Microsoft
Latest flaws affect Windows Graphics Rendering Engine
R E L A T E D   C O N T E N T
ADVERTISEMENT

More WMF woes for Microsoft

Redmond dismisses new flaws as just 'performance issues'

Iain Thomson, vnunet.com 11 Jan 2006
ADVERTISEMENT

Even as Microsoft was releasing its latest batch of patches, two previously undocumented Windows Meta File (WMF) flaws have been exposed. 

The new vulnerabilities were discovered by a computer enthusiast known as 'cocoruder' and affect all Windows operating systems beyond Windows 95.

The flaws are in the Graphics Rendering Engine and could allow a hacker to exploit a memory overrun and crash a PC. 

"Our initial investigation has found that these are not security vulnerabilities but rather performance issues that could cause an application to stop responding," said Microsoft in a statement.

"These issues do not allow an attacker to run code or crash the operating system. They may cause the WMF application to crash, in which case the user may restart the application and resume activity.

"Microsoft had previously identified these issues as part of its ongoing code maintenance and is evaluating them for inclusion in the next service pack for the affected products."

The flaws were posted on the Bugtraq mailing list, and code purporting to exploit the flaws appeared shortly afterwards.

See also:

Microsoft'Extremely critical' vulnerability to remain unpatched for another week  04 Jan 2006
Internet wormUsers could get infected just by visiting a website  29 Dec 2005
MicrosoftSoftware improperly handles graphic files  09 Nov 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities