|
|
|
A WMF is a Windows Metafile, an
image that contains additional information, and is the method for
attacking Windows PCs around the globe.
WMF security "exploits" are not new,
infact it can all be traced back to code written in the 1980's and
affects all versions from Windows 3.0, released in 1990 to Windows
XP. The guys over at F-Secure, a security company based in Finland,
say "it probably affects more computers than any other security
vulnerability".
The good news is that this will not
be an issue in the next release - Windows Vista due fall of 2006
|
Microsoft Release A New WMF Security Patch...
Microsoft have as of the 5th January 2006 issued a
security patch for the current WMF vulnerability - known as KB912919
or MS06-01.
This security update
APPLIES TO:
• Microsoft Windows Server 2003 Service Pack 1, when used with:
Microsoft Windows
Server 2003, Datacenter Edition (32-bit x86)
Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
Microsoft Windows Server 2003, Standard Edition (32-bit x86)
Microsoft Windows Server 2003, Web Edition
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based
Systems
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based
Systems
• Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
• Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
• Microsoft Windows Server 2003 R2 Standard Edition (32-bit x86)
• Microsoft Windows Server 2003 R2 Enterprise Edition (32-Bit x86)
• Microsoft Windows Server 2003 R2 Datacenter Edition (32-Bit x86)
• Microsoft Windows Server 2003 R2 Standard x64 Edition
• Microsoft Windows Server 2003 R2 Datacenter x64 Edition
• Microsoft Windows Server 2003 R2 Enterprise x64 Edition
• Microsoft Windows Server 2003, Standard Edition (32-bit x86)
• Microsoft Windows Server 2003, Web Edition
• Microsoft Windows Server 2003, Enterprise Edition for
Itanium-based Systems
• Microsoft Windows Server 2003, Datacenter Edition for
Itanium-Based Systems
• Microsoft Windows Server 2003, Standard x64 Edition
• Microsoft Windows Server 2003, Enterprise x64 Edition
• Microsoft Windows Server 2003, Datacenter x64 Edition
• Microsoft
Windows XP Service Pack 2, when used with:
Microsoft Windows XP
Professional
Microsoft Windows XP Home Edition
• Microsoft Windows XP Service Pack 1, when used with:
Microsoft Windows XP
Professional
Microsoft Windows XP Home Edition
• Microsoft Windows XP Tablet PC Edition
• Microsoft Windows XP Tablet PC Edition 2005
• Microsoft Windows XP Media Center Edition 2002
• Microsoft Windows XP Media Center Edition 2005
• Microsoft Windows XP Professional x64 Edition
• Microsoft Windows
2000 Service Pack 4, when used with:
Microsoft Windows
2000 Advanced Server
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Professional Edition
Microsoft Windows 2000 Server
Microsoft Small Business Server 2000 Standard Edition
How Do I Get KB912919?
The good news is that you may already have it installed!
Many PC owners will have "Automatic
Updates" turned on.... More info here:
http://www.updatexp.com/windows-automatic-updates.html
If that is your situation then the
patch is already installed by now. HOWEVER you can check by looking
in the Add / Remove programs section.
To do this:
1) Click on the
Start Menu
2) Select Control Panel
from the menu
3) Now Select Add or Remove
programs
4)
What If KB912919 Is Not There?
What If I Want More Technical Information On KB912919 ?
Simple...
Go now to this Microsoft webpage:
http://www.microsoft.com/technet/security/bulletin/ms06-001.mspx
What If I Applied The "Workaround" You Mentioned In Your
Previous Warning?
Simple...
If you applied the "workaround" by
disabling the Windows Picture and fax Viewer that I showed in my
article at
http://www.updatexp.com/wmf-exploit.html You will now
need to re-register this software on your PC.
(This was also advised by many other
websites too.)