Workaround for the critical WMF zero-day exploit



The Windows Meta File (WMF) zero-day (0-day) exploit is apparently, VERY nasty, no user intervention required (unless running firefox or opera). Just VISITING a malicous site (viewing a malicious email with image…) would be enough to get the system owned. It sounds as though a FULL reinstall is the best solution. Sunbelt has had some coverage…


There’s also a good deal over at The security fix. There is reported a workaround to immunize a system against the attack….

1. Click on the Start button on the taskbar.
2. Click on Run…
3. Type “regsvr32 /u shimgvw.dll” to disable.
4. Click ok when the change dialog appears.

iDefense notes that this workaround may interfere with certain thumbnail images loading correctly, though I have used the hack on my machine and haven’t had any problems yet. The company notes that once Microsoft issues a patch, the WMF feature may be enabled again by entering the command “regsvr32 shimgvw.dll” in step three above.

They are now reporting the exploit on thousands of web sites installing bogus anti-spyware software (prompting for credit card information to clean up the infection.) It also installs a mail server and starts sending out SPAM.

Be cautious and hope for a fix from Microsoft SOON. Given that we’re in between Christmas and New Year’s web traffic seems to be higher, home machines may be getting hammered by this.

Related Posts

Blog Traffic Exchange Related Posts
  • New IM worm using WMF vulnerability There is news this morning of a new twist in the WMF vulnerability (it was only a matter of time.) There are reports of an instant messenger worm using the vulnerability to spread. Currently incidents.org is reporting that the worm is spreading through the MSN messenger IM network and contains......
  • Lotus Notes WMF vulnerability This is really the same zero-day wmf vulnerability, but there is a twist. It's been found that Lotus Notes v. 6.x and up are vulnerable to the Windows Meta File (WMF) exploit that's making the rounds. Probably not surprising given that there are reports of many vectors of attack, not......
  • More WMF exploit testing on Windows 98 I've spent some more effort on trying to infect Windows 98 SE in a virtual machine with some of the exploit samples I can find. The first attempt was at a website with the .wmf download. No luck infecting the system there. Then, I've loaded up the image and visited......
Blog Traffic Exchange Related Websites
  • Asset Allocation Basis Part 4: What Are My Other Investing Options? After reviewing which kind of investments fall into the category of fixed income and looking at the stock market, as an investor, we may think that we have covered all the asset classes. However, there are what we can call “hybrid” products that are not necessarily classified as fixed......
  • Homegrown Jihad Haulted by NYPD & FBI... Don't Sleep... Sunday Paper - May 24th, 2009 While the Department of Homeland Security is fast at work issuing reports on Rightwing Extremists (which are later retracted due to public outrage) and cutting funding to New York City's urban security funds by 40% , four Muslim men from Newburgh, NY (three who are U.S. citizens) were......
  • Warning: Visiting This Site May Harm Your Computer Removal So you've just noticed that when you search for your website in Google, along with your standard listing you also have a message which reads "Warning Visiting This Site May Harm Your Computer". This article is all about *why* this warning appears, how to correct any issues with your......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site