Re: Unofficial WMF fix gets thumbs up by SANS.org and NIST.org



Copied from alt.computer.security

A working patch (even if not official)

For more and to download the patch (now - today! -availble as an msi
rather than an exe) see:

http://isc.sans.org/

Regards,


_________________________________________________________________________

"NIST.org" <google@xxxxxxxxxxxxxx> wrote in news:1136278459.673672.283040
@g44g2000cwa.googlegroups.com:

> The SANS recommended hotfix (by: Ilfak Guilfanov) intercepts calls to
> the exploitable program routines in the vulnerable shimgwv.dll file.
> It completely mitigates any threat from this vulnerability. No need to
> run Microsoft suggested unregister command but it doesn't hurt to do so
> (belt and suspenders is what SANS called it).
>
> My only problem with this fix is that its not very enterprise friendly.
> It requires installation on every machine through non-automated
> processes (yes, you can automate an install yourself) and should be
> uninstalled after Microsoft releases their fix.
>
> The latest exploit kits being circulated allows creation of WMF files
> with varying signatures. This was intended to make detection by
> IDS/IPS and antivirus programs much harder or impossible. So this
> unofficial hotfix maybe all we have at the moment.
>
> You can download the hotfix and read more at http://www.NIST.org
> Check back often for updates or subscribe to the NIST.org RSS feed.
>
>

.



Relevant Pages

  • RE: Exchange 2000 ms02-025 hotfix Q320436 caused SA to hang on re start[Scanned]
    ... you need to do two things to fix it. ... Delete it and reboot your machine... ... Exchange 2000 ms02-025 hotfix Q320436 caused SA to hang on ... * After hotfix installation, the installer starts up Exchange services. ...
    (Focus-Microsoft)
  • Unofficial WMF fix gets thumbs up by SANS.org and NIST.org
    ... The SANS recommended hotfix ... the exploitable program routines in the vulnerable shimgwv.dll file. ... It completely mitigates any threat from this vulnerability. ...
    (alt.computer.security)
  • Re: Stop the negativism!
    ... I, for one, have seen concrete demonstration of the efforts to fix the quality issues in BDS 2006. ... none of the reports I have been interested in have ever been fixed. ... Near the top of this page they have a section "Higher Performance and Better Quality" that says "Over 500 bug reports tracked by our internal system have been fixed in this release. ... Furthermore, the user who reported the problem was still using BCB 6, and he didn't get an update or hotfix, so this issue is not resolved for him unless he pays for an update to BDS 2006 and installs update 2. ...
    (borland.public.delphi.non-technical)
  • Re: svchost.exe inexplicably hogs cpu
    ... The so-called final fix will definitely come down Automagically and be available from WU/MU and the MS Download Center. ... it refers to 2 hotfixes by MS. i acquired the hotfix with KB id. ... i can't ascertain whether it is the automatic update feature that makes the CPU go wild or some other service. ... RAM consumption by svchost.exe is typically around 60-70MB when the problem occurs. ...
    (microsoft.public.windowsxp.general)
  • Re: Unable to Install SQL2005 SP2
    ... Below is the summary.txt from the Hotfix folder. ... Package Language: 1033 ... Product Installation Status ... The log file name is at "C:\Program Files\Microsoft SQL Server\90\Setup ...
    (microsoft.public.sqlserver.setup)