Pavlov Scope

2006 January 4

WMF Exploit (Update6)

Filed under: ITSec — FreyGuy @ 14:36:31

Hi again all;

Steve Gibson’s (great security researcher and asset to the IT Security community) GRC site has reported that the fix for this problem has been leaked from Microsoft. He has tested it and it appears to work as expected, and thankfully, doesn’t appear to cause any problems with the previous, unofficial, Ilfak fix. So, you will not need to uninstall the Ilfak fix to update from Microsoft next Tuesday when the fix is deployed via Windows Update.

 But, I recommend to uninstall the Ilfak fix after you have verified that the Microsoft fix is stable (in other words, after you reboot post-update, make sure you can properly use your computer for a couple days, then uninstall the Ilfak fix). Once you have uninstalled the Ilfak fix, reboot, and test your computer using the Ilfak "checking" utility (mentioned in previous posts here) to verify that the computer is no longer vulnerable.

 Then, stay tuned for the inevitable next 0day software problem which I’ll do my best to keep you updated here.

_____________________________________________________________
KevFrey

kevfrey@gmail.com
.     .    .   .  . .. .  .   .    .     .

Leave a Reply

You must be logged in to post a comment.