Attackers Exploit Critical Windows Metafile Flaw
Code for what Secunia is deeming an "extremely critical flaw" in Windows Metafile Format (.wmf) files is in the wild and is now being exploited on fully patched systems by malicious attackers. Vulnerable operating systems include a slew of Windows Server 2003 editions: Datacenter Edition, Enterprise Edition, Standard Edition and Web Edition. Also at risk are Windows XP Home Edition and Windows XP Professional, making both home users and businesses open to attack.
According to the Sunbelt Software blog, "any application that automatically displays a WMF image" can be a vector for infection, including older versions of Firefox, current versions of Opera, Outlook and all current versions of Internet Explorer on all Windows versions.
Code for what Secunia is deeming an "extremely critical flaw" in Windows Metafile Format files is being exploited on fully patched systems.(continue at source)








