Personal Tech Pipeline | Windows Media Player Worm Set To Strike

White Papers

Sponsor Resources

Free Newsletter GlossaryContact UsAbout Us
Players & CamsPhones & PDAsHome & AutoOnline

February 16, 2006

Windows Media Player Worm Set To Strike

Courtesy of TechWeb News

UPDATE: This story was updated at 4:54PM ET Thursday.

An exploit against the Windows Media Player vulnerability disclosed by Microsoft two days ago is nearly finished, a security company said Thursday, and may be only hours away from hitting unpatched users.

The bug, which was made public Tuesday in security bulletin MS06-005, allows attackers armed with malicious .bmp image files to hijack Windows PCs.

"There are two exploits circulating," said Mike Puterbaugh, the vice president of marketing at eEye Digital Security, the Aliso Viejo, Calif.-based company which first uncovered the Media Player vulnerability.

"One is somewhat minor, and can cause a denial-of-service, but the second we're taking far more seriously," said Puterbaugh. "It's 95 percent there as a propagated mass attack.

"All the guy needs to do is add shell code to it to remotely exploit machines."

The exploit, which was posted to the Bugtraq security mailing list is "minutes or days from being completed," Puterbaugh said. "The exploit hasn't been able to reliably write to the same part of memory every time, but once he gets that, it's game over."

The exploit's author -- identified only as "ATmaCA" -- claimed that the attack would work against Windows 98, Millennium, 2000, NT, XP, and 2003 Server systems. He also acknowledged that he was having trouble wrapping up the exploit.

"In this vulnerability, payload is loaded to different places in memory each time," a comment in the proof-of-concept code read. "But some time is very easy to call our shell code…but some times not."

While experts believed that the Windows Media Player flaw would be used by spyware and adware purveyors to silently install malicious software, as they had used the Windows Metafile bug that surfaced in December 2005, Puterbaugh said eEye's researchers believed ATmaCA would package the exploit into a mass-mailed, and self-propagating, worm.

Users can download Microsoft's patch via Windows Update, Microsoft Update, or direct from the developer's Download Center.

E-mail This Story
Print This Story
Reprint This Story

Get the latest Personal Tech news, product info, and trends every week.

Related Content

  Right-click and choose Copy to extract RSS Feed URL  Personal Tech Pipeline's Main RSS Feed
  Right-click and choose Copy to extract RSS Feed URL  Personal Tech Pipeline's Blog RSS Feed

Keeping Up To Date On Enterprise Server Tech?
Review our compilation of columns on server security, database software, and Linux issues.
How to Achieve High Performance Through IT
Learn to achieve high performance by aligning IT to
strategic objectives and solutions to unlock that value.
Using Current Performance to Shape
Future Results

Hear new strategies for improving business
performance and results.

<A HREF=";FlightID=48963&amp;AdID=81851&amp;TargetID=347&amp;Segments=118,902,1411,3108,3448,4763,5080&amp;Targets=347,2625,2878,4234&amp;Values=34,46,51,63,77,85,93,100,140,205,222,227,442,645,646,1184,1405,1431,1766,1785,1798,1901,1925,1945,2217,2299,2329,2352,2678,2787,2956,3244,3256,3347,3385&amp;RawValues=&amp;Redirect=" target="_top"><IMG SRC="" WIDTH=125 HEIGHT=125 BORDER=0></A>
Editor's Picks

Well, Microsoft has "unfolded" its "Origami" ultra-mobile PC platform Thursday. It turned out to be a full-featured PC smaller than a tablet but bigger than a PDA. Are you impressed?
Yes! I want one!
Sort of. We'll see.
No! It's too big for a pocket and too small for real computing. What's the point?

In search of personal tech products? See our new Product Finder, where you'll find personal computing devices, communications solutions, security products, and more.

Trend Micro Enterprise Anti-Spyware Solutions
"Trend Micro is delivering what enterprise customers want." -The Forrester WAVE/Enterprise Anti-Spyware, Q1 2006/Forrester 2006. Download a FREE 30-day trial of Trend Micro Anti-Spyware Solutions for Enterprise Today.

Prevent Information Leaks from your Network
With GTB Inspector Appliance. Free Trial (March 2006 only). GTB Inspector is a hardware appliance. It is installed easily and transparently on the network edge and prevents leaks of confidential information to the Internet.

Cost-Effectively Secure Sensitive Data
Encrypting data in servers and databases can address security gaps and privacy legislation. Ingrian DataSecure Platforms offer granular encryption, seamless integration, and centralized security management. Combat data theft--with unprecedented ease and cost effectiveness. Download a white paper that outlines best practices for securing data.

Symantec Backup Solutions
Desktop to Data Center Protection. Explore the Official Symantec Site.

SEC & HIPAA IM Compliance
Satisfy regulatory and compliance requirements for instant messaging.

Buy a Link Now

Top ten search terms from the TechWeb TechEncyclopedia
The powerful new Sun FireTM T2000 server. Try it risk-free for 60 days. a>
Mobilized Solutions Guide: Find and compare solutions for your business
Top Requested White Paper Categories from TechWeb White paper Library
Top ten search terms from the TechWeb TechEncyclopedia