{"id":378186,"date":"2025-12-24T09:47:09","date_gmt":"2025-12-24T08:47:09","guid":{"rendered":"https:\/\/realites.com.tn\/fr\/?p=378186"},"modified":"2025-12-24T09:47:09","modified_gmt":"2025-12-24T08:47:09","slug":"eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images","status":"publish","type":"post","link":"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/","title":{"rendered":"ESET Research analyse une faille critique qui s\u2019appuie sur des images"},"content":{"rendered":"<p>La CVE-2025-50165 est une vuln\u00e9rabilit\u00e9 qui affecte le m\u00e9canisme d\u2019encodage et de compression des images JPG, sans effet sur leur d\u00e9codage.<\/p>\n<p>ESET Research fournit une analyse technique d\u00e9taill\u00e9e de la faille, incluant une m\u00e9thode de reproduction du crash \u00e0 partir d\u2019images JPG en 12 ou 16 bits, ainsi qu\u2019une \u00e9tude du correctif initial.<\/p>\n<p>Selon ESET, le risque d\u2019exploitation \u00e0 grande \u00e9chelle de cette vuln\u00e9rabilit\u00e9 demeure faible.<\/p>\n<p>Les chercheurs d\u2019ESET ont analys\u00e9 la CVE202550165, une vuln\u00e9rabilit\u00e9 critique affectant Windows et susceptible, en th\u00e9orie, de permettre l\u2019ex\u00e9cution de code \u00e0 distance via l\u2019ouverture d\u2019un fichier JPG sp\u00e9cialement forg\u00e9. Un format d\u2019image parmi les plus courants. L\u2019analyse approfondie men\u00e9e par ESET a permis d\u2019identifier pr\u00e9cis\u00e9ment le code en cause et de reproduire le crash. N\u00e9anmoins, les chercheurs estiment que le sc\u00e9nario d\u2019exploitation r\u00e9el est nettement plus complexe qu\u2019il n\u2019y para\u00eet. La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 initialement signal\u00e9e par Zscaler ThreatLabz et corrig\u00e9e par Microsoft dans sa mise \u00e0 jour de s\u00e9curit\u00e9 d\u2019ao\u00fbt.<\/p>\n<p>&nbsp;<\/p>\n<p>\u00ab WindowsCodecs.dll se retrouve en erreur lorsqu\u2019une image JPG, encod\u00e9e avec une pr\u00e9cision de 12 ou 16 bits, est soumise au processus d\u2019encodage. Bien que Microsoft ait class\u00e9 cette vuln\u00e9rabilit\u00e9 comme critique, notre analyse d\u00e9taill\u00e9e montre qu\u2019une exploitation \u00e0 grande \u00e9chelle est tr\u00e8s peu probable \u00bb, explique Romain Dumont, chercheur chez ESET qui a \u00e9tudi\u00e9 la faille. \u00ab Le simple fait d\u2019ouvrir, et donc de d\u00e9coder ou d\u2019afficher, une image malveillante ne suffit pas \u00e0 d\u00e9clencher la vuln\u00e9rabilit\u00e9. En revanche, la fonction vuln\u00e9rable jpeg_finish_compress peut \u00eatre appel\u00e9e lors de l\u2019enregistrement de l\u2019image ou lorsque certaines applications h\u00f4tes, comme Microsoft Photos, g\u00e9n\u00e8rent des vignettes \u00bb, pr\u00e9cise-t-il.<\/p>\n<p>La CVE202550165 provient d\u2019un d\u00e9faut dans le processus d\u2019encodage et de compression des images JPG, et non dans leur d\u00e9codage. ESET Research propose \u00e0 la fois une m\u00e9thode interne pour reproduire le crash \u00e0 partir d\u2019une image JPG en 12 ou 16 bits, ainsi qu\u2019une analyse du correctif initial publi\u00e9 par Microsoft. L\u2019enqu\u00eate r\u00e9v\u00e8le \u00e9galement que le composant vuln\u00e9rable repose sur la biblioth\u00e8que open source libjpeg-turbo, dans laquelle des failles similaires avaient d\u00e9j\u00e0 \u00e9t\u00e9 identifi\u00e9es et corrig\u00e9es en d\u00e9cembre 2024.<\/p>\n<p>Bien que le format JPG soit ancien, omnipr\u00e9sent et largement utilis\u00e9 dans les tests automatis\u00e9s, certaines impl\u00e9mentations de codecs peuvent encore r\u00e9v\u00e9ler des failles. Cette recherche men\u00e9e par ESET autour de la CVE202550165 rappelle l\u2019importance de maintenir \u00e0 jour les biblioth\u00e8ques tierces int\u00e9gr\u00e9es aux applications. Comme WindowsCodecs.dll est une biblioth\u00e8que partag\u00e9e, une application h\u00f4te devient vuln\u00e9rable d\u00e8s lors qu\u2019elle autorise l\u2019encodage ou le r\u00e9encodage d\u2019images JPG, et ce uniquement si un attaquant dispose d\u2019un contr\u00f4le suffisant sur l\u2019environnement d\u2019ex\u00e9cution (fuite d\u2019adresses, etc.).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>La CVE-2025-50165 est une vuln\u00e9rabilit\u00e9 qui affecte le m\u00e9canisme d\u2019encodage et de compression des images JPG, sans effet sur leur d\u00e9codage. ESET Research fournit une analyse technique d\u00e9taill\u00e9e de la&hellip;<\/p>\n","protected":false},"author":60,"featured_media":373784,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_lmt_disableupdate":"","_lmt_disable":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[4,1464],"tags":[],"class_list":["post-378186","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-actualites","category-entreprises"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>ESET Research analyse une faille critique qui s\u2019appuie sur des images - R\u00e9alit\u00e9s Magazine<\/title>\n<meta name=\"description\" content=\"La CVE-2025-50165 est une vuln\u00e9rabilit\u00e9 qui affecte le m\u00e9canisme d\u2019encodage et de compression des images JPG, sans effet sur leur d\u00e9codage. ESET Research\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ESET Research analyse une faille critique qui s\u2019appuie sur des images - R\u00e9alit\u00e9s Magazine\" \/>\n<meta property=\"og:description\" content=\"La CVE-2025-50165 est une vuln\u00e9rabilit\u00e9 qui affecte le m\u00e9canisme d\u2019encodage et de compression des images JPG, sans effet sur leur d\u00e9codage. ESET Research\" \/>\n<meta property=\"og:url\" content=\"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/\" \/>\n<meta property=\"og:site_name\" content=\"R\u00e9alit\u00e9s Magazine\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/realites.tn\/\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-24T08:47:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/realites.com.tn\/fr\/wp-content\/uploads\/2025\/10\/eset.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1201\" \/>\n\t<meta property=\"og:image:height\" content=\"631\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"La R\u00e9daction\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"La R\u00e9daction\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/\",\"url\":\"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/\",\"name\":\"ESET Research analyse une faille critique qui s\u2019appuie sur des images - R\u00e9alit\u00e9s Magazine\",\"isPartOf\":{\"@id\":\"https:\/\/realites.com.tn\/fr\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/realites.com.tn\/fr\/wp-content\/uploads\/2025\/10\/eset.jpg\",\"datePublished\":\"2025-12-24T08:47:09+00:00\",\"author\":{\"@id\":\"https:\/\/realites.com.tn\/fr\/#\/schema\/person\/438b71c29a257d955d96d8aef42336e7\"},\"description\":\"La CVE-2025-50165 est une vuln\u00e9rabilit\u00e9 qui affecte le m\u00e9canisme d\u2019encodage et de compression des images JPG, sans effet sur leur d\u00e9codage. ESET Research\",\"breadcrumb\":{\"@id\":\"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/#primaryimage\",\"url\":\"https:\/\/realites.com.tn\/fr\/wp-content\/uploads\/2025\/10\/eset.jpg\",\"contentUrl\":\"https:\/\/realites.com.tn\/fr\/wp-content\/uploads\/2025\/10\/eset.jpg\",\"width\":1201,\"height\":631},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/realites.com.tn\/fr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ESET Research analyse une faille critique qui s\u2019appuie sur des images\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/realites.com.tn\/fr\/#website\",\"url\":\"https:\/\/realites.com.tn\/fr\/\",\"name\":\"R\u00e9alit\u00e9s Magazine\",\"description\":\"Actualit\u00e9s de la Tunisie\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/realites.com.tn\/fr\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/realites.com.tn\/fr\/#\/schema\/person\/438b71c29a257d955d96d8aef42336e7\",\"name\":\"La R\u00e9daction\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/realites.com.tn\/fr\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/fbe9ab25fcc82b6e660ad5648f91eadb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/fbe9ab25fcc82b6e660ad5648f91eadb?s=96&d=mm&r=g\",\"caption\":\"La R\u00e9daction\"},\"url\":\"https:\/\/realites.com.tn\/fr\/author\/realites5201\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ESET Research analyse une faille critique qui s\u2019appuie sur des images - R\u00e9alit\u00e9s Magazine","description":"La CVE-2025-50165 est une vuln\u00e9rabilit\u00e9 qui affecte le m\u00e9canisme d\u2019encodage et de compression des images JPG, sans effet sur leur d\u00e9codage. ESET Research","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/","og_locale":"fr_FR","og_type":"article","og_title":"ESET Research analyse une faille critique qui s\u2019appuie sur des images - R\u00e9alit\u00e9s Magazine","og_description":"La CVE-2025-50165 est une vuln\u00e9rabilit\u00e9 qui affecte le m\u00e9canisme d\u2019encodage et de compression des images JPG, sans effet sur leur d\u00e9codage. ESET Research","og_url":"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/","og_site_name":"R\u00e9alit\u00e9s Magazine","article_publisher":"https:\/\/www.facebook.com\/realites.tn\/","article_published_time":"2025-12-24T08:47:09+00:00","og_image":[{"width":1201,"height":631,"url":"https:\/\/realites.com.tn\/fr\/wp-content\/uploads\/2025\/10\/eset.jpg","type":"image\/jpeg"}],"author":"La R\u00e9daction","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"La R\u00e9daction","Dur\u00e9e de lecture estim\u00e9e":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/","url":"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/","name":"ESET Research analyse une faille critique qui s\u2019appuie sur des images - R\u00e9alit\u00e9s Magazine","isPartOf":{"@id":"https:\/\/realites.com.tn\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/#primaryimage"},"image":{"@id":"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/#primaryimage"},"thumbnailUrl":"https:\/\/realites.com.tn\/fr\/wp-content\/uploads\/2025\/10\/eset.jpg","datePublished":"2025-12-24T08:47:09+00:00","author":{"@id":"https:\/\/realites.com.tn\/fr\/#\/schema\/person\/438b71c29a257d955d96d8aef42336e7"},"description":"La CVE-2025-50165 est une vuln\u00e9rabilit\u00e9 qui affecte le m\u00e9canisme d\u2019encodage et de compression des images JPG, sans effet sur leur d\u00e9codage. ESET Research","breadcrumb":{"@id":"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/#primaryimage","url":"https:\/\/realites.com.tn\/fr\/wp-content\/uploads\/2025\/10\/eset.jpg","contentUrl":"https:\/\/realites.com.tn\/fr\/wp-content\/uploads\/2025\/10\/eset.jpg","width":1201,"height":631},{"@type":"BreadcrumbList","@id":"https:\/\/realites.com.tn\/fr\/eset-research-analyse-une-faille-critique-qui-sappuie-sur-des-images\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/realites.com.tn\/fr\/"},{"@type":"ListItem","position":2,"name":"ESET Research analyse une faille critique qui s\u2019appuie sur des images"}]},{"@type":"WebSite","@id":"https:\/\/realites.com.tn\/fr\/#website","url":"https:\/\/realites.com.tn\/fr\/","name":"R\u00e9alit\u00e9s Magazine","description":"Actualit\u00e9s de la Tunisie","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/realites.com.tn\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/realites.com.tn\/fr\/#\/schema\/person\/438b71c29a257d955d96d8aef42336e7","name":"La R\u00e9daction","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/realites.com.tn\/fr\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/fbe9ab25fcc82b6e660ad5648f91eadb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fbe9ab25fcc82b6e660ad5648f91eadb?s=96&d=mm&r=g","caption":"La R\u00e9daction"},"url":"https:\/\/realites.com.tn\/fr\/author\/realites5201\/"}]}},"jetpack_featured_media_url":"https:\/\/realites.com.tn\/fr\/wp-content\/uploads\/2025\/10\/eset.jpg","jetpack_sharing_enabled":true,"views":86,"_links":{"self":[{"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/posts\/378186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/users\/60"}],"replies":[{"embeddable":true,"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/comments?post=378186"}],"version-history":[{"count":1,"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/posts\/378186\/revisions"}],"predecessor-version":[{"id":378187,"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/posts\/378186\/revisions\/378187"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/media\/373784"}],"wp:attachment":[{"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/media?parent=378186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/categories?post=378186"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/realites.com.tn\/fr\/wp-json\/wp\/v2\/tags?post=378186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}