 |
|
|
JPEG Flaw Exploited
Last
Updated:
November 30, 1999
According to a report published Friday by Netcraft (netcraft.com), code that claims to partially exploit a weakness in Microsoft software's handling of image files has been published.
If the epxloit was used on you it would reportedly enable a hacker to grain control of your esystem by creating a JPEG image that would compromise a range of Microsoft Software, including Microsoft's Office Suite, and most versions of Internet Explorer.
The site publishing the Exploit reports that the code has been downloaded some 32,000 times by Sunday.
This exploit creates a huge problem for IT staffs. Since the extent of the flaw requires patching of almost every machine that runs Microsoft software, any of which could be vulnerable to a JPEG exploit while on the web using internet explorer or reading an HTML e-mail in MS Outlook.
According the Micrsoft's Website the following software packages are effected.
Affected Software:
• Microsoft Windows XP and Microsoft Windows XP Service Pack 1
• Microsoft Windows XP 64-Bit Edition Service Pack 1
• Microsoft Windows XP 64-Bit Edition Version 2003
• Microsoft Windows Server™ 2003
• Microsoft Windows Server 2003 64-Bit Edition
• Microsoft Office XP Service Pack 3
Microsoft Office XP Service Pack 2
Microsoft Office XP Software:
• Outlook® 2002
• Word 2002
• Excel 2002
• PowerPoint® 2002
• FrontPage® 2002
• Publisher 2002
• Microsoft Office 2003
Microsoft Office 2003 Software:
• Outlook® 2003
• Word 2003
• Excel 2003
• PowerPoint® 2003
• FrontPage® 2003
• Publisher 2003
• InfoPath™ 2003
• OneNote™ 2003
• Microsoft Project 2002 Service Pack 1 (all versions)
• Microsoft Project 2003 (all versions)
• Microsoft Visio 2002 Service Pack 2 (all versions)
• Microsoft Visio 2003 (all versions)
• Microsoft Visual Studio .NET 2002
Microsoft Visual Studio .NET 2002 Software:
• Visual Basic .NET Standard 2002
• Visual C# .NET Standard 2002
• Visual C++ .NET Standard 2002
• Microsoft Visual Studio .NET 2003
Microsoft Visual Studio .NET 2003 Software:
• Visual Basic .NET Standard 2003
• Visual C# .NET Standard 2003
• Visual C++ .NET Standard 2003
• Visual J# .NET Standard 2003
• The Microsoft .NET Framework version 1.0 SDK Service Pack 2
• Microsoft Picture It!® 2002 (all versions)
• Microsoft Greetings 2002
• Microsoft Picture It! version 7.0 (all versions)
• Microsoft Digital Image Pro version 7.0
• Microsoft Picture It! version 9 (all versions, including Picture It! Library)
• Microsoft Digital Image Pro version 9
• Microsoft Digital Image Suite version 9
• Microsoft Producer for Microsoft Office PowerPoint (all versions)
• Microsoft Platform SDK Redistributable: GDI+
Visit Microsoft's Site to download the Update Patches for JPEG Explot.
http://www.microsoft.com/technet/security/bulletin/MS04-028.mspx
|
|
 |
|