New Windows Metafile Flaws Emerge

January 10th 2006 | Microsoft

Just days after Microsoft patched a critical vulnerability in the way the Windows operating system renders certain types of graphics files, a hacker has published details of two new flaws that affect the same part of the operating system. The new vulnerabilities were posted to the Bugtraq security mailing list today by a hacker using the name "cocoruder."

PCWorldTwo New Windows Metafile Bugs Found

A Microsoft spokesperson insists the publicly released code can simply cause a denial-of-service crash.

"As it turns out, these crashes are not exploitable but are instead Windows performance issues that could cause some WMF applications to unexpectedly exit. These issues do not allow an attacker to run code or crash the operating system. They may cause the WMF application to crash, in which case the user may restart the application and resume activity," said Lennart Wistrand, lead security program manager in the MSRC (Microsoft Security Response Center).

In a blog posting, Wistrand said Microsoft had already identified the issues as part of its ongoing code maintenance and is evaluating them for inclusion in the next service pack for the affected products.

PCMagNew Batch of WMF Flaws Flagged

Compare prices for AntiSpam AntiVirus Software
New Windows Metafile Flaws Emerge
Published in: Microsoft on 2006-01-10