All the latest UK technology news, reviews and analysis

Microsoft rushes out VML patch

by Tom Sanders in California

27 Sep 2006

Be the first to comment

  • Tweet this
Microsoft has released a one-off update that repairs an actively exploited vulnerability in the Vector Markup Language component of Windows
Microsoft's 'out-of-band' update should halt active attacks

Microsoft has released a one-off update that repairs an actively exploited vulnerability in the Vector Markup Language component of Windows. 

The flaw could allow an attacker to take control of a system through a specially crafted website, or by sending out spam email messages.

Microsoft originally planned to release the patch on 10 October, as part of its monthly patch release cycle. The vendor issues 'out-of-band' updates in rare cases if it helps to halt active attacks.

The VML vulnerability surfaced last week when a small group of websites in Russia started exploiting the unpatched vulnerability.

The abuse of the vulnerability became widespread over the weekend after the exploit was included in a malware toolkit known as 'WebAttacker'.

Users who have applied a third-party workaround need to undo those changes before the patch can be applied.

Security experts recommend that users apply the patch as soon as possible. The update can be obtained through the built-in auto-update feature in Windows or from the Microsoft Update website.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Network Support Engineer Up To £40k

(Roc Search - Network Support Engineer, 2nd line, 3rd...

3rd Line Engineer / Infrastructure Engineer - VMware, Server,

3rd Line Engineer / Infrastructure Engineer - Berkshire...

SQL Server DBA - Database Administrator - MySQL Suffolk - £50k

MySQL SQL SERVER DBA / Database Administrator - Online...

PMO Analyst - Banking

PMO Analyst - Banking Client A financial organisation...

To send to more than one email address, simply separate each address with a comma.