Exploitation of unpatched Microsoft Internet Explorer Vector Markup Language Code Execution Vulnerability
Various Antivirus vendors has alerted about the Trojans and exploits;
and recognizing these as Trojan.Vimalov [ Symantec ] , EXPL_EXE
COD.A (Trend Micro) , HTML/Levem.C (Microsoft), Exploit-VMLFill [McAfee] , Troj/Dloadr-ANO, Troj/Goldun-EC, Troj/Goldun-EE [ Sophos].
Users are advised to take following precautions until a patch is available to address this vulnerability
- Un-register Vgx.dll on Windows XP Service Pack 1; Windows XP Service Pack 2; Windows Server 2003 and Windows Server 2003 Service Pack 1
- Modify the Access Control List on Vgx.dll to be more restrictive
- Configure Internet Explorer 6 for Microsoft Windows XP Service Pack 2 to disable Binary and Script Behaviors in the Internet and Local Intranet security zone.
- Read e-mail messages in plain text format to help protect yourself from the HTML e-mail attack vector
Microsoft has released patches on 26th Sep 2006 to address this secuirty issue vide Security Bulletin MS06-055. Users are advised to apply appropriate patches as mentioned in this bulletin.
References:
http://www.microsoft.com/
http://vil.nai.com/
http://www.symantec.com/
http://www.sophos.com/
http://www.isc.sans.org/

0 Comments:
Post a Comment
<< Home