Windows Zero Day WMF Exploit

Okay kids, this is the last page you should visit for today.
As soon as you are done reading this just turn off your computer until sometime in May.
I’ll let you know when it’s safe, okay?

Microsoft just released a Security Advisory (912840) entitled: “Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution.” (Soon to be a major motion picture) (Rendered on Linux no doubt).

Here is a synopsis:
1. It’s bad and affects everything between Windows Server 2003 and DOS 2 (actually 98 – XP)
2. You don’t have to click on it, once it downloads Windows will run it for you.
3. It doesn’t even need to be named with the .wmf extension
4. It will make fun of you and tell your friends about the teddy bear you still sleep with.

So far the only advise I have read is from this Techweb article entitled:How To Beat Back The New Zero-Day Windows Bug on $2 a day.
Their recommendation? enter the following on the Run line in the Start menu
“regsvr32 -u %windir%\system32\shimgvw.dll”
(without the ” or ” (their the ones who said it)).

Have you done it yet?
Congratulations you just did something. But nobody seems to be saying what to do to undo the thing you did.

Update your virus ware
Update your Firewall
Update your spyware protection
Just don’t do it by visiting any web sites.

0 Response to “Windows Zero Day WMF Exploit”


  • No Comments

Leave a Reply