Computing is some nasty business
Thursday, December 29th, 2005So I was just reading the Cuteness Megathread in the SA forums and then opened another thread with details on the latest Windows exploit. From F-Secure’s blog…
There’s a new zero-day vulnerability related to Windows’ image rendering - namely WMF files (Windows Metafiles). Trojan downloaders, available from unionseek[DOT]com, have been actively exploiting this vulnerability. Right now, fully patched Windows XP SP2 machines machines are vulnerable, with no known patch.
Do note that it’s really easy to get burned by this exploit if you’re analysing it under Windows. All you need to do is to access an infected web site with IE or view a folder with infected files with the Windows Explorer.
You can get burned even while working in a DOS box! This happened on one of our test machines where we simply used the WGET command-line tool to download a malicious WMF file. That’s it, it was enough to download the file. So how on earth did it have a chance to execute?
More here. Time to join my coworkers and buy a Mac, I guess. ;P It’s no longer a matter of “Don’t download da filez from Joebob’s House of Viruses”