![]() |
| Just the facts | ||
| Title | UPDATE 2A - RED ALERT - Out of cycle patch from Microsoft available NOW (MS06-001) - Windows meta file (wmf) vulnerability | |
| Description | User could be tricked into opening a malicious file with 'wmf' extension in Window Picture and Fax Viewer mode or previewing such a file in Microsoft Internet Explorer.
Microsoft has issued a patch for this highly critical vulnerability - see 'How do I fix' section of alert below - patch your system NOW. |
|
| CyTRAP Labs ID | CT110036 | |
| Original release date | 2006-01-06 | |
| Systems affected | ||
| Version number | 1.2A | |
| ISSN | 1603-9858 | |
| Verify threat | http://casescontact.org/alerts/110036 | |
| Risk assessment | Severe/Red Alert | |
| Impact/Severity | High | |
| Audio/Podcast files |
CyTRAP PodCast show - Error in the handling of corrupted Windows Meta Files - Wednesday, December 28, 2005
CyTRAP PodCast Show - Windows Meta File Verletzbarkeit - Mittwoch, 28. Dezember 2005 |
|
| Update | UPDATE 2A - 2006-01-05 - MS has released patch - update now - see 'How do I fix' section of alert below with de-installation instructions for hotfix and other work arounds. | |
Why not get new tips and alerts by e-mail directly to your in-box? It's much more convenient: |
||
| What is the problem? | ||
| Admin | We appreciate you looking at one of our alerts. However, to assure that you have the latest version in front of you, please always click the link above to visit the website, because small changes are made without e-mailing the alerts out again Please share this information with your colleagues, because they will be thankful you did. |
|
| How does it affect me? | Should I Worry?
Yes ==> If you are like about another 90% of the people that use Windows Operating systems on your PC or server, this is a highly critical vulnerability. A) The Threat may result in an attacker exploiting a vulnerable system. The exploit code is publicly available and being taken advantage of by some malicious users. B) Vulnerability is as follows: C) Impact . Successulf exploitation can result in the execution of arbitrary code on the user's machine. |
|
| Systems affected | ||
| Not affected systems | If you have a Windows version shipped after 1990 your system is vulnerable, plain and simple. | |
| Minimize your exposure to this threat - follow the steps outlined below | ||
| Much Gain - Little Pain - Do this | There is a temporary fix, however you no longer should do it this way...
Ilfak Guilfanov: Vulnerability in Windows WMF metafile hotFix (2005-12-31). |
|
| How do I fix it |
2006-01-05-Patch Available
Microsoft has released an out of cycle patch for the WMF file handling vulnerability described in Microsoft Security Advisory 912840 (see link further below).
If you installed the hotfix as we also recommended, you must do as follows with your PC, preferably before you download the patch to be safe:
Microsoft has issued an advisory:
|
|
| Other Actions | WMF = Windows Meta File - for a definition see below - Glossary section.
The vulnerability has been confirmed on a fully patched system
running
|
|
| Additional risk minimization | None, just download the patch NOW. | |
| If you need more information, please read on. Otherwise follow the steps outlined above. | ||
| Source | Secunia | |
| Source URL | http://secunia.com/advisories/18255/ | |
| Source date | 2005-12-28 | |
| Other source | H D Moore | |
| Other source URL | http://metasploit.com/projects/Framework/exploits.html#ie_xp_pfv_metafile | |
| Other source date | 2005-12-27 | |
| More information | More information and exploit provided by noemailpls | |
| CVE | CVE-2005-4560 | |
| Secunia | SA18255 | |
| USCert | VU#181038 | |
| CyTRAP labs ID | CT110036 | |
| Other source | AL-2005.0043 | |
| Administrative | ||
| Author | Urs E. Gattiker - CyTRAP Labs | |
| Revisions | ||
| Contact details | Web: http://CASEScontact.org E-mail: support01 at CASEScontact.org Tel: +41(0)76-200-7778 or + 44(0)70-9237-6036 Fax: +44(0)70-9237-6036, dial 3 send fax |
|
|
--END of ADVISORY - Important Info Below-- | |
| We recommend that you VERIFY ALL ADVISORIES you receive IMMEDIATELY, by clicking on the link provided at the top of this alert. |
|
NO WARRANTY Any material furnished by CASEScontact.org is furnished on an 'as is' basis. CASEScontact.org, writers & sponsors make no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results obtained from use of the material. |
|
Ride the rollercoaster successfully by subscribing to our alerts, tips, tools and skills training receiving them either via: 1) e-mail
| |
NO WARRANTY Any material furnished by CASEScontact.org is furnished on an 'as is' basis. CASEScontact.org, writers & sponsors make no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results obtained from use of the material. |
|
CASES writers & sponsors do not make any warranty of any kind with respect to freedom from patent, trademark, or copyright infringement. Full DISCLAIMER notice at: http://www.casescontact.org/terms.php |
|
UNSUBSCRIBE If you no longer wish to receive this THREAT ALERT, please Unsubscribe at: http://www.casescontact.org/unsubscribe.php QUESTIONS, comments, ideas? Cheer us up at:Alerts-Comments at CASEScontact.org CASEScontact.org -- Threat Alerts and Security Notices --clear and precise, no compromise - |
|
-- END of THREAT ALERT -- Copyright (c) 2007 by CyTRAP labs - Urs E. Gattiker. All rights reserved. | |