You are here: silicon.com > Software > Security Strategy

Security Strategy

Trio of Windows flaws opens door to nasties

Image-handling in the picture...

Tags: security flaws, microsoft windows

By Joris Evers

Published: 9 November 2005 08:45 GMT

Three security flaws in the way Windows handles certain graphics files could create an opening for spyware and Trojan horse attacks, Microsoft has warned.

The vulnerabilities relate to how the operating system renders the Windows Metafile (WMF) and Enhanced Metafile (EMF) image formats, Microsoft said on Tuesday in its MS05-053 security bulletin. Two of them could allow a remote intruder to gain complete control over a Windows PC, Redmond warned in the bulletin, the sole one in its monthly patch cycle.

Microsoft has tagged the security bulletin "critical", its most serious rating. The software maker urges Windows users to install the security update that accompanied the alert as soon as possible to protect against any attacks via the security bugs.

To exploit the flaws, an attacker could craft a malicious image and trick a Windows user to look at it on a malicious website or in an HTML email, for example, according to Microsoft. This type of vulnerability could be a conduit for the installation of spyware, Trojan horses, bots or other harmful programs on an unsuspecting user's machine.

While two of the vulnerabilities disclosed on Tuesday could allow an outsider to commandeer a Windows PC, the third is limited in scope and would crash only an application used to view a malformed file, Microsoft said.

Bugs in file format handling are increasingly being uncovered. That's because image formats are complicated, and applications have to support many image file types, experts said. In August Microsoft warned of a similar flaw, which is related to an error in the way Internet Explorer handles JPEG images.

Neel Mehta, a team leader at Internet Security Systems, said: "We will continue to see this type of vulnerabilities in every major application for the foreseeable future. It is not just images but any type of complex file format. This is something that security researchers and hackers have realised to be a weak point in many applications."

Mehta doesn't expect the latest Windows flaws to be exploited in a widespread attack. "We're not bracing for any major worm or malware outbreak but we do expect them to be used in targeted attacks," he said. "There is user interaction required, there has to be someone sitting at the other end in order to be compromised."

Of the three vulnerabilities, the most serious affects all current Windows operating systems. The two other flaws are found in Windows 2000, Windows XP with Service Pack 1 and Windows Server 2003 but don't exist in Microsoft's latest desktop and server products, Windows XP with SP 2 and Windows Server 2003 with SP1, Microsoft said.

Microsoft is not aware of any malicious code that exploits the two flaws that could allow a PC to be fully compromised, the software maker said. However, code that exploits the third flaw and can crash an application running on Windows has been posted to the internet, Microsoft said.

Microsoft released only one security bulletin on this November "Patch Tuesday". Mehta suggested that people take the time to catch up on patches. "Because it is quiet, it does give people an opportunity to catch up and make sure they are protected," he said. People who have signed up for Microsoft's update service should receive the patch download automatically.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Front End Web Developer

A fundamental knowledge of computer programming Coding experience for websites (HTML, XHTML, DHTML, CSS, Actionscript, Javascript) Graphic design ...

Vision Scientist - Image Tracking, Oxford

The ideal candidate will have specific experience with Algorithm development and the optimisation for image based tracking, Object detection ...

CharacterAnimator

Websites are great if they're easy to navigate and show images at a high res, but often they are confusing with small pixelated images! Requirements: ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: