Pavlov Scope

2006 January 9

(Updated) With renewed scrutiny, WMF strikes again

Filed under: ITSec — FreyGuy @ 22:44:31

Hi again all;

As of today, yet another WMF vulnerability, complete with exploit code, has been discovered. In case any of you don’t read assembly programming code, thankfully, this one is less severe ;-)

The WMF vulnerability disclosed today subjects WMF-related programs (things like Internet Explorer, built-in image viewers, etc.) to crash. This is known as a Denial of Service (or, DoS) – meaning that when the exploit is accomplished it Denies you (crashes or prevents you from using) the Service (where, in this case, the service is Internet Explorer and related imaging programs).

This is clearly not a red alert since the code doesn’t appear to be able to infiltrate your computer, but it is important to stay vigilant as always. Follow this link for Microsoft’s official response to this vulnerability so far.

I’ll update when a patch has been released or if any more develops take place.

P.S. New (additional) Windows updates are due out tomorrow (Tues., 2005/Jan/10), which are unrelated to this and the previously WMF flaw.

FYI;

_____________________________________________________________


KevFrey

kevfrey@gmail.com
.     .    .   .  . .. .  .   .    .     .

Leave a Reply

You must be logged in to post a comment.