By Jennifer LeClaire TechNewsWorld Part of the ECT News Network
01/03/06 10:07 AM PT
"Current WMF activity has already risen to levels similar to that of the emerging zero-day attacks against Internet Explorer in the fall of 2003," said Ken Dunham, senior engineer at iDefense. "In that situation, attacks skyrocketed over a one month period, which is highly likely for the existing WMF attacks in early 2006."
eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.
It's not exactly a happy new year for millions of PC users exposed to a Microsoft (Nasdaq: MSFT) Windows flaw that leaves the door wide open for hackers, Trojans, worms, spyware and other malicious attacks.
F-Secure first reported the zero-day vulnerability on Dec. 27. Microsoft does not plan to issue a patch until Jan. 10. In the meantime, virus writers could have a field day with the vulnerability, according to security experts.
The vulnerability is related to Windows' WMF files. Windows metafiles are image files used by popular applications, such as Microsoft Word. So far WMF exploits typically have been used to install spyware and adware, although the threat of virus and worm exploits remains.
Viruses Coming
"So far, we've only seen this exploit being used to install spyware -- or fake antispyware and antivirus software -- on the affected machines," F-Secure Chief Research Officer Mikko Hypponen said. "I'm afraid we'll see real viruses using this soon. We've seen 70 different versions of malicious WMF files so far."
The WMF exploit has been used with a clear criminal motivation to install spyware and to dupe ordinary consumers into purchasing fake security products for their computers, Hypponen pointed out.
Users can be infected simply by visiting a Web site with an image file containing the WMF exploit. Internet Explorer users are at the greatest risk of automatic infection, while Firefox and Opera browser users are prompted with a question whether they'd like to open the WMF image or not. They get infected too if they answer "Yes."
Microsoft's Response
Microsoft and CERT.ORG issued bulletins on the Windows Metafile vulnerability and also announced a workaround, while Microsoft is creating a patch.
The vulnerability applies to all the main versions of Windows: Windows ME, Windows 2000, Windows XP and Windows 2003, Microsoft confirmed. This means there are hundreds of millions of vulnerable computers at the moment.
"We are working closely with our antivirus partners and aiding law enforcement in its investigation," Microsoft said in a security bulletin on its Web site.
Unsuspecting PC Users
Consumers are starting to report spyware problems and performance issues without realizing they are related to the zero-day attack, said Ken Dunham, senior engineer at threat intelligence firm iDefense.
In many situations, consumers have partially removed code, but they do not have a full understanding of how much data is compromised, and they do not realize that malicious code is likely still functional on their computer, Dunham told TechNewsWorld.
"Current WMF activity has already risen to levels similar to that of the emerging zero-day attacks against Internet Explorer in the fall of 2003," he noted. "In that situation, attacks skyrocketed over a one-month period, which is highly likely for the existing WMF attacks in early 2006."
WMF exploitation started the year with a bang and a pop that clearly wins the title as the first significant malcode threat of 2006, Dunham said, and it will likely become a long-term persistent threat utilized by Trojan and bot hackers throughout 2006.
Blueprint Drawn for Mobile Device Security January 03, 2006
While the Trusted Network Connect specification is promising, a number of issues could curb its acceptance. "Vendors have not always been in synch about what is the best way to offer security functions to handheld device users," noted Gartner Group's John Pescatore.
Related Stories
Study: Data Loss, Network Vulnerabilities Top Security Issues December 29, 2005
"Security issues continue to mount, impacting all users of computer technology and threatening the data, endpoints and networks of every organization," said Al Sisto, chairman, president and chief executive officer of Phoenix Technologies.
Google, Microsoft Settle Suit Over China-Based Executive December 23, 2005
Preliminary court proceedings had already resulted in some interesting, if disputed, anecdotes about the rivalry between Microsoft and Google, including one story in which Microsoft CEO Steve Ballmer was said to have thrown a chair to emphasize his desire to crush Google.
EU Gives Microsoft Deadline to Comply or Face Fines December 22, 2005
"We will continue to take new steps to address each new demand ... in order to ensure our compliance with the commission's March 2004 decision in a timely manner," said Microsoft General Counsel Brad Smith. "At the same time, we will contest today's statement to the full extent permitted under EU law."
Related News Alerts
More by Jennifer LeClaire
The Digital Car: Cool Automotive Accessories, Part 2 January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.