Temporary fix for security breach with WMF files

The possible solution given here is insufficient. Use the patch mentioned in the Steve Gibson reference given by Joel May in his comment.

The security problem mentioned previously grows apace. One possible temporary solution is to remove the WMF file type. Go to any folder and open the menu Tools-Folder Options- File Types. Scroll down the list of file types until you find WMF. Click the “Delete” button. (Picture below) If the “delete” button is grayed out , as sometimes happens, Click the “Edit” button (not shown) and remove “Open” as an action. Then try deleting again. The WMF file type can be reinsituted with the “New” function. See the extensive discussion here for more on this exploit.

WMF file type

2 Responses to “Temporary fix for security breach with WMF files”

  1. joelmay Says:

    See also the patch made available on Steven Gibson’s web site http://www.grc.com/sn/notes-020.htm

  2. Vic Says:

    Thanks for the reference, Joel. There is more on this subject by security expert Larry Seltzer.