Friday, December 30, 2005

Windows Metafile Exploit Workaround

There is a nasty Windows security vulnerability in the Windows Metafile handler that can cause any Windows machine to become infected via an email attachment or browsing to a web page. Until Microsoft releases a patch, Security Now has simple directions to disable Metafile handling.
All versions of Windows from Windows 98 through ME, NT, 2000, XP, and 2003 are known to be vulnerable, and a large and rapidly growing number of malicious exploits (57 at last count) are already circulating in the wild. They are being actively used to install malware and Trojans into user's machines. Viruses and worms are expected to appear shortly. Although NOT a complete solution, Microsoft has recommended temporarily disabling the automatic display of some images by the operating system and web browser. This can be done, as detailed below, by "unregistering" the "SHIMGVW.DLL" Windows DLL. THIS IS NOT A COMPLETE SOLUTION, but it significantly lowers the risk from this vulnerability from web surfing.

0 Comments:

Post a Comment

<< Home