new WMF flaws

Ice Czar

Inscrutable
Joined
Jul 8, 2001
Messages
27,174
http://www.redherring.com/Article.a...Windows&sector=Industries&subsector=Computing

doesnt allow remote code execution, but something to be aware about anyway

Less than a week after Microsoft released a patch to fix a security breach in its Windows operating system, antivirus companies warned Tuesday about two additional bugs related to image files.

The newly discovered issues, while not as critical as the earlier flaws, can cause programs to crash and lead to what security experts call a denial-of-service attack.

“It is not quite the same vulnerability as last time,” said Craig Schmugar, virus research manager at McAfee AVERT Labs. “Code execution is not possible, so hackers cannot use it to install everything from spyware to viruses on a system. But they can still affect one or two programs on the machine.”
 
Thanks for reminding me about patch Tuesday. I'm finally going to patch that "critical" (har har) WMF flaw right now.
 
Back
Top