WMF flaw fails to spark attacks on AU users: Microsoft

Microsoft said today there had been "no evidence" of any consumer or enterprise users in Australia being attacked via a serious vulnerability in the Windows Meta File area of code in the Windows operating system.

Peter Watson, chief security advisor for Microsoft Australia, made the comment in a statement this morning confirming the company had delivered an urgent fix for the widely-publicised flaw ahead of the Redmond vendor's first monthly bulletin of security patches, scheduled for Tuesday next week in the United States.

"Microsoft's monitoring of the situation continues and I can let you know that at this stage there has been no evidence of any exploitation both on a consumer and enterprise customer level in Australia," Watson said.

Security experts have warned that thousands of malicious Web sites, some Trojan horses and at least one instant messaging worm exploiting the vulnerability have surfaced. Microsoft last night (AEDT) updated earlier advice that an attack could only occur if a user visited a Web site containing a malicious image or opened such a file attached to an e-mail, saying attackers could also exploit the flaw via a malicious image embedded in a Microsoft Office document.

Watson said Microsoft had not encountered any situation in which simply opening an e-mail could result in attack.

He said testing for the fix had been completed "earlier than anticipated," allowing Microsoft to release it last night (AEDT). The fix is available for download here.

In an interview with ZDNet Australia, Watson attributed the dearth of infection and exploitation in Australia to the fact most users here only visited trusted Web sites or had updated their anti-virus signatures to the latest versions which mitigated attacks based on the WMF vulnerability.

Watson said while early completion of the testing process was one factor in allowing Microsoft to push out the fix earlier than it originally intended, it had also been prompted to do so by the large number of queries about the problem from enterprise customers worldwide, including Australia.

The fix is also being pushed out to consumers and enterprise customers through Microsoft's automatic update services.

Watson's remarks follow comments last night (AEDT) from a director in Microsoft's Security Response Center, Debbie Fry Wilson, acknowledging the issue was "critical".

"Although the attacks based on WMF are very real, and the exploitation and the threats are evolving on a very fast basis, our analysis is consistent that the infection rate is low to moderate," Fry Wilson said. "However, the threat is very real, and customers should take the action of deploying this update as soon as possible."

CNET News.com's Joris Evers contributed to this report.

Advertisement

Talkback 3 comments

    What they can't see doesnt exist? Anonymous -- 07/01/06 (in reply to #120126653)

    I know of all kinds of places this exploit was used and was used in web based html emails, not to mention forum signatures of some people who grabbed the earlier developed "un-official" patch to just cause havoc on other forum browsers.

    Just because they don't open their eyes, means they can say without lying "We have no reported cases...".

    Not everyone escaped Anonymous -- 09/01/06

    Unfortunately this fix from Microsoft came about 3 days too late for me. This was a vicious little bugger, and the first virus I've actually had infect my computer in over 20 years of using them.

    All I did was went to a site I regularly visit (just a band site - not even a suspicious one), and that was it. I didn't open any files or anything - it was quick. Even after various antivirus and spyware updates, the computer that it occurred on will have to undergo a complete reformat, as there are still various nasties lurking there.

    Are they sure? Anonymous -- 09/01/06

    I recieved dozens of emails trying to lure me to web sites with the infrcted WMF files, i saw people posting them on forums to try to hack others.
    I bet there are thousands of "ma and pa" users out there infected, most probably just don't know it.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured