MS Security Bulletin

Microsoft have patched there WMF problem that I mentioned earlier. Check here for more information.

MS Security problem

There has been a Microsoft security issue turn up. The patch will be out on the 10th but until then I highly recommend you take one of the following actions.

Run - regsvr32 -u %windir%\system32\shimgvw.dll to unregister the effected DLL.

Make sure your anti-virus/antispyware is up to the minute up to date (Symantec have this covered in the daily from yesterday)

Why? well all that is needed to exploit this attack is to open a web page or HTML Mail with an ‘infected’ WMF file.

What will unregistering the DLL do, it will ‘break’ the Picture and Fax viewer, so if you have a picture viewer/editor that you use instead then this is not a problem. If you do use MS Picture and Fax viewer (right click, preview on an image) then until the fix is out on Windows Update then you will be without the functionality.

At the end of the day it’s up to you, but I would recommend it as the attack allows the attacker to gain System level access to the PC.

« Previous Page