Home > Security News > Experts express concern over WMF patch delay
Security News:
EMAIL THIS

Experts express concern over WMF patch delay

By Joan Goodchild, News Writer
05 Jan 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Microsoft's plans to hold the release of an urgently needed patch until next Tuesday does not sit well with security experts.

The fix is for an extremely critical Windows Meta File glitch involving the way Windows handles its image files. It could become a major headache for IT professionals this week as exploits are released and enterprise users return from a long holiday break.

Security firms are urging IT managers to take serious precautions in the next few days while they wait for the patch.

Several companies have raised their alert and threat levels in response to the lapse in time before the patch is released. Cupertino, Calif.-based antivirus firm Symantec Corp. has raised its ThreatCon status to Level 3 on a 1-to-4 scale. The firm has not placed its threat level at 3 since July 2004 during the MyDoom attack.

"What makes this special is there are a lot of systems that could be exploited," said Jonah Paransky, a senior manager with Symantec. "Will there be a widespread attack? We don't know. Could there be one? Certainly."

More on the WMF flaw

Microsoft plans WMF fix next week  

New WMF worm in wild; unofficial fixes circulating  

Windows image flaw now 'extremely critical'
Pointing to the quick nature of exploits once a vulnerability has been found, Paransky said waiting for four or five days for a patch is an eternity in some enterprise environments. "The average time between a vulnerability ID and a patch from a vendor is 42 days," he said. "The average time for an exploit to be released in response to a vulnerability is six days."

Other antivirus experts are also urging vigilance for IT administrators. Carole Theriault, a security consultant with U.K. firm Sophos Plc, said there are already a few hundred exploits trying to take advantage of the glitch. The exploits are arriving in e-mail, instant messaging and through Web browsing. Sophos has moved its threat level warning from low to medium-high.

"The likeliest scenario is that you would receive an unsolicited e-mail, which would then attempt to entice you to click on a link," said Theriault. "The link would bring you to a compromised Web page, which would attempt to exploit the vulnerability."

Finnish security firm F-Secure Corp. has raised its Radar Alert to its second highest level. Mikko HyppÖnen, the company's antivirus research director, was hesitant to get into scenarios because of the massive risk. HyppÖnen said he was especially concerned because almost all Windows machines are vulnerable.

"We're afraid of an e-mail worm that would use image files to spread. If that would happen, it would be a massive, global outbreak almost immediately," he said.

SANS Internet Storm Center (ISC) in Bethesda, Md., is hosting an online poll to gauge how users have been impacted so far by the WMF vulnerability. According to results on Wednesday, 11% of respondents had already been hit by some infection. However, the large majority, 78%, had not seen an exploit yet.

"Given that the vulnerability can spread through e-mail and does not require any user interaction, there is a real potential for a mass outbreak via e-mail," said SANS chief research officer Johannes Ullrich. "I don't think a 'blaster type' attack is possible, but something like 'zotob' is possible."

Further illustrating the seriousness of the threat, the ISC has taken the unusual step of endorsing an unofficial fix available via Russian programmer Ilfak Guilfanov's blog.

While they wait for Tuesday's fix, antivirus experts advise managers to educate users about what sites they visit and what e-mail attachments they open. Symantec's Paransky said managers should go a step further and block access to untrustworthy sites if possible.

"This is not a time for users to go plumbing the depths of the Internet," said Paransky. It's like dangerous neighborhoods -- there are times when you may feel safe visiting them. But right now, don't go there."

Tags: Application Attacks (Buffer Overflows, Cross-Site Scripting)Malware, Viruses, Trojans and SpywareWindows Security: Alerts, Updates and Best PracticesEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Application Attacks (Buffer Overflows, Cross-Site Scripting)
Quiz: How to build secure applications
Black box and white box testing: Which is best?
Adobe warns of critical update for Reader, Acrobat 9.1.3
9 Ways to Improve Application Security After an Incident
Developers Need Help with Security Errors
Buffer overflow tutorial: How to find vulnerabilities, prevent attacks
SQL injection protection: A guide on how to prevent and stop attacks
Experts rebuke programmers who use SQL injection as feature
SANS: Application threats, website flaws pose biggest security threats
Mozilla helps Adobe push out faster patches
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

Malware, Viruses, Trojans and Spyware
The world's top 5 riskiest domains
New Zeus spam poses as Social Security statements
Increase in Gumblar backdoors poses FTP credential problems
Hackers to sharpen malware, malicious software in 2010
iPhone worm Rickrolls jailbroken phones
Israeli Mossad add Trojan Horse to Syrian laptop
Schneier-Ranum Face-Off: Is antivirus dead?
Modern malware, stealthy botnets, adapt quickly, expert says
Computer worm infections up, scareware antivirus down, Microsoft says
Web-based attacks skyrocket, pirating sites surge, security firms say

Windows Security: Alerts, Updates and Best Practices
Microsoft to address 12 vulnerabilities, IE display zero-day
Exploit code targets Internet Explorer zero-day display flaw
Windows 7 DoS flaw allows hackers to freeze Microsoft's newest OS
Microsoft patches serious Windows kernel flaws
Microsoft to address flaws in Windows, Office for Mac
Microsoft fixes security update that breaks Internet Explorer
What is the best database patch management process?
Microsoft addresses critical SMBv2 flaw, fixes record number of flaws
Microsoft to address SMB zero-day, IIS FTP Service vulnerabilities
Microsoft releases temporary fix for SMB2 zero-day vulnerability

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
buffer overflow  (SearchSecurity.com)
cache poisoning  (SearchSecurity.com)
cyberterrorism  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
directory harvest attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
ping of death  (SearchSecurity.com)
stack smashing  (SearchSecurity.com)
SYN flooding  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts