Quantcast

Microsoft Fixes Critical Windows Graphics Problem

Vulnerability involves processing of Windows Metafile images.

Robert McMillan, IDG News Service

  • 0 Yes
  • 0 No

SAN FRANCISCO -- Microsoft today issued a patch that addresses three critical security vulnerabilities in the way that its operating system processes Windows Metafile images. The patch, called Windows Update MS05-053 was released as part of the Redmond, Washington, company's monthly security update process.

The Metafile vulnerabilities, which affect most versions of Windows, could theoretically be exploited to allow a user to shut down or even gain control of an unpatched system by tricking a user into viewing a maliciously formatted Metafile image. Microsoft's explanation of the problem may be found here.

Windows Metafile is a graphics format used by some computer-aided design applications. Files that use this format have either a .wfm or .emf extension, according to a spokesperson for Microsoft's public relations agency.

How They Might Be Used

Though the vulnerabilities are rated "critical" by Microsoft, they may not be widely exploited according to Neel Mehta, team leader of Internet Security Systems' X-Force group. "There's still some user interaction required to exploit these issues, so we expect to see them used in the more sophisticated targeted attacks that we see, but it's unlikely that they'll be used in a widespread attack," he said.

The most likely way for an attacker to take advantage of these bugs would be by sending e-mail with a malicious graphic and hoping that it would be opened in Microsoft Outlook's preview pane. Attackers could also trick users into viewing such an image on a Web site, Mehta said.

The bugs are similar to one that was patched in Macromedia's Flash player earlier this week. That flaw, also rated critical, could be exploited in Macromedia Flash files, which have the extension .swf.

The Windows Metafile problems affect virtually all supported versions of Windows, according to Microsoft's statement. However, Windows 98, Windows 98 Second Edition, and Windows Millennium Edition are not affected, the statement said.

  • Recommend this story?
  • 0 Yes
    0 No

"Microsoft Fixes Critical Windows Graphics Problem" Comments

Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.

Featured APC Accessories For Your System
10% Off Entire Cart at Online Store

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

  • HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
  • Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...

PC World's Marketplace