The flaw could allow an attacker to take control of a system with a specially
crafted
Windows
Metafile (WMF) or Enhanced Metafile (EMF) image. Windows handles the images
incorrectly, opening a backdoor in the operating system.
Security provider
eEye first reported the
flaw to Microsoft more than six months ago. A second vulnerability affecting
only the WMF format was reported over two months ago.
Both bugs are rated critical because an attacker could exploit them by
posting a maliciously crafted image on a website or sending it by email. After
the system is infected, the attacker could install programs as well as view or
change data.
The patch also fixes a bug in the EMF format with a 'moderate' severity
rating. It causes a crash of the application that is trying to open the file,
but does not open any backdoors.
The bugs affect systems running Windows 2000, XP and Server 2003. Users can
update their systems through the
Windows
Update website.
Security issues relating to software that improperly handles image formats
are not limited to Windows.
Apple issued
a patch in September for critical vulnerabilities in its
OS X operating system that affected the Pict image format
and in the ImageIO tool.
The flaws could have been used to gain control over a system through a buffer
overflow attack.
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >More job opportunities