11 Nov 2005
Trend Micro claims to have discovered a Trojan horse that attacks Windows users through an image rendering flaw, just a day after Microsoft provided a fix for the bug.
The security firm said initially that the Trojan, referred to as 'emfsploit.a', crashes 'explorer.exe' on unpatched Windows machines.
But Trend Micro revised its statement later, saying only that it "exhibits behaviour similar to the Enhanced Metafile vulnerability of MS05-053" .
"Our Trend Labs team is currently working with Microsoft to resolve whether Troj_emfsploit.A does indeed fall under the category of code exploiting the MS05-053 vulnerability, or whether it is only a related piece of code but not totally exploiting MS05-053," the company said in a statement.
Trend Micro describes the new Trojan as a "proof of concept". It received one sample of the code from a customer in Japan, but it has not been detected anywhere else.
The company rates the overall risk as 'low', but the speed at which the exploit was developed has raised concerns in the industry.
Alan Bentley, UK managing director of patch management vendor PatchLink, said: "The emergence of this exploit within just 48 hours of Patch Tuesday just reinforces the movement towards zero-day attacks.
"As virus writers become more sophisticated, IT staff will really be tested when it comes to security protection.
"The time to patch has been diminishing for some time, and it is only a matter of time before we are faced with hours to patch rather than days."
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Java Developer - Belfast - Banking Skills: Core Java...
I am recruiting for a Shared Accounting Service Manager...
QA Tester/Automation Tester - C# .NET Agile, Epsom, Surrey...
3RD LINE EXCHANGE 2010 / 2003, QUEST, LONDON, GLOBAL...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?