Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
    • Risk Management Delivery Group
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > December 2005 > Exploitation of unpatched vulnerability in Windows Metafile (Update)

December 2005

Exploitation of unpatched vulnerability in Windows Metafile (Update)

ID: 01142
Ref: 1074/05
Date: 30 December 2005:14:26:39
Version: 1

Title: Exploitation of unpatched vulnerability in Windows Metafile (Update)
Abstract:
Vendors affected: Microsoft
Operating systems affected: Microsoft
Applications affected: Microsoft


This briefing is an update to UNIRAS brief 1070/05 issued on 28 December 2005.

There are reports of active exploitation of a vulnerability in the graphics rendering engine within the Microsoft Windows. The Windows Picture and Fax Viewer is used to view Windows Meta Files (WMF).

Additional information and mitigation regarding this vulnerability is now available from

http://www.microsoft.com/technet/security/advisory/912840.mspx

This page contains a suggested workaround (Suggested Actions -> Workarounds) which disables Windows Picture and Fax Viewer, until a patch is provided.

Previous mitigation advice continues to apply
- block WMF files in your HTTP and SMTP content checkers
- ensure anti-virus software is fully updated
- exercise caution when clicking on links or emails from untrusted sources

There have been no reports of activity related to this vulnerability from the Uniras community.

  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |