strikes again! Loverock Davidson   | 11/09/05
I know so by Loverock Davidson btljooz   | 11/09/05
Whelp... Cardinal_Bill   | 11/08/05
I think what you meant to say was.... tic swayback   | 11/08/05
Not widespread, not a problem, already patched rpmyers1   | 11/08/05
a couple of Questions wexwimpy@...   | 11/09/05
well what was balmer saying about been different toxicfreak   | 11/08/05
yadayada top cost yadyada bottom quality yaDA ... nt michael_t   | 11/09/05
Adult Section MarkieMark   | 11/09/05
"Been Different"? MarkieMark   | 11/09/05
Ah the irony! Linux Advocate   | 11/08/05
A quote from Loverock...cuz he's wize like that... techboy_z   | 11/08/05
Very fun day indeed Loverock Davidson   | 11/09/05
LOL... Like this is SURPRISING news... asrai   | 11/08/05
The entire Windoze O/S code is a SECURITY FLAW... realitycheck101   | 11/08/05
Shut up troll Jeff the god of biscuits   | 11/08/05
Way to go!!! dsentman@...   | 11/09/05
UK Law MarkieMark   | 11/09/05
The ideas of 'fitness for consumer usage' and quality michael_t   | 11/09/05
The ideas of 'fitness for consumer usage' and quality wjarvis@...   | 11/11/05
RE:The entire Windoze O/S code is a SECURITY FLAW... by YEAHRIGHT btljooz   | 11/09/05
The entire Windoze O/S code is a SECURITY FLAW... zzbottom   | 11/20/05
WMF? Is this a Web Format? Not Where I'm Sitting PMC-CON   | 11/08/05
That Would Be WMF File ... Damn Typos PMC-CON   | 11/08/05
Hackers will always be a reality erniem1970@...   | 11/08/05
Just In Time... The Rifleman   | 11/08/05
Time to sing Kumbaya kray_z   | 11/08/05
Were You In Illinois? PMC-CON   | 11/08/05
Champaign? MarkieMark   | 11/09/05
Mike Cox 2 ??? . . . Try harder - I'll give you a 3.2 (nt) Bit's_Conscience   | 11/08/05
Ya think??? Hardly Mike Cox (2 or otherwise) (nt) mdsmedia   | 11/09/05
Firing Policy MarkieMark   | 11/09/05
hmmm, what does anyone think? u2in99   | 11/08/05
The Windows architects are responsible kevin.cline@...   | 11/08/05
first sensible message in thread mdsmedia   | 11/09/05
Nothing is 100% fragos   | 11/08/05
WINDOWS VS VISTA fakir005@...   | 11/08/05
Anyone here ever study statistics? Jeff the god of biscuits   | 11/08/05
Todays critical flaws from SecuritySpace.com Jeff the god of biscuits   | 11/08/05
Nice list. Cardinal_Bill   | 11/08/05
And... Hugh Jass   | 11/08/05
Shut up troll Jeff the god of biscuits   | 11/08/05
Troll? yourkiddingright   | 11/09/05
YHBT HAND Jeff the god of biscuits   | 11/09/05
lmfao IT Scion   | 11/10/05
Irony escapes some Jeff the god of biscuits   | 11/08/05
Did irony escaped you when you posted data that michael_t   | 11/09/05
Hey Mike Jeff the god of biscuits   | 11/09/05
And your point would be what? Chad_z   | 11/09/05
I think IT Scion   | 11/09/05
You "think" ? Isn't that a stretch ? ...;) nt michael_t   | 11/09/05
Shhhhhhh!!!! Jeff the god of biscuits   | 11/10/05
Sounds Fishy To Me... bmcgrath   | 11/08/05
The graphic file is just the vehicle. Hugh Jass   | 11/08/05
Its not a flaw Outside T. Box   | 11/09/05
Not good IT Scion   | 11/08/05
So, while on this image handling flaw Boot_Agnostic   | 11/09/05
(nt)There have been similar image handling flaws for other platforms. toadlife   | 11/09/05
Oh Boy tslocum7   | 11/09/05
Oh Boy tslocum7   | 11/09/05
My question STILL stands.... btljooz   | 11/09/05
My questions are Boot_Agnostic   | 11/09/05
My Question is... The Rifleman   | 11/09/05
God! how out dated! Old News! New File Formats Behold   | 11/11/05
Simple fix go to fire fox opensource-geek   | 12/09/05

What do you think?

advertisement
advertisement

The Green Enterprise

advertisement
Click Here