• On CHOW: Sexy vampire party
January 17, 2006 2:21 PM PST

WMF flaw not intentional, Microsoft says

by Joris Evers
  • Font size
  • Print
  • Post a comment

Microsoft has denied a suggestion that a widely-publicized security vulnerability in its Windows operating system is a secret "back door" added by the software maker as a way to access PCs.

"Now, there??s been some speculation that ... this trigger was somehow intentional. That speculation is wrong," Stephen Toulouse, a program manager in Microsoft's Security Response Center, wrote on a Microsoft corporate blog Friday.

On Thursday last week, researcher Steve Gibson suggested that the image processing flaw in Windows is so bizarre that it must have been intentional. The suggestion caused a deluge of comments on Slashdot and many responses to security mailing lists, with most dismissing the back door theory.

The flaw lies in the way the Windows Graphics Rendering Engine processes Windows Meta File images. The bug was first discovered late last month as it was being exploited by cybercriminals. Microsoft rushed out a fix on Jan. 5, breaking its monthly patching cycle.

Toulouse's comment is part of a blog post that discusses the history of the vulnerability and how it was introduced in Windows. He mentions that WMF support was first included with Windows 3.0 in early 1990, a" different time in the security landscape." Microsoft has said it was unfamiliar with this type of attack vector and will scour its code for similar problems.

Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
advertisement

A CNET Conversation with Eric Schmidt

CNET's Tom Krazit and Molly Wood sit down with Google CEO Eric Schmidt to discuss the future of Android, the Chrome OS, the problem of real-time search indexing, and more.

Verizon tests sending RIAA copyright notices

The No. 2 phone company, known for its reluctance to intervene in antipiracy cases, strikes an agreement to forward copyright notices on behalf of the music industry.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right