it almost seems redundant to say that microsoft sucks

Jan 02, 2006 22:23

Alright guys, if you're running ANY VERSION OF WINDOWS AT ALL, you NEED to read this. There's a rather bad bug in how Windows deals with images that can install all sorts of malicious stuff on your machine. Having all the Windows updates and/or a good anti-virus program is not enough for this one, because all you have to do is look at a malicious image to have the code execute on your computer. In fact, even having something like Google Desktop index a file is enough to run the code. Microsoft has not released a fix for it and it looks like they won't do it any earlier than this weekend.

I recommend you read http://isc.sans.org/diary.php?storyid=994 for a quick overview.
Read http://www.kb.cert.org/vuls/id/181038 for more information, if you're interested.

And I recommend that you install the (unofficial) patch at http://www.hexblog.com/2005/12/wmf_vuln.html. (If you use this, you should also uninstall it once Microsoft releases theirs and install that one.)

Just another example of how Microsoft is working for you. (Though anyone who would work to exploit this code can sure go to hell too.)
Previous post Next post
Up