Bink.nu Services

Subscribe to our feed 
Alerts 
 


Order Now!

Windows 7 for XP Professionals
Updating Support Skills from XP to Windows 7
by Bink.nu's Raymond Comvalius

Who is online

There are 68 guest(s) online.

There are 0 member(s) online.

Sponsors



Posted by Steven Bink December 28, 2005 2:00 PM with 1 comment(s)
Filed under:

Extremely critical!

Effected:
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows Small Business Server 2003
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional
Microsoft Windows Small Business Server 2003
Microsoft Windows Storage Server 2003
Microsoft Windows XP Tablet PC
Microsoft Windows XP Media Center 2004/2005
Microsoft Windows XP Embedded??
Microsoft Windows Server 2003 R2 Enterprise Edition
Microsoft Windows Server 2003 R2 Standard Edition

Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.

Description:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an error in the handling of corrupted Windows Metafile files (".wmf"). This can be exploited to execute arbitrary code by tricking a user into opening a malicious ".wmf" file in "Windows Picture and Fax Viewer" or previewing a malicious ".wmf" file in explorer (i.e. selecting the file). This can also be exploited automatically when a user visits a malicious web site using Microsoft Internet Explorer.

NOTE: Exploit code is publicly available. This is being exploited in the wild.

The vulnerability has been confirmed on a fully patched system running Microsoft Windows XP SP2. Microsoft Windows XP SP1 and Microsoft Windows Server 2003 SP0 / SP1 are reportedly also affected. Other platforms may also be affected.

Solution:
Do not open or preview untrusted ".wmf" files and set security level to "High" in Microsoft Internet Explorer.

4105 Views
Source: secunia.com

Comments

 

ericmedici said:

This happened to me when browsing the web. I saw the Picture and Fax Viewer pop up and thought "Crap!" It took me an hour or so to get rid of all the spyware, trojans, etc...
December 28, 2005 4:19 PM

About Steven Bink

Founder of Bink.nu
Bink.nu 3.0. Copyright © 1999-2010 Steven Bink. All Rights Reserved.
Microsoft and Microsoft logo's are trademarks of Microsoft Corporation.