The Channel logo

News

By | John Leyden 3rd January 2006 14:08

World+dog scrambles to fight Windows flaw

Protect and survive

Microsoft rushed out a temporary fix on Monday to defend against a dangerous new Windows Meta File vulnerability that became the focus of numerous exploits late last week. Redmond's workaround disables some functions in Windows and is only partially effective. Fortunately, there is an alternative. Security researchers at the SANS Institute advise users to both unregister affected library (DLL files) and to use an unofficial patch, as explained here.

The WMF vulnerability exists in computers running Microsoft Windows XP (SP1 and SP2) and Microsoft Windows Server 2003 and stems from a flaw in a utility used to view picture and fax files. The security flaw might be exploited by inducing victims to view maliciously constructed sites, particularly where IE is used as a browser, or when previewing *.wmf format files with Windows Explorer. Hackers have created a range of Trojan programs which exploit the flaw. Microsoft said it plans to release a patch against the security hole on 10 January as part of its regular "Patch Tuesday" monthly update cycle. ®

alert Send corrections

Opinion

Merlin Data Center Interior

Trevor Pott

Enterprises want them, but they're still a pain in the ASCII
WWI French tank picture via Shutterstock
Vinod_Khosla

Chris Mellor

A VC with startup agenda slams established suppliers. Surprised? Neither were we
ZenPad_RealRacing

Features

Eclipse image via Shutterstock
The Azure Portal: Microsoft is betting on cloud for its future business
container_ship_hamburg_shutterstock_648
Michael Dell. Pic by Joi Ito
Cool Texas dude is just your average billionaire