Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Virus and Vulnerability Roundup
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

New, dangerous Microsoft JPEG exploit code released

Two new 'proof of concept' exploits appeared yesterday

September 23, 2004 12:00 PM ET

IDG News Service - New computer code that exploits a recently disclosed hole in Microsoft Corp.'s Internet Explorer Web browser is circulating on the Internet and could allow remote attackers to take full control of vulnerable Windows machines, according to warnings from antivirus companies and Internet security experts.
Two new "proof of concept" exploit programs first appeared yesterday and were posted to Web sites and Internet newsgroups frequented by security experts. The new code is more dangerous than an exploit for the vulnerability that appeared earlier this week (see story), since it allows malicious hackers to run their own code on vulnerable machines instead of just freezing or crashing Windows systems, according to Johannes Ullrich, chief technology officer at the SANS Institute's Internet Storm Center.
The two new exploits were published yesterday on the security discussion list Full-Disclosure and have also appeared on www.k-otik.com, a French language Web site that specializes in software exploits, Ullrich said.
The exploits take advantage of a flaw in the way Microsoft applications process JPEG image files, a common format for displaying images on the Web. Microsoft designated the flaw a "critical" problem and released a software patch for it, MS04-028, on Sept. 14. A Windows user would have to open a JPEG file that had been modified to trigger the flaw using a wide range of applications, such as the Internet Explorer Web browser or Outlook e-mail client.
The exploits create a JPEG file formatted to trigger an overflow in a common Windows component called Gdiplus.dll, used by Windows, Internet Explorer, Outlook and other applications, Elia Florio, a computer engineer in Rome who created the exploits and posted them to Full-Disclosure, said in an interview with IDG News Service.
The first exploit opens a command shell on a vulnerable Windows system when the rigged JPEG file is opened using Windows Explorer, which is used to browse file directories on Windows systems. While that, in itself, is not damaging, a remote attacker could easily add malicious commands to the script that would run on the affected system, Ullrich said.
The second exploit, published late yesterday, further modifies the attack code to add a new administrator-level account, named simply "X," to affected Windows systems when a JPEG file is opened through Windows Explorer. The account could then be used by the attacker to log into the machine using standard Windows networking features, he said.
In both cases, malicious commands could be executed only by using the permission level of the user running Windows Explorer, he said.
The new exploits could


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Viruses

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

White Papers & Webcasts

Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.  

Effectively Implementing Datacenter Automation
Effectively select and deploy the best datacenter automation solution today!

Aligning IT to Business: The Rising Importance of Application Delivery Networks
Application Delivery Networking (ADN) will play a vital role in helping enterprises incorporate strategic technologies to achieve business initiatives.

Security Pathways to Less Complexity
Find pathways to security solutions, possibly peace of mind about your information security.  

Mitigate Risk, Lower Costs and Improve Network Efficiency
Create a stable IP network that not only meets today's challenges, but is flexible enough to also meet future demands.