[CS-FSLUG] Another Major MS Windows Security Flaw

Frank Bax fbax at sympatico.ca
Mon Jan 2 08:42:57 CST 2006


At 06:35 PM 1/1/06, Ed Hurst wrote:
>Worse, some say the registry tweak doesn't work.


Perhaps because there are backslashes missing in the original quote?

I suspect that perhaps:
         %windir%system32shimgvw.dll
should be:
         %windir%\system32\shimgvw.dll

Or perhaps, it's because

http://weblog.infoworld.com/zeroday/archives/2005/12/new_years_eve_a.html

This viruslist.com 
<http://www.viruslist.com/en/weblog?discuss=176892530&return=1>entry also 
goes on to point out that the problem seems to be in gdi32.dll and not in 
shimgvw.dll as previously thought as it is possible to exploit a system 
where shimgvw.dll has been unregistered and deleted.





More information about the Christiansource mailing list