FRISK Software International

Serious vulnerability in rendering of Windows Metafile image files (.wmf)

2 January 2006

Microsoft has released a security advisory warning of a vulnerability in a Windows graphics rendering engine that could allow for remote code execution by an attacker on an affected system. Over the past few days a number of Trojans and other malware have appeared that take advantage of this vulnerability via doctored image files sent as attachments to e-mails or embedded in webpages.

The vulnerability lies in the way Windows handles the Windows Metafile (.wmf) image file format. Since the vulnerability was first discovered, a numerous websites and mass-delivered e-mail messages have taken advantage of this vulnerability to install spyware and as well as viruses and other malware on vulnerable machines. Among other things, affected computers are used to send out thousands of spam e-mails without the knowledge or consent of their owners.

Although the behaviour creating this vulnerability is currently causing serious problems, it was originally a important feature of the Windows operating system and appears to have been part of Windows since version 3.0 was first released 15 years ago. This vulnerability therefore affects a very large number of computer users.

F-Prot Antivirus currently detects all know exploits of this vulnerability and tags them as "Security risk". We are also working on pre-emptive protection against any and all future threats attempting to take advantage of this vulnerability. Microsoft has not yet released a patch against this vulnerability but has described a workaround for the problem for users of Windows XP: These users can avoid exploit attacks by unregistering the Windows Picture and Fax Viewer.

For more information please see:

FRISK Software International is a leading developer of anti virus software and anti spam filtering services. FRISK Software International's anti virus computer software, F-PROT Antivirus, is available for a number of operating systems such as Windows, Linux, BSD, Solaris, and AIX as well as the Microsoft Exchange groupware. The company also offers F-PROT AVES, the anti spam and anti virus filtering service.

 
1 December 2008
F-PROT Antivirus Achieves a VB100 Award
F-PROT Antivirus for Windows 6.0.9.1 achieves a VB100 award in the December 2008 issue of Virus Bulletin

11 July 2007
Security Bulletins for July 2007
Microsoft releases six patches this month, three of which are deemed critical

Virus news and information directly to your desktop.


agoat@klaki.net argentina@f-prot.com argentina@frisk.is argentina@complex.is argentina@f-prot.is argentina@frisk-software.com argentina@f-prot.net argentina@f-prot.co.uk brazil@f-prot.com brazil@frisk.is brazil@complex.is brazil@f-prot.is brazil@frisk-software.com brazil@f-prot.net brazil@f-prot.co.uk malta@f-prot.com malta@frisk.is malta@complex.is malta@f-prot.is malta@frisk-software.com malta@f-prot.net malta@f-prot.co.uk a.bjani@f-prot.com a.bjani@frisk.is a.bjani@complex.is a.bjani@f-prot.is a.bjani@f-prot.co.uk a.bjani@frisk-software.com a.bjani@f-prot.net z.fifl@f-prot.com z.fifl@frisk.is z.fifl@complex.is z.fifl@f-prot.is z.fifl@f-prot.co.uk z.fifl@frisk-software.com z.fifl@f-prot.net strumpuri@complex.is strumpure@complex.is strumpuru@complex.is 00a@eircom.net 0maaahonyy@eircom.net 950@eircom.net af@eircom.net am@eircom.net ar@eircom.net as@eircom.net b1@eircom.net boss3@eircom.net ceih@eircom.net cera@eircom.net chxe@eircom.net cs@eircom.net cydw@eircom.net d71@eircom.net dpfy@eircom.net dzuv@eircom.net ehpa@eircom.net epin@eircom.net f1@eircom.net fa@eircom.net fdld@eircom.net fdnv@eircom.net gacg@eircom.net gafj@eircom.net gc@eircom.net gz@eircom.net ha@eircom.net he@eircom.net ia@eircom.net ja@eircom.net k2@eircom.net lleahy6@eircom.net m1@eircom.net no@eircom.net pb@eircom.net qq@eircom.net r6oo@eircom.net ra@eircom.net s2@eircom.net t2@eircom.net ua@eircom.net va@eircom.net vb@eircom.net w2@eircom.net ww2@eircom.net xxxkiss@eircom.net y1@eircom.net ya@eircom.net zz@eircom.net