more WMF
Tom Liston at SANS has more on the WMF vulnerability and thinks it could be very very bad indeed and suggests that everyone take an unprecedented step in unregistering this DLL and applying an unofficial patch in lieu of action from Microsoft:
To the best of my knowledge, over the past 5 years, this rag-tag group of volunteers hasn't asked for your trust: we've earned it. Now we're going to expend some of that hard-earned trust:
This is a bad situation that will only get worse. The very best response that our collective wisdom can create is contained in this advice - unregister shimgvw.dll and use the unofficial patch. You need to trust us.
Read the whole post for more.
Click here to get the unofficial patch. I am not prone to hysteria, but folks this doesn't look good, and we ought to all be safe rather than be sorry.
Comments