SHARE
Facebook X Pinterest WhatsApp

Critical Windows Metafile Flaw Being Exploited

Microsoft Corp. has issued a security advisory for what Secunia is deeming an “extremely critical flaw” in Windows Metafile Format (.wmf) that is now being exploited on fully patched systems by malicious attackers. Websense Security Labs is tracking thousands of sites distributing the exploit code from a site called iFrameCASH BUSINESS. That site and numerous […]

Written By
thumbnail Lisa Vaas
Lisa Vaas
Dec 29, 2005
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Microsoft Corp. has issued a security advisory for what Secunia is deeming an “extremely critical flaw” in Windows Metafile Format (.wmf) that is now being exploited on fully patched systems by malicious attackers.

Websense Security Labs is tracking thousands of sites distributing the exploit code from a site called iFrameCASH BUSINESS.

That site and numerous others are distributing spyware and other unwanted software, replacing users’ desktop backgrounds with a message that warns of spyware infection and which prompts the user to enter credit card information to pay for a “spyware cleaning” application to remove the detected spyware.

Vulnerable operating systems include a slew of Windows Server 2003 editions: Datacenter Edition, Enterprise Edition, Standard Edition and Web Edition. Also at risk are Windows XP Home Edition and Windows XP Professional, making both home users and businesses open to attack.

In this fluid attack, researchers have kept up a steady stream of new details about the extent of the exploit’s reach, with Google Desktop being the latest reported vector.

F-Secure reported on Wednesday that Google Desktop tries to index image files with the exploit, executing it in the process. F-Secure reports that this exploitation-via-indexing may wind up occurring with other desktop search engines as well.

Read the full story on eWEEK.com: Critical Impact: Windows Metafile Flaw a ‘Zero-Day Exploit’

Recommended for you...

Manny Rivelo on Evolving Channel & How MSPs Can Get Ahead
Victoria Durgin
Aug 20, 2025
Databricks Raises at $100B+ Valuation on AI Momentum
Allison Francis
Aug 20, 2025
Keepit Achieves SOC 2 Type 1 & Canadian Ingram Micro Deal
Jordan Smith
Aug 20, 2025
AI Customer Service Fails to Satisfy Consumer Needs: Verizon
Franklin Okeke
Aug 19, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.