On CNET: Start your holiday tech shopping
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Oct 1, 2006 11:45:00 PM

For the second time in as many weeks a group of security professionals has released a third-party fix for a Windows flaw that is actively being used in cyberattacks.

The group, calling itself the Zeroday Emergency Response Team, or ZERT, created the patch so Windows users can protect their PCs while Microsoft works on an official update. People have a choice of third-party fixes. Security company Determina on Friday released a patch it authored for the same flaw.

The flaw affects Windows 2000, Windows XP and Windows Server 2003, and could be exploited via the Internet Explorer Web browser through a component called WebViewFolderIcon, Microsoft said in a security advisory issued Thursday. Windows Shell is the part of the operating system that presents the user interface.

Attackers have added the flaw to their arsenal, security experts said Saturday. Web sites that exploit the vulnerability are popping up and attempt to load malicious software onto vulnerable Windows PCs in a way that is undetectable to users, they said.

This is the second time in as many weeks that ZERT has beaten Microsoft to the punch in patching a flaw. A little over a week ago the group crafted a fix to plug a flaw in a Windows component called "vgx.dll." This component supports Vector Markup Language (VML) graphics in the operating system.

A word of caution is always warranted when it comes to third-party fixes, and Microsoft does not recommend using them. ZERT does test its fixes, but does not have the same resources Microsoft does when it produces patches, the group has said. ZERT does provide the source code of its fix, allowing people to validate what it does.

The Windows Shell flaw was found almost two months ago as part of HD Moore's "month of browser bugs." However, sample attack code became available only recently.

Microsoft plans to issue a fix for the problem on Oct. 10, its regularly scheduled patch day, it said last week. With attacks mounting, the company might be forced to issue its patch sooner. On Tuesday Microsoft rushed out a fix for the VML flaw, which was also being exploited in attacks and for which ZERT also released a patch.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 31 Talkback(s)
Hard to fly under the radar
WHEN YOU'RE THE BIGGEST THING OUT THERE!!! (Read the rest)
Posted by: bayliner79 Posted on: 10/07/06 You are currently: a Guest | | Terms of Use
Wow, aren't you glad we have the village idiots at MS working on this!!  DonnieBoy | 10/01/06
Well at least they have the source code.  Suicida| | 10/02/06
so?  darthgummibear | 10/02/06
I think he was making fun of MS, saying the only thing they have going for  DonnieBoy | 10/02/06
banker's hours  ChazzMatt | 10/01/06
Exactly  Suicida| | 10/01/06
Wonderful  opensourcepro | 10/02/06
we can only hope that...  darthgummibear | 10/02/06
Well, there you go......  joe6pack_z | 10/02/06
I am glad I have removed it  jackie40d@... | 10/02/06
Well too bad the bug isn't in Internet Explorer  PB_z | 10/02/06
So I just downloaded the ZERT patch and look at the source code.  PB_z | 10/02/06
If they don't have the source code, then what more could they do?  balsover | 10/02/06
priorities?  darthgummibear | 10/02/06
RE: So I just downloaded the ZERT patch and look at the source code.  hjmulholland | 10/03/06
Hard to fly under the radar  bayliner79 | 10/07/06
Never anything useful  andy88488 | 10/02/06
What MS really needs...  jolumoar | 10/02/06
heh...  darthgummibear | 10/02/06
MS should give up on the software  Boot_Agnostic | 10/02/06
What are you smoking?  darthgummibear | 10/02/06
No, they'd divest from the software, maybe even OSS it  Boot_Agnostic | 10/03/06
Microsoft Damage Control  imguessing | 10/02/06
Responsibuility.......  Kobashrer | 10/02/06
Never gonna happen.  darthgummibear | 10/02/06
I think the ZERT team should....  Jay E Court | 10/02/06
Hmm haven't heard from the ultimate authority.  Seenidog | 10/02/06
What am I doing right?  interested_amateur@... | 10/03/06
Masochism or confusion? Who could really tell ? ... nt  Dr-T | 10/03/06
Mikey, where are you??? Daniel's broiler???  techboy_z | 10/03/06
3rd party fix  als2375 | 10/03/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline