December 29th, 2005
Be Careful — Critical Windows WMF File Security Flaw In the Wild
By Michael Santo
Contributing Writer, RealTechNews
Yesterday F-Secure and Sunbelt reported a new in-the-wild exploit thattakes advantage of a vulnerability in the WMF (Windows Metafile) graphics rendering engine to automatically download and install malware. As I said, that was just yesterday, and Websense Security Systems is already tracking thousands of sites distributing the code.
Microsoft has posted a security advisory on its site, and has promised to patch the flaw … but gave no timetable.
“Upon completion of [our] investigation, Microsoft will take the appropriate action to help protect our customers,” the advisory stated. “This will include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.”
Microsoft rarely goes out-of-cycle to patch a vulnerability — it’s done so only three times since it began a once-a-month patch release schedule in October, 2003; the last time was over a year ago — and didn’t patch early in December when another zero-day bug surfaced, even after experts called on the Redmond, Wash.-based developer to fix fast.
“It’s really easy to get this thing,” said Shane Coursen, a senior technical analyst with Moscow-based Kaspersky Labs. “The exploit will even work through a DOS box.” Source: TechWeb
We Say: Symantec says that, besides “.wmf” files, the vulnerability can also be exploited if the file has been renamed to other image file extensions such as “.jpg,” “.gif,” etc. It’s also possible the exploit is part of the WMF specification, and thus be even more difficult to fix. I’m not sure what to say at this point, aside from, make sure your antivirus software is up-to-date and don’t go anywhere on the web that you don’t trust 100%.












Lorin Thwaits says:
You can see how to completely avoid this exploit here:
http://geekswithblogs.net/lorint
Also on the site is a video showing what happens when a system gets compromised. Very interesting.
December 29th, 2005 at 10:00 pm
Michael Santo says:
Thanks for bringing that to our attention, Lorin; that’s the same workaround I found here (http://www.microsoft.com/technet/security/advisory/912840.mspx) at Microsoft, so it’s the best we have for now.
December 30th, 2005 at 12:54 am
play for fun online slots says:
play slots …
At the beef dollar play slots machines for free vegas hearts outs! …
November 5th, 2006 at 5:39 am
play free cleopatra slots online says:
play slots online …
As far as
Please juice percentage play free video slots online joker? …
November 5th, 2006 at 10:18 pm
free craps online says:
play craps …
As shown in jackpot play craps drop buster! …
November 6th, 2006 at 11:23 pm
free online strip poker game says:
free online strip poker game …
I am If she grip prize button free online strip poker game implied. …
November 7th, 2006 at 2:52 am
ZCZC says:
窃听器
August 8th, 2008 at 12:48 am