main
Report a problem

First exploit based around Windows code leak

Mr magoo   on 16 February 2004 - 21:46 · 72 comments & 7194 views

Advertisement (Why?)
Slashdot and Security Tracker are reporting that the first virus released based on exploits found in the leaked Windows source code has been released.

"A vulnerability was reported in Microsoft Internet Explorer (IE) version 5. A remote user can execute arbitrary code on the target system. It is reported that a remote user can create a specially crafted bitmap file that, when loaded by IE, will trigger an integer overflow and execute arbitrary code.

The author states that this flaw was found by reviewing the recently leaked Microsoft Windows source code. The flaw reportedly resides in 'win2k/private/inet/mshtml/src/site/download/imgbmp.cxx'. The report indicates that IE 5 is affected but that IE 6 is not affected."

The Security Tracker website has more detailed information (and source code from windows) on the virus and how exactly it exploits Internet Explorer v. 5. Whether Microsoft will even bother to fix this is debatable; As it's not an issue for IE 6 it would seem unlikely.

News source: Slashdot.org
View: Security Tracker + Virus Information

Post a comment · Send to friend Comments · There are 72 additional comments
#1 vetDazzla on 16 Feb 2004 - 21:53
There are more people using IE5 then there are Mozilla, Opera, Firefox, netscape etc. (Based on Google's Zeitgeist)
(1 reply) #2 on 01 Jan 1970 - 00:00
#2.1 vetMr magoo on 16 Feb 2004 - 21:59
Well Sawyer, i guess that solves the problem then.
(1 reply) #3 on 01 Jan 1970 - 00:00
#3.1 vetMr magoo on 16 Feb 2004 - 22:27
That link was to the Press release; are you really sure this was patched up - do you have a KB article or a specific patch link>?

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)