Three new Windows security holes come at a bad time

From: Shoe (scman_at_hotmail.com)
Date: 12/25/04


Date: Sat, 25 Dec 2004 13:38:18 -0600

Three new Windows security holes come at a bad time
By Angela Gunn, USATODAY.com
Three new vulnerabilities have been discovered in Microsoft’s Windows
operating system, leaving computers running that OS open to possible hacker
attacks – including PCs running the recently released XP SP2 (Service Pack
2).
The vulnerabilities were published on various online security newsgroups and
confirmed by antivirus firm Symantec. The discoveries raise particular
concern since, with the holidays underway, interested worm-writers may have
a significant head start on security professionals hoping to plug the hole.

According to a report on eWeek.com, one of the three vulnerabilities
involves image handling, which has posed problems for Windows and Unix
systems in the past. The other two vulnerabilities involve Windows’ Help
system and its .hlp files, and Windows’ ANI (Automatic Number
Identification) authentication capabilities.

The image-handling problem turned up in LoadImage, a Windows component that
loads icons, cursors or bitmaps on the desktop. An image with a malicious
payload could cause a heap buffer overflow, which would leave a system open
to exploitation.

Exploiting the ANI hole – known as the Windows Kernel ANI File Parsing Crash
and DoS Vulnerability - would require the target to click on a link or open
a message that would load a malicious ANI file. The file could trigger a
denial-of-service attack.

A Chinese security group reports not one but two possible ANI exploits.
Xfocus.org has published details on its Web site.

The Help system hole involves a potential decoding error when Help (.hlp)
files are run. Such an error could cause a heap buffer overflow, which would
(as with the LoadImage vulnerability) leave a system open to exploitation.

Machines running Windows NT, Windows 2000 or Windows XP with SP (Service
Pack) 1 are vulnerable to such exploits. Windows XP users who have applied
the SP2 service pack are protected from the image and ANI vulnerabilities,
but not from all possible aspects of the Help problem.

Users are urged to block e-mail attachments arriving with .hlp files
attached and strongly encouraged to read e-mail in plain-text format to keep
malicious images from utilizing LoadImage.



Relevant Pages

  • SecurityFocus Microsoft Newsletter #179
    ... pinpointing the exact location of security vulnerabilities that are the ... ArGoSoft FTP Server Multiple Vulnerabilities ... Windows file move restriction ... Relevant URL: http://www.securityfocus.com/bid/9761 ...
    (Focus-Microsoft)
  • Black Hat Windows Security 2002 Speakers Announced
    ... With the recent Windows vulnerabilities announced by eEye and @stake as ... BLACK HAT WINDOWS SECURITY BRIEFINGS & TRAINING 2002 IN NEW ORLEANS ADDRESS ...
    (Vuln-Dev)
  • Worm hole found in Windows 2000
    ... A serious flaw has been discovered in a core component of Windows 2000, ... Maiffret, chief hacking officer at eEye Digital Security, said on ... The vulnerabilities affect Windows 2000, ...
    (comp.sys.mac.advocacy)
  • Re: Web Application Testers.
    ... > automatically alerts you to the latest security vulnerabilities please see: ... Platforms: ... A Windows/MS-DOS CGI scanner which scans for 65 remote ... Windows 2000 and Windows NT ...
    (Pen-Test)
  • Is this a hackers trick?? **WARNING**
    ... out whether it was legit or not,,, i have norton security ... >((Microsoft Customer, ... >MS Outlook/Express as well as six new vulnerabilities, ... >malicious Web site operator to open two browser windows, ...
    (microsoft.public.security)