Third Party WMF patch



The F-secure blog is reporting on a third party patch for the WMF exploit. I have not tested it, it seems to come from a knowledgable source though. As I’m writing this though, the thought strikes me that a really nasty trick would be a claimed fix that actually exploited the vulnerability. It pays to check up on the source of ANY third-party fix for Windows (or any other operating system or software suite…) Anyway, this seems to be a good source though. He’s the primary author of IDA Pro (Interactive Disassembler Pro).


For someone htat’s REALLY anxious for a fix other than the unregister workaround this looks like a good option. He describes it in the blog post linked to above. It basically is a dll that hooks into user32.dll and disables the SETABORT escape sequence in gdi32.dll

His fix is currently available only for Windows XP SP2 (64-bit as well) it will have an entry in add/remove programs. He suggests to remove it 1) if you have any problems with it and 2) when Microsoft patches the bug. In other words, when MS patches the problem uninstall this and install their patch.

It does not cause the problems with image browsing that the registry workaround does. He’s also asking for input on any experience with the patch (i.e. does this break anything?) The expected disclaimers for this apply…. (no responsibility for system breakage – read and decide for yourself if you want to try this.)

Related Posts

Blog Traffic Exchange Related Posts
  • Microsoft releases patch early for WMF exploit Microsoft has released the patch for the WMF vulnerability that's been all over the news early. It was released to http://windowsupdate.microsoft.com ahead of the previously announced January 10th "patch Tuesday". Congrats to Microsoft for getting this out the door early. That should go a long ways to blunting the attacks......
  • WMF exploit situation summary... Since there's been quite a bit of flux the last couple of days I thought I'd try to "reset" the situation and give a general overview of where we stand now with regards to the recent WMF zero-day exploit. 1st there is a vulnerability in the way Windows renders WMF......
  • IE exploit unofficial patches While we wait for Microsoft to release a patch for the MOST recent Internet Explorer vulnerability..... it looks as though MS is "planning" to release a patch on their routine patch day of April 11th. (However they could always change their mind...) As before though there are some 3rd party......
Blog Traffic Exchange Related Websites
  • The Truth of Green Product Claims If you are confused when it comes to green building products and the claims that are being made by their manufacturers, you are not the only one. Navigating the complex world behind green products and the claims that they make is not always easy, but it has become necessary in......
  • Finovate Demos - Part 1 Here are some updates from the first batch of demos at Finovate. Authentium - Safe Central makes keystroke loggers or screenshot grabbers “blind.” Runs on top of Firefox. Prevents man in the middle and phishing. Credit Karma - Free credit score tracking using their proprietary scoring system. Cons are that......
  • The elusive nature of happiness, part 1 I got a chance to read a bit on the flight we took recently. The US Airways September 2007 issue had some insights on happiness worth thinking about. The editor, Lance Elko, began the issue with his own letter in which he quoted: Happiness is a mystery, like religion, and......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site