This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS VML patch is out - MS06-055

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.f-secure.com/weblog/archives/ar…6.html#00000980
"Microsoft has released a patch against the VML vulnerability outside of their normal update cycle. Which is great. The patch is available right now via http://update.microsoft.com . Get it."

~or~

- http://isc.sans.org/diary.php?storyid=1738
Last Updated: 2006-09-26 19:22:11 UTC …(Version: 3)…
"Microsoft has just released an update to address the VML (VGX) issue. The update can currently be found on Microsoft Update and is titled:

Microsoft Security Bulletin MS06-055
Vulnerability in Vector Markup Language Could Allow Remote Code Execution (925486)
> http://www.microsoft.com/technet/security/…n/MS06-055.mspx
Published: September 26, 2006
Version: 1.0
"A security issue has been identified in the way Vector Markup Language (VML) is handled that could allow an attacker to compromise a computer running Microsoft Windows and gain control over it. You can help protect your computer by installing this update from Microsoft. After you install this item, you may have to restart your computer…"

It is recommended that the patch be applied immediately (after testing) unless a suitable mitigation strategy is in place.
Update: Also, note that if you applied the ACL mitigation (removing Everyone Read access from the DLL), you will need to undo that before this update will apply successfully…"

> http://blogs.technet.com/msrc/archive/2006/09/26/459194.aspx

.
FYI…

- http://blogs.technet.com/msrc/archive/2006/09/26/459237.aspx
September 26, 2006
"…One thing to note, we recommend that you undo any of the previously recommended workarounds involving VGX.DLL before applying this update. Information on how to undo those workarounds is detailed in the bulletin. This is very important because if you do not revoke the VGX.DLL changes, the update could fail to install or deploy…"

- http://www.f-secure.com/weblog/archives/ar…6.html#00000980
…Updated to add: For those of you that applied the work-around that we suggested, the vgx.dll file will need to be re-registered before applying the Microsoft Update. Otherwise, the update might not find anything to fix.

Use the command below from Start, Run:

regsvr32 "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"

.
FYI…

A Report from the Field
- http://isc.sans.org/diary.php?storyid=1745
Last Updated: 2006-09-29 14:34:55 UTC
"Kevin Shea wrote in to report:
Yesterday morning (9/27) when dropping off my son at school, I told his first grade teacher about the VML exploits and patch availability. She said she had computers at home and would call her husband to make sure they were patched. When my signifigant-other picked him up around 5:30, the teachers were all talking about how her husband checked and found out they were infected with one of the trojans. Their bank accounts had been drained, by electronic withdrawals and money transfers. Since it had occurred the day before, the bank (unknown) was able to reverse the transfers and replace the money in their accounts. They won't even bounce a check.
After receiving the report, I had a few questions and I received a prompt follow-up. What the thieves did with the money was interesting. Most of the funds were transferred out using one of those services where you can wire cash to people. I'm not sure if these were wired to other accounts using the intermediary, of it people actually walked up to a counter to retrieve the funds. They also used funds in this account to purchase background checks at certain people-search/information-broker companies. Most likely this is an attempt to gather further identities in a way that won't tip-off the broker…"

.