Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


December 31, 2005

Start 2006 With A Temporary Patch?

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

The Windows metafile vulnerability is undoubtedly a story that will carry over from 2005 into 2006. Ilfak Guilfanov brings everyone a gift in the form of a temporary patch while Microsoft works on an official patch.

Guilfanov writes in his
Hex Blog, "The fix does not remove any functionality from the system, all pictures will continue to be visible. It should work for Windows 2000, XP SP2 and XP 64-bit. It might also work for XP SP1 or XP without any service packs applied. This is a DLL which gets injected to all processes loading user32.dll. It patches the Escape() function in gdi32.dll. The result of the patch is that the SETABORT escape sequence is not accepted anymore."

Tom Liston as
SANS Internet Storm Center said that he has "taken this [patch] apart and looked at it very, very closely.  It does exactly what it advertises and nothing more. [...] This should allow for Windows to display WMF files normally while still blocking the exploit.  We want to give a huge thanks to Ilfak Guilfanov for building this and for allowing us to host and distribute it."

So there you have it. Madmen are creating still more working exploits. So, if you feel adventurous then consider using this patch to temporarily protect your systems.

That said, I'm off to celebrate the New Year!  Happy New Year to you all !

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now





Search Security Matters
 
Security Matters
NOVEMBER 2009
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30      
or

 Recently in Security Matters
Wordpress 2.8.4 Fixes A Big Security Hole
Make a Comment
Microsoft Releases 5 Critical Patches
Make a Comment
How To Help Secure HTTP Data Without SSL

Last Comment
The article has very less information. Need some elaboration....
(1 Comments)
Sometimes The Cookie Doesn't Crumble
Make a Comment
SecureTweets for Twitter
Make a Comment

More blogs about technology,
software, and Windows.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement