Enterprises urged to use unofficial Windows patch

By Tom Espiner, ZDNet UK
Wednesday, January 04, 2006 11:56 AM

Experts are advising corporations to use an unofficial patch to combat the latest Microsoft Windows Meta File exploit.

Antivirus vendor F-Secure and the Internet Storm Center, a volunteer security group, separately urged businesses on Tuesday to use the unofficial patch, as Microsoft has not yet offered an authorized fix for the problem.

Microsoft, though, has advised businesses not to use third-party updates, even though its own patch won't be available until next Tuesday.

The WMF vulnerability can be exploited in Windows XP with Service Pack 1 and 2, as well as Windows Server 2003, security experts said.

Mikko Hypponen, director of antivirus research at F-Secure, said he believes corporations can trust the unofficial patch, which was created by security software developer Ilfak Guilfanov.

"This is a very unusual situation--we've never done this before. We trust Ilfak, and we know his patch works," Hypponen said. "We've confirmed the binary does what the source code said it does. We've installed the patch on 500 F-Secure computers, and have recommended all of our customers do the same. The businesses who have installed the patch have said it's highly successful."

The Internet Storm Center admitted that many businesses would be very reluctant to deploy an unofficial patch on their systems, but insisted that such action is needed.

"We've received many e-mails from people saying that no one in a corporate environment will find using an unofficial patch acceptable," Tom Liston of the Internet Storm Center said in his blog. "Acceptable or not, folks, you have to trust someone in this situation."

Systems administrators can also work around the problem by unregistering a file called "shimgvw.dll".

"The very best response that our collective wisdom can create is contained in this advice--unregister shimgvw.dll and use the unofficial patch," Liston said.

A Microsoft representative advised businesses to wait for a week, as the software giant can't guarantee third-party updates will be effective.

"Microsoft recommends that customers download and deploy the security update for the WMF vulnerability that we are targeting for release on Jan. 10, 2006. Microsoft cannot provide assurance for independent third-party security updates," the representative said.

Security experts say the WMF exploit is potentially dangerous because conventional antivirus software and IDS (Intrusion Detection System) signatures do not recognize the malicious code in spam, as the exploit is sent in seemingly normal JPEG, GIF or bitmap files.

Hackers are increasingly using a wider variety of techniques to penetrate corporate defenses with attacks launched through different methods including spam, IM worms, and defaced and fake Web sites. Computer users need only visit a compromised or fake Web site to be attacked.

Click here to see Microsoft's security advisory about the WMF flaw.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web