Wednesday, September 10, 2008
Microsoft has identified a number of network security issues in its GDI+ software development platform.
According to the firm, a number of privately reported flaws could potentially allow hackers to execute code on compromised machines by developing specifically crafted image files or web sites.
The software giant warned that users operating with more system privileges were likely to be placed at greater risk than those with lower user rights.
Microsoft announced details of the network security threat in its monthly security update, which also identified bugs in Windows Media Encoder 9, Windows Media Player and Microsoft Office.
Elsewhere, Redmond Developer insisted that the GDI+ vulnerability is the one that is likely to catch the interest of network security researchers, as it echoes a similar vulnerability identified in 2005.
"There are four advisories and eight vulnerabilities this month but it comes down to GDI+ ... That is what is going to be on everyone's mind," commented analyst Tyler Reguly.
Related News:
SMBs giving security bigger slice of budget pie - 1.6.2009
A new report from a research firm has found large corporations and SMBs will be using a bigger percentage of their IT budgets toward security this year.
Gaza strip conflict spurs cyberattack - 1.2.2009
Last weekend, more than 300 Israeli websites have been defaced in massive cyberattacks in a form of retaliation for the brutal conflict emerging between the Jewish state and Hamas targets in the Gaza Strip.
DOS attack for smartphones possible - 1.2.2009
A German security researcher has shown how a malicious text message may be used as a denial-of-service (DOS) attack for some Nokia smartphones that is now prompting some security providers to release updated software.
Big network security threat in 09: angry employee - 12.30.2008
While network security has evolved to block botnets and various phishing attacks, there is still no cure for the "malicious insider" with the knowledge and the will to take down a company from the comfort of their cubicle.
Childs stands trial for hijacking San Francisco network - 12.29.2008
A San Francisco superior court ruled yesterday that there is enough evidence for Terry Childs, a former network administrator, to stand trial for allegedly hijacking the city's online system he helped design.


