ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Firms urged to use unauthorised Windows patch

Tom Espiner ZDNet.co.uk

Published: 03 Jan 2006 17:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Corporations were advised by security experts on Tuesday to use an unofficial patch to combat the latest Microsoft Windows Metafile (WMF) exploit.

Both antivirus vendor F-Secure and volunteer security group the Internet Storm Center urged businesses to use the unofficial patch, as Microsoft has so far failed to offer an authorised patch to address the problem.

Microsoft, though, has advised businesses not to use third-party updates, even though its own patch won't be available until next Tuesday.

As reported last week, the WMF vulnerability can be exploited by Trojan horse malware to compromise a PC — by installing spyware on it or by turning it into part of a botnet.

Mikko Hypponen, director of antivirus research at F-Secure, said that he believes corporations can trust the unofficial patch, developed by security software developer Ilfak Guilfanov.

"This is a very unusual situation — we've never done this before. We trust Ilfak, and we know his patch works. We've confirmed the binary does what the source code said it does. We've installed the patch on 500 F-Secure computers, and have recommended all of our customers do the same. The businesses who have installed the patch have said it's highly sucessful," said Hypponen.

The Internet Storm Center admitted that many businesses would be very reluctant to deploy an unofficial patch on their systems, but insisted that such drastic action is needed.

"We've received many emails from people saying that no-one in a corporate environment will find using an unofficial patch acceptable," said Tom Liston of the Internet Storm Center, in his blog. "Acceptable or not, folks, you have to trust someone in this situation."

Systems administrators can also work around the problem by unregistering a file called shimgvw.dll.

"The very best response that our collective wisdom can create is contained in this advice — unregister shimgvw.dll and use the unofficial patch," said Liston.

A Microsoft spokeswomen advised businesses to wait for a week, as the software giant can't guarantee third party updates would be effective.

"Microsoft recommends that customers download and deploy the security update for the WMF vulnerability that we are targeting for release on January 10, 2006. Microsoft cannot provide assurance for independent third party security updates," she said.

Security experts say the WMF exploit is potentially very dangerous as conventional antivirus software and IDS signatures do not recognise the malicious code in email spam, as the exploit is sent in seemingly normal JPEG, GIF, or Bitmap files.

Hackers are increasingly using a wider variety of techniques to penetrate corporate defences with attacks launched through different vectors including spam, IM worms, and defaced and fake Web sites. Users need only visit a compromised or fake Web site to be attacked.

Click here to see Microsoft's security advisory about the WMF flaw.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
280 out of 377 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Project Manager - Order Management Systems

In particular the role will involve managing the assessment and implementation of a third party solutions and in-house developed tools.The role will ...

Business Analyst - Hedge Fund / Asset Management

Analyst in order to launch new hedge funds and to migrate existing hedge funds from an internal system to a third party application. The third party ...

SQL Server DBA - Local Council - South West of Uk 150 per day

SQL Server 2005 DBA required to assist a council in the South West with a project to design and build a consolidated SQL server environment to ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment