Windows flaw spawns flurry of attacks

"We estimate 99 per cent of computers worldwide are vulnerable"

NEWS

A flaw in Microsoft's Windows Meta File (WMF) has spawned dozens of attacks since its discovery last week, security experts warned on Tuesday.

The attacks so far have been wide-ranging, the experts said, citing everything from an MSN Messenger worm to spam that attempts to lure people to click on malicious websites.

The vulnerability can be easily exploited in Windows XP with Service Pack 1 and 2, as well as Windows Server 2003, security experts said. Older versions of the operating system, including Windows 2000 and Windows ME, are also at risk, though in those cases the flaw is more difficult to exploit, said Mikko Hypponen, chief research officer at F-Secure.

Hypponen said: "Right now, the situation is bad but it could be much worse. The potential for problems is bigger than we have ever seen. We estimate 99 per cent of computers worldwide are vulnerable to this attack."

The WMF flaw uses images to execute arbitrary code, according to a security advisory issued by the Internet Storm Center. It can be exploited just by the user viewing a malicious image.

Microsoft plans to release a fix for the WMF vulnerability as part of its monthly security update cycle on 10 January, according to the company's security advisory.

Hypponen added: "We have seen dozens of different attacks using this vulnerability since Dec 27. One exploits image files and tries to get users to click on them; another is an MSN Messenger worm that will send the worm to people on your buddy list, and we have seen several spam attacks."

He added that some of the spam attacks have been targeted to select groups, such as one that purports to come from the US Department of State. The malicious email tries to lure the user to open a map attachment and will then download a Trojan horse. The exploit will open a backdoor on the user's system and allow sensitive files to be viewed.

The WMF flaw has already resulted in attacks such as the Exploit-WMF Trojan, which made the rounds last week.

Although Microsoft has not yet released a patch, security vendors such as F-Secure and the Internet Storm Center are noting that Ilfak Guilfanov, a Russian security engineer, has released an unofficial fix that has been found to work.

In its daily security blog F-Secure noted: "Ilfak Guilfanov has published a temporary fix which does not remove any functionality from the system. All pictures and thumbnails continue to work normally."

Security companies also are advising computer users to unregister the related "shimgvw.dll" portion of the Windows platform. Unregistering the dll, however, may also disable certain Windows functions and has not been thoroughly tested, according to a security advisory issued by Secunia.

Despite the potential for a large number of computer users to be affected by exploits related to this vulnerability, Hypponen said the chances of a widespread outbreak from a virus, as people return to work from the long holiday, are unlikely.

He said: "We are still far away from a massive virus. Most people get attacked by this if they [search for something on the internet] and get a million results. They may click on a link that goes to a malicious website or one that has been hacked, and then get infected."

Dawn Kawamoto writes for CNET News.com

Comments

There are 4 comments. Join the discussion

  1. 1. John Klos

    99% of computers worldwide? Windows does not account for 99% of computers worldwide.

    • 4 January 2006 09:58
    • Add comment
  2. 2. SmartITGuy

    You KNOW, Microsoft will use this flaw to leverage users into buying new software. They will ONLY patch Windows XP, and anyone using Windows 2000 or older, who wants their systems fixed or made more secure will be FORCED to buy WIndows XP.
    In alot of cases this will force people to have to buy new hardware.

    So far Microsoft has seen surges in sales of Windows XP for every flaw and exploit that has come out. THIS IS VERY WRONG! Microsoft should not be rewarded for poor programming. What's to stop them from deliberately creating flaws and vulnerabilities to increase sales?

    The LAW needs to step in and FORCE Microsoft to patch "EVERY" version of Windows that is affected by this flaw... AT NO COST TO THE USER.

    • 4 January 2006 16:37
    • Add comment
  3. 3. Rod Moore

    Perhaps the article meant to say that 99% of Windows-based PCs (worldwide) are vulnerable...

    • 4 January 2006 19:04
    • Add comment
  4. 4. Frankly Disgusted

    While this severe WMF vulnerability is no laughing matter, the F-Secure chief's ridiculous 99% remark is.

    It's a great way to ruin your reputation and unless he's been misquoted, quite stupid, too.

    • 5 January 2006 00:57
    • Add comment

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters