Critical Vulnerability: MS06-01 Microsoft .WMF (912840)
|
REVISED!!! FNAL Critical Vulnerability A new critical flaw has been discovered in the Microsoft Windows operating system through the rendering of WMF images. The attack vectors range from HTML email, images hosted on malicious web sites, instant messaging clients and recently, malicious images posted to community forums such as message boards, discussion forums and blogs. This flaw affects not only Internet Explorer, but Mozilla packages, various email clients, folder browsing, third party applications and other applications which use the built in image viewing or preview functions of Microsoft Windows.
At this time, no official Microsoft patch exists.
It is suggested you download the patch as soon as it is available to test and report of any problems caused from the installation.
There have been a few published workarounds, including an unofficial patched produced outside of Microsoft. None of the workarounds completely protect you from the ever growing attack vectors, so implementation of these workarounds are at your own risk. Antivirus vendors are constantly updating their signatures to detect the many variants being produced, so it is strongly recommended to have your antivirus clients checking for updates frequently throughout the day.
More information can be found at |
|
For assistance contact helpdesk@fnal.gov.
Information compiled and maintained by Computer Security Team ; last modified by TR on July 13, 2006. (Address comments about page to the Computer Security Team.) |