
A banner advertisement posted on the MySpace Web site may have infected more than one million users with adware, according to security firm iDefense. The advertisement was included in user profiles on MySpace and could have been operating for about one week. The deckoutyourdeck.com advertisement exploited a flaw in the way Microsoft’s Internet Explorer browser handles Windows Metafile image files. Users running unpatched versions of IE would never have realized that the banner ad had silently installed programs that generate pop-up ads on their system.