Tomorrow morning, when a hundred
million corporate PCs boot up, the Windows WMF exploit is likely to
become front-page news. This has the potential to be the worst one yet.
Microsoft has issued no patch, nor even a real workaround. You can't
firewall the exploit. Short of disconnecting your systems from the
Internet or replacing Windows with Linux, there's not much you can do,
at least officially.
The folks at the Internet Storm Center have come up with an unofficial
patch. Just as they never thought they'd be asking people to trust
them, I never thought I'd recommend installing an unofficial operating
system patch. But there it is. Microsoft has abdicated its
responsibility to get a fix posted, even if it's not perfect. But
something has to be done, with or without Microsoft's blessing. This
looks like the best bet until Microsoft gets around to releasing an
official patch.
<
http://isc.sans.org/diary.php?storyid=996>
I haven't installed this unofficial patch myself, because I don't have
any Windows systems. If I did, I'd install this patch. For all I know,
it'll break your Windows installation completely. But the folks at ISC
are good people, who have proven themselves reliable over the years,
and under these circumstances I don't see any alternative to trusting
them.
The decision is yours. If it were my system, I'd install the patch.
Good luck.