Re: Why no patch for the .wmf problem?



Jim,

Microsoft probably thought that it would take until about Tuesday to fully
test the update. I never believed they were waiting for Tuesday or would
wait for Tuesday if they had a finished product to release. And, in fact,
they released an update last night (the previous Thursday), which confirms
that.

I was infected with spyware because of this vulnerability, and I had up to
date antivirus and antispyware. The problem is that you don't get infected
by the spyware, you get infected by anything that can take advantage of the
vulnerability, which then downloads spyware of its choice. Antivirus and
antispyware software might kick in at that point, but you're already
screwed.

This is not to be taken lightly. Arbitrary code being allowed to run without
any consent from the user and with up to date antivirus and antispyware and
Windows Critical Updates is not cool at all. People just assume that I did
something wrong, but my only crime was to use a search engine.

Paul

"karl levinson, mvp" <levinson_k@xxxxxxxxxxxxx> wrote in message
news:eCXLlCsEGHA.3700@xxxxxxxxxxxxxxxxxxxxxxx
>I didn't say I like it or am unconcerned. But I suggest it is necessary to
>either accept it as reality, or switch to a different software vendor.
>This is nothing new, it is the way it is, for the next several years if not
>longer.
>
> I suspect most people who were infected by this were not running up to
> date antivirus. While there are always ways for such malware to try to
> evade antivirus, I suspect using these methods were not necessary.
>
>
> "Jim" <Jim@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:487BCDB6-032C-4E9C-B0AA-C065CD5E4A7F@xxxxxxxxxxxxxxxx
>> Greetings,
>>
>> I am glad that you can be that comfortable considering the enormity of
>> the
>> issue. I however cannot afford to be of such an amenable mindset.
>>
>> Jim
>>
>> "Karl Levinson, mvp" wrote:
>>
>>> I really have no idea why you're surprised by this. Microsoft always
>>> takes
>>> around 40 days to test, localize and release patches. [You probably
>>> have no
>>> idea how painful it is to localize what would otherwise be "a simple
>>> patch."] It's been that way for years. You're going to have to switch
>>> to
>>> another non-Microsoft operating system if you don't like this. This is
>>> possibly one of the fastest patches they've ever released.
>>>
>>> You do have a number of workarounds at your disposal. Antivirus
>>> protects
>>> you as well as it protects you from any other virus. An attacker could
>>> use
>>> various methods to try to evade signature-based antivirus, but this has
>>> always been possible with most viruses.
>
>


.



Relevant Pages

  • Re: CA vs. Symantec vs. Microsoft
    ... > beta testing and Spysweeper has been able to remove spyware that was not ... I suspect that virtually all third party antispyware will find ... more false positives than Microsoft -- after all, ... the Microsoft is a beta in name only (it is a slightly modified ...
    (microsoft.public.windowsxp.general)
  • Re: Spying the messenger :-)
    ... I do not use any antivirus or any kind of protection software on the 'main' ... installation for viruses and perform backup/restore tasks. ... you may run the following tools to clean up spyware. ... Microsoft is providing this information as a convenience to you. ...
    (microsoft.public.windowsxp.general)
  • Re: symantec identified as spyware by ms antispyware
    ... | Microsoft just released a new Beta version of their AntiSpyware tool. ... | Symantec Anti Virus as spyware and identifies it for removal. ...
    (alt.comp.anti-virus)
  • Re: Question
    ... > I found that and it seems like microsoft is bundling a antivirus and ... > antispyware together and it looks like they are going to chare for it. ... You should know that you aren't talking to Microsoft when ... These newsgroups can be accessed via NNTP or HTTP. ...
    (microsoft.public.windowsxp.security_admin)
  • symantec identified as spyware by ms antispyware
    ... Microsoft just released a new Beta version of their AntiSpyware tool. ... Symantec Anti Virus as spyware and identifies it for removal. ...
    (alt.comp.anti-virus)

Loading