Firms urged to use unauthorised Windows patch

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Corporations were advised by security experts on Tuesday to use an unofficial patch to combat the latest Microsoft Windows Metafile (WMF) exploit.

Both antivirus vendor F-Secure and volunteer security group the Internet Storm Center urged businesses to use the unofficial patch, as Microsoft has so far failed to offer an authorised patch to address the problem.

Microsoft, though, has advised businesses not to use third-party updates, even though its own patch won't be available until next Tuesday.

As reported last week, the WMF vulnerability can be exploited by Trojan horse malware to compromise a PC — by installing spyware on it or by turning it into part of a botnet.

Mikko Hypponen, director of antivirus research at F-Secure, said that he believes corporations can trust the unofficial patch, developed by security software developer Ilfak Guilfanov.

"This is a very unusual situation — we've never done this before. We trust Ilfak, and we know his patch works. We've confirmed the binary does what the source code said it does. We've installed the patch on 500 F-Secure computers, and have recommended all of our customers do the same. The businesses who have installed the patch have said it's highly sucessful," said Hypponen.

The Internet Storm Center admitted that many businesses would be very reluctant to deploy an unofficial patch on their systems, but insisted that such drastic action is needed.

"We've received many emails from people saying that no-one in a corporate environment will find using an unofficial patch acceptable," said Tom Liston of the Internet Storm Center, in his blog. "Acceptable or not, folks, you have to trust someone in this situation."

Systems administrators can also work around the problem by unregistering a file called shimgvw.dll.

"The very best response that our collective wisdom can create is contained in this advice — unregister shimgvw.dll and use the unofficial patch," said Liston.

A Microsoft spokeswomen advised businesses to wait for a week, as the software giant can't guarantee third party updates would be effective.

"Microsoft recommends that customers download and deploy the security update for the WMF vulnerability that we are targeting for release on January 10, 2006. Microsoft cannot provide assurance for independent third party security updates," she said.

Security experts say the WMF exploit is potentially very dangerous as conventional antivirus software and IDS signatures do not recognise the malicious code in email spam, as the exploit is sent in seemingly normal JPEG, GIF, or Bitmap files.

Hackers are increasingly using a wider variety of techniques to penetrate corporate defences with attacks launched through different vectors including spam, IM worms, and defaced and fake Web sites. Users need only visit a compromised or fake Web site to be attacked.

Click here to see Microsoft's security advisory about the WMF flaw.

Talkback

Un-official patches can be considered helpfull. But for some reason-or-another I did not find any reference to the source-code, of the patch, only an "click this executable (which will install <whatever> onto your computer), and you will be safe" promiss.

In what way is this un-disclosed patch beter that any closed-source "solution" MS can deliver ?

In other words : closed-source is "bad", but we should trust a closed-source patch from an un-known source ?

Maybe I'm just paranoid, but there is *NO WAY* that I'm going to install that on the computer I'm working on.

via Facebook 4 January, 2006 01:23
Reply

which would you consider more trustworthy:
a.) a patch from someone with lots of references, including vendors of anti-virus software?
b.) a worm embedded in a .jpg file?

i can understand why you're skiddish about this, but i'm more worried about what could happen in the next week when hackers have an open door.

via Facebook 4 January, 2006 03:49
Reply

I went to the download site and received this message:-

"Account for domain hexblog.com has been suspended"

Has the bandwidth been exceeded or has it been taken down by MS or other?

Does anybody know an alternate site, if so please post. Thanks

via Facebook 4 January, 2006 11:39
Reply

Go here

http://tinyurl.com/cos3x

or here

http://tinyurl.com/8stt5

for the patch

via Facebook 4 January, 2006 12:27
Reply

Maybe it's me or something, and I am a little paranoid, But to accept a supposed third-party patch, for a virus is kinda crazy. What if the patch is the cause of the virus, I mean, we can't trust Microsoft in the first place, but it's better than trusting a third-party sometimes. How many times have you downloaded a third-party plugin or extra and don't they always warn you? How do we know it's not the same thing this time? How do we know it won't cause the virus and that's it's just some guys making crap up? But that's me. I'm a paranoid psycho, So you don't have to listen to me.

via Facebook 4 January, 2006 17:37
Reply

Don't be so hard on your self. You are not a psycho. We all know that. But you are spreading FUD. Fear, uncertainty and doubt. At the end of the day, you have to choose who you trust, and trust those that they trust. I would trust those that makes the effort to protect me, not those that only tells me what is suppose to be good for me without making the effort.

via Facebook 4 January, 2006 20:17
Reply

I am not an expert but I took the advice written and downloaded the unofficial patch. After installing it and following all instructions regarding unregistering a dll. etc I found that I could no longer access ANY of my jpegs. I could not do anything with them at all. Lucky that I set a restore point before I installed it or I would have been in trouble. Looks to me that this was tested about as much as an XP service pack !

via Facebook 4 January, 2006 22:42
Reply

In the end whether you install the patch or not, this is all about trust, and risk assesmsnt. Do you trust the prople who are reccomending you install the patch. Are you prepared to risk the consequences of your decision?

I've told my mother, my wife and all my friends to install this, walked my folks through the install in simple easy to understand terms.

I trust F-secure, even though I use Symantec AV. I read the ISC handlers dairy every day so I'm willing to trust them with this, they've earned that much.

Our CERT, (I work for an international agency) is telling people who maintain thier own coproprate PC's to install the patch.

I know who I trust, do you?

via Facebook 4 January, 2006 22:42
Reply

John L.

>After installing it and following all instructions
>regarding unregistering a dll. etc I found that I could
>no longer access ANY of my jpegs.

This is by design, this is what the Microsoft part of the workaround is actually supposed to do.

I draw your attention to the penultimate paragraph of the article you are replying to:

>Security experts say the WMF exploit is potentially
>very dangerous as conventional antivirus
>software and IDS signatures do not recognise the
>malicious code in email spam, as the exploit is
>sent in seemingly normal JPEG, GIF, or Bitmap
>files.

This means that untill either Microsoft release a patch, or the exploit is foiled, any graphical image format supported by the dll you just unregistered is potentially a virus risk.

Any image file, any you view with a web browser, or recieve through the mail. Including those spam images you didn't ask for, are all potential plague rats.

That's how big this problem has the potential of being.

This page:
http://isc.sans.org/diary.php

Is advising Organisations to think about disconnecting from the internet. Switching off all web and email traffic. This has the potential to be a lot more serious that not being able to view a few jpegs.

via Facebook 4 January, 2006 22:54
Reply

To John L and others.

Windows paint and third party software still work - to view your own safe images.

It is only the the actual windows mechanisms which are affected by the unofficial patch - to protect your system from unauthorised malicious activity.

The unofficial patch is fully reversible and must be unistalled before installing MS patch when issued and confirmed effective. Shimgvw.dll should also be re-registered if you have unregistered it (run regsvr32.exe C:\windows\system32\shimgvw.dll).

via Facebook 5 January, 2006 12:24
Reply

It is only one personal opinion but---the patch may well be a good one,was one of the first to get it,utilize it.However,what it does is completely block off all your photos,digital photos etc,so I re-registered the dll the next day.This patch,I suspect,is more for large corporations,large computer networks,work stations etc and not so much for home-users.I have found that rather than un-register this dll,taking advantage of Windows OneCare program offers quite a good protection from the WMF problem.My thanks for the opportunity to respond.

via Facebook 5 January, 2006 15:33
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

7 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

14 hours ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

14 hours ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

14 hours ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

20 hours ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

20 hours ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission
awbMaven

""As a result of Butyka's alleged conduct, researchers were unable to use the computers for more than two months while NASA removed the malicious...

23 hours ago by awbMaven on US indicts Romanian over NASA climate change hack
subhorup

It simultaneously worries me and uplifts me that a self-proclaimed group of internet activists name themselves after Indian mythical figures....

1 day ago by subhorup on Anonymous activists release PCAnywhere source code
naviathan

It's actually far easier to work anonymously on the internet than you think. With tools like Tor bouncing your traffic around the world before...

1 day ago by naviathan on Anonymous activists release PCAnywhere source code
Agnostic_OS

1000272134 and bluedalmatian with you both there but then I'm still in 10.04 land (and happy with it)

1 day ago by Agnostic_OS on Ten factors that make Ubuntu 11.10 a hit
apexwm

Interesting article and definitely see your points on the products mentioned. One of the top products for our Help Desk (approximately 20% of all...

2 days ago by apexwm on Ten flawed products that derail productivity
Paul Hutchinson

Absolutely - this should obviously not be handled my isp - but handled by their hosting operator. What's been suggested here is that my isp police...

2 days ago by Paul Hutchinson via Facebook on MPs urge ISPs to take down terrorist material
Techs UK

Looks like a great phone. I don't notice any deficiencies in WP7. used IOS before, that's pretty good. I don't spend much time in Apps, all i need...

2 days ago by Techs UK on Nokia pins US 're-entry' hopes on Lumia 900
Larry Bloggy

Now with the help of these apps you are always synced with MS outlook while on the move. Just download apps like xobni or outlookreflex and get...

2 days ago by Larry Bloggy via Facebook on Outlook Social Connector beta 2 and the LinkedIn connector
mike40g123

Your details are wrong. The version currently being made is the one with 2 USB ports, 256MB RAM and a network port. This is the Model B. The...

2 days ago by mike40g123 on Raspberry Pi boards set to go on sale
Moley

The thing that has been puzzling me for quite a while is how Anonymous can remain anonymous whilst not only being active on the Internet but also...

3 days ago by Moley on Anonymous activists release PCAnywhere source code
Don Dilly

If what Semantec is saying is rue, that is even worse and shows a complete disregard for thier users. If what Anonymous claims is true and the...

3 days ago by Don Dilly via Facebook on Anonymous activists release PCAnywhere source code
MattChurchy

Didn't seem particularly biased to me either. Oh though you might have mentioned some other competitors with free search and email services...

3 days ago by MattChurchy on Time for an evil umpire: Google, Microsoft & privacy
Simon Bisson and Mary Branscombe

James - exactly as much as anyone paid you for your comment; I don't feel that I need to say that I'm independant and unbiased, but just for you...

3 days ago by Simon Bisson and Mary Branscombe on Time for an evil umpire: Google, Microsoft & privacy
Carl White

Once they realise symantec are willing to pay real money, they will simply keep extorting, unless of course symantec/authorities can use the...

3 days ago by Carl White via Facebook on Symantec offered hackers $50k in source code sting