Advertisement
Promo

Desktop platforms Toolkit

More Windows exploit code published

Joris Evers CNET News

Published: 30 Nov 2005 09:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer code posted on Tuesday can crash vulnerable Windows machines by exploiting a "critical" Windows flaw disclosed by Microsoft in October.

The exploit code takes advantage of a flaw in the way Windows handles certain graphics files. Microsoft provided a patch in November with security bulletin MS05-053 and warned that the vulnerability could create an opening for spyware and Trojan horse attacks.

"Microsoft is aware that detailed exploit code has been published on the Internet for the vulnerability that is addressed by Microsoft security bulletin MS05-053," a company spokeswoman said on Tuesday. Microsoft is not aware of any attacks that use the code, she said. The code was posted on various security Web sites.

"Initial investigation of this exploit code has verified that successful exploitation could lead to a denial-of-service attack...not remote code execution," the Microsoft spokeswoman said. With a denial-of-service attack a computer would crash, while remote code execution would mean the attacker has full control over a PC.

The MS05-053 update fixes bugs in the way Windows renders the Windows Metafile and Enhanced Metafile image formats. Microsoft tagged the patch "critical" for all its current operating system versions. The company said that to exploit the flaws, an attacker could craft an image and trick a Windows user into looking at it on a spoof Web site or in an HTML e-mail, for example.

The public release of the exploit code for the image handling flaw comes just days after computer code that takes advantage of another Windows flaw was posted to the Web. The public posting of exploit code could be a sign that an attack is coming, security experts have said.

Microsoft has urged all customers to apply the most recent security updates to protect their systems.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
76 out of 132 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Microsoft Windows 7 Special Report Special Report

How Microsoft can make Windows 7 a success

How Microsoft can make Windows 7 a success

Comment Many businesses have given Vista a wide berth; Microsoft must focus on five areas to make sure Windows 7 doesn't suffer the same fate, argues TechRepublic's Jason Hiner

More Special Reports

Win a Creative Zen X-Fi2 player and accessories

Win a Creative Zen X-Fi2 player and accessories

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters