New, dangerous Microsoft JPEG exploit released

Saturday, September 25, 2004 by BX | Discussion: WinCustomize News

New computer code that exploits a recently disclosed hole in Microsoft Corp.'s Internet Explorer Web browser is circulating on the Internet and could allow remote attackers to take full control of vulnerable Windows machines, according to warnings from antivirus companies and Internet security experts.

Two new "proof of concept" exploit programs first appeared Wednesday, and were posted to Web sites and Internet news groups frequented by security experts. The new code is more dangerous than an exploit for the vulnerability that appeared earlier in the week, since it allows malicious hackers to run their own code on vulnerable machines, instead of just freezing or crashing Windows systems.

The exploits take advantage of a flaw in the way Microsoft applications process JPEG image files, a common format for displaying images on the Web. The first exploit opens a command shell on a vulnerable Windows system when the rigged JPEG file is opened using Windows Explorer, an application for browsing file directories on Windows systems. While that, in itself, is not damaging, a remote attacker could easily add malicious commands to the script that would run on the affected system.

The second exploit, which was published late Wednesday, East Coast time in the U.S., further modifies the attack code to add a new administrator-level account, named simply "X," to affected Windows systems when a JPEG file is opened through Windows Explorer. The account could then be used by the attacker to log in to the machine using standard Windows networking features.

In both cases, malicious commands could only be executed using the permission level of the user running Windows Explorer.

The new exploits could be spread by a virus in corrupted JPEG images sent as e-mail attachments or served from Web sites. In fact, the scripts could be used to dynamically modify JPEG files as they are sent from a Web server, provided the attacker was able to access the Web server sending the images and place the attack script on it.

While the new exploits work when the JPEGs they create are opened in Windows Explorer, they only crash Windows systems when opened in Internet Explorer or Outlook. However, the scripts could be modified to work with most versions of Microsoft's operating system applications.

Microsoft has issued a fix for the flaw. Get it from
http://www.microsoft.com/security/bulletins/200409_jpeg.mspx
Visceral
Reply #1 Monday, September 27, 2004 8:08 PM
Only Microsoft could make a program in which a hacker could use A PICTURE FILE to create an Admin account on your machine and take full control of it.

Yet another reason to use Mozilla Firefox, as if I needed one.
paxx
Reply #2 Monday, September 27, 2004 9:57 PM
How the hell could you put a virus in an image? It's not even an executable! I'm baffled.
Tesla Tank
Reply #3 Monday, September 27, 2004 10:28 PM
You are wrong in this case. Linux has the same problem. Everything that uses GDI can be exploited by this bug. Do your research before you start to blindly blame someone.
BX
Reply #4 Monday, September 27, 2004 10:34 PM
Paxx, this technqiue is known as "cloaking", try google to findout more stuff on it.
jelvis
Reply #5 Tuesday, September 28, 2004 3:12 AM
Tesla, I thought that GDI was a Microsoft technology?
Septimus
Reply #6 Tuesday, September 28, 2004 4:05 AM
It doesn't affect XP SP2. Only Office XP/2003 and older versions of Windows.
BX
Reply #7 Tuesday, September 28, 2004 9:02 AM
Paul, it effects XP SP2. Read MS Warning.
Psikotik
Reply #8 Tuesday, September 28, 2004 4:21 PM
Reminds me why I use Firefox now.....
grindlestone
Reply #9 Thursday, September 30, 2004 5:56 PM
As far as Operating Systems go, XPsp2 and 2Ksp3 and sp4 don't have this problem. However, if you have Office installed on those machines you'll be in strife if you don't patch. If you have XP and XPsp1 you'll be in trouble (if the exploit hits the web with any force) even without Office.

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01