WMF FAQ
Last Updated: 2006-01-07 17:16:23 UTC
by Swa Frantzen (Version: 5)
[a few users offered translations of this FAQ into various languages. Obviously, we can not check the translation for accuracy, nor can we update them. Most of these translations are hosted on servers operated by the translation authors. So use at your own risk: Deutsch and Deutsch (pdf), Catalan , Espaņol , Italiana and Italiana, Polski, Suomenkielinen, Danish, Japanese, Slovenian, Chinese, Norwegian and Nederlands ]
To assist with internal presentations about this issue, we made a slide set available:
PDF, Power Point , OpenOffice 2.0
- Why is this issue so important?
- Is it better to use Firefox or Internet Explorer?
- What versions of Windows are affected?
Note: If you're still running on Win98/ME, this is a watershed moment: we believe (untested) that your system is vulnerable and there will be no patch from MS. Your mitigation options are very limited. You really need to upgrade.
- What can I do to protect myself?
- How do I re-register the DLL and remove the patch?
To re-register the DLL, click State, click Run, type
regsvr32 %windir%\system32\shimgvw.dllThis is the same command as you used to unregister, with the -u part).
To remove the patch, open the control pannel, open the "Add/Remove Programs" icon, find the patch in the list and uninstall.
To uninstall the patch from the command line (vs. using the Control Panel), enter this command:
msiexec.exe /X{E1CDC5B0-7AFB-11DA-8CD6-0800200C9A66} /qn- How does the unofficial patch work?
- Are there other patches?
- Is there a test to see if I am vulnerable?
- Would unregistering the DLL (without using the official or unofficial patch) protect me?
- Should I just delete the DLL?
- Should I just block all .WMF images?
- What is DEP (Data Execution Protection) and how does it help me?
- How good are Anti Virus products to prevent the exploit?
- How could a malicious WMF file enter my system?
- Is it sufficient to tell my users not to visit untrusted web sites?
- What is the actual problem with WMF images here?
- Should I use something like "dropmyrights" to lower the impact of an exploit.
- Are my servers vulnerable?
- What can I do at my perimeter / firewall to protect my network?
- Can I use an IDS to detect the exploit?
- If I get hit by the exploit, what can I do?
- Does Microsoft have information available?
http://www.microsoft.com/technet/security/advisory/912840.mspx
but Microsoft in the mean time has release an official patch
http://www.microsoft.com/technet/security/bulletin/ms06-001.mspx
- What does CERT have to say?
Comments
New Comments closed for all Diaries older than two(2) weeks
Please send your comments to our Contact Form

Diary Archives