Aircraft of World War II - Warbird Forums

Windows Exploit - WMF

Announcements Discuss Windows Exploit - WMF in the News & Announcements :: READ forums; There is a new exploit out which affects all windows versions, and only requires viewing of an image to become ...


Go Back   Aircraft of World War II - Warbird Forums > News & Announcements :: READ > Announcements

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 12-30-2005, 11:14 AM   #1
Administrator
 
horse[USA]'s Avatar
 
Join Date: Mar 2003
Location: Florida, USA
Posts: 536
Country:
Windows Exploit - WMF

There is a new exploit out which affects all windows versions, and only requires viewing of an image to become infected. Please read up on this exploit and be very careful in vewing images. The F-Secure blog has some good info ( http://www.f-secure.com/weblog/ ), and windows currently has no patch released but they do have a workaround available at http://www.microsoft.com/technet/sec...ry/912840.mspx located in General Info > Suggested Actions.

Quote:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an error in the handling of Windows Metafile files (".wmf") containing specially crafted SETABORTPROC "Escape" records. Such records allow arbitrary user-defined function to be executed when the rendering of a WMF file fails. This can be exploited to execute arbitrary code by tricking a user into opening a malicious ".wmf" file in "Windows Picture and Fax Viewer" or previewing a malicious ".wmf" file in explorer (i.e. opening a folder containing a malicious image file).

The vulnerability can also be exploited automatically when a user visits a malicious web site using Microsoft Internet Explorer.

NOTE: Exploit code is publicly available. This is being exploited in the wild. The vulnerability can also be triggered from explorer if the malicious file has been saved to a folder and renamed to other image file extensions like ".jpg", ".gif, ".tif", and ".png" etc.

The vulnerability has been confirmed on a fully patched system running Microsoft Windows XP SP2. Microsoft Windows XP SP1 and Microsoft Windows Server 2003 SP0 / SP1 are reportedly also affected. Other platforms may also be affected.
Description From http://secunia.com/advisories/18255/



Info Sites:
http://www.f-secure.com/weblog/
http://www.securityfocus.com/bid/16074
http://secunia.com/advisories/18255/
__________________

Aircraft of WW2 :: Site Admin
horse[USA] is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Old 12-30-2005, 11:16 AM   #2
Senior Member
 
syscom3's Avatar
 
Join Date: Jun 2005
Location: Orange County, CA
Posts: 7,876
Funny you posted this message as I was just reading about it on yahoo.

http://news.yahoo.com/s/nf/20051229/tc_nf/40530
__________________
"Pilot to copilot..... what are those mountain goats doing up here in the clouds?"
syscom3 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Old 12-30-2005, 11:29 AM   #3
Master of Ewes
 
the lancaster kicks ass's Avatar
 
Join Date: Dec 2003
Posts: 19,959
Country:
Send a message via MSN to the lancaster kicks ass
thanks for the heads up............
__________________

"Reminds me of the time I sank the Tirpitz" comments a Spitfire pilot, "One pass of course, old boy."
the lancaster kicks ass is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Old 12-30-2005, 01:12 PM   #4
Senior Member
 
Pisis's Avatar
 
Join Date: Nov 2004
Posts: 5,817
thanks for the warning horse.
Pisis is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Old 01-07-2006, 11:39 AM   #5
Master of Ewes
 
the lancaster kicks ass's Avatar
 
Join Date: Dec 2003
Posts: 19,959
Country:
Send a message via MSN to the lancaster kicks ass
just checked out that site again, a patch has been released by microsoft..........

http://www.f-secure.com/weblog/archi...ve-012006.html

go down one entry to jan. 5th...........
__________________

"Reminds me of the time I sank the Tirpitz" comments a Spitfire pilot, "One pass of course, old boy."
the lancaster kicks ass is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply



Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 08:59 AM.


Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
   

AVIATION TOP 100 - www.avitop.com Avitop.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83