Graphics Tools - Publish.com
Publish.com Ziff-Davis Enterprise  
SEARCH · ONLINE MEDIA · MOBILE · WEB DESIGN · GRAPHICS TOOLS · PRINTING · PHOTO · TIPS · OPINIONS
Home arrow Graphics Tools arrow Microsoft Patches Critical WMP, Windows Flaws
Microsoft Patches Critical WMP, Windows Flaws
By Matt Hines

Rate This Article:
Add This Article To:
The software giant released its monthly security update, offering seven different fixes including an anticipated patch for critical flaws in its Windows Media Player.

Microsoft released fixes for seven vulnerabilities in its Windows products as part of its monthly security update, including an anticipated patch addressing remote exploitable code execution issues in its Windows Media Player.

As expected, the company released five advisories with "important" severity ratings and two bulletins meant to solve "critical" flaws, the company's highest severity rating, as part of the bulletin.

For WMP, one of the software giant's most widely deployed products, Microsoft said that a critical vulnerability exists in the software's Graphics Rendering Engine that could allow for remote code execution.

The software maker said the WMP issue is related to the manner in which the application handles the processing of bitmap files.

According to the patch update, the security issue identified could allow an attacker to remotely compromise Windows-based systems using WMP and potentially gain control over such machines.

Microsoft instant messaging goes mobile. Click here to read more.

Someone targeting the flaw could exploit the vulnerability by constructing a malicious bitmap file that allows remote code execution if a user visits a malicious Web site or views an e-mail message, Microsoft said.

However, the firm claims that significant user interaction would be required to exploit the vulnerability.

A second, less dangerous WMP issue addressed in the update involves a vulnerability in Windows Media Player plug-ins with non-Microsoft Internet browsers that could also allow for remote code execution.

Microsoft said that issue was related to the manner in which WMP's plug-in handles malformed EMBED elements.

The second critical patch, labeled as a cumulative security update for Microsoft's ubiquitous Internet Explorer Web browser, includes a number of "hotfixes" for the product released since last month's security update.

Microsoft said the vulnerabilities covered by the patch are related to a remote code execution issue in the way Explorer handles WMF (Windows Metafile) images.

Microsoft said an attacker could potentially exploit the flaw by constructing a WMF image that allows remote code execution when an Explorer user visits a malicious Web site, opens or previews an e-mail message, or opens a specially crafted attachment in e-mail meant to target the vulnerability.

Of the less serious flaws covered in the patch update, Microsoft addressed one issue in its popular PowerPoint presentation software that it said could allow for unintended information disclosure by users.

The company said that an attacker who successfully exploited the vulnerability could remotely attempt to access objects in a computer's TIFF (Temporary Internet Files Folder) explicitly by name.

Microsoft gives workarounds for new IE, Windows flaws. Click here to read more.

Microsoft said that the PowerPoint vulnerability would not allow an outside attacker to execute code or to elevate their user rights directly on someone else's PC, but the firm said the flaw could be used to produce useful information about the computer that could be used to try and further compromise the affected system.

Other vulnerabilities addressed by the update included a flaw in the company's Windows XP and Windows server software related to its Web Client Service, and another related to those products' TCP/IP settings, both of which could allow for denial-of-service attacks on Web sites.

Another problem tackled in the update is a flaw in Microsoft's Windows or Office products related to the software's Korean Input Method Editor, which could allow for unauthorized elevation of privileges on machines running the software.

Check out eWEEK.com's for Microsoft and Windows news, views and analysis.


Discuss Microsoft Patches Critical WMP, Windows Flaws
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Graphics Tools Articles          >>> More By Matt Hines
 


Buyer's Guide
Explore hundreds of products in our Publish.com Buyer's Guide.
Web design
Content management
Graphics Software
Streaming Media
Video
Digital photography
Stock photography
Web development
View all >

ADVERTISEMENT


FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 10, 4 p.m. ET
    Eliminate the Drawbacks of Traditional Backup/Replication for Linux
    with Michael Krieger. Sponsored by InMage
  • Dec 11, 1 p.m. ET
    Data Modeling and Metadata Management with PowerDesigner
    with Joel Shore. Sponsored by Sybase
  • Dec 12, 12 p.m. ET
    Closing the IT Business Gap: Monitoring the End-User Experience
    with Michael Krieger. Sponsored by Compuware
  • Dec 12, 2 p.m. ET
    Enabling IT Consolidation
    with Michael Krieger. Sponsored by Riverbed & VMWare
  • VTS
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT
    IT LINK DISCUSSION - MIGRATION
    A Windows Vista® migration introduces new and unique challenges to any IT organization. It's important to understand early on whether your systems, hardware, applications and end users are ready for the transition.
    Join the discussion today!



    .NAME Charging For Whois
    Whois has always been a free service, but the .NAME registry is trying to change that.
    Read More >>

    Sponsored by Ziff Davis Enterprise Group

    NEW FROM ZIFF DAVIS ENTERPRISE


    Delivering the latest technology news & reviews straight to your handheld device

    Now you can get the latest technology news & reviews from the trusted editors of eWEEK.com on your handheld device
    mobile.eWEEK.com

     


    RSS 2.0 Feed


    internet
    rss graphic Publish.com
    rss graphic Google Watch

    Video Interviews


    streaming video
    Designing Apps for Usability
    DevSource interviews usability pundit Dr. Jakob Nielsen on everything from the proper attitude for programmers to the importance of prototyping in design to the reasons why PDF, Flash and local search engines can hurt more than they help.
    ADVERTISEMENT