About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Microsoft has released a one-off update that repairs an actively exploited vulnerability in the Vector Markup Language component of Windows
Microsoft's 'out-of-band' update should halt active attacks
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Microsoft rushes out VML patch

Widespread exploits force out-of-cycle update

Tom Sanders in California, vnunet.com 27 Sep 2006
ADVERTISEMENT

Microsoft has released a one-off update that repairs an actively exploited vulnerability in the Vector Markup Language component of Windows. 

The flaw could allow an attacker to take control of a system through a specially crafted website, or by sending out spam email messages.

Microsoft originally planned to release the patch on 10 October, as part of its monthly patch release cycle. The vendor issues 'out-of-band' updates in rare cases if it helps to halt active attacks.

The VML vulnerability surfaced last week when a small group of websites in Russia started exploiting the unpatched vulnerability.

The abuse of the vulnerability became widespread over the weekend after the exploit was included in a malware toolkit known as 'WebAttacker'.

Users who have applied a third-party workaround need to undo those changes before the patch can be applied.

Security experts recommend that users apply the patch as soon as possible. The update can be obtained through the built-in auto-update feature in Windows or from the Microsoft Update website.


All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
System Integrator - Applications Hosting Location - Reading Job Description: A skilled System Integrator to integrate Microsoft based applications to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and ... more >
(Poole, Bournemouth, Dorset, Hampshire), United Kingdom | RNLI
Analyst - Network & Telecoms - £35,000+ - Poole, Bournemouth, Dorset, Hampshire Our data and voice network team's impact on the organisation is considerable. And with something in the region of 5,000 direct users connected ... more >
London, United Kingdom | MHRA
Senior Technical Analyst - £26,781 - £28,562 - London The Medicines and Healthcare products Regulatory Agency (MHRA) is the government agency which is responsible for ensuring that medicines and medical devices work, and are acceptably ... more >
Reading, Berkshire, United Kingdom | EDS
Position # 396477 Environment Support Engineer Location - Reading Job Description: There is an initial requirement an Environment Support Engineer to provide support and maintenance for the development environments within ATLAS. This role encompases many ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT