Gary Richardson
09-22-2006, 03:18 PM
Yet another way for the bad guys to directly infect Windows without any aid from you. Important you attend to this.
Once again there is a browser vulnerability that allows for the remote execution of code. And the only action necessary to become infected is to view a malicious webpage using Internet Explorer or an HTML formatted e-mail...Like the WMF exploit it is advised to unregister the susceptible dll from the system as a workaround for the vulnerability.
"Microsoft has confirmed new public reports of a vulnerability in the Microsoft Windows implementation of Vector Markup Language (VML)...A security update to address this vulnerability is now being finalized through testing to ensure quality and application compatibility Microsoft’s goal is to release the update on Tuesday, October 10, 2006, or sooner depending on customer needs...
There are already sites using this exploit, so to protect yourself from this till October when M$ get round to patching things, follow these instructions from Grinler at Bleeping Computer. http://www.bleepingcomputer.com/forums/topic66086.html
Once again there is a browser vulnerability that allows for the remote execution of code. And the only action necessary to become infected is to view a malicious webpage using Internet Explorer or an HTML formatted e-mail...Like the WMF exploit it is advised to unregister the susceptible dll from the system as a workaround for the vulnerability.
"Microsoft has confirmed new public reports of a vulnerability in the Microsoft Windows implementation of Vector Markup Language (VML)...A security update to address this vulnerability is now being finalized through testing to ensure quality and application compatibility Microsoft’s goal is to release the update on Tuesday, October 10, 2006, or sooner depending on customer needs...
There are already sites using this exploit, so to protect yourself from this till October when M$ get round to patching things, follow these instructions from Grinler at Bleeping Computer. http://www.bleepingcomputer.com/forums/topic66086.html