
Gartner warns on WMF problem
By Steve Ranger
Published: 4 January 2006 16:00 GMT
Analyst Gartner is warning that a flaw in Windows Meta File (WMF) code in Windows could be a risk to "many" enterprise IT systems, and not just those that directly use the affected process.
Security companies are already warning that the flaw in the Microsoft image-rendering process has spawned dozens of attacks since its discovery last week.
Gartner warned in a research note: "This critical vulnerability could damage many enterprise systems, not just those that directly use the affected process."
The analyst group added: "Mitigating this vulnerability will be difficult", because it is within a Dynamic Link Library file used by an unknown number of applications.
Gartner is recommending companies block WMFs in email attachments and web downloads for "immediate, partial protection until a patch can be deployed".
The note, written by analysts Amrit Williams, Jay Heiser and Neil MacDonald, said URL filtering products should be activated and inline network intrusion prevention systems, antivirus and anti-spyware tools should be updated with the latest signature updates.
Microsoft aims to release a security update to address the vulnerability on 10 January, as part of its monthly release of security bulletins.
A third-party patch is available but Gartner recommends against the use of this unsupported patch, particularly by large enterprises, "because the patch would require extensive testing and eventual de-installation and could introduce additional risk".
Our ambitions are big, our aims are high and right now there's everything to achieve. ITIL foundation certification desirable Please note, this role ...
The role is to provide day to day support, troubleshooting, tuning, administration, systems hardening (security), and project work for a wide range ...
Patch Management, Systems Tuning, Systems Hardening (security), Backup/Recovery, Shell Scripting, Hardware Setup/Configuration, Production ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...