New WMF zero-day vulnerability
p2p news / p2pnet: A new zero-day vulnerability is targetting Windows WMF files (Windows Metafiles) and, "Right now, fully patched Windows XP SP2 machines are vulnerable," with no known fix, says F-Secure.
Trojan downloaders, available from unionseek[DOT]com, have been actively exploiting this vulnerability, it states, going on that the exploit is currently being used to distribute:
Trojan-Downloader.Win32.Agent.abs
Trojan-Dropper.Win32.Small.zp
Trojan.Win32.Small.ga
Trojan.Win32.Small.ev.
Some install hoax anti-malware programs such as Avgold, says the post, and, "You can get infected if you visit a web site that has an image file containing the exploit. Internet Explorer users might automatically get infected. Firefox users can get infected if they decide to run or download the image file.
"In our tests (under XP SP2) older versions of Firefox (1.0.4) defaulted to open WMF files with "Windows Picture and Fax Viewer", which is vulnerable. Newer versions (1.5) defaulted to open them with Windows Media Player, which is not vulnerable…but then again, Windows Media Player is not able to show WMF files at all so this might be a bug in Firefox. Opera 8.51 defaults to open WMF files with "Windows Picture and Fax Viewer" too. However, all versions of Firefox and Opera prompt the user first.
"As a precaution, we recommend administrators to block access to unionseek[DOT]com and to filter all WMF files at HTTP proxy and SMTP level."
Also See:
F-Secure - New WMF 0-day exploit, December 28, 2005





p2pnet - rss feed: 
December 29th, 2005 at 9:46 am
If your company email scanner doesn’t already quarantine all attachments, you’ve won the Special IT Security Award. To find it, ram your head into the nearest 17″ crt monitor really really hard. When you hear the bang, you’ve found it.
If your company doesn’t have an email scanner, you’ve won the Really Special IT Security Award. But it’s being stolen! Quick!! Jump out the window and chase them into oncoming traffic!!!