• On TechRepublic: Hidden Vista tricks boost productivity

January 17, 2006 12:20 PM PST

Windows Vista gets image flaw fix

  • Font size
  • Print
A security update for preview releases of Windows Vista fixes the same image-rendering vulnerability found in earlier versions of the operating system.

Microsoft on Friday released what's believed to be the first security patch for Windows Vista, the next version of its flagship operating system. Updates are available for Windows Vista beta 1, released in July, and last month's Community Technology Preview release. The final version of Windows Vista is due by year's end.

The patch fixes a vulnerability in the way the operating system's Graphics Rendering Engine processes Windows Meta File images. That bug was first discovered late last month as it was being exploited by cybercriminals to load spyware, adware and other malicious code onto the PCs of unwitting Windows users.

Microsoft earlier this month broke its monthly patching cycle to rush out a "critical" fix for Windows XP, Windows Server 2003 and Windows 2000. Vista is not listed in Microsoft's security bulletin as vulnerable, but the updates for the forthcoming OS release refer to the same page on Microsoft's support Web site for details on the security issue.

The WMF security problem drew an unusual response in the security world. One expert crafted his own fix for the problem, before Microsoft provided its security update. Industry experts called the WMF bug one of the most serious Windows flaws to date and recommended the third-party fix. Microsoft, meanwhile, said users were not under massive attack.

The flaw in the way WMF images are handled is not a typical security vulnerability that can be exploited by attackers, such as a buffer overflow. Instead, the WMF problem lies in a software feature being used in an unintended way, Microsoft has said.

When WMF files were designed in the late 1980s, a feature was included that allowed the image files to contain computer code that could be executed on a PC to increase usability on the slow systems of yesteryear. The graphics file format was introduced with Windows 3.0 in early 1990.

It was found that the WMF feature could be abused. A vulnerable Windows computer might have been compromised simply if the user visited a Web site that contained a malicious image file, or opened such a file in an e-mail message or an Office document.

See more CNET content tagged:
Microsoft Windows Metafile, flaw, Microsoft Windows Vista, security, Microsoft Windows

Add a Comment (Log in or register) 3 comments
Congratulations Joris
by n3td3v January 17, 2006 12:43 PM PST
You've managed to write an article that doesn't upset anyone.
Reply to this comment
The first security related article
by n3td3v January 17, 2006 12:49 PM PST
The first security related article on Cnet without rent-a-quotes from a "researcher" or "expert". I'm amazed... did they put something in the water?
Reply to this comment
Interesting
by thedreaming January 18, 2006 7:53 AM PST
When this security flaw came out only after a third party made their own fix and everyone else started using it, that's when microsoft sent out their fix ahead of schedule. Interesting...
Reply to this comment
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (-2.88%) -0.55 18.56
Dow Jones Industrials (-2.91%) -243.48 8,132.76
S&P 500 (-3.14%) -26.56 818.66
NASDAQ (-2.64%) -38.16 1,407.40
CNET TECH (-3.10%) -32.44 1,012.57
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right