1. Home
  2. Computing & Technology
  3. Internet / Network Security
Network Security Blog

From Tony Bradley, CISSP-ISSAP, for About.com

JPEG Exploit Toolkit In The Wild

Friday September 24, 2004
Last week Microsoft released Security Bulletin MS04-028 regarding a Critical flaw in the way JPEG graphic images are processed. The vulnerability affects a wide range of Microsoft operating systems and products and unfortunately patching to protect against the flaw being exploited requires separate patching for each affected platform and application. A proof-of-concept exploit had been made public last week which simply caused a denial-of-service and was not considered too serious. Now it is being reported that a toolkit has been made public which makes it trivial even for non-programmers to create an exploit which will open a CMD.exe screen for the attacker and allow them to run any code they choose. It has not been turned into self-propagating malware yet, but users should apply the patch or take other preventive actions to protect their systems before it does. For more news about the exploit and the new exploit toolkit see this article in The Register: JPEG Exploit Toolkit Spotted Online.
Explore Internet / Network Security
About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >

  1. Home
  2. Computing & Technology
  3. Internet / Network Security

©2009 About.com, a part of The New York Times Company.

All rights reserved.