Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Virus and Vulnerability Roundup
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

New, dangerous Microsoft JPEG exploit code released

Two new 'proof of concept' exploits appeared yesterday

September 23, 2004 12:00 PM ET

IDG News Service - New computer code that exploits a recently disclosed hole in Microsoft Corp.'s Internet Explorer Web browser is circulating on the Internet and could allow remote attackers to take full control of vulnerable Windows machines, according to warnings from antivirus companies and Internet security experts.
Two new "proof of concept" exploit programs first appeared yesterday and were posted to Web sites and Internet newsgroups frequented by security experts. The new code is more dangerous than an exploit for the vulnerability that appeared earlier this week (see story), since it allows malicious hackers to run their own code on vulnerable machines instead of just freezing or crashing Windows systems, according to Johannes Ullrich, chief technology officer at the SANS Institute's Internet Storm Center.
The two new exploits were published yesterday on the security discussion list Full-Disclosure and have also appeared on www.k-otik.com, a French language Web site that specializes in software exploits, Ullrich said.
The exploits take advantage of a flaw in the way Microsoft applications process JPEG image files, a common format for displaying images on the Web. Microsoft designated the flaw a "critical" problem and released a software patch for it, MS04-028, on Sept. 14. A Windows user would have to open a JPEG file that had been modified to trigger the flaw using a wide range of applications, such as the Internet Explorer Web browser or Outlook e-mail client.
The exploits create a JPEG file formatted to trigger an overflow in a common Windows component called Gdiplus.dll, used by Windows, Internet Explorer, Outlook and other applications, Elia Florio, a computer engineer in Rome who created the exploits and posted them to Full-Disclosure, said in an interview with IDG News Service.
The first exploit opens a command shell on a vulnerable Windows system when the rigged JPEG file is opened using Windows Explorer, which is used to browse file directories on Windows systems. While that, in itself, is not damaging, a remote attacker could easily add malicious commands to the script that would run on the affected system, Ullrich said.
The second exploit, published late yesterday, further modifies the attack code to add a new administrator-level account, named simply "X," to affected Windows systems when a JPEG file is opened through Windows Explorer. The account could then be used by the attacker to log into the machine using standard Windows networking features, he said.
In both cases, malicious commands could be executed only by using the permission level of the user running Windows Explorer, he said.
The new exploits could


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Viruses

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.