Posts: 3,108
Location: Toronto, Ontario
|
MS has released an official patch now, for anyone reading. It got so much recognition that they didn't dare wait 'til their usual second Tuesday of each month.
As for not installing unofficial patches: usually. This "feature" of WMF allows an attacker to insert any arbitrary code into an image file that will be run anywhere an image could be displayed. In any browser viewing any page, your email etc. You don't need to click or accept or anything for this code to be run, and it will be run with the same permissions as the current user (and in Windows, that means 95% of the time, administrator). Waiting for MS to release a patch (and at first they said they were going to stick to their usual "Update Tuesday" schedule, which would mean another week) could be disastrous. The patch was written by a known author and has been recommended by trusted sources, there is no more risk in installing the temporary unofficial patch then there is running without it. But I do agree with you on the whole, but in this case I think it was better to install the unofficial patch.
|