MS Warns of Exploit for Windows Flaw

By Ed Oswald | Published November 29, 2005, 7:46 PM

Microsoft on Tuesday acknowledged the existence of exploit code that could crash vulnerable Windows computers through a flaw in image file handling. The company had provided a patch for the problem as part of its November Patch Tuesday security update.

The flaw affects the way the OS renders Windows Metafile and Enhance Metafile image formats. While the vulnerability could lead to remote code execution, Microsoft says that, based on its research, this particular exploit would only cause a denial of service attack. So far, the company has not been made aware of any reported attacks using the code.

Comments

View comments by with a score of at least

lol I love doinbg a fresh install of ANY windows.... go to windows update... get the 6-18 critical updates, the 40+ other updates (total of 46-58 updates), reboot and thinking I am now all updated and secure... nope... gotta do 18+ more security updates... now I am done... nope... 4-10 more security updates to the security updates... LOL

Score: 0

|

Yup, that's why you slipstream the updates into a Windows installation directory on your computer as you go. That way, you can burn that to a CD any time you need it, install Windows from that CD, and all the updates will already be applied.

It's amazing how much time that saves, especially when you have a bunch of workstations that need to be reloaded.

Score: 0

|

ahh...bugs..bugs...n more bugs... Hey M$, can you guys send my a bug fix for my cold????? lol

Score: 0

|

*sigh*

Besides, who uses Metafile these days?

Score: 0

|

Hell every OS has issues and patches! Linux has patches at least once a week, MAC has been updating a LOT lately, and MS once a month. So whose better now? Sorry, I forgot.

Score: 0

|

At this point, there's no such thing as better overall... only better for circumstance based on your use and preferences.

Score: 0

|

Yup.

Windows for desktops.

Linux for servers.

Mac for... well... umm... a nice paperweight?

(ooh... that's flame bait right there... yikes)

**EDIT**
To Mac's credit, they have been the standard for multimedia development for a long time. However, I think Windows is catching up in that department. That's just my opinion anyway.

Score: 0

|

You mean:

Windows for games,

Mac for multimedia work (I heard it's good with graphics)

Linux for EVERYTHING ELSE.

"Mac for... well... umm... a nice paperweight?"
lol, an expensive papweight maybe :P

Score: 0

|

I was being sarcastic. Normally I would have had about 30-45 posts about that now. The only thing I think there is different is that facts are getting harder to lie about now.

Score: 0

|

That or the bait was just too obvious to take. ;o)

Score: 0

|

I will resign IT before I accept an administration job that requires maintaining Linux servers. I'll stick to my Windows Servers, lol. I'll continue to use *nix systems from a user perspective and web development and leave the server administration to our *nix guys.

And it works out... they come to me with all their Windows issues. :)

Oh and btw, LMAO @ your Mac comment... I won't call it a joke, because as far as I'm concerned it's reality. :)

Score: 0

|

Meh, the article was posted late... give it until tomorrow, lol.

And btw, I know you were being sarcastic... I was too in hopes someone like wincement would take it and run with it.

Score: 0

|

I don*t think that this is right since windows for beginers mac for intermediate and linux for professional that is why each one has it's advatges and disadvantges

Score: 0

|

You couldn't have said it better.

Score: 0

|

WOW, Linux isn't THAT hard.

:-P

Score: 0

|

Happy to oblige =p

Score: 0

|

LMAO MACs are for people that never learn that everything u can do on a MAC can be done better, faster, and cheaper on a Windows AMD box, and Linux has it's uses.

Score: 0

|

Not everyone views everything as simply a tool. Not everyone must have the fastest tool for the job. Some people view ease, presentation, and style as a higher priority than raw speed.

It's not that they don't know they can get a faster machine, it's simply that they don't *want* one if it means giving up the MAC OS.

And no, I ain't one of those folks, but I know a few.

Score: 0

|

This is simply prejudiced seeing, man.

The new Apple G5 Quads are the fastest machines currently available on the consumer market.And on top of that: double dual core machines, which would equal or top the Quads, are a lot more expensive than the new Quads from Apple.

Simply NOT TRUE what you say. Full stop.

And - no, I am NOT an Apple fan, never had an Apple computer in my whole life. But what is true is simply true . . .

Score: 0

|

I don't believe any MAC is faster than the AMD 64's I want some proof.

Score: 0

|

Power is power, and software is software.

Sure, you've got all that power, but what can you do with it?

Unless you have a home studio, you really can't do anything with it. However, for that use, it's probably the best.

Score: 0

|

There are no MAC's faster than the 64's... anyways, the only reason they resorted to the quad is because their feeble chip couldn't break the 3.0, so they had to do SOMETHING to at least try to keep up with the rest of the world :)

Score: 0

|

The PDF redaction problem: TSA may have been using old software

Betanews tests and research reveals that if the Transportation Security Administration was using modern software, it might not have a security issue now.

Google Maps doesn't prevent car accidents, only search accidents

This week, Google updated Maps for Android 3.3.1, adding topography, nearby points of interest, and error reporting.

The $1 DVD rental debate: LA group says Redbox will lose movie makers $1B

A report from the Los Angeles Economic Development Corporation says cheap Redbox DVD rentals could seriously damage the movie business.

After telling US to mind its own business, Kroes slaps caps on Rambus royalties

The holder of many patents worldwide pertaining to DDR memory offered to reduce its royalty stake in that technology, and today the EU said yes.

Third-party mobile browsers Skyfire and Bolt give Opera a run for its money

Opera may be the biggest name in third party mobile browsers, but Skyfire and Bolt are charging forth with compelling updates.

In a peace offering to newspapers, Google offers a new news format

It's probably not a solution to the woes of major news publishers, but Living Stories may gather a few of those publishers together in search of one.

DOJ: Microsoft interop docs are now 'substantially complete'

A major milestone in the US Government's oversight of Microsoft is passed, as the Justice Dept. is now saying the company's protocol documents make sense.

First impressions of Droid: Easy, breezy, friendly, if a little fat

Though it's not quite as well-polished as Apple's iPhone OS, the version of Android that Motorola's Droid phone sports is still a breeze to use.

EC's Kroes to US senators: Mind your own business on Oracle + Sun

UPDATED The EU's antitrust chief told the United States Senate Tuesday that any merger that takes place in the world is more her affair than theirs.

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.