When Independent Security Experts Patch Windows Faster Than Microsoft

from the doesn't-look-good dept

There's been a lot of talk the last few days about the latest exploit found on Microsoft Windows platforms that could be used to install various malware just by making someone view an image. However, the really interesting thing is that while Microsoft is scrambling to make a patch, an independent security researcher has come out with his own patch that security firms are recommending people use until Microsoft gets its act together. In the past, of course, people were warned not to trust third-party patches, but as exploits taking advantage of vulnerabilities show up faster and faster, the race will soon be on for others to create security patches as well, which could create problems if not all of those patches are safe. Update: Meanwhile Microsoft is telling folks to just hang in there, and they'll get a patch out in a week or so.

5 Comments | Leave a Comment..


If you liked this post, you may also be interested in...
 

Reader Comments (rss)

(Flattened / Threaded)

  1.  

    now all they need is...

    identicon
    nonuser, Jan 3rd, 2006 @ 6:53pm

    ... FEMA's Michael Brown to go on the news shows and tell people there is very limited damage, everything is under control.

    reply to this | link to this | view in thread ]

  2.  

    Re: now all they need is...

    identicon
    Anonymous Coward, Jan 4th, 2006 @ 8:23am

    Gates: You're doing a great job, MS! There's massive resouces en-route as we speak, and people shall be rejoicing soon.

    reply to this | link to this | view in thread ]

  3.  

    Re: now all they need is...

    identicon
    crankysysadmin, Jan 4th, 2006 @ 10:44am

    I'm sure Microsoft is pleased as punch to have other people racing to beat them to patch their buggy OS. This sets a precedent that's very favorable for MS. "People pay for our buggy OS and patch it themselves!"

    reply to this | link to this | view in thread ]

  4.  

    Must be nice...

    identicon
    Nate, Jan 4th, 2006 @ 9:38pm

    Must be nice to not have to answer to the customers, or in reality the media more, if the patch destroys certain configurations. That's pretty much the view of the writers of that "patch". If the patch screws up hundreds of thousands of computers everyone will say, "Oh well, at least they tried. It was more than Microsoft did." (Wow...I actually managed to write Microsoft without putting dollar signs in it or spelling it wrong...imagine that)

    reply to this | link to this | view in thread ]

  5.  

    the recent WMF exploit

    identicon
    Stu, Jan 5th, 2006 @ 5:35pm

    If you are referring to the "WMF" exploit, you should be aware that all browsers are vulnerable.

    To quote Brian Livingston's excellent - and free Windows Secrets newsletter, "Every browser is vulnerable — IE, Firefox, Opera, and others — because the image is not being rendered by the browser. It's rendered by Windows' own Picture and Fax Viewer (Shimgvw.dll, also known as the Shell Image View Control). New versions of Firefox do display an alert when a suspicious image is encountered on a Web page. But since viewing an image is usually harmless, most users will click OK, exposing themselves to infection."

    I installed the unofficial patch on my network. It was quick, easy, and includes an uninstall. It does require a reboot.

    Check out Windows Secrets at: http://www.windowssecrets.com/

    reply to this | link to this | view in thread ]


Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here
Get Techdirt’s Daily Email
Save me a cookie
  • Note: A CRLF will be replaced by a break tag (<br>), all other allowable HTML will remain intact
  • Allowed HTML Tags: <b> <i> <a> <em> <br> <strong> <blockquote> <hr> <tt>


A word from our Sponsors...
Follow Techdirt
Flattr rss rss
From the Techdirt Archive...
A word from our Sponsors...

Close

Email This