Jump to content

serious flaw in Internet Explorer


Rebel=UK=
 Share

Recommended Posts

Sorry if this has been posted already

Microsoft has issued warnings about a serious flaw in Internet Explorer that allows attackers to hijack a PC via the popular browser.A properly crafted webpage can exploit this problem and install almost anything they want on the target machine.

http://news.bbc.co.uk/1/hi/technology/5365296.stm

Link to comment
Share on other sites

Thanks for the post, its good to know. In looking up more info about it I found a good site that discribes many ways to quick fix the problem till the patch comes out. All of the fixes are decent and problem free. Here they all are...

1. Type regsvr32 -u "%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll in a run box to unregister the VML component. Which is only needed to view Vector Markup Language sites (not many use VML).

2. Have hardware-enforced DEP running. Software DEP may also prevent infection. If you don't know about DEP, this site explains how and where you can configure it.

3. 3rd party unofficial patch from Zeroday Emergency Response Team (ZERT). Clicking the link will tell you more about who they are.

There are probably more ways but this seems to be a good list and hopefully will prevent people from any infection.

Link to comment
Share on other sites

If it doesn't work or you need to visit a site with VML like this one, you can just enter this in run regsvr32 "%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll and it will reregister/enable the file. The vgx.dll file is what IE uses to display VML graphics. If you try to view these pages the images won't show, but I think it was MS that made VML and I just read only IE on Windows will run VML pages. So not many sites use VML unless they have to.

Link to comment
Share on other sites

A security update has been made available for this vulnerability; see KB925486 for details and manual download. The update is also available through http://update.microsoft.com/ and Windows automatic updates.

[Edit] see also Microsoft Security Bulletin Summary for September, 2006 (Version 2.0)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy