Alert

Microsoft Windows Image Processing Vulnerabilities

Last Revised
Alert Code
SA05-312A

Systems Affected

 
  • Microsoft Windows
 

Overview

 

Microsoft has released updates that address critical vulnerabilities in Windows.

Solution

Apply Update

Microsoft has released security updates for Windows. To obtain the updates, visit the Microsoft Update web site. US-CERT also recommends enabling Automatic Updates.

 

Description

 

The Microsoft Security Bulletin for November 2005 addresses vulnerabilities in the way Microsoft Windows processes image files. By tricking you into viewing maliciously altered image files, such as pictures on web sites or in email messages, an attacker may crash or take over your computer.

For more technical information, see US-CERT Technical Alert TA05-312A.


 

References

  • Microsoft Security Bulletin MS05-053 - <http://www.microsoft.com/technet/security/bulletin/MS05-053.mspx>
  • Microsoft Security Bulletin Summary for November 2005 - <http://www.microsoft.com/technet/security/bulletin/ms05-nov.mspx>
  • US-CERT Vulnerability Note VU#300549 - <http://www.kb.cert.org/vuls/id/300549>
  • US-CERT Vulnerability Note VU#433341 - <http://www.kb.cert.org/vuls/id/433341>
  • Microsoft Update - <https://update.microsoft.com/microsoftupdate>


 

Author: US-CERT. Feedback can be directed to US-CERT -->.

Produced by US-CERT, a government organization. Terms of use

Revision History

  • November 8, 2005: Initial release
    May 12, 2006: Corrected production statement
     

Last updated 

This product is provided subject to this Notification and this Privacy & Use policy.