Friday, December 30, 2005

Racing Against the (WMF) Clock

The last time Microsoft was notified of a remote code execution bug in the rendering of WMF (Windows Metafile) images, it took 7+ months before a patch was made available.

At the time, the MSRC's Stephen Toulouse explained the lengthy delay:

"The graphics rendering system is an extremely important component of the operating system. It's critical to functioning of operating system. Any time you make a change to such an important component, you absolutely have to ensure you're not introducing new problems."

I can't imagine the MSRC having that kind of luxury this time around.