1.02.2006

Re: How Exposed IS The WMF Vulnerability?

Tom asked:
Window, what does this quote from the Microsoft WMF Advisory mean?
Windows Metafile (WMF) images can be embedded in other files such as Word documents. Am I vulnerable to an attack from this vector? No. While we are investigating the public postings which seek to utilize specially crafted WMF files through IE, we are looking thoroughly at all instances of WMF handling as part of our investigation. While we're not aware of any attempts to embed specially crafted WMF files in, for example Microsoft Word documents, our advice is to accept files only from trusted source would apply to any such attempts.
I asked the MSRC (Microsoft Security Research Center) Team if they could clarify what they meant by "No" in the FAQ for the WMF advisory. I agreed with Tom, that it seemed like "No" is probably not the right answer, unless MS knows there is something specific blocking this as a vector.

MSRC responded that they have not yet seen a way to to exploit this issue via compound documents, but that it was still under investigation. So, they're looking.

I don't think that users can dismiss this as a threat to their environment, but there are other vectors that are much higher risk.

We're Matasano Security: Thomas Ptacek, Jeremy Rauch, Window Snyder, David Goldsmith, and Dino Dai Zovi. We're a startup, building a new network security product we hope to be talking about in 2006.

Additionally, we're offering security services: application and infrastructure threat modeling, code review, and black-box penetration testing. Do you have applications or appliances that need to be verified before they can be deployed? Give us a call!

Questions? Suggestions? Harass us all simultaneously at blog@matasano.com.

Powered by Blogger

ATOM