« Spybot S&D Definitions Updated on September 29, 2006 | Blog Home | Spybot S&D Definitions Updated on October 6, 2006 »

Microsoft Patch MS06-055 Issued for VML Exploit

Microsoft Security Bulletin MS06-055:

Vulnerability in Vector Markup Language Could Allow Remote Code Execution - Patched

Published: September 26, 2006

This information deals with the VML vgx.dll buffer overflow vulnerability announced on September 19, 2006, and the VML exploits that are currently in the wild.

http://www.microsoft.com/technet/security/bulletin/ms06-055.mspx

VML Buffer Overrun Vulnerability - CVE-2006-4868:

A remote code execution vulnerability exists in the Vector Markup Language (VML) implementation in Microsoft Windows. An attacker could exploit the vulnerability by constructing a specially crafted Web page or HTML e-mail that could potentially allow remote code execution if a user visited the Web page or viewed the message. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Microsoft has issued an out-of-cycle patch for the Vector Markup Language vulnerability mentioned above and in a previous entry on my blog. This is a critical vulnerability and if you have not already obtained the patch you should do so immediately. Go to Windows Updates to receive it manually, or turn on Automatic Windows Updates (Control Panel > Automatic Updates), or visit the page linked to above and download the patch for your OS.

Undo the suggested Microsoft workaround if you applied it! See my extended comments for details.

Internet Security 2008 - Windows Vista Certified

Impact of Workaround: Applications that render VML will no longer do so once Vgx.dll has been unregistered. This security update does not automatically re-register vgx.dll so any applications that render VML will no longer do so until vgx.dll has been re-registered.

To re-register vgx.dll follow these steps:

Copy and paste this code into your Run box (Start > Run) and hit Enter:

regsvr32 "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"

A dialog box appears to confirm that the registration process has succeeded. Click OK to close the dialog box.

If you get an error message and the code fails, try copying and pasting this command instead:

Click Start, click Run, and type, or copy and paste :

"%SystemRoot%\System32\regsvr32.exe" "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"

and then click OK. A dialog box appears to confirm that the registration process has succeeded. Click OK to close the dialog box.

Spyware Doctor is a multi-award winning spyware removal utility that detects, removes and protects your PC from thousands of potential spyware, adware, Trojans, keyloggers, spybots and tracking threats.

Spyware Doctor
Spyware Doctor utilizes a sophisticated database of malware infections to detect and remove malware from your computer. The database currently incorporates over 50,000 signatures. Multiple databases are released each week, assisting you to keep your system free of new infections.

Spyware Doctor is fully capable of detecting and removing hidden processes associated with complex threats and rootkits. Such threats are otherwise difficult to remove by conventional means since they may be hidden to the operating system.

A Startup Scanner removes references to malicious programs that run at startup in the registry and Windows startup files, as well as malicious files in Windows startup locations.

State-of-the-art scanning engines, including file scan, memory scan, registry scan, browser helper objects scan, cookie scan and much more.

MailWasher Pro is a POP3 email client spam filter

Powered by
Movable Type 3.36

Start your blog today