January 03, 2006
All versions of Microsoft Windows are now thought to be vulnerable to viruses and spyware exploiting Windows Metafile (WMF) files.
From Financial Times via The Drudge Report:
The flaw, which allows hackers to infect computers using programs maliciously inserted into seemingly innocuous image files, was first discovered last week. But the potential for damaging attacks increased dramatically at the weekend after a group of computer hackers published the source code they used to exploit it. Unlike most attacks, which require victims to download or execute a suspect file, the new vulnerability makes it possible for users to infect their computers with spyware or a virus simply by viewing a web page, e-mail or instant message that contains a contaminated image.The Russian patch is available here. Guilfanov recommends uninstalling it as soon as Microsoft gets off the dime and offers their own patch. I can't vouch for the patch. Most corporate system administrators will not use unofficial patches. If you install it, read everything carefully and proceed at your own risk.“We haven’t seen anything that bad yet, but multiple individuals and groups are exploiting this vulnerability,” Mr Hyppönen said. He said that every Windows system shipped since 1990 contained the flaw.
...some security experts were urging system administrators to take the unusual step of installing an unofficial patch created at the weekend by Ilfak Guilfanov, a Russian computer programmer.
Also posted at The Dread Pundit Bluto.
Posted by: Bluto at
01:16 AM
| Comments (11)
| Add Comment
Post contains 255 words, total size 2 kb.
Posted by: Agent Smith at January 03, 2006 06:07 AM (0kwVT)
Posted by: Oyster at January 03, 2006 07:26 AM (YudAC)
Posted by: Tiny Elvis at January 03, 2006 08:50 AM (D3+20)
Posted by: Jesusland Carlos at January 03, 2006 09:15 AM (8e/V4)
Posted by: hondo at January 03, 2006 09:40 AM (3aakz)
Posted by: Howie at January 04, 2006 08:59 AM (D3+20)
Posted by: The Dread Pundit Bluto at January 04, 2006 11:14 AM (RHG+K)
Posted by: hondo at January 04, 2006 12:56 PM (3aakz)
Posted by: The Dread Pundit Bluto at January 04, 2006 01:18 PM (RHG+K)
Posted by: hondo at January 04, 2006 01:34 PM (3aakz)
Posted by: The Dread Pundit Bluto at January 04, 2006 01:52 PM (RHG+K)
118 queries taking 0.375 seconds, 240 records returned.
Powered by Minx 1.1.6c-pink.