Windows WMF vulnerability FAQ

Internet Storm CenterThe SANS Internet Storm Center has posted an FAQ about the WMF exploit that has been making the rounds lately. It says that all versions of Windows are affected and that even if you don't use Internet Explorer you may not be protected. On the ISC blog Tom Liston writes, "This is a bad situation that will only get worse. The very best response that our collective wisdom can create is contained in this advice—unregister shimgvw.dll and use the unofficial patch. You need to trust us." Instructions for using the patch and unregistering the DLL can be found in the FAQ.

[Via The Unofficial Microsoft Weblog]

Tags: exploit, internet storm center, isc, sans, vulnerability, windows, wmf