Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » Security Watch » NEW Critical Windows Patch Fights Takeover Attacks

Security Watch - NEW Critical Windows Patch Fights Takeover Attacks posted in the Security & Safety forums; NEW Critical Windows Patch Fights Takeover Attacks Three image-rendering flaws in the Windows operating system could put millions of Internet-connected users at risk of PC takeover attacks, Microsoft Corp. warned ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-09-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default NEW Critical Windows Patch Fights Takeover Attacks

NEW Critical Windows Patch Fights Takeover Attacks


Three image-rendering flaws in the Windows operating system could put millions of Internet-connected users at risk of PC takeover attacks, Microsoft Corp. warned on Tuesday.

The flaws could be exploited via any software that displays images, including the widely used Microsoft Outlook, Microsoft Word and Internet Explorer programs.




The bugs are considered particularly dangerous because users could be at risk by merely browsing to a malicious rigged site with rigged image files, or by displaying images in the preview pane of an e-mail program.

Microsoft tagged the update as "critical," its highest severity, and urges Windows users to download and apply the patches immediately.
The flaws affect Windows 2000, Windows XP (including Service Pack 2) and Windows Server 2003.
According to the MS05-053 bulletin, the nastiest of the three is a remote code execution bug in the rendering of WMF (Windows Metafile) and EMF (Enhanced Metafile) image formats.


"Any program that renders WMF or EMF images on the affected systems could be vulnerable to this attack. An attacker who successfully exploited this vulnerability could take complete control of an affected system," the company warned.

The bulletin also addresses two separate unchecked buffers in the way the operating system renders EMF and WMF images.
Image-rendering vulnerabilities are deemed particularly serious because malicious hackers can simply place a rigged photograph on a Web site and trick users into visiting. By merely browsing to the malicious site, the user allows the attacker to execute harmful code to take complete control of an unpatched machine.


In the past, image-rendering bugs have been used in widespread attacks. In one case, a hacker broke into an ad server and successfully loaded exploit code on banner advertising served on hundreds of Web sites. European tech publisher The Register was among those affected.

The latest flaw was discovered by at least three private research teams and reported to Microsoft more than seven months ago.

eEye Digital Security, one of the research firms credited with finding the vulnerability, reported it to Microsoft on March 29, but a comprehensive fix was delayed for a long time because of the complicated nature of testing such an important update, according to Stephen Toulouse, a program manager in the MSRC (Microsoft Security Response Center).
"There's absolutely a good reason [for the delay]," Toulouse said in an interview with Ziff Davis Internet News. "The graphics rendering system is an extremely important component of the operating system. It's critical to functioning of operating system. Any time you make a change to such an important component, you absolutely have to ensure you're not introducing new problems."


FROM:
http://www.eweek.com/article2/0,1895,1883850,00.asp


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 11-09-2005 at 08:34 PM.

Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Partition Hard Drives merlin Windows Tutorials 2 02-22-2008 09:05 AM
Critical Windows patch may wreak PC havoc. joe5 Security Watch 0 10-16-2005 03:55 AM
[FIXED] AIM and msn keep sing off and on [censored] is going on? Bighomedog11 [Fixed] Hijackthis! Logs 77 10-01-2005 01:30 AM
Fake Windows Patch Is a Windows Killer. joe5 Security Watch 4 09-03-2005 01:55 AM
[Resolved] Boot up issue enner100 Motherboards 26 08-02-2005 03:08 AM


All times are GMT +1. The time now is 09:29 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top