For the second time this week, hackers have posted a sample of code that could be used to attack a Windows machine that has not been updated with the most recent Microsoft Corp. security patches. The French Security Incident Response Team (FrSIRT) Web site today posted a sample of a maliciously encoded image file that could be used by attackers to grind a Windows PC to a halt.
This latest example exploits a critical vulnerability in the way Windows processes files saved in the Windows Metafile graphics format. Metafile is a graphics format used by CAD (computer-aided design) software. Files that use this format have either a .wfm or .emf extension.
|