Less than a week after the release of patches for a pair of code execution flaws in Microsoft’s Windows graphics device interface, malicious hackers are firing in-the-wild exploits against those vulnerabilities.
According to virus hunters tracking malicious Internet activity, a booby-trapped file named TOP.JPG is in circulation, exploiting one of the vulnerabilities described in Microsoft’s MS08-001 bulletin.
“[The malicious .JPG file] was found hosted on sites, and arrives on a system as an executable which is now detected as EXPL_NEVAR.B,” says Christina Cruz, a virus analyst at Trend Micro.
The malware linked to the exploit is a Trojan downloader that creates a backdoor for silent communication with a malicious server.
According to Patrick Jungles, an analyst with Symantec’s DeepSight Threat Management System, the GDI attacks were first spotted on April 10, a mere two days after Microsoft’s Patch Tuesday release. “The attacks we identified weren’t successful; no honeypot instances were compromised,” Jungles said.
Upon further analysis, Jungles said the DeepSight team identified multiple images disguised as JPEGs being used to exploit the Microsoft Windows GDI Stack Overflow vulnerability.
Since then, attack code that provides a road map to launch attacks has been posted to Milw0rm.com, a publicly available repository for exploit code.
“We have tested the proof of concept and it does trigger the vulnerability, crashing Explorer on Win XP SP2,” Jungles added.
The appearance of in-the-wild attacks and public exploit code means that MS08-021 is a patch that should be deployed immediately, Jungles said.
The MS08-021 bulletin, rated “critical,” provides cover for all supported versions of Windows — from Windows 2000 SP4 through Windows XP SP2, Windows Server 2003 SP1, Windows Vista and Windows Server 2008.

AI thrives on data but feeding it the right data is harder than it seems. As enterprises scale their AI initiatives, they face the challenge of managing diverse data pipelines, ensuring proximity to insights, and supporting a growing range of workloads. In this episode, Corey Knowles speaks with Vrashank Jain, lead product manager for Dell’s AI Data Platform, about how businesses can overcome these hurdles with solutions that simplify data management, enhance performance, and unlock the full potential of their AI investments.

In this episode of eSpeaks, Jennifer Margles, Director of Product Management at BMC Software, discusses the transition from traditional job scheduling to the era of the autonomous enterprise.

eSpeaks’ Corey Noles talks with Rob Israch, President of Tipalti, about what it means to lead with Global-First Finance and how companies can build scalable, compliant operations in an increasingly uncertain world. They explore how automation, AI, and integrated platforms are helping finance teams tackle today’s biggest challenges, from cross-border compliance and FX volatility to […]
-
Latest News - Resources Resource HubsFeatured ResourcesLink to The Real AI Power Play: Who Controls Your Enterprise Data Layer?
The Real AI Power Play: Who Controls Your Enterprise Data Layer?IT and data teams were promised that AI would make work easier. Instead, it's created new layers of complexity.Link to Building the Backbone of Agentic AI with Trusted, Context-Rich Data
Building the Backbone of Agentic AI with Trusted, Context-Rich DataIn this 10-minute take video, Reltio Principal Solutions Consultant Guy Vorster explains how organizations can overcome fragmented data challenges to power AI agents.Link to IHG scales real-time, trusted data across global brands
IHG scales real-time, trusted data across global brandsAccelerating time to value while powering data-driven engagementLink to Dell’s Vrashank Jain on The Data Problem That Could Break Your AI
Dell’s Vrashank Jain on The Data Problem That Could Break Your AIAI thrives on data but feeding it the right data is harder than it seems. As enterprises scale their AI initiatives, they face the challenge of managing diverse data pipelines, ensuring proximity to insights, and supporting a growing range of workloads. In this episode, Corey Knowles speaks with Vrashank Jain, lead product manager for Dell’s AI Data Platform, about how businesses can overcome these hurdles with solutions that simplify data management, enhance performance, and unlock the full potential of their AI investments.
Link to BMC’s Jennifer Margules on Intelligent Enterprise Orchestration
BMC’s Jennifer Margules on Intelligent Enterprise OrchestrationIn this episode of eSpeaks, Jennifer Margles, Director of Product Management at BMC Software, discusses the transition from traditional job scheduling to the era of the autonomous enterprise.
Link to Global-First Finance: Building Scalable, Compliant Operations in an Uncertain World
Global-First Finance: Building Scalable, Compliant Operations in an Uncertain WorldeSpeaks’ Corey Noles talks with Rob Israch, President of Tipalti, about what it means to lead with Global-First Finance and how companies can build scalable, compliant operations in an increasingly uncertain world. They explore how automation, AI, and integrated platforms are helping finance teams tackle today’s biggest challenges, from cross-border compliance and FX volatility to […]
-
Artificial Intelligence -
Video -
Big Data & Analytics -
Cloud -
Networking - Cybersecurity Cybersecurity
- Applications Applications
- IT Management IT Management
- Storage Storage
- Mobile Mobile
- Small Business Small Business
- Development Development
- Database Database
- Servers Servers
- Android Android
- Apple Apple
- Innovation Innovation
- PC Hardware PC Hardware
- Reviews Reviews
- Search Engines Search Engines
- Virtualization Virtualization
-
- Blogs Blogs
- Events Events