Security news January 17, 2006

Microsoft Corp. has issued a patch for a preliminary version of its Vista OS for the same graphics-rendering problem that raised concerns about current versions of the Windows OS earlier this month.


The patch applies to a Community Technology Preview (CTP) of Vista released in December, a version available to Microsoft Developer Network (MSDN) Universal subscribers and beta testers, according to Microsoft’s Web site. Vista isn’t due for a general release to the public until later this year.

The fix amends how Windows Vista deals with graphics in the WMF (Windows Metafile) format, as those files could force a machine to run arbitrary code. If opened, WMF files (perhaps disguised with a suffix such as .jpg instead of the usual .wmf) could trigger the execution of code that tries to download more malicious software.

After the WMF vulnerability came to light last month, it caused a somewhat unorthodox response given the danger security experts felt it posed. One researcher created an unofficial patch, which some security organizations advised users to apply immediately. Meanwhile, Microsoft broke with its regular patch schedule, usually the second Tuesday of the month, and issued a fix on Jan. 5, while company officials sought to address concerns it waited too long.

Related Articles:
  • Microsoft Delivers Vista's Final Test Version: Microsoft today released what it believes will be the last
  • IE 7 Release Apparently Slips: The next prerelease version of Microsoft Internet Explorer 7 for
  • Microsoft probes Outlook Express patch trouble: Does bad luck indeed come in threes? A Microsoft security
  • Launch for Vista on schedule: Microsoft: Microsoft Corp. released on Friday the final test version of
  • OS wars over as Leopard mauls Vista: I love IT wars, always have. Back in the day,
  • Articles:

    Leave a Reply

    You must be logged in to post a comment.