- Innovation, regulation and research on tap at RSA 2008
- Researchers uncover 100 VoIP vulnerabilities
- Badware not pushing users offline
- Web attacks won't stop
- Most sites still hack-able
- Tips on employee monitoring
- Research: IT security maturing, but misaligned
- Clarke sharply criticizes Bush cyber-security plans
- Conference seeks to bridge risk, research
- Core finds new CEO
December 30, 2005 | Comments: (0)
Microsoft's WMF screen door still open but small patch available
Earlier this week Microsoft announced a Zero-Day buffer overflow vulnerability in its Windows Metafile (WMF) graphics format affecting all version of Windows. Here it is days later and there's still no resolution.
Unfortunately, F-Secure is reporting that there are over seventy different dangerous WMF files capable of causing system damage in the wild so far using publicly available exploits.
Along with updating anti-virus signatures on your machines it is also suggested to update Intrusion Detection and Prevention System signatures and filter WMF files at HTTP proxies.
While Microsoft hasn't been able to stem the tide of malicious Web page images or HTML email causing problems, the main developer of the IDA Pro Disassembler & Debugger, Ilfak Guilfanov has a temporary fix for XP SP2 on his blog.
This patch should work for some Windows XP systems in the short term, at least until MS provides an alternative.
Listen now to the audio companion for this blog. InfoWorld Zero Day Podcast: 30 Seconds to Zero.
Download file
Posted by Victor R. Garza on December 30, 2005 05:30 PM
RATE THIS ARTICLE:
-

- COMMENTS
Very few articles on this security hole point out that it only autoinstalls using Internet Explorer. Firefox and Opera prompt you first. Superior products. What does Netscape do?
Posted by: Dan Coleman at January 3, 2006 11:58 AM| ZERO DAY PODCAST |
| Listen to the latest podcast: |
MP3
•
•
•
Archive
•
|
TOP STORIES
ADDITIONAL RESOURCES

- Best Practices for Successful SOA Governance
- Application Grid: Oracle's Vision for Next-Generation Application Servers and Infrastructure
- Do you have the power to resolve technical issues with one call?

- Sun Microsystems: The Green Tide Is Coming.
- More Effective Antivirus Protection
- Stop Spam, Phishing and Viruses






![[VoiceIndigo Mobilize - Listen to podcasts on your mobile phone]](http://www.voiceindigo.com/ht/images/mobilize_logo_sm.gif)
