Irc News wrote:Software tools to create malicious images began appearing last month, and this week security experts saw images employing them posted on adult-oriented Usenet newsgroups.
To get the malicious code, a visitor must download the image and view it using Microsoft's Windows Explorer software. The computer then contacts a server to obtain code that would let an attacker take over the machine remotely. The current exploit is fairly limited but it is expected that future attempts to create malicious images would work on Outlook and Internet Explorer, both of course made by Microsoft.
Computers with updated versions of antivirus software should be protected, according to the Internet Storm Center at the SANS Institute. Microsoft also has a software patch to fix the flaw and said users who have the Service Pack 2 security update for Windows XP are not affected. It affects people running Windows XP, Windows Server 2003 and later versions of Office. The flaw is in a technology that is used to render JPEG images.
I think everybody should be aware of this, we all know what malware is like, pretty soon it will be everywhere!