[41837] in bugtraq
Is this a new exploit?
daemon@ATHENA.MIT.EDU (noemailpls@noemail.ziper)
Tue Dec 27 19:29:56 2005
Date: 27 Dec 2005 20:20:14 -0000
Message-ID: <20051227202014.7446.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: noemailpls@noemail.ziper
To: bugtraq@securityfocus.com
Warning the following URL successfully exploited a fully patched windows xp system with a freshly updated norton anti virus.
unionseek.com/d/t1/wmf_exp.htm
The url runs a .wmf and executes the virus, f-secure will pick up the virus norton will not.