Tuesday, January 03, 2006

More on the Vulnerability

Just wanted to provide more on the vulnerability in all versions of windows. Don't forget the fix I reported yesterday.
FT.com / By industry / IT - Windows PCs face ‘huge’ virus threat
“The potential [security threat] is huge,” said Mikko Hyppönen, chief research officer at F-Secure, an antivirus company. “It’s probably bigger than for any other vulnerability we’ve seen. Any version of Windows is vulnerable right now.” The flaw, which allows hackers to infect computers using programs maliciously inserted into seemingly innocuous image files, was first discovered last week. But the potential for damaging attacks increased dramatically at the weekend after a group of computer hackers published the source code they used to exploit it. Unlike most attacks, which require victims to download or execute a suspect file, the new vulnerability makes it possible for users to infect their computers with spyware or a virus simply by viewing a web page, e-mail or instant message that contains a contaminated image. “We haven’t seen anything that bad yet, but multiple individuals and groups are exploiting this vulnerability,” Mr Hyppönen said. He said that every Windows system shipped since 1990 contained the flaw. Microsoft said in a security bulletin on its website that it was aware that the vulnerability was being actively exploited. However an official patch to correct the flaw was not expected to be released until January 10.

No comments: