Shavlik Technologies, LLC Offers Emergency Workaround for Zero-Day Exploit in WMF Graphic Files


Microsoft's recent Security Advisory (912840) warns of a vulnerable exploit that could allow an attacker to execute arbitrary code on a user's system by hosting a specially crafted Windows Metafile (WMF) image on a malicious Web site. For administrators that want a workaround to protect against this vulnerability, Shavlik Technologies offers a solution to help network administrators quickly protect their systems.

Shavlik NetChk(TM) Protect allows users to un-register the SHIMGVW.DLL files that enable the malicious code to attack systems on Windows XP and Windows 2003. Microsoft suggests in its advisory that un-registering the .dll files are the only work-around available at this time.

For Shavlik HFNetChkPro(TM) users, Shavlik Technologies has developed a workaround to help administrators address this vulnerability. For more information visit Shavlik's Support Forum at forum.shavlik.com/viewtopic.php?t=2731 .

For more information about this security advisory, visit the Shavlik web site at www.shavlik.com/ .

To view the Microsoft Security Advisory, visit Microsoft's web site at www.microsoft.com/technet/security/advisory/912840.mspx .

Shavlik Technologies helps information technology managers and administrators manage computer system security including policy based assessment, security scanning and remediation of security vulnerabilities due to missing patches, weak accounts and passwords. Shavlik's security solutions include Shavlik NetChk(TM) Protect, a unified console for multiple security products including Shavlik HFNetChkPro(TM), the industry standard for security patch management; Shavlik NetChk(TM) Spyware, an enterprise anti- spyware solution, and Shavlik NetChk(TM) Compliance, a solution for managing critical system and security configurations. Other security solutions include Shavlik Security Agents(TM), the company's new agent-based patch management solution; Shavlik HFNetChkPro(TM) for Solaris, the company's web-based interface for the Linux and Solaris environments; Shavlik EnterpriseInspector(TM), a powerful network inspection tool; and Shavlik AccountInspector(TM), an interactive account and password security tool.

Mark Shavlik, CEO of Shavlik Technologies, is available to discuss this latest security vulnerability.

All Topics