Microsoft
Flaw could allow an attacker to take control of a system
R E L A T E D   C O N T E N T
ADVERTISEMENT

Windows graphics bug opens backdoor

Software improperly handles graphic files

Tom Sanders in California, vnunet.com 09 Nov 2005
ADVERTISEMENT

Microsoft has released an update that plugs three vulnerabilities in the Windows operating systems. 

The flaw could allow an attacker to take control of a system with a specially crafted Windows Metafile (WMF) or Enhanced Metafile (EMF) image. Windows handles the images incorrectly, opening a backdoor in the operating system.

Security provider eEye first reported the flaw to Microsoft more than six months ago. A second vulnerability affecting only the WMF format was reported over two months ago.

Both bugs are rated critical because an attacker could exploit them by posting a maliciously crafted image on a website or sending it by email. After the system is infected, the attacker could install programs as well as view or change data.

The patch also fixes a bug in the EMF format with a 'moderate' severity rating. It causes a crash of the application that is trying to open the file, but does not open any backdoors.

The bugs affect systems running Windows 2000, XP and Server 2003. Users can update their systems through the Windows Update website.

Security issues relating to software that improperly handles image formats are not limited to Windows.

Apple issued a patch in September for critical vulnerabilities in its OS X operating system that affected the Pict image format and in the ImageIO tool.

The flaws could have been used to gain control over a system through a buffer overflow attack.

See also:

Trojan horseSpoofed Microsoft patch catches unwary users  08 Nov 2005
MicrosoftWindows flaw rated 'critical'  07 Nov 2005
MicrosoftPatch MS05-051 disables firewall for some users  17 Oct 2005
Microsoft chief executive Steve BallmerBeta of enterprise desktop security suite promised later this year  07 Oct 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities