Friday, January 06, 2006

Latest: Microsoft patch for WMF image vulnerability just released

Check out the patch from Microsoft for the vulnerability I wrote about in a previous post. If you have de-registered Shimgvw.dll, be sure to re-register it as described in the same post above before you apply the update.

For those who are keen to know what this vulnerability is all about, check out this interview with Ilfak Guilfanov, one of the first to come up with a fix for this vulnerability. I am not endorsing this fix as it lacks support from Microsoft, but the interview sheds light on how the vulnerability can be exploited as well as touches on Data Execution Prevention, which is another layer of protection that can be enabled on XP with SP2.

Category: c4e1_scty

No comments: