internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
QuickTime for Windows
Ad-Aware 2008 Free
Internet Explorer 8
Adobe Flash Player
Paint Shop Pro
Windows Live Suite
AVG Anti-Virus Free
Winamp
Spybot Search and Destroy

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Microsoft Readies WMF Patch
Zero-Day Exploit to be Patched Next Tuesday
Sean Michael Kerner

The Windows Metafile Format (WMF) flaw is not quite a zero-day exploit anymore, but it's not quite patched yet, either.

Microsoft has completed the development of a security update to fix the WMF flaw, which appeared last week. However, the update is being tested for quality control and isn't going to be released until Tuesday, Jan. 10.

An attacker could take advantage of the flaw to execute arbitrary code on a vulnerable Windows XP and Windows 2003 system.

The exploit targets how IE handles pictures that are transmitted by malicious sites hosting the .wmf file. The flaw saw numerous variants and was reportedly being exploited in the wild. The WMF exploit also had been added to the popular Metasploit Framework, which could potentially also allow for easy execution.

The updated Microsoft advisory acknowledges that, though the vulnerability is "serious" and attacks are being attempted, "the scope of the attacks are not widespread."

Part of the reason for the mitigation of the flaw's impact is the fact that the major antivirus companies have updated their virus signatures to prevent execution of the associated virus.

Microsoft's own Windows OneCare Live Beta also provides protection against the vulnerability.

In its updated advisory, Microsoft also addresses the reason it is taking Microsoft so long to issue a security update.

"Creating security updates that effectively fix vulnerabilities is an extensive process," the advisory states.

The advisory explains that Microsoft security personnel spend time to investigate the severity of the vulnerability, as well as its impact on applications. Updates are developed for every supported version of the supported product, localized for 23 languages and then issued simultaneously worldwide.

News courtesy of internetnews.com

January 3, 2006

Download Windows OneCare Live Now!Download

View All Anti-Malware Software

View All Anti-Virus Software

Contents:
1. Zero-Day Exploit to be Patched Next Tuesday


Additional Articles:

  • Windows Metafile Exploit Could Spell Trouble
  • Windows Live OneCare Takes Retail Leap
  • Qwest a Microsoft Security Customer
  • Microsoft OneCare Jumps Out to a Big Start
  • Exploit Looks for Unpatched Windows Servers
  • Microsoft OneCare Bombs Out In Antivirus Test
  • Next Peek Arrives for Microsoft OneCare
  • Microsoft Tries Annual Fee in New Office Bundle




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers