Re: Unofficial WMF fix gets thumbs up by SANS.org and NIST.org



NIST.org wrote:
> The SANS recommended hotfix (by: Ilfak Guilfanov) intercepts calls to
> the exploitable program routines in the vulnerable shimgwv.dll file.
> It completely mitigates any threat from this vulnerability. No need
> to run Microsoft suggested unregister command but it doesn't hurt to
> do so (belt and suspenders is what SANS called it).
>
> My only problem with this fix is that its not very enterprise
> friendly. It requires installation on every machine through
> non-automated processes (yes, you can automate an install yourself)
> and should be uninstalled after Microsoft releases their fix.
>
> The latest exploit kits being circulated allows creation of WMF files
> with varying signatures. This was intended to make detection by
> IDS/IPS and antivirus programs much harder or impossible. So this
> unofficial hotfix maybe all we have at the moment.
>
> You can download the hotfix and read more at http://www.NIST.org
> Check back often for updates or subscribe to the NIST.org RSS feed.

Ilfak's site is up again, http://www.hexblog.com/ or
http://216.227.222.95/ since the server has changed. The latest SANS
logs are here http://isc.sans.org/diary.php?storyid=1013



.



Relevant Pages

  • Re: Unofficial WMF fix gets thumbs up by SANS.org and NIST.org
    ... >the exploitable program routines in the vulnerable shimgwv.dll file. ... >unofficial hotfix maybe all we have at the moment. ... >You can download the hotfix and read more at http://www.NIST.org ... Ilfak's hotfix for the WMF vulnerability can be downloaded from any ...
    (alt.computer.security)
  • Unofficial WMF fix gets thumbs up by SANS.org and NIST.org
    ... The SANS recommended hotfix ... the exploitable program routines in the vulnerable shimgwv.dll file. ... It completely mitigates any threat from this vulnerability. ...
    (alt.computer.security)
  • Re: DCOM Hotfix breaks our software
    ... There was a workaround before the fix came out. ... vulnerability for the time being. ... DCOM Hotfix breaks our software ... Checked by AVG anti-virus system. ...
    (Security-Basics)
  • Re: Vulnebrability level definition
    ... vulnerability can get varying risk levels across different ... If you're referring to the weekly "SANS Critical Vulnerability ... exploitation in widespread software with root/admin level privileges. ... I've tried tackling the risk level problem. ...
    (Security-Basics)
  • Re: Vulnebrability level definition
    ... vulnerability can get varying risk levels across different ... If you're referring to the weekly "SANS Critical Vulnerability ... I've tried tackling the risk level problem. ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)

Quantcast