Tuesday, January 03, 2006

Security Alert: Windows WMF exploits. Now with 100% better solution

A Couple of posts back I mentioned that there's a new exploit out there in the windows world. MS offered a immediate solution: turn off the .dll that's involved.

Turned out that the solution breaks a couple of things: Image Tumbnail and image and Fax Viewer amoung other things.

A better Solution
First, reverse what we did last time (skip this if you didn't apply the fix) by typing
regsvr32 c:\windows\system32\shimgvw.dll
in "Start -> Run". then follow the following steps.

  1. Download WMF Vulnerablility Checker[.exe, 4kb], run it to check if your system is vulnerable.
  2. If it is, download the patch HERE [.exe, 284kb], run it.
  3. restart
  4. ...
  5. Profit!
You should be fine after installing the patch.

Thanks to Iifak Guilfanov for the fix, and Security Now Podcast Steve Gibson for mentioning it.

And patch your systems, NOW!

No comments: