Security Update for Windows XP (KB912919)


Recommended Posts

I hope all that argued about the with me about the importance of getting this patched quickly, will kindly eat humble pie now, yes admin might not like to update out of cycle but its allot easer than spending an hour repairing 300 of the 1000 machines.

It works fine on my 2 other comps.

If you have the temporary patch, you should uninstall it after you get the MS patch:

"You SHOULD REMOVE THIS PATCH to restore full functionality to Windows Metafile processing once Windows has been officially updated and repaired."

- http://www.grc.com/sn/notes-020.htm

This is the patch for the WMF thing according to microsoft. Follow a few links around and you end up on this page which clearly describes the problem as "The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com. "

Security update for WMF vulnerability

Published: January 5, 2006

Get the security update for the Windows Meta File (WMF) vulnerability from Microsoft Update. The bulletin title for this update is: Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution (912919).

To update your home computer, follow the steps on this page.

IT professionals and systems administrators should review the guidance on Microsoft TechNet.

Source: Microsoft.com

For those who would like some more info here is a link to a CastleCops HexBlog FAQ:

http://castlecops.com/p690060-Hexblog_WMF_FAQ.html

Also, there is a Forum section which is administered by a MS-MVP, but moderated by ilfak, the author of the non-official wmf hotfixes, and vunerability checker: Some interestings questions and scenarios to review:

http://castlecops.com/f212-Hexblog.html

One thread relates to installing the Official Microsoft Patch:

http://www.microsoft.com/technet/securi...6-001.mspx

and ilfak's vuneability checker...Here's the title of just one thread:

'checker doesnt detect official patch?'

"after installin the official microsoft patch and re-registering the DLL, i ran the wmf checker again, and it said that my system is vulnerable. is it because of the DLL? or something else? or does the result of the checker not matter anymore?

thanks."

Answer:

"Once the MS patch is applied, the wmf checker no longer applies"

._________________

Microsoft MVP

Windows-Security CastleCops:

Is this a patch for the newly discussed WMF Vulnerability ???

And another question do we need to uninstall the original Un-official patch by SANS before applying this ? cos if this is not the real patch for the WMF i wont be un-installing the SANS one

Yup, uninstall it :)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I'm still rocking iOS 25.x on my primary phone cuz iOS 26 still has usability quirks (mostly aesthetic and thus its UX) which I don't wanna deal with -- and I've been piloting them with all of these updates on my backup phone, so I'm well aware of its "improvements" since iOS 26 was first released (compared to version 26.5.x).
    • Firefox 152.0.4 is out.
    • Then why are you still here?  
    • Glary Utilities 6.44.0.48 by Razvan Serea Glary Utilities offers numerous powerful and easy-to-use system tools and utilities to fix, speed up, maintain and protect your PC. Glary Utilities allow you to clean common system junk files, as well as invalid registry entries and Internet traces. You can manage and delete browser add-ons, analyze disk space usage and find duplicate files. You can also view and manage installed shell extensions, encrypt your files from unauthorized access and use, split large files into smaller manageable files and then rejoin them. Furthermore, Glary Utilities includes the options to find, fix, or remove broken Windows shortcuts, manage the programs that start at Windows startup and uninstall software. All Glary Utilities tools can be accessed through an eye-pleasing and totally simplistic interface. Glary Utilities 6.44.0.48 changelog: Optimized Context Menu Manager: Improved features based on user feedback. Optimized Wipe Free Space: Optimized the interface display for a better user experience. Minor GUI improvements. Minor bug fixes. Download: Glary Utilities 6.44.0.48 | 27.0 MB (Freeware) Download: Portable Glary Utilities | 32.3 MB View: Glary Utilities Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • why to touch this audio corpse? use aimp
  • Recent Achievements

    • Reacting Well
      Juan Dela earned a badge
      Reacting Well
    • Week One Done
      Collagen Project earned a badge
      Week One Done
    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
    • Apprentice
      jahara21 went up a rank
      Apprentice
  • Popular Contributors

    1. 1
      +primortal
      514
    2. 2
      +Edouard
      266
    3. 3
      PsYcHoKiLLa
      146
    4. 4
      Steven P.
      96
    5. 5
      macoman
      54
  • Tell a friend

    Love Neowin? Tell a friend!