WMF vulnerability advisory update



Microsoft has updated their security bulletin on the WMF vulnerability to note a couple things. One, they acknowledge that embedded images within a document can trigger the exploit. Previously they said this needed further investigation. Second, they are seconding what I’ve been finding that Windows 98 and other pre-XP systems are not as critically at risk for this vulnerability….


Although Windows 98, Windows 98 Second Edition, and Windows Millennium Edition do contain the affected component, at this point in the investigation, an exploitable attack vector has not been identified that would yield a Critical severity rating for these versions. Per the support life cycle of these versions, only vulnerabilities of Critical severity would receive security updates. For more information about the security update support policy for these versions of Windows, visit the following Web site.

Unfortunately it’s their reason for not issuing a fix for those platforms, which mens the second unofficial patch mentioned earlier today from an antivirurs company may be the only patch those systems get.

It’s not comforting that they will not release an update because it’s not critical. If you recall there was a recent 0-day explorer exploit that was a variation on an earlier known vulnerability that originally was not deemed critical.

Related Posts

Blog Traffic Exchange Related Posts
  • System patching 0-days and ancient-day vulnerabilities There's a good article at Michael Sutton's Blog which points out something that really makes sense and I think many people are aware of, but with all the buzz that a new previously undisclosed vulnerability has, we forget. The point is this, there are plenty of machines online vulnerable to......
  • OTHER Sony DRM software has security flaws too. You almost want to bury your head in the sand at this point if you're Sony.... Freedom-to-tinker has some details. The last couple weeks the XCP copy protection that Sony uses has been the center of a Firestorm for rootkit capabilities and massive security problems. Well, it seems the OTHER......
  • Wireless Driver Vulnerabilities There are a couple notes to pass along with regards to some pretty serious vulnerabilities in various wireless network adapter drivers. First, Sans has information on some Intel Centrino updates that resolve some vulnerabilities that would affect the Windows Centrino driver and the ProSet management software. F-secure chimes in on......
Blog Traffic Exchange Related Websites
  • Updating My Value Dividend Portfolio One of my favorite parts of my financial “empire” is my Dividend Portfolio (a/k/a Perpetual Income Machine).  While it is not big by any stretch of the imagination worth only a couple grand, I have been throwing more and more money at it per month so I feel that......
  • Prosper Site Update -- Nationwide 36% Except Texas and South Dakota With a banking partner in WebBank, Prosper opens up to a nationwide audience of borrowers.  Their timing couldn't have been better.  Welcome borrowers! (Except Texas and South Dakota) Minimum instant transfer of $50 on 50% of your active loan value is now possible... In my opinion, this change greatly reduces (maybe......
  • Determining the Best Age to Start Social Security Many baby boomers are in the home stretch toward retirement and thinking about what will be the best age for them to claim Social Security retirement benefits.  I have already written about this issue from several different angles but I thought it would make sense to pull all of that......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site