A serious new remotely exploitable vulnerability has been discovered in Microsoft Windows' image processing code.
UNTIL THIS IS REPAIRED BY MICROSOFT, ANY ATTEMPTTO DISPLAY A MALICIOUS IMAGE IN WINDOWS COULDINSTALL MALICIOUS SOFTWARE INTO THE COMPUTER.
This is a so-called "0-day vulnerability" because exploits for the vulnerability appeared before any updates or patches were available. All versions of Windows from Windows 98 through ME, NT, 2000, XP, and 2003 are known to be vulnerable, and a large and rapidly growing number of malicious exploits (57 at last count) are already circulating in the wild. They are being actively used to install malware and Trojans into user's machines. Viruses and worms are expected to appear shortly. Although NOT a complete solution, Microsoft has recommended temporarily disabling the automatic display of some images by the operating system and web browser. This can be done, as detailed below, by "unregistering" the "SHIMGVW.DLL" Windows DLL. THIS IS NOT A COMPLETE SOLUTION, but it significantly lowers the risk from this vulnerability from web surfing.
Temp WMF Exploit Patch avialable here
I've used this patch myself and would say that it is safe, as I have experienced no problems with it.
Aqua-Soft Forums