WMF vulnerability advisory update



Microsoft has updated their security bulletin on the WMF vulnerability to note a couple things. One, they acknowledge that embedded images within a document can trigger the exploit. Previously they said this needed further investigation. Second, they are seconding what I’ve been finding that Windows 98 and other pre-XP systems are not as critically at risk for this vulnerability….


Although Windows 98, Windows 98 Second Edition, and Windows Millennium Edition do contain the affected component, at this point in the investigation, an exploitable attack vector has not been identified that would yield a Critical severity rating for these versions. Per the support life cycle of these versions, only vulnerabilities of Critical severity would receive security updates. For more information about the security update support policy for these versions of Windows, visit the following Web site.

Unfortunately it’s their reason for not issuing a fix for those platforms, which mens the second unofficial patch mentioned earlier today from an antivirurs company may be the only patch those systems get.

It’s not comforting that they will not release an update because it’s not critical. If you recall there was a recent 0-day explorer exploit that was a variation on an earlier known vulnerability that originally was not deemed critical.

Related Posts

Blog Traffic Exchange Related Posts
  • Official WMF exploit patch leak It looks like, the Windows patch (or a beta) for the WMF exploit has been leaked online. It sounds as though Steve Gibson got a hold of a copy and has tested it along side the unofficial patch. All seems to go well. He notes that the build date was......
  • How to Remove Cyber Protection Center | Removal Guide Cyber Protection Center is related to Cyber Security (see how to remove cyber security). These are rogue antivirus applications that will generate many warnings and error messages on your system claiming (falsely) that your system is infected with countless virus and trojan infected files. In reality, Cyber Protection Center may......
  • Mac Wireless driver Security vulnerability revisited A couple weeks ago the hot story was about the demonstration of a vulnerability in a 3rd party wireless card driver on a Mac. The individuals that demonstrated the vulnerability (in a video taped presentation) also claimed that many wireless drivers were vulnerable to this same flaw and it included......
Blog Traffic Exchange Related Websites
  • Prosper Site Update -- Nationwide 36% Except Texas and South Dakota With a banking partner in WebBank, Prosper opens up to a nationwide audience of borrowers.  Their timing couldn't have been better.  Welcome borrowers! (Except Texas and South Dakota) Minimum instant transfer of $50 on 50% of your active loan value is now possible... In my opinion, this change greatly reduces (maybe......
  • Antioch Marina, Antioch, CA Antioch Marina is located in: Antioch, CA Phone: (925) 779-6957 Boat Launch: Yes, this facility does offer a boat launch. Berth Fees: - Open berths: $5.50 per foot per month. - Covered berths: $7.00 per foot per month "Charges are for the length of the berth, or the length of......
  • PwnageTool and Redsn0w released to untether jailbreak iOS 4.3.1 Sunday us surely a Funday! iPhone Dev Team has released updated versions of PwnageTool and Redsn0w which give untethered jailbreak for iPhone / iPod Touch / iPad 1 on iOS 4.3.1. The release also jailbreaks Apple TV on iOS 4.3.1. But iPad 2 is not supported yet. Comex is still......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site