
Patch and be damned...
By Joris Evers
Published: 27 September 2006 08:45 BST
Microsoft issued a "critical" security fix for Windows on Tuesday, two weeks before its scheduled release date.
The company is breaking with its monthly patch cycle to fix a flaw that cyber crooks have been using to attack Windows PCs via Internet Explorer. Malicious software can be loaded, unbeknown to the user, onto a vulnerable Windows PC when the user clicks on a malicious link on a website or in an email.
Alex Eckelberry, president of anti-spyware toolmaker Sunbelt Software, said in an email interview: "This was an excellent move on the part of Microsoft, and we're pleased to see them respond to the concerns of the security community." Sunbelt had been monitoring attacks that exploit the flaw, which it said have been increasing.
The vulnerability, first reported last week, lies in a Windows component called 'vgx.dll'. This component is meant to support Vector Markup Language (VML) documents in the operating system. VML is used for high-quality vector graphics on the web and is used for viewing pages in the IE browser that is part of Windows. Microsoft deems the flaw "critical", its highest severity rating.
Microsoft said in security bulletin MS06-055: "An attacker could exploit the vulnerability by constructing a specially crafted web page or HTML email that could potentially allow remote code execution if a user visited the web page or viewed the message."
The vulnerability does not apply to IE 7, the upcoming version of IE that is available right now in a pre-release form, Microsoft said.
Microsoft typically releases fixes each second Tuesday of the month, which has become known as Patch Tuesday. The last time the software maker rushed out a fix was in January, when another image-related flaw in IE was being used to compromise Windows PCs through malicious websites.
Security experts had pushed Microsoft to rush out a fix for the VML flaw. A group of security professionals even crafted an unofficial fix for the problem, which was released on Friday.
Ken Dunham, director of the rapid response team at VeriSign's iDefense, said: "Exploitation has already eclipsed that of the last out-of-cycle patch. It appears that there were several million domains that were redirecting to malicious VML sites."
Microsoft's security update is being pushed out to Windows users via Automatic Updates and will also be available on Windows Update.
Joris Evers writes for CNET News.com
Trouble shoot and fix technical problems, liaising with product management and technical support to organise a patch if necessary. Websphere IT ...
Analyst within Programme Control Services (PCS) part of Systems Integration & Technology Consulting London, Manchester and Newcastle 31,000 + 10,000 ...
Fix Protocol Analyst - Contract - London City / NY My client is seeking an experienced FIX protocol analyst to join their team on a contractual ...
CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.
Staffing Service Coordinates Sales Activities, Utilizes Business Intelligence With...
Teachers Association Turns to Centralized Data Repository to Improve Member Service
Financial-Software Leader Credits Productivity Boost, Reduced IT Costs to 2007 Software
Staying Ahead of the Curve: Oracle Database 11g vs. Microsoft SQL Server 2005
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com... XP lives, the femtocell 'truth', BlackBerry bashing… Reader Comments of the Week
Martin Brampton The Brampton Factor: Open source 'brotherhood' closed to co-operation Where's the real sharing?