Microsoft patches critical bugs in Windows graphics system

Microsoft issued a critical patch for two vulnerabilities in the core graphics subsystem of Windows as one of eight fixes released Tuesday

Microsoft issued a critical patch for two vulnerabilities in the core graphics subsystem of Windows, one of eight fixes released Tuesday as part of its monthly security updates.

Microsoft released a total of five critical patches in its April security bulletin. Two of them fix bugs in Windows, two fix bugs in Windows and Internet Explorer (IE), and one fixes a vulnerability in Microsoft Office. The critical rating means an attacker could potentially exploit the flaws to hack into a victim's computer.

The other patches fix vulnerabilities in Windows and Office and were rated "important." Microsoft releases patches on the second Tuesday of every month, which has become known in the industry as "Patch Tuesday."

MS08-021 fixes two vulnerabilities in Windows' graphics device interface (GDI), one of three core Windows subsystems, that could allow a hacker to take over someone's computer if a user opens certain kinds of image files, according to Microsoft.

Eric Schultze, chief technology officer of security and patch-management company Shavlik Technologies, said the GDI patch is the most important because it fixes vulnerabilities that could create "a trifecta of problems" across all versions of Windows, from Windows 2000 to the latest Windows Server 2008 release. "If you visit an evil Web site, read an evil e-mail or open an evil document, you can get hacked," he said.

Schultze said the GDI issue has come up twice before, "dating back to January 2006," which means that this is Microsoft's third attempt at fixing the problems. "Hackers have come up with different variants" to attack the same vulnerabilities, he said.

Of the five patches marked critical, Schultze recommended that users also immediately install two others -- MS08-022, which affects Windows, and MS08-024, which affects both Windows and IE.

MS08-022 patches a vulnerability in VBScript and JScript scripting engines in Windows that originally was supposed to be patched in January, but Microsoft pulled the patch at the last minute because it wasn't ready, Schultze said. MS08-24 patches a vulnerability found in all versions of IE.

Amol Sarwate, manager of the Vulnerability Research Lab at security service provider Qualys, agreed that MS08-021 and MS08-022 are among the top three most important patches, but considers critical patch MS08-023 more important than MS08-022. MS08-023 fixes an ActiveX vulnerability that affects both Windows and Internet Explorer.

In Sarwate's opinion, MS08-021, MS08-022 and MS08-023 are especially important for users because they affect all versions of Windows, even if no other software is installed on the machine.

He also noted that because five of the eight patches affect both early client and server versions of Windows through the most current Windows Vista and Windows Server 2008 OSes, hackers are taking advantage of Microsoft's reuse of code throughout different versions of the OS.

The fifth critical patch, MS08-018, affects Microsoft Office, fixing a vulnerability that can be exploited when a user opens an Office Project file.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Elizabeth Montalbano

IDG News Service
Show Comments



Sansai 6-Outlet Power Board + 4-Port USB Charging Station

Learn more >

Victorinox Werks Professional Executive 17 Laptop Case

Learn more >



Back To Business Guide

Click for more ›

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?