First sign of malicious code exploiting Windows Jpeg security flaw

29 Sep 2004

Be the first to comment

A Computing logo

The first malicious codes to exploit security flaws in Microsoft Windows' handling of jpeg image files has appeared on internet newsgroups.

The trojan is embedded in Jpegs that, once downloaded and viewed, allow hackers to gain control of the user's PC.

Microsoft acknowledged the vulnerability and issued a security patch earlier this month but at the time no viruses exploiting the flaw had been seen.

Online newsgroup access provider Easynews found the trojan code in pictures posted to its site earlier this week.

The current situation poses little risk of a major virus attack because the code cannot replicate itself and spread.

But a more serious way to exploit the flaw has also been posted on Bugtraq, a site that tracks and reports flaws in major software products. According to security software provider Finjan, the new method would allow the hacker to take over an end user's PC simply by having them browse a web page that contains the malformed image file using Internet Explorer.

What do you think? Email feedback@computing.co.uk

If you want to be first with the news, visit Computing every day.

Reader comments

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

  • Digg
  • Tweet

Newsletters

Sign up for our FREE newsletters

Do you think the G-Cloud will be a success?

The government’s £60m G-Cloud framework continues to take shape with infrastructure, platform and software-as-a-service suppliers being named on Sunday 19th February. The cloud services will be made available via a CloudStore and it is hoped that it will erode government IT silos, as well as make IT cheaper and more flexible. Do you think the G-Cloud will be a success?

84 %

3 %

10 %

3 %