The Food Blog for Hungry Bachelors
Powered by MaxBlogPress  

It is better to suffer wrong than to do it, and happier to be sometimes cheated than not to trust.
-Samuel Johnson

neri-v-senate
Your ad here

« Wow! Philippines Web site Hacked!
» A New Year Quote

Tech Security

WMF Handling Vulnerability Warning

12.30.05 | Comment?


If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

Microsoft has recently released a security advisory with regards to vulnerability in how Windows handles specially-crafted Windows Metafile images using Windows Picture and Fax Viewer.

This vulnerability occurs when Windows opens a specially-crafted Windows Metafile (WMF) image that could allow arbitrary code to be executed. Microsoft’s security bulletin is here.

This is a zero-day exploit and it has the potential to be abused. Zero-day exploits as such that a vulnerability in a software is discovered, and an exploit code to exploit that vulnerability has been released hours after the vulnerability has been discovered. Malware authors can exploit this vulnerability, and potentially many users can be affected, since the exploit code is released even before the software maker has released a patch. This may have a very dangerous consequence.

Currently, there is no patch for this vulnerability.

Already, several malwares have been discovered specifically exploiting the said vulnerability. Here is Trend Micro’s descriptions for TROJ_NASCENE.A and TROJ_WMFCRASH.A. Here is Symantec’s heuristic detection for the said vulnerability.

Also, as a workaround, here is Trend Micro’s suggestion:

1. Click Start>Settings>Control Panel. Double-click on Internet Options.
2. In the Security tab, click on the Default Level button.
3. Move the slider to HIGH.
4. Click Apply, then Ok.

Like my article? Leave a tip! Or, treat me to a cup of coffee!

Visit the AWBHoldings.com Online Store!


RSS feed | Trackback URI

Comments »

No comments yet.

Name (required)
E-mail (required - never shown publicly)
URI
Subscribe to comments via email
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

Comments will be sent to the moderation queue.


« Wow! Philippines Web site Hacked!
» A New Year Quote