[dba-Tech] WMF vulnerability

MartyConnelly martyconnelly at shaw.ca
Sun Jan 1 21:16:48 CST 2006


Yup, if you don't want to use the partial patch from Stuart's url.

Un-register the Windows Picture and Fax Viewer (Shimgvw.dll) on Windows 
XP Service Pack 1; Windows XP Service Pack 2; Windows Server 2003 and 
Windows Server 2003 Service Pack 1

http://www.microsoft.com/technet/security/advisory/912840.mspx

This will stop browser infections. BUT

Just remember this won't protect you, if you store and save a downloaded 
jpeg, then view it with MS window fax viewer,  these guys can disguise a 
.wmf  file extension as a .jpeg file and the exploit will work as the 
fax viewer will interpret it correctly as a virus loaded wmf file.


Stuart McLachlan wrote:

>Don't know how many of you are up on this, but be careful out there.
>This one is VERY nasty
>
>http://isc.sans.org/
>
>
>
>
>  
>

-- 
Marty Connelly
Victoria, B.C.
Canada






More information about the dba-Tech mailing list