You are here: silicon.com > Software > Security Strategy

Security Strategy

Two new WMF flaws emerge

They're "performance issues" not security holes, says Microsoft

Tags: wmf, microsoft windows, microsoft

By Joris Evers

Published: 10 January 2006 08:35 GMT

Just days after Microsoft rushed out a patch to fix a critical Windows flaw related to the processing of Windows Meta File (WMF) images, two more problems with the component were flagged.

The newly disclosed issues could be a conduit for denial of service attacks, according to a description sent to the Bugtraq mailing list on Monday. A core function of the Windows operating system, explorer.exe, will crash a vulnerable Windows PC if a user views a specially crafted WMF image, according to the description. Explorer runs the Windows user interface, including the Start menu, taskbar, desktop and file manager.

Microsoft is aware of the problems, a representative for the software maker said in an emailed statement. The company had identified these issues before the report and is evaluating fixes for inclusion in the next service pack for the affected products, the representative said.

The representative added: "Microsoft's initial investigation has found that these are not security vulnerabilities but rather performance issues that could cause an application to stop responding."

Microsoft disputes that the flaws can cause Windows to stop responding but said they may affect an application used to view a WMF image. Such applications include the Windows Picture and Fax Viewer.

The software maker said: "[The issues] may cause the WMF application to crash, in which case the user may restart the application and resume activity." The issues do not allow an attacker to commandeer a Windows system, Microsoft noted.

Word of the new problems comes just days after Microsoft rushed out a critical update for a vulnerability related to the rendering of WMF files. Cyber criminals were taking advantage of that flaw to attack Windows computers via malicious websites, Trojan horses and instant-messaging worms.

It is no surprise that more WMF flaws are being found, said Mike Murray, the director of vulnerability and exposure research at nCircle, a vulnerability management company in San Francisco. He said: "When a part of Windows yields up a couple of vulnerabilities, it draws attention, and many malicious researchers start looking at that part more closely."

Bugs affecting components of software typically come out in bunches, Murray said. "A few years ago it was IIS, then SQL Server, then RPC, now it's the Windows Graphics Engine," he said. IIS is Internet Information Services (the web server part of Windows Server), SQL Server is Microsoft's database product, and RPC is the Remote Procedure Call component.

The newly reported Windows issues aren't as serious as the one Microsoft just patched - at least, not yet, Murray cautioned. He said: "In the current release, they're only denial of service attacks. However, it's likely that they could be leveraged to be more severe.

"If it's possible to write an exploit to take control of an attacked machine, we'll see one in the next week or two."

Microsoft is not aware of any attacks that use the newly disclosed issues as a conduit, it said.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Web Applications Vulnerability Tester

Title: Web Applications Vulnerability Tester / Penetration Tester Salary: market rates but probably 40k to 60k Company: online / ecommerce company ...

Sales Office Manager- Electronic Component Distribution

The successful applicant will have extensive and broad electronic component product knowledge, which will enable you to be a pro-active decision ...

Penetration Testers Required - Must be CREST / CHECK Accredited

Overview • To work in their security testing team, you will need a strong technical background in the area of network security including a ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: