# Windows Latest Security Flaw

**URL:** <https://boards.straightdope.com/t/windows-latest-security-flaw/337574>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [December 29, 2005, 3:13pm UTC](https://boards.straightdope.com/t/windows-latest-security-flaw/337574 "2005-12-29T15:13:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tuckerfan](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@Tuckerfan](https://boards.straightdope.com/u/Tuckerfan)\
**Post date:** [December 29, 2005, 3:13pm UTC](https://boards.straightdope.com/t/windows-latest-security-flaw/337574/1 "2005-12-29T15:13:54Z")

</div>

[Spyware embedded in image files.](http://news.bbc.co.uk/2/hi/technology/4566504.stm)

> [@](#):
>
> The US net watchdog, the Computer Emergency Response Center (Cert), and security firms have issued warnings about certain types of image files called Windows Metafiles.
> 
> Experts said numerous websites were taking advantage of the flaw to sneak into computers and install spyware.
> 
> Microsoft has said it is looking into the issue.
> 
> Spam bots
> 
> The flaw centres on the way Microsoft’s operating system handles Windows Metafiles (.wmf). These are image files that can contain both vector and bitmap-based picture information.

Apparently, sites are using it to try and steal credit card numbers as well as create zombi PCs that send out tons of spam emails. As of yet, there doesn’t seem to be a patch for it.

---

<div class="post-metadata">

**Author:** ![spingears](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@spingears](https://boards.straightdope.com/u/spingears)\
**Post date:** [December 30, 2005, 12:04am UTC](https://boards.straightdope.com/t/windows-latest-security-flaw/337574/2 "2005-12-30T00:04:39Z")

</div>

> [@Tuckerfan](#):
>
> Windows Latest Security Flaw

Bless dear old MicroMush and B.G.  
**It won’t be the last!**
