Virus: EXP/MS06-001.WMF
Type: Exploit
In the wild: Yes
Reported Infections: Medium
Distribution Potential: Low
Damage Potential: Medium
Static file: No
Aliases:
Non working variants may be identified as:
• EXP/MS06-001.WMF.Intended
It was previously detected as:
• EXP/IMG.WMF
MS06-001 (Vulnerability in Graphics Rendering Engine)
Description:
EXP/IMG.WMF is a generic detection for exploits using a vulnerability in the Microsoft Windows Graphics Rendering Engine.
Modified WMF files that make use of this vulnerability can activate payload code without execution of the file itself. This may happen while marking a file in Windows Explorer or surfing to a malicious website using Microsoft Internet Explorer.
Note that we received many files that make use of this vulnerability. Some of them were available even before the official patch was available which gained it the "0-day exploit" name.
Please make sure that you download and install the patch in order to be protected against this threat. The patch itself among further technical information can be found here: MS06-001