Microsoft patch for WMF flaw to be released Jan 10


Recommended Posts

Better late than never I guess :p

It only takes common sense to avoid the vulnerability. Firefox will ask you to download and run the dodgy .wmf, and other browsers probably do too. It's only IE that will automatically run the file...but IE users deserve to get exploited anyway.

That's great. :rolleyes: Some of us are actually anti-spyware and anti-viruses, and don't want to see anyone get infected. The fact is, most people use IE, and I hardly blame them. It came with the OS.

Plus, Firefox has plenty of its own problems, as I've noticed.

indeed, if an infected image made its way into an advert distrobution service then bang, so many people could be effected

Exactly. :yes:

That's why I think this is so critical.

The WMF problem isn't actually an exploit as such (as in a buffer overrun etc) it's actually working the way it was supposed to. WMF files can contain code which is automatically executed if WMF rendering fails. So you just make a corrupt WMF file which you know will fail to render and then add your code to the abort procedure within the WMF file. A WMF file can be renamed to just about anything and IE or Windows Explorer will look at the contents to determine the file type, so any file could be suspect.

Now because it's simply a valid WMF file, anti-virus programs can't go simply quarantiening every WMF file so it needs to scan the payload and if someone creates a nasty worm with enough variants quickly enough then AV isn't going to be able to update it's definititions quick enough to keep up with the releases of the variants - hence AV isn't enough and a patch is required.

Now then, if MS have said it'll be a week before an official patch is available then that will surely act as a red rag to all those who would exploit this hole - the message is to get your spyware/virus/worm out within the week and enjoy are a very large vulnerable audience! If you were particularly set on maximum infection imagine a variant that targetted web content - you get the virus and it starts hunting down any JPEG files in the same folder or subfolders as .html/.htm/.php/.asp etc and infects one or two of those JPEG files - if you are lucky malicious fellow or fellowette you could find your way onto lots of web servers and make a big tasty worm for dinner!

Since my last post I've gone and rearched this. Interesting stuff, but again this still comes down to public awareness though. Who many 'normal' users open every email they get? I'd say at least the majority, which is why they need to be tought if you don't know the sender or if the email is suspecious, don't open it.

The public awareness you talk about is an utopia and therefore a nice thing to strife for, but not a solution.

There are always people who "don't know"..... and therefore the problem remains.

If everbody in the world used condoms we wouldn't have aids.... but not everyone does. Not everybody likes condoms, not everybody knows how to properly use it, not everyone has access to condoms.

Public awareness is not a full-proof solution.

To the people claiming that they've always assumed images are safe... did you miss the JPEG rendering vulnerability that appeared as MS04-028? Remember the fun trying to identify all GDI32.dlls?

This was in September 2004, so if you've been keeping up you should have stopped blindly trusting image files quite a while ago ;)

You might've read elsewhere about the Windows Meta File (WMF) vulnerability discovered on December 27th. It didn't last long at all for the first worm exploiting it to make its debut on MSN Messenger.

The worm spreads using a link to a file named xmas-2006 FUNNY.jpg. The image is in fact an HTML page linking to a malicious wmf file (Exploit.Win32.IMG-WMF), which will download and execute a vbs file which is detected as Trojan-Downloader.VBS.Psyme.br... which in turn will download an Sdbot (Backdoor.Win32.SdBot.gen). Are you still following?

Source: Mess.be

To the people claiming that they've always assumed images are safe... did you miss the JPEG rendering vulnerability that appeared as MS04-028? Remember the fun trying to identify all GDI32.dlls?

This was in September 2004, so if you've been keeping up you should have stopped blindly trusting image files quite a while ago ;)

Missed that one, did the patch come out before the exploit for that one though?

It's a little disturbing that MS isn't moving more quickly here. This is a key vulnerability.

Would you have rather them releasing a patch that didn't work for all or caused something else to **** up? They can take as long as the want, as long as it works. I'm not an idiot who visits warez/porn sites all the time :pinch:

Since my last post I've gone and rearched this. Interesting stuff, but again this still comes down to public awareness though. Who many 'normal' users open every email they get? I'd say at least the majority, which is why they need to be tought if you don't know the sender or if the email is suspecious, don't open it.

Exaclty. People make these stupid mistakes and then blame Microsoft. I have yet to be infected by viruses, spyware/adware eve since I learned about this stuff.

Edited by amrinders87

Would you have rather them releasing a patch that didn't work for all or caused something else to **** up? They can take as long as the want, as long as it works. I'm not an idiot who visits warez/porn sites all the time :pinch:

You don't need to browse warez/porn sites, as I said earlier there're already "trusted" sites with this wmf exploit embeded. It might be even possible to attach a rigged wmf in this forum, disguised as jpg.

Ichi that's something I've been pondering at work the past few days. People trust forum content without question. Sticking it as a users avatar or sig, or even just in a 'January Desktops' thread woulbd be painful but short lived...assuming you can get hold of the admins.

Hitting adverts on the front page would be far more effective.

anyone know how real this is?

could this patch have leaked like most other ms beta stuff or should one wait?

just wandering since this is such a big deal and all.

Would you have rather them releasing a patch that didn't work for all or caused something else to **** up? They can take as long as the want, as long as it works. I'm not an idiot who visits warez/porn sites all the time :pinch:

No, they can't take as long as they want. Every day they wait, hundreds of people get infected.

I think they just put out a patch, which is good.

You don't need to browse warez/porn sites, as I said earlier there're already "trusted" sites with this wmf exploit embeded. It might be even possible to attach a rigged wmf in this forum, disguised as jpg.

:yes: Exactly.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Most boring game ever. Repetitive, empty, predictable, and full of cliches. Total waste of time and money, IMO.
    • Mafia: The Old Country expansion Man of Honor announced, brings back Salieri from original by Pulasthi Ariyasinghe During Summer Game Fest, 2K and Hanger 13 brought out a new Mafia: The Old Country trailer, revealing the game's first expansion. Named Man of Honor, this is slated to add two new chapters to the Enzo storyline that the game follows. There is an iconic character returning to the series with this expansion, with players set to run into Ennio Salieri, the future Don of the Salieri crime family. Fans of the original Mafia, or its Definitive Edition remake, may remember that name as one of the biggest characters in the storyline. This expansion is set prior to his rise to being the kingpin in the City of Lost Heaven. "Set in Sicily during the winter of 1905, Enzo Favara has proven himself a reliable soldier of the Torrisi crime family in the months since his initiation," says the studio about the new chapters. "Now, the Don entrusts him and Cesare with a delicate assignment of assisting Ennio Salieri, a man of honor recently released from prison and intent on reclaiming what is his." Working at Salieri's side, players will be heading into fresh environments as they return to the role of Enzo as a high-ranking soldato. The studio also promises brand-new weapons, fresh vehicles, and charms to collect in this expansion. Moreover, the expansion will add new content to the updated Free Ride mode. Alongside new collectibles and locations, this will add more challenges to beat alongside Salieri, which are described as runs that will "test the skills of even the most elite mafiosi." The Mafia: The Old Country Man of Honor story expansion will release on August 14, 2026, across PC, Xbox Series X|S, and PlayStation 5. It will cost $10 for owners of the base game to jump into.
    • Try installing Logitech Options
    • Telltale returns with The Wolf Among Us, re-revealing the sequel and a new remaster by Pulasthi Ariyasinghe Telltale Games, the studio known for its episodic games from the 2000s, had a surprise appearance at the Summer Game Fest showcase today. The studio has gone through a collapse, an acquisition, and a revival but has largely gone silent in recent years. Today's sudden announcement was for the popular The Wolf Among Us series, with news about the sequel and a remaster dropping. Set after the events of the 2013-released title, the sequel will bring back Biby Wolf for a new adventure in Fabletown. This town of fairy tale characters is becoming unstable, with Snow White not being able to keep order as before. "When a brutal series of crimes threatens to fracture the fragile balance holding Fabletown together, Bigby Wolf, sheriff of Fabletown, finds himself drawn into a dangerous conspiracy that reaches deep into the city’s criminal underworld," says the studio. "As suspicion spreads across the city and powerful forces work against him, Bigby must uncover the truth and decide what kind of sheriff - and what kind of wolf - he is willing to become." At the same time, Telltale also announced The Wolf Among Us Remastered, bringing back the classic with a fresh coat of paint. This will include all five episodes from the original game plus over an hour of extra content that will offer behind-the-scenes videos, cast interviews, image galleries, and deleted scenes. The remaster will also have updated visuals and improved UI elements and accessibility features, alongside upgrades to the animations, audio, and frame rates. Telltale has been working on this project for almost a decade now, but if the new release schedule holds, fans will be able to jump into The Wolf Among Us 2 sometime in 2027. As for The Wolf Among Us Remastered, this is slated to release during this holiday season.
    • I use a Linux laptop every day. I have tried to switch to Linux on my gaming PC which has a 5070 ti. It was not a great experience
  • Recent Achievements

    • Rookie
      moog19 went up a rank
      Rookie
    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      486
    2. 2
      PsYcHoKiLLa
      270
    3. 3
      Skyfrog
      77
    4. 4
      Steven P.
      68
    5. 5
      FloatingFatMan
      62
  • Tell a friend

    Love Neowin? Tell a friend!