Bugtraq mailing list archives
Re: WMF Exploit
From: Justin Myers <masterbofh () gmail com>
Date: Sun, 1 Jan 2006 14:31:57 -0600
Apologies if you've already read this, but this is interesting news: Apparently shimgvw.dll isn't the problem; according to the Kaspersky Lab blog, gdi32.dll is.
From http://www.viruslist.com/en/weblog?discuss=176892530&return=1
(which talks about an IM worm that uses this): "Going back to the wmf vulnerability itself, we see number of sites mention that shimgvw.dll is the vulnerable file. This doesn't seem correct as it's possible to exploit a system on which shimgvw.dll has been unregistered and deleted. The vulnerability seems to be in gdi32.dll."
Current thread:
- Re: WMF Exploit Justin Myers (Jan 03)
- <Possible follow-ups>
- Re: RE: WMF Exploit grasshopa (Jan 03)
- Re: WMF Exploit Joshua (Jan 05)
- Re: WMF Exploit Frank Knobbe (Jan 03)
- RE: WMF Exploit Paul (Jan 03)
- WMF exploit Andreas Marx (Jan 04)
- Re: WMF Exploit Paul Laudanski (Jan 04)
- RE: WMF Exploit Discussion Lists (Jan 04)