Skip to main content

Jpeg exploit virus appears

posted onSeptember 25, 2004
by hitbsecnews

A virus designed to exploit a recent disclosed hole in Internet Explorer is already doing the rounds on the Internet. Security experts have warned it could allow remote attackers to take full control of vulnerable Windows machines.

Two new "proof of concept" exploit programs were posted to French security website www.k-otik.com and the Full-Disclosure news group. The new code is more dangerous than an exploit for the vulnerability that appeared earlier in the week, since it allows malicious hackers to run their own code on vulnerable machines, instead of just freezing or crashing Windows systems, according to Johannes Ullrich, chief technology officer at The SANS Institute's Internet Storm Center.

The exploit takes advantage of a flaw in the way Microsoft applications process jpeg image files, a common format for displaying images on the Web. Microsoft designated the flaw a "critical" problem and released a software patch for it, MS04-028, on 14 September. A Windows user would have to open a jpeg file that had been modified to trigger the flaw using a wide range of applications, such as the Explorer browser or Outlook.

The exploits create a jpeg file formatted to trigger an overflow in a common Windows component called Gdiplus.dll, said Elia Florio, a computer engineer living in Rome who created the exploits and posted them to Full Disclosure.

The first exploit opens a command shell on a vulnerable Windows system when the rigged file is opened using Windows Explorer, an application for browsing file directories on Windows systems. While that, in itself, is not damaging, a remote attacker could easily add malicious commands to the script that would run on the affected system, Ullrich said.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th