Third Party WMF patch



The F-secure blog is reporting on a third party patch for the WMF exploit. I have not tested it, it seems to come from a knowledgable source though. As I’m writing this though, the thought strikes me that a really nasty trick would be a claimed fix that actually exploited the vulnerability. It pays to check up on the source of ANY third-party fix for Windows (or any other operating system or software suite…) Anyway, this seems to be a good source though. He’s the primary author of IDA Pro (Interactive Disassembler Pro).


For someone htat’s REALLY anxious for a fix other than the unregister workaround this looks like a good option. He describes it in the blog post linked to above. It basically is a dll that hooks into user32.dll and disables the SETABORT escape sequence in gdi32.dll

His fix is currently available only for Windows XP SP2 (64-bit as well) it will have an entry in add/remove programs. He suggests to remove it 1) if you have any problems with it and 2) when Microsoft patches the bug. In other words, when MS patches the problem uninstall this and install their patch.

It does not cause the problems with image browsing that the registry workaround does. He’s also asking for input on any experience with the patch (i.e. does this break anything?) The expected disclaimers for this apply…. (no responsibility for system breakage – read and decide for yourself if you want to try this.)

Related Posts

Blog Traffic Exchange Related Posts
  • Another Win98 patch for WMF vulnerability There's another patch for those Win98 users that are nervous about the WMF vulnerability that was announced at the tail end of the year. This site has made the patched version of gdi32.dll available to any and all. Their patch is open source. They basically say "it works for them..."......
  • More on the Windows WMF zero-day exploit There seems to be quite a bit developing on the Windows Meta File (WMF) zero-day (0-day) exploit which was first reported yesterday. Sans has raised their alert level to yellow in an effort to get attention to this problem. It looks like the original site serving the exploit is down,......
  • WMF exploit situation summary... Since there's been quite a bit of flux the last couple of days I thought I'd try to "reset" the situation and give a general overview of where we stand now with regards to the recent WMF zero-day exploit. 1st there is a vulnerability in the way Windows renders WMF......
Blog Traffic Exchange Related Websites
  • Microsoft to Improve User Access Control in Windows 7 I was just reading a Slashdot article about Microsoft improving User Access Control (UAC) in Windows 7. In the cited PC Pro article, Microsoft engineer Ben Fathi says: We've heard loud and clear that you are frustrated. You find the prompts too frequent, annoying, and confusing. We still want to......
  • Free Registry Cleaner- Free Download Safely Scan And Repair Registry Problems A good registry cleaner can help fix several common computer ailments. If you're experiencing problems such as frequent error message, slow bootups, crashes and freezes, and overall sluggish performance, you probably have errors in the Windows registry. These errors can cause Windows to "trip" over itself when looking for files......
  • Finovate Demos - Part 1 Here are some updates from the first batch of demos at Finovate. Authentium - Safe Central makes keystroke loggers or screenshot grabbers “blind.” Runs on top of Firefox. Prevents man in the middle and phishing. Credit Karma - Free credit score tracking using their proprietary scoring system. Cons are that......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site