Saturday, September 23, 2006

IE/Windows VML Exploit - Short Term Fix

F-Secure Weblog : News from the Lab - VML Exploit - Internet Explorer

"...

It was discovered in the wild by Sunbelt. Microsoft published Microsoft Security Advisory (925568) yesterday regarding the issue. The update is currently scheduled for October 10th - the next regular patch Tuesday.

Like the WMF exploit it is advised to unregister the susceptible dll from the system as a workaround for the vulnerability.

To unregister the dll you should execute from Start, Run:
regsvr32 /u "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"

This differs slightly from Microsoft's recommendation - so as to include localized versions of Windows.

The vgx.dll component solely handles Vector Markup Language (VML). ..."

Note To Self: Do this on my all machines...

No comments: