On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Sep 26, 2006 8:35:00 PM

Microsoft issued a "critical" security fix for Windows on Tuesday, two weeks before its scheduled release date.

The company is breaking with its monthly patch cycle to fix a flaw that cybercrooks have been using to attack Windows PCs via Internet Explorer. Malicious software can be loaded, unbeknownst to the user, onto a vulnerable Windows PC when the user clicks on a malicious link on a Web site or in an e-mail message.

"This was an excellent move on the part of Microsoft, and we're pleased to see them respond to the concerns of the security community," Alex Eckelberry, president of anti-spyware toolmaker Sunbelt Software, said in an e-mail interview. Sunbelt had been monitoring attacks that exploit the flaw, which it said have been increasing.

The vulnerability, first reported last week, lies in a Windows component called "vgx.dll." This component is meant to support Vector Markup Language documents in the operating system. VML is used for high-quality vector graphics on the Web and is used for viewing pages in the IE browser that is part of Windows. Microsoft deems the flaw "critical," its highest severity rating.

"An attacker could exploit the vulnerability by constructing a specially crafted Web page or HTML e-mail that could potentially allow remote code execution if a user visited the Web page or viewed the message," Microsoft said in security bulletin MS06-055. E-mail messages that use HTML, or HyperText Markup Language, look like a Web page.

The vulnerability does not apply to IE 7, the upcoming version of IE that is available right now in a pre-release form, Microsoft said.

Microsoft typically releases fixes each second Tuesday of the month, which has become known as Patch Tuesday. The last time the software maker rushed out a fix was in January, when another image-related flaw in IE was being used to compromise Windows PCs through malicious Web sites.

Security experts had pushed Microsoft to rush out a fix for the VML flaw. A group of security professionals even crafted an unofficial fix for the problem, which was released on Friday.

"Exploitation has already eclipsed that of the last out-of-cycle patch," said Ken Dunham, director of the rapid response team at VeriSign's iDefense. "It appears that there were several million domains that were redirecting to malicious VML sites."

Microsoft's security update is being pushed out to Windows users via Automatic Updates and will also be available on Windows Update.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 34 Talkback(s)
Sometimes I run the spell check and
sometimes, a lot of posters at Zdnet don't. (Read the rest)
Posted by: Boot_Agnostic Posted on: 09/28/06 You are currently: a Guest | | Terms of Use
Microsoft rushes out 'critical' fix  Loverock Davidson | 09/26/06
Please explain ...  phburks | 09/26/06
Don't waste your breath on Loverock , he's a MS shill .  I'm Ye, the MS SHILL . | 09/26/06
Gladly  Loverock Davidson | 09/26/06
So why is it...  nix_hed | 09/27/06
Still slower than the DRM fix  rpmyers1 | 09/26/06
And?  Loverock Davidson | 09/26/06
Shows where priorities are  rpmyers1 | 09/26/06
Well God bless Bill Gates.... Hail Microsoft  shawkins | 09/27/06
You should really be upset...  jasonp@... | 09/27/06
Why would I be upset?  Loverock Davidson | 09/27/06
You really think admins are that stupid?  jasonp@... | 09/27/06
What are you babbling about?  Loverock Davidson | 09/27/06
What do you mean Yesterday?  julied.16@... | 09/27/06
Now my patch cycle is all messed up!!!  nucrash | 09/27/06
WSUS  Loverock Davidson | 09/27/06
Waxing poetic again?  Shelendrea | 09/27/06
Yes! Yes! Yes!  Ole Man | 09/27/06
Microsoft rushes out 'critical' fix  Mr. Roboto | 09/26/06
And it doesn't require a reboot  toadlife | 09/26/06
true enough  Shelendrea | 09/27/06
About time  Boot_Agnostic | 09/27/06
"You are marketshare?" Hmm... Interesting!  Grayson Peddie | 09/27/06
Sometimes I run the spell check and  Boot_Agnostic | 09/28/06
Not critical  rpmyers1 | 09/27/06
WU says High Priority, the bulletin says Critical  PB_z | 09/27/06
The saftest thing to do...  xunil skcor | 09/27/06
My Windows machine...  toadlife | 09/27/06
perhaps not  phburks | 09/27/06
Patches? Yuck, the term 'Spaghetti Code' has to be a gross understatement  Irritated_User | 09/27/06
temporary fix  rljensen@... | 09/27/06
look here  rpalmeri | 09/27/06
Why wait?  raymarc001 | 09/27/06
Microsoft fixed vulnerability?  woodzybooger | 09/28/06

What do you think?

SmartPlanet

Click Here