BleepingComputer.com: Windows WMF 0-day Exploit

Jump to content

  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Windows WMF 0-day Exploit BE ALERT and stay tuned on this one

#16 User is offline   Mr Alpha 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 1,875
  • Joined: 25-November 04
  • Gender:Male
  • Location:Finland

Posted 05 January 2006 - 03:19 PM

Microsoft Security Bulletin Advance Notification

Quote

Important Information for Thursday 5 January 2006

Microsoft announced that it would release a security update to help protect customers from exploitations of a vulnerability in the Windows Meta File (WMF) area of code in the Windows operating system on Tuesday, January 2, 2006, in response to malicious and criminal attacks on computer users that were discovered last week.

Microsoft will release the update today on Thursday, January 5, 2006, earlier than planned.

Microsoft originally planned to release the update on Tuesday, January 10, 2006 as part of its regular monthly release of security bulletins, once testing for quality and application compatibility was complete. However, testing has been completed earlier than anticipated and the update is ready for release.

"Anyone who cannot form a community with others, or who does not need to because he is self-sufficient [...] is either a beast or a god." Aristotle
Intel Core 2 Quad | XFX 780i SLI | 8GB Corsair | Gigabyte GeForce 8800GTX | Auzentech X-Fi Prelude| Logitech G15 | Logitech MX Revolution | LG Flatron L2000C | Logitech Z-5500 Digital

#17 User is offline   Daisuke 

  • Cleaner on Duty
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 5,575
  • Joined: 01-September 04
  • Gender:Male
  • Location:Romania

Posted 05 January 2006 - 04:00 PM

Microsoft said:

The security update will be available at 2:00 pm PT as MS06-001.

You can download the patch right now :thumbsup: .
Everyday is virus day. Do you know where your recovery CDs are ?
Did you create them yet ?

Posted Image

#18 User is offline   Thunder 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 3,294
  • Joined: 12-December 05
  • Gender:Male
  • Location:Belgium

Posted 05 January 2006 - 04:24 PM

Yes, I patched my PC's ten minutes ago. :thumbsup:
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#19 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,517
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 05 January 2006 - 06:37 PM

Quote

Published: 2006-01-05,
Last Updated: 2006-01-05 22:49:16 UTC by Marcus Sachs

Many of you already know this if you receive advance notification from Microsoft. For everybody else, see their announcement about an early release of the WMF patch. The patch and details about it are available here. If you have installed any of the earlier patches or workarounds, here is our recommendation for updating:

1. Reboot your system to clear any vulnerable files from memory
2. Download and apply the new patch
3. Reboot
4. Uninstall the unofficial patch, by using Add/Remove Programs on single systems.
If you used msi to install the patch on multiple machines you can uninstall it with this:

msiexec.exe /X{E1CDC5B0-7AFB-11DA-8CD6-0800200C9A66} /qn

5. Re-register the .dll if you previously unregistered it (use the same command but without the "-u"):

regsvr32 %windir%\system32\shimgvw.dll

6. Reboot one more time just for good measure

We tested the patch, and it does block the attack just like the unofficial patch does.

If you experience any problems with the official patch, check support.microsoft.com and call the toll-free number listed for free assistance. Microsoft will not support the unofficial patch. As an alternative to the sequence shown above, you may want to uninstall the unofficial patch first. But make sure you keep shimgvw.dll unregistered until the official patch is applied. Either sequence works in our testing. Removing the unofficial patch later provides an extra layer of protection.

You can use our test image at http://sipr . net/test . wmf as a test to make sure you are not vulnerable. The test image will start the calculator if you are vulnerable.

I'd like to take this opportunity to thank all of our incident handlers for the endless hours of analysis over the past week. Also, many thanks to the hundreds of readers who sent in analysis and observations. Finally, thanks to the response team at Microsoft for issuing the patch today. We all appreciate the extra internal effort it took to do this out of cycle.

Marcus H. Sachs
Director, SANS Internet Storm Center

http://isc.sans.org/diary.php?storyid=1019
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

#20 User is offline   Datababe 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 21-November 05

Posted 05 January 2006 - 06:50 PM

I'd bet it's already posted, but I'm sick as a dog with a cold and scatter-shooting this as I can:

http://www.microsoft.com/athome/security/u...200601_WMF.mspx

Cheers!

#21 User is offline   hithereitstim 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 43
  • Joined: 10-December 05

Posted 06 January 2006 - 12:07 PM

I can't download the patch, all I see in the updates is Service Pack 2, anyone know why?

*edit* nevermind found it.

This post has been edited by hithereitstim: 06 January 2006 - 12:15 PM


Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users