About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Microsoft
Attackers could use the vulnerability to take control of a computer
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Windows WMF patch promised for next week

'Extremely critical' vulnerability to remain unpatched for another week

Paul Briggs, vnunet.com 04 Jan 2006
ADVERTISEMENT

Microsoft will issue patch for a widely abused security vulnerability in the Windows operating system next Tuesday as part of its monthly cycle, the company said in an update of the security advisory about the flaw.

Attackers could use the vulnerability to take control of a computer through a specially crafted Windows Metafile (.wmf) image.

Such an image can be used on a website or sent by email or in an instant message. Security vendors have reported that attackers are actively using all these methods in an attempt to infect systems.

Security website Secunia gave the vulnerability its most severe rating of 'extremely critical'.

All versions of Windows are vulnerable, according to security provider F-Secure, but systems running Windows XP or Server 2003 are most at risk.

Microsoft has developed a patch for the security hole and is currently testing it to enable a release next week.

Although Microsoft acknowledged that the flaw is being actively exploited, the company claimed that the scope of the attacks is not widespread.

Antivirus software is blocking most of the attacks through updated signature files, allowing the security software to recognise infected files before they can cause any harm, according to Microsoft.

Russian software engineer Ilfak Guilfanov has already released an unofficial fix which F-Secure has endorsed on its company blog.

Users who choose to install Guilfanov's patch will have to uninstall it before they run next week's Microsoft patch.


All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, Haringey, United Kingdom | Haringey Council
PMO Support Officer - Haringey, London - £32,289 - £37,542 pa   Experienced project support officer required by the internal IT services organisation of a London borough council to work within its Programme Management Office ... more >
Berkshire, Berkshire, United Kingdom | EDS
EDS are currently looking to recruit an experienced Core Infrastructure Project Manager to join our Project Management Defence team in one of the following locations: Reading or Bracknell (Berkshire) or Camberley (Surrey). Summary: Within DII ... more >
London, United Kingdom | Royal Borough of Kensington and Chelsea
Web Content Manager - c.£40,000 plus bonus - London   As one of the country's best-performing councils, we're always looking for new ways to improve on excellence. Providing an innovative, high-quality internet site for our ... more >
United Kingdom | Nottingham University NHS
Analyst/Developer - Nottingham University NHS - £24,103 - £32,653   An analyst/developer is required within the Systems Development Section of Nottingham University Hospitals ICT Services. The successful applicants will be part of a team whose ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT