Advertisement
Promo

Security threats Toolkit

Windows attack code made public

Joris Evers CNET News

Published: 17 Jan 2007 08:48 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer code that exploits a security vulnerability in Windows has been published on the internet, making it more urgent for users of the operating system to patch.

The attack code exploits a flaw in the way Windows handles Vector Markup Language, or VML, documents, which are used for a type of high-quality graphic on the web. The bug lies in a Windows component called "vgx.dll" that supports these files.

Microsoft provided a fix for the flaw last week with security bulletin MS07-004. At the time, the company warned that it had already seen limited cyberattacks exploiting the vulnerability. However, attack code hadn't been available publicly. On Tuesday, exploit code was published to a widely-read online security forum.

"Microsoft is aware that detailed exploit code was published on the internet that may take advantage of the vulnerability addressed by Microsoft security bulletin MS07-004," a company representative said in a statement. "Microsoft encourages all customers to apply the most recent security updates."

Prior to the public posting of the exploit, other code that takes advantage of the flaw had been made available to users of a security testing tool made by Immunity. However, these attack blueprints are private, supplied to people who pay for the tool.

Functionality of the public exploit code appears to be limited, Symantec said in an alert to users of its DeepSight security intelligence service on Tuesday. Symantec was unable to get the exploit to work on English language versions of Windows XP and Windows 2000, the company said. Still, the exploit could provide a starting point for other hackers, Symantec said.

"The author has posted the exact location of the flaw, shown in a screen shot from a binary analyser, increasing the likelihood of other exploits being developed," according to the Symantec alert.

The VML flaw is similar to a bug for which Microsoft rushed out a fix in September after Windows users came under attack. The vulnerability can be exploited by tricking a user into viewing a malicious VML file on a website with Internet Explorer.

All recent versions of Windows are vulnerable when all recent versions of IE, including IE 7, are in use, according to Microsoft. The exception is Windows Vista, which is not affected, the software maker said. Microsoft's patches are distributed via Automatic Updates and on the company's Microsoft Update downloads website.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
20 out of 20 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters