• On MovieTome: See the TRAILER for TERMINATOR 4!

September 26, 2006 1:35 PM PDT

Microsoft rushes out 'critical' fix

Last modified: September 26, 2006 3:40 PM PDT

Microsoft issued a "critical" security fix for Windows on Tuesday, two weeks before its scheduled release date.

The company is breaking with its monthly patch cycle to fix a flaw that cybercrooks have been using to attack Windows PCs via Internet Explorer. Malicious software can be loaded, unbeknownst to the user, onto a vulnerable Windows PC when the user clicks on a malicious link on a Web site or in an e-mail message.

"This was an excellent move on the part of Microsoft, and we're pleased to see them respond to the concerns of the security community," Alex Eckelberry, president of anti-spyware toolmaker Sunbelt Software, said in an e-mail interview. Sunbelt had been monitoring attacks that exploit the flaw, which it said have been increasing.

The vulnerability, first reported last week, lies in a Windows component called "vgx.dll." This component is meant to support Vector Markup Language documents in the operating system. VML is used for high-quality vector graphics on the Web and is used for viewing pages in the IE browser that is part of Windows. Microsoft deems the flaw "critical," its highest severity rating.

"An attacker could exploit the vulnerability by constructing a specially crafted Web page or HTML e-mail that could potentially allow remote code execution if a user visited the Web page or viewed the message," Microsoft said in security bulletin MS06-055. E-mail messages that use HTML, or HyperText Markup Language, look like a Web page.

The vulnerability does not apply to IE 7, the upcoming version of IE that is available right now in a pre-release form, Microsoft said.

Microsoft typically releases fixes each second Tuesday of the month, which has become known as Patch Tuesday. The last time the software maker rushed out a fix was in January, when another image-related flaw in IE was being used to compromise Windows PCs through malicious Web sites.

Security experts had pushed Microsoft to rush out a fix for the VML flaw. A group of security professionals even crafted an unofficial fix for the problem, which was released on Friday.

"Exploitation has already eclipsed that of the last out-of-cycle patch," said Ken Dunham, director of the rapid response team at VeriSign's iDefense. "It appears that there were several million domains that were redirecting to malicious VML sites."

Microsoft's security update is being pushed out to Windows users via Automatic Updates and will also be available on Windows Update.

See more CNET content tagged:
Sunbelt Software, Windows PC, fix, flaw, Microsoft Internet Explorer

Add a Comment (Log in or register) 27 comments (Showing first 20 comments)
Windows source code: spaghetti with no logic.
by katamari September 26, 2006 2:24 PM PDT
> The vulnerability, first reported last week,
> lies in a Windows component called "vgx.dll."
> This component is meant to support Vector
> Markup Language documents in the operating
> system. VML is used for high-quality vector
> graphics on the Web and is used for viewing
> pages in the IE browser that is part of
> Windows.

Creeping featurism. Because Macromedia and Adobe Flash don't do any of that, right? Right.
Reply to this comment View reply
Avoid IE, better yet avoid MICROSOFT..!!!
by imacpwr September 26, 2006 3:04 PM PDT
IE is nothing more than a hackers dream come true (backdoor to
the core). You want internet security? Avoid using Internet Explorer,
better yet AVOID Microsoft all together..!!!!
Reply to this comment View all 4 replies
I use a Mac, but atleast
by SeaMoose77 September 26, 2006 3:28 PM PDT
but alteast Microsoft is on the ball and releasing patches.

Every company gets flaws, Apple included, so it's nice to see the
company that many people use get a quick patch.
Reply to this comment
Microsoft's Release Model:
by bob donut September 26, 2006 6:20 PM PDT
if (vulnerability_found
&& (nice_neat_day_for_release
|| press_writes_article ))
{
release_fix();
}
else
{
wide_open_vulnerability = 1;
}
Reply to this comment
I use a Mac, but this is a good thing
by NeverFade September 26, 2006 7:44 PM PDT
Any company that releases a patch for a venerability is a good
thing. Apple releases patches and so does MS.

People shouldn't always have to 'harp' on another person's
computer company if that company is trying to help their own
product for their consumers.
Reply to this comment
With all the remote control viruses out there.
by bigfeet123 September 26, 2006 7:54 PM PDT
Why can't I get easy to install and run remote control software??
Reply to this comment
Critical patches within 24 hours
by wbenton September 27, 2006 7:34 AM PDT
Something Microsoft has yet to learn.

Even though they broke again this time by releasing this Critical patch earlier... it's still FAR TOO LATE by most security concious company's standards!!!

Walt
Reply to this comment
So when will the other Patches go out ?
by kthor12 September 27, 2006 9:55 AM PDT
Microsoft should stop putting it's spyware program unto there updates !!







http://www.stateof-california.com
Reply to this comment
what is and isn't news
by thedreaming September 28, 2006 6:50 AM PDT
Microsoft patching a flaw isn't news. Microsoft patching a flaw ahead of schedule because everyone and their mother started screaming at them about it, that's still not news, but at least it shows that Microsoft is listening.
Reply to this comment
Slam Microsoft! (Don't bother reading the story.)
by Vegaman_Dan September 29, 2006 7:38 AM PDT
Sometimes I wonder why people even bother posting if all they are going to do is complain about Microsoft/Apple/Linux/Jello Pudding is evil and should be destroyed. Do they actually read the story or do they have a macros set to make anti-whatever posts regardless of what the story is about and just rant?

Even when MS does something good like make security patches available, people complain. Since they don't even have to do that much and could leave you all hanging in the wind, I think I wouldn't be complaining so loudly.

It's a case of being damned if you do, damned if you don't.
Reply to this comment View all 2 replies
 See all 27 Comments >>
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right