SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > General Computing > Internet
User Name
Password


Windows WMF Metafile Vulnerability HotFix

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 01-01-2006, 07:18 PM
Oleg's Avatar
Oleg Offline
Registered User
 
Join Date: Dec 2004
Location: Mars
Posts: 36
Windows WMF Metafile Vulnerability HotFix

This week a new vulnerability was found in Windows:

http://www.microsoft.com/technet/sec...ry/912840.mspx

Browsing the web was not safe anymore, regardless of the browser. Microsoft will certainly come up with a thouroughly tested fix for it in the future, but meanwhile I developed a temporary fix - I badly needed it.

The fix does not remove any functionality from the system, all pictures will continue to be visible. You can download it here:

http://www.hexblog.com/security/file..._hexblog13.exe

It should work for Windows 2000, XP 32-bit, XP 64-bit, and Windows Server 2003.

Technical details: this is a DLL which gets injected to all processes loading user32.dll.
It patches the Escape() function in gdi32.dll. The result of the patch is that the SETABORT escape sequence is not accepted anymore.

I can imagine situations when this sequence is useful. My patch completely disables this escape sequence, so please be careful. However, with the fix installed, I can browse files, print them and do other things.

If for some reason the patch does not work for you, please uninstall it. It will be in the list of installed programs as "Windows WMF Metafile Vulnerability HotFix". I'd like to know what programs are crippled by the fix, please tell me.

I recommend you to uninstall this fix and use the official patch from Microsoft as soon as it is available.

The usual software disclaimer applies...

File: wmffix_hexblog13.exe (the source code is included)

UPD: more error checking
UPD: Version 1.1 with Win2000 support
UPD: Version 1.2: if the hotfix has already been applied to the system, inform the user at the second installation attempt.
UPD: Version 1.3: added support for Windows 2000 SP4

There is no need to reinstall anything!
Old hotfixes are perfectly ok.

Posted by Ilfak Guilfanov on December 31, 2005 06:53 AM | Permalink

http://www.hexblog.com/2005/12/wmf_vuln.html
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Installer Issue Triple_X Windows XP 3 10-14-2007 04:27 AM
Reinstalling Windows - need to erase everything hiddenmyztery Windows XP 6 12-13-2005 04:18 AM
windows me to windows 98? epower Windows 95/98/ME 4 10-25-2004 02:40 PM
Windows xp hotfix arzes Windows XP 1 04-10-2003 11:17 AM
Microsoft sketches Windows management road map The Tool Internet 0 05-05-2002 12:14 AM



All times are GMT -5. The time now is 02:15 AM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.