Microsoft confirms graphics engine flaw

Powered by SC Magazine
 

Out-of-band patch unlikely.

Microsoft has confirmed the existence of a vulnerability affecting the graphics rendering engine of some Windows operating systems.

The Redmond giant said it was working on a patch but that it was unlikely to be released separately as an emergency out-of-band update.

"We are not aware of any affected customers, nor of any active attacks targeting customers [using this vulnerability]," Microsoft's senior marketing communications manager for trustworthy computing Angela Gunn said.

The vulnerability was first disclosed at a security conference in South Korea last month, according to the SANS Technology Institute.

According to the Institute's Johannes Ullrich, the vulnerability affected all current versions of Windows, barring Windows 7 and 2008 R2.

"The vulnerability is exploited via malicious thumbnail images that may be attached to various documents (e.g. Microsoft Office documents)," Ullrich stated.

"The most likely exploit vector would use e-mail attachments. However, it is also possible to use network shares."

Copyright © iTnews.com.au . All rights reserved.


Microsoft confirms graphics engine flaw
 
 
 
Top Stories
Qld Transport to replace core registration system
State's biggest citizen info repository set for overhaul.
 
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
More 4G from Optus in Darwin
Nov 21, 2014
Click to see where Optus has expanded coverage to the suburbs near Darwin.
Optus steps up regional 4G coverage
Nov 20, 2014
Once 700Mhz services are working, Optus claims regional users will have a "faster and more ...
This Huawei 4G phone costs $99
Nov 12, 2014
The $99 Huawei Ascend Y550, available through Vodafone, enters the budget market as one of the ...
4G smartphones: Microsoft's Lumia 830
Nov 7, 2014
Microsoft has announced its flagship Windows Phone, the Nokia Lumia 830 4G, will be available in ...
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  21%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 847

Vote