Tuesday, January 10, 2006

New Batch of WMF Flaws Flagged

Updated: Just days after the release of Microsoft's out-of-cycle WMF patch, researchers publish details—and exploit code—for two new denial-of-service vulnerabilities. Redmond is investigating.

That's right! There are NEW WMF bugs!

The good news is that these bugs do not appear to allow for arbitrary code execution (unlike the last one). These just cause denial-of-service (DOS) type problems, which just tends to be pretty annoying.

There is speculation that more examination of these bugs may lead to arbitrary code execution.

