Security Update for Windows XP (KB912919)


Recommended Posts

WMF patch released early.

Security Update for Windows XP (KB912919)

Here's the other platforms also:

Security Update for Windows Server 2003 (KB912919)

Security Update for Windows 2000 (KB912919)

Security Update for Windows XP x64 Edition (KB912919)

Security Update for Windows Server 2003 64-bit Itanium Edition (KB912919)

The Security bulletin ( MS06-001 ) is now available and confirms this covers the WMF vulnerability.

Graphics Rendering Engine Vulnerability - CVE-2005-4560:

A remote code execution vulnerability exists in the Graphics Rendering Engine because of the way that it handles Windows Metafile (WMF) images. An attacker could exploit the vulnerability by constructing a specially crafted WMF image that could potentially allow remote code execution if a user visited a malicious Web site or opened a specially crafted attachment in e-mail. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

The KB article ( 912919 ) is still not available.

Edited by Joe User 99

Is this a patch for the newly discussed WMF Vulnerability ???

And another question do we need to uninstall the original Un-official patch by SANS before applying this ? cos if this is not the real patch for the WMF i wont be un-installing the SANS one

lol dude !!! it comes from SANS which is a very reputed organisation if you know even a little about security

SANS? Institute - Computer Security Education and Information ...

http://isc.sans.org/

* Microsoft Patches Released (NEW)

Published: 2006-01-05,

Last Updated: 2006-01-05 21:11:22 UTC by Marcus Sachs (Version: 2(click to highlight changes))

Many of you already know this if you receive advance notification from Microsoft. For everybody else, see their announcement about an early release of the WMF patch. The patch and details about it are available here. If you have installed any of the earlier patches or workarounds, here is our recommendation for updating:

1. Reboot your system to clear any vulnerable files from memory

2. Download and apply the new patch

3. Reboot

4. Uninstall the unofficial patch, by using Add/Remove Programs on single systems. If you used msi to install the patch on multiple machines you can uninstall it with this:

msiexec.exe /X{E1CDC5B0-7AFB-11DA-8CD6-0800200C9A66} /qn

5. Re-register the .dll if you previously unregistered it (use the same command but without the "-u"):

regsvr32 %windir%\system32\shimgvw.dll

6. Reboot one more time just for good measure

I'd like to take this opportunity to thank all of our incident handlers for the endless hours of analysis over the past week. Also, many thanks to the hundreds of readers who sent in analysis and observations. Finally, thanks to the response team at Microsoft for issuing the patch today. We all appreciate the extra internal effort it took to do this out of cycle.

Marcus H. Sachs

Director, SANS Internet Storm Center

Why isn't this on the front page? Oh well, glad they got it out early, should keep some bashers quieter for about a min ;)

The frontpage of neowin is not a great source of "up to the minute" news source. It usually takes some time to appear on frontpage after has been on the forums.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Tor Browser 15.0.17 by Razvan Serea Protect your privacy. Defend yourself against network surveillance and traffic analysis. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. The Tor software protects you by bouncing your communications around a distributed network of relays run by volunteers all around the world: it prevents somebody from watching your Internet connection and learning what sites you visit, it prevents the sites you visit from learning your physical location, and it lets you access sites which are blocked. The Tor Browser Bundle lets you use Tor on Windows, Mac OS X, or Linux without needing to install any software. It can run off a USB flash drive, comes with a pre-configured web browser to protect your anonymity, and is self-contained. Tor Browser 15.0.17 changelog: All Platforms Updated Tor to 0.4.9.11 Updated NoScript to 13.6.25.1984 Build System / All Platforms Bug tor-browser-build#41821: Update gpg subkeys for boklm Bug tor-browser-build#41827: Update morgan's keychain with renewed key Download: Tor Browser (64-bit) | Tor Browser (32-bit) | 109.0 MB (Open Source) View: Tor Browser Website | Other Operating Systems Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Very fitting name since AI users have air where there brains should be.
    • Yes, it was amusing at the time because even then dbrand was well known for stealing the designs of products from other companies. That’s what they do.
  • Recent Achievements

    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
    • Apprentice
      jahara21 went up a rank
      Apprentice
    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      530
    2. 2
      +Edouard
      266
    3. 3
      PsYcHoKiLLa
      148
    4. 4
      Steven P.
      99
    5. 5
      macoman
      56
  • Tell a friend

    Love Neowin? Tell a friend!