Warning: mysql_result(): supplied argument is not a valid MySQL result resource in /var/www/hosts/cases/inc/refcount_alerts.php on line 23
UPDATE 2A - RED ALERT - Out of cycle patch from Microsoft available NOW (MS06-001) - Windows meta file (wmf) vulnerability
Just the facts
     
Title   UPDATE 2A - RED ALERT - Out of cycle patch from Microsoft available NOW (MS06-001) - Windows meta file (wmf) vulnerability
Description   User could be tricked into opening a malicious file with 'wmf' extension in Window Picture and Fax Viewer mode or previewing such a file in Microsoft Internet Explorer.
Microsoft has issued a patch for this highly critical vulnerability - see 'How do I fix' section of alert below - patch your system NOW.
CyTRAP Labs ID   CT110036
Original release date   2006-01-06
Systems affected  
Version number   1.2A
ISSN   1603-9858
Verify threat   http://casescontact.org/alerts/110036
Risk assessment   Severe/Red Alert
Impact/Severity   High
Audio/Podcast files   CyTRAP PodCast show - Error in the handling of corrupted Windows Meta Files - Wednesday, December 28, 2005
CyTRAP PodCast Show - Windows Meta File Verletzbarkeit - Mittwoch, 28. Dezember 2005
Update   UPDATE 2A - 2006-01-05 - MS has released patch - update now - see 'How do I fix' section of alert below with de-installation instructions for hotfix and other work arounds.
 

Why not get new tips and alerts by e-mail directly to your in-box? It's much more convenient:

Your email: or press here.

 

What is the problem?
     
Admin  

We appreciate you looking at one of our alerts. However, to assure that you have the latest version in front of you, please always click the link above to visit the website, because small changes are made without e-mailing the alerts out again

Please share this information with your colleagues, because they will be thankful you did.

     
How does it affect me?   Should I Worry?

Yes ==> If you are like about another 90% of the people that use Windows Operating systems on your PC or server, this is a highly critical vulnerability.

A) The Threat may result in an attacker exploiting a vulnerable system. The exploit code is publicly available and being taken advantage of by some malicious users.

B) Vulnerability is as follows:

  • The vulnerability is caused due to an error in the handling of corrupted Windows Metafile files with the extension .wmf

    C) Impact . Successulf exploitation can result in the execution of arbitrary code on the user's machine.

  •      
    Systems affected  
  • Windows XP Home Edition and Professional.
  • Microsoft Windows Server 2003 Datacenter Edition
  • Microsoft Windows Server 2003 Enterprise Edition
  • Microsoft Windows Server 2003 Standard Edition
  • Microsoft Windows Server 2003 Web Edition
  •      
    Not affected systems   If you have a Windows version shipped after 1990 your system is vulnerable, plain and simple.
     

    Minimize your exposure to this threat - follow the steps outlined below
         
    Much Gain - Little Pain - Do this   There is a temporary fix, however you no longer should do it this way...
    1. Do not open or preview untrusted files with the .wmf extension and,
    2. set security level to "High" in Microsoft Internet Explorer by doing as follows.
      1. Tools > Internet Options > Security >click on custom level,
      2. Click on Reset custom level settings ==> reset to high (BUT this will make it tougher to log into certain websites using Explorer),
    3. The best is a temporary fix that we endorse if you are tech savvy, it comes from Ilfak Guilfanov. The fix does does not remove any functionality from the system (all pictures and thumbnails continue to work normally - which they do not if you use option 2 above). This is a DLL which gets injected to all processes loading user32.dll. It patches the Escape() function in gdi32.dll. The result of the patch is that the SETABORT escape sequence is not accepted anymore.
      Ilfak Guilfanov: Vulnerability in Windows WMF metafile hotFix (2005-12-31).
     
         
    How do I fix it   2006-01-05-Patch Available

    Microsoft has released an out of cycle patch for the WMF file handling vulnerability described in Microsoft Security Advisory 912840 (see link further below).
    Details regarding where to get the patch for your version of Windows/Server/XP, etc. including URLs can be found here:

    Additionally, administrators who have deregistered shimgvw.dll as per the instructions in our previous release must re-register the library and re-enable the 'Windows Picture and Fax Viewer', run the following command after the patch has been applied:
    • regsvr32 %windir%\system32\shimgvw.dll

    If you installed the hotfix as we also recommended, you must do as follows with your PC, preferably before you download the patch to be safe:

    1. Start, Control Panel, Add or Remove Programs
    2. Uninstall 'Windows WMF Metafile Vulnerability HotFix',
    3. restart your computer, and finally
    4. download patch
    If you did nothing so far, just get the patch now and do not wait until automatic update gets it for you - too late.

    Microsoft has issued an advisory:
    Microsoft Security Advisory (912840) Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution (2005-12-28).
    The advisory provides you with more information.  

         
    Other Actions   WMF = Windows Meta File - for a definition see below - Glossary section.

    The vulnerability has been confirmed on a fully patched system running
    - Microsoft Windows XP SP2,
    - Microsoft Windows XP SP1, and
    - Microsoft Windows Server 2003 SP0 / SP1 are reportedly also affected.

         
    Additional risk minimization   None, just download the patch NOW.   
     

    If you need more information, please read on. Otherwise follow the steps outlined above.
         
    Source   Secunia
    Source URL   http://secunia.com/advisories/18255/
    Source date   2005-12-28
    Other source   H D Moore
    Other source URL   http://metasploit.com/projects/Framework/exploits.html#ie_xp_pfv_metafile
    Other source date   2005-12-27
    More information   More information and exploit provided by noemailpls
    CVE   CVE-2005-4560
    Secunia   SA18255
    USCert   VU#181038
    CyTRAP labs ID   CT110036
    Other source   AL-2005.0043
     

    CYTRAP resources - check it out - because it will help you better protect yourself
         
    Related tips  
    Glossary   Please get a free account, or log in as a member, to get the definition.
    English
  • WMF - Windows Meta File - what is it?
  • Watch out   Various groups are exploiting this vulnerability and every Windows user is vulnerable. Hence, patch now, see software fix section above.

    TIDBIT

    While the CT210009: Windows XP 101 - Windows auto-update will download the patch eventually, it is not as fast as if you downloaded it using the link we provide above.


    Administrative
         
    Author   Urs E. Gattiker - CyTRAP Labs
         
    Revisions  
  • 1.0 - 2005-12-28 - First Version
  • 1.1 - 2006-01-01 - with temporary hotfix until MS comes up with one - see temporary fix section
  • 1.2A - 2006-01-05 - out of cycle patch from Microsoft available - 'How do I fix' section of alert with de-installation instructions for hotfix and other workarounds.
  • Contact details   Web: http://CASEScontact.org
    E-mail: support01 at CASEScontact.org

    Tel: +41(0)76-200-7778 or + 44(0)70-9237-6036
    Fax: +44(0)70-9237-6036, dial 3 send fax
     

    --END of ADVISORY - Important Info Below--
     
    We recommend that you VERIFY ALL ADVISORIES you receive IMMEDIATELY, by clicking on the link provided at the top of this alert.

    NO WARRANTY
    Any material furnished by CASEScontact.org is furnished on an 'as is' basis. CASEScontact.org, writers & sponsors make no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results obtained from use of the material.

    Ride the rollercoaster successfully by subscribing to our alerts, tips, tools and skills training receiving them either via:

    1) e-mail
    2) RSS feeds, or else, just get a
    3) free skills tune-up


    NO WARRANTY
    Any material furnished by CASEScontact.org is furnished on an 'as is' basis. CASEScontact.org, writers & sponsors make no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results obtained from use of the material.

    CASES writers & sponsors do not make any warranty of any kind with respect to freedom from patent, trademark, or copyright infringement.
    Full DISCLAIMER notice at: http://www.casescontact.org/terms.php

    UNSUBSCRIBE
    If you no longer wish to receive this THREAT ALERT, please Unsubscribe at:
    http://www.casescontact.org/unsubscribe.php

    QUESTIONS, comments, ideas? Cheer us up at:Alerts-Comments at CASEScontact.org

    CASEScontact.org -- Threat Alerts and Security Notices --clear and precise, no compromise -
    --currently hosted by Flashcable

    -- END of THREAT ALERT --
    Copyright (c) 2007 by CyTRAP labs - Urs E. Gattiker. All rights reserved.