Thursday, January 05, 2006

Major XP security flaw

1-5-2006 Microsoft has released the patch. It is available via Windows Update. It should be downloaded and installed on most XP computers automatically at 3:00am tonight. Be sure to uninstall the Windows WMF patch if you installed it.

1-4-2006: Oh oh - this is worse than I thought. The following is from Brian Livingston's 'Windows Secrects' newsletter:
If your PC catches an infected metafile — perhaps through instant messaging or file-sharing software — the payload can run even if you don't consciously open or view the image. Google Desktop Search, for example, causes the payload to be executed when the metadata of the image is accessed. If the image is an icon, merely displaying a file directory in certain views of Windows Explorer can silently execute a Trojan.

1-3-2006 From Microsoft:
Our goal is to release the update on Tuesday, January 10, 2006, as part of the regular, monthly security update release cycle, although quality is the gating factor. Customers will be able to get the update through all the usual deployment tools: Microsoft Update, Windows Update, Automatic Update, the Download Center and Windows Server Update Services.


Hackers have discovered a 'back door' into Windows 2000 or XP that let's them install all sorts of scary stuff if you visit one of their web sites. Latest reports are that it can also be spread by Microsoft Messenger.

This web site seems to have the best temp. fix. Download and install the file.
Remember to uninstall when Microsoft issues a fix.
http://www.grc.com/sn/notes-020.htm

No comments: