Sophos

Online support

Product maintenance

Contact support

Support services

Advisory: Guarding against the WMF vulnerability

The Windows Metafile (WMF) vulnerability uses WMF images to execute arbitrary code without the prior consent of the user. This exploit can be triggered by simply viewing such an image in indexing software, or as a Windows Explorer thumbnail. It is not necessary to manually open the affected image for the code to run.

In all versions of Sophos Anti-Virus you should add the following extensions:

wmf
jpg
jpeg

A knowledgebase article gives instructions on adding extensions to Sophos Anti-Virus.

Note: Adding file types to the extensions list can affect system performance.

There is no need to make changes to your PureMessage configuration, as all versions of PureMessage scan all files by default.

If you need more information or guidance, then please contact technical support.