This is an informational alert that Microsoft has just released a patch for
the WMF vulnerability. WebsenseŽ Security Labs(TM) was acknowledged as as a contributor in the bulletin from Microsoft.
http://www.microsoft.com/technet/sec.../ms06-001.mspx
At this time more than 1100 URLs are still actively attempting to exploit users who have not installed the patch. Most attacks are Trojan horse downloaders which update over HTTP and install and run other pieces of malicious code.
Depending on your patch rollout procedures, we still recommend that customers block all URLs that end in .WMF. Customers who have Websense Real-Time Security Updates (RTSU) will be protected automatically with frequent updates to the Security categories throughout the day. Customers who have the Websense Security Premium Group without RTSU will receive updates to these categories once per day.
Additional recommendations are provided in the Detect and Prevent sections of this article.
For additional details and information on how to detect and prevent this type of attack:
http://www.websensesecuritylabs.com/...hp?AlertID=392