Spotlightingnews

SCI/Tech

Symantec Warns About New Windows Metafile Vulnerabilities

Microsoft’s patch doesn’t seem to have solved all the issues around the WMF bugs

Soon after Microsoft released an early patch for the Windows Metafile (WMF) image processing flaw, a security company warned about multiple memory corruption vulnerabilities in the patched version.

According to Symantec, an attacker could use these problems to carry out denial-of-service (DoS) attacks, or even execute arbitrary code, which usually means complete control of a users' computer.

These bugs might be introduced with the patch issued by Microsoft on Thursday, but apparently, they exploit different functions in the WMF rendering engine.

"Reports indicate that these issues lead to a denial-of-service condition, however, it is conjectured that arbitrary code execution is possible as well," Symantec said.

Everyone that opens an email which contains an attached malicious image, or visits a website that has such images can be attacked through this vulnerability, just as they could before the patch.

According to Symantec, viewing a malicious file in Windows Explorer might automatically trigger the issues. Any gif, jpg, png or tif file can carry malicious code to perform denial of service or run arbitrary code.

Symantec advised Internet users to disable the Windows Picture and Fax Viewer application, just as it did for the original vulnerability.

User Box

» Send to friend
» Print view
» Contact Editor

Search







Posted at 09:59:22 MST (GMT -0700), Monday January 9th, 2006
Comments
Announcement the SpotlightingNews team Posted on Wednesday January 25th, 2006, 10:00:00 EST
We are sorry to announce that we have decided to temporarily disable the comments system from the SpotlightingNews website.

We noticed our users do like to comment and discuss on certain matters, and we added the comment system as you probably noticed or used it. However, some users have been abusing it by spamming, posting off-topic or starting flame wars.

The comment system on this website was meant to allow users to discuss on the topic, add a personal view to objective stories.

The SpotlightingNews team is currently working on a better comment system that will attempt to increase the overall level of comments.

Meanwhile, you can still have your say through our contact page.


Thank you,
The SpotlightingNews team