On CBS.com: Get More On Amazing Race Eliminated Team
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Sep 30, 2006 5:32:00 PM

A group of security professionals has released a patch to repair a serious flaw in older Windows versions for which Microsoft no longer provides security updates.

The group, which calls itself the Zeroday Emergency Response Team, or ZERT, created the patch so users of Windows versions that are no longer officially supported can protect their PCs against increasing attacks that utilize a recently disclosed Windows flaw.

The vulnerability, first reported last week, lies in a Windows component called "vgx.dll." This component supports Vector Markup Language (VML) graphics in the operating system. Malicious software can be loaded, unbeknownst to the user, onto a vulnerable PC when the user clicks on a malicious link on a Web site or an e-mail message.

Microsoft rushed out a "critical" fix for Windows on Tuesday to address the problem, two weeks before its regularly scheduled patch day. Microsoft's updates are available for Windows 2000 with Service Pack 4, Windows XP with Service Pack 1 or later, Microsoft Windows XP Professional x64 Edition, and Windows Server 2003.

But Microsoft no longer provides updates for its older operating systems. ZERT sought to fill that void. "A ZERT patch has just been made available for unsupported system versions," the group said on its Web site. The patch has been tested on Windows 98, Windows 98 Second Edition, Windows Millennium Edition, Windows 2000 and Windows 2000 with Service Pack 3, the group said.

ZERT is made up of security professionals from around the world who volunteer their time. Last week the group crafted a patch to plug the VML flaw ahead of Microsoft's fix, so IE users can protect themselves while Microsoft worked on an official patch.

Meanwhile, there are several other security vulnerabilities in Microsoft products waiting to be fixed. Some of these flaws are already being used in cyberattacks, though not as widespread as the VML flaw, according to security experts.

A word of caution is always warranted when it comes to third-party fixes, ZERT has noted. The group does test its fixes, but does not have the same resources Microsoft does when it produces patches. ZERT does provide the source code of its fix, allowing people to validate what it does.

ZERT stresses on its Web site that its fix has no warranties.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 23 Talkback(s)
Here is what I did
Download the zip file. Run the executable file named ZVGPatcher.exe (the first one, it is about 18KB in the archive.) When it runs, click the "patch" button. That is all you do. When you go to the tes... (Read the rest)
Posted by: agbags Posted on: 10/05/06 You are currently: a Guest | | Terms of Use
in a sense we dont need opensource  galileon | 09/30/06
Linux and Mac OS are also crap, too!  Grayson Peddie | 09/30/06
YEAH RIGHT !  Intellihence | 10/01/06
really?  galileon | 10/01/06
Riiiiiiiiiiiight  Shelendrea | 10/03/06
O(pen)bfuscated source  pj-xmesh | 10/03/06
Alternate Obsolesence  wjkahlssmd@... | 10/01/06
Who says the marketshare isn't already 10%?  PB_z | 10/02/06
zert and fixes  TekkWise@... | 10/01/06
We can't even trust Microsoft to patch its current versions of software  rh0 | 10/01/06
How long should ANY company  John Zern | 10/02/06
How long?  wallywalters | 10/02/06
Good on them, proactively protecting old versions  Boot_Agnostic | 10/02/06
Now here is a market for Symantec  No_Ax_to_Grind | 10/02/06
Symantec fixing problems?  sbarringer@... | 10/03/06
ZERT  Dumber_z | 10/02/06
Sheesh!  DarbyOhara | 10/02/06
ZERT what?  Krazyken39 | 10/02/06
Microsoft what?  pkrdk | 10/02/06
Right, the sky didn't fall.  sbarringer@... | 10/03/06
Microsoft patches galore  Eaglehawk_z | 10/03/06
ZERT Patch for Unsupported Windows Versions  wpinnix@... | 10/03/06
Here is what I did  agbags | 10/05/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here