1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

WMF Exploit: Temporary Patch Available!

Discussion in 'Security and Privacy' started by SpywareDr, 2006/01/02.

  1. 2006/01/02
    SpywareDr

    SpywareDr SuperGeek WindowsBBS Team Member Thread Starter

    Joined:
    2005/12/31
    Messages:
    3,752
    Likes Received:
    338
    A temporary WMF Exploit patch is available. Started reading about it on Steve Gibson's site: More about this WMF Patch can be found on the author's site (Ilfak Guilfanov):
    Windows WMF Metafile Vulnerability HotFix
    http://www.hexblog.com/2005/12/wmf_vuln.html
    Ilfak has also written a little utility named:Tip: For those of you that have used the CMD:
    regsvr32 -u shimgvw.dll​
    you can now run the CMD:
    regsvr32 shimgvw.dll​
    to restore the "Thumbnail" view in Windows Explorer and Window's Image and FAX viewer.
     
  2. 2006/01/02
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Thanks for the heads up on that :)
     

  3. to hide this advert.

  4. 2006/01/02
    SpywareDr

    SpywareDr SuperGeek WindowsBBS Team Member Thread Starter

    Joined:
    2005/12/31
    Messages:
    3,752
    Likes Received:
    338
  5. 2006/01/03
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
  6. 2006/01/03
    alboy

    alboy Well-Known Member

    Joined:
    2002/01/09
    Messages:
    539
    Likes Received:
    4
    At the moment http://www.hexblog.com/2005/12/wmf_vuln.html is unavailable i wonder if it is due to a lot of webb traffic ?

    Would disabling all the items in in Internet Explorers Tools/Internet Options/Advanced/Multimedia section help ?
     
  7. 2006/01/03
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
  8. 2006/01/03
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi alboy,

    Would disabling all the items in in Internet Explorers Tools/Internet Options/Advanced/Multimedia section help ?
    I don't know, but if you do try this, make sure you can undo these settings, either by a manual SR point or drive imaging or take a "picture" of the before settings.

    I can't get to the site either right now and yes, the traffic must heavy.

    If you're using one of the major AV's, they have updated their defs for this.

    Forgive me, but you're sounding panic driven, could cause more damage then the threat.

    Regards - Charles
     
  9. 2006/01/03
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    This site seems still accessible for Ilfak's fix.
    http://www.grc.com/sn/notes-020.htm
    See the Green Box.
    Interestingly the fix has a different number than yesterday's version (#14 now).
     
  10. 2006/01/03
    alboy

    alboy Well-Known Member

    Joined:
    2002/01/09
    Messages:
    539
    Likes Received:
    4
    charlesvar
    I am not panic driven just asking if a few simple setting changes might help.

    the latest message on the site reads

    Account for domain hexblog.com has been suspended

    But it's good news is that GRC.com is offering the downloads from it's site
     
    Last edited: 2006/01/03
  11. 2006/01/03
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    I am not panic driven just asking if a few simple setting changes might help.
    I stand corrected, apologies.

    Regards - Charles
     
  12. 2006/01/04
    SpywareDr

    SpywareDr SuperGeek WindowsBBS Team Member Thread Starter

    Joined:
    2005/12/31
    Messages:
    3,752
    Likes Received:
    338
  13. 2006/01/04
    alboy

    alboy Well-Known Member

    Joined:
    2002/01/09
    Messages:
    539
    Likes Received:
    4
    No problem Charles, installed the patch and everything seems okay
    all the best for 2006

    alboy
     
  14. 2006/01/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
  15. 2006/01/05
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Thanks Pete and Steve - guess MS didn't want to wait another 5 days :D

    Regards - Charles
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.