[Full-disclosure] Windows VML security update MS06-055 released



Security update for Windows Vector Markup Language (VML) vulnerability has been released.

Fix is available via Microsoft Update or downloadable with links included to MS06-055:
http://www.microsoft.com/technet/security/bulletin/ms06-055.mspx

Fix information has been added to Windows VML Vulnerability FAQ (CVE-2006-4868)
http://blogs.securiteam.com/?p=640

and details will be added shortly.

It appears that the timestamp of updated Vgx.dll library is 18th September, 2006.

From the Security Update Information / File Information section of new MS bulletin:

Windows XP Service Pack 2 (all versions) and Windows XP Professional x64
Vgx.dll - 6.0.2900.2997 - 18-Sep-2006 - 14:28 (UTC) - 851,968

It is exactly the same day when Sunbelt reported that they were informed Microsoft security people:
http://sunbeltblog.blogspot.com/2006/09/seen-in-wild-zero-day-exploit-being.html

- Juha-Matti

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Terminating Application
    ... In one of the greater disasters I was involved in, and had to fix at great expense, ... Windows by changing it to ExitWindowswhich exited ... The disasters you describe ensued. ... went back to my client and we ditched the product. ...
    (microsoft.public.vc.mfc)
  • Re: XP Automatic Update
    ... "Another IT professional, based in California, who runs Windows XP systems ... said that after installing the latest batch of XP ... even unusable until the vendor releases the fix to fix the fix. ... headache for administrators, to have Microsoft update all these machines, ...
    (Security-Basics)
  • Re: Windows wont start properly--get message in dos mode
    ... thred but I relly need help to fix my machine. ... Microsoft MVP [Windows] ... ethernet cable and phone cable from the modem. ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Updates are downloaded but fail to install
    ... So I applied the fix for that (see ... and then applied the below quoted registry fix. ... dl'd it) but when I again tried to install the update from the MS Update ... Windows Updates problem" on a few computers that I have worked on....The ...
    (microsoft.public.windowsupdate)
  • Re: Comp crash
    ... But after about of week of trying to fix my computer, ... The sound didnt work.. ... thing and switch to windows xp home edition. ... Beginning dump of physical memory ...
    (microsoft.public.windowsxp.general)