
Pair of flaws...
By Joris Evers
Published: 1 February 2007 09:15 GMT
A security company has found a pair of bugs in Microsoft's Windows Mobile which, if exploited, could crash phones and other devices running the software.
The vulnerabilities lie in Windows Mobile Internet Explorer and Windows Mobile Pictures and Video, Trend Micro said in a pair of security alerts. Viewing a rigged web page or malicious JPEG image file on a Windows Mobile device will cause it to fail, according to the security vendor.
Todd Thiemann, director of device security marketing at Trend Micro, said: "Both of these vulnerabilities are potential denial of service factors. What we're seeing over time is an uptick in the threats against smart phones, particularly those running Symbian and Windows Mobile."
Trend Micro has told Microsoft about the problems and has not publicly shared the vulnerability details. Thiemann said: "The sky isn't falling. Nobody out there is aware of this." The company doesn't expect any imminent attacks exploiting the problems, he said.
Microsoft is aware of the issues and is investigating them, according to a company representative. If needed, the software maker will provide an update to hardware makers for distribution to people who use the Windows Mobile devices, it said. The problems affect Windows Mobile 2003 and Windows Mobile 5.0, according to Trend Micro.
While the number of threats to phones today is low, security experts and analysts agree the situation is likely to change with the advent of smart phones running common operating systems. Security companies, including Trend Micro, are hawking software to shield phones against possible attacks.
In addition to the Windows Mobile issues, Microsoft is also investigating a report of yet another vulnerability in Word. Symantec and the French Security Incident Response Team, or FrSirt, say they have spotted a fifth zero-day flaw in the word-processing application. Microsoft, however, said the problem is previously known.
A company representative said: "Microsoft's initial investigation shows that this is not a new vulnerability but a duplicate of an already known public issue."
The newest problem allows an attacker to hijack systems running Word 2003, Symantec said in an alert. The company has advised people to make sure their security software is up to date and urges caution when opening Word documents.
Joris Evers writes for CNET News.com
You will be involved in the design and development of 2G/3G functionalities in mobile phones and the development and implementation of a user ...
Huxley Associates has anew requirement for a Software Engineer to start a new 6-month contract in Dorset. You will have solid development skills in ...
Identify and implement a mobile solution involving new generation Smart phones. Cisco VoIP / IPT Engineer - Oxfordshire 35,000 - 50,000 basic + 5% ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Momentum Webcast: Assessment and Deployment Best Practices for Windows Vista (Level...
Momentum Webcast: Moving Forward With Windows Vista SP1 (Level 100)
Microsoft Office System Webcast: Tips and Tricks for Office 2008 for Mac: Incredible...
Microsoft Office System Webcast: Compatibility Tips for Office 2008 for Mac and the...
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com... ZX Spectrum nostalgia, Mac attack, tag a bag… Reader Comments of the Week
Steve Ranger Editor's Blog: Home computing from Acorn, Amiga and Amstrad, to the ZX Spectrum Nostalgia 2.0...