Submit your breaking news stories and original articles to us by contacting us
If you pay any attention to computer security, you have probably already heard about the WMF Exploit that can affect a fully patched Windows system. It has also been referred to as the 0-day Exploit. Here is a brief explanation of the exploit:
The WMF vulnerability uses images (WMF images) to execute arbitrary code. It will execute just by viewing the image. In most cases, you don’t have click anything. Even images stored on your system may cause the exploit to be triggered if it is indexed by some indexing software. Viewing a directory in Explorer with ‘Icon size’ images will cause the exploit to be triggered as well. Microsoft announced that an official patch will not be available before January 10th 2006 (next regular update cycle).
Yes, you read that correctly. Microsoft will not have an update available to patch this hole until next week sometime. In the mean time, there is really little you can do to protect yourself. Yes, using Firefox does provide some extra bit of security in the fact that it will prompt you before opening the file, rather than trying to open it. However, as soon as an unknowing user views the image, the code is executed.
So, until the official patch comes down from on high to the masses, a few people have gotten together and created a temporary patch that seems to have been thoroughly tested by security sites. Download it if you like, or you can wait.
Category: Uncategorized
4 Responses for "Windows Metafile Exploit Patch Available"
January 3rd, 2006 at 10:31 am
1Just FYI, a 0-day exploit is any vulnerability in which exploits are out in the wild at nearly the same time at which it is announced. They are becoming more and more common, which scares the crap out of security freaks like me.
January 6th, 2006 at 3:20 am
2There is a patch available but I can’t place the link without jeremy’s approval. Copy paste the following text and erase the spaces.
microsoft.com / technet / security / bulletin / ms06-001.mspx
May 26th, 2006 at 2:13 am
3is not so bad comparing whit the jpg problem creo que ese es peor aunque una vulnerabilidad es una vulnerabilidad y pues tiene qeu ser parchada lo antess posible
December 18th, 2006 at 8:41 am
4Exelent! Good work!
[url=][/url]
RSS feed for comments on this post
Leave a reply