GDI+ Mess
You have got to be kidding. I saw all the people complaining in the blogs for the past week or so, and finally decided I better patch my boxes last night. What a mess. Windows update installs a patch that tells you to get another one?! Office update only has some junk mail update. Download and install some file from a KB article (yeah, sure, my mom will be able to find that file, and will care enough to do it). Meanwhile I see other people predicting Blaster like outcome from this.
This is bad. Very bad. Obviously everyone else has been screaming about it for a while now, so it's not new news. But c'mon MS. This could be a huge problem. You guys have worked so hard to make us (relatively) trust windows update again, and you will ruin all of it in one swoop if this gets loose.
To top the cake, saw this, ran the “search” app, and according to this, I'm still not out of the water. If I don't know how to protect myself, how can I protect my clients (read professional, personal, family).
Oh, and in case you need it, here is where I got the MS patch since its not obvious where to get it.
If anyone has definitive instructions on how to fix, and check to make sure it's fixed, please let (me and) the community know.
[EDIT] More useless links. Ms detection tool. Tells me I might still have issues. Redirects me to this instructions page. (Note again, all after running the 2k3 update from link above). Tells me to update office. Ok, I will install that junk email update. (WTF?!) Junk email filter update needs a reboot. Ok. Brb.
[EDIT 2] After that update I bit the bullet and decided to give .net 1.1 sp1 a whirl. A week before a deadline is not the time to patch the framework, but it's even worse to lose a workstation. After all of this (doing everything I could find), the MS tool tells me I might still be vuln, but the third party tool gives many more details, and even though I have some dll's that might be bad, the core dll's seem to be ok. Now it's just time to test our app and make sure 1.1 sp1 didn't break it.
Do I feel safe? Hell no. Do I feel I have done all I can? Yes. Will I be ripshit when I notice a reverse telnet shell to some country and someone rifling through my files? Absolutely.
[EDIT 3] Found a couple more links with details here. Someone has to step up on this front and give us a way to be sure we are ok. If it's not MS, maybe one of the virus companies will step up to bat. Well, more really good details are found within the link at this article.
If I find more, I'll update more in comments.