Slashdot Log In
Microsoft Patches VML Vulnerability
Posted by
kdawson
on Wed Sep 27, 2006 11:33 AM
from the not-a-moment-too-soon dept.
from the not-a-moment-too-soon dept.
Uncle Rummy writes, "Microsoft has quietly released an official patch for the zero-day VML vulnerability. The patch was publicly available yesterday, But Microsoft has just added it to the Security Bulletin Index." Eight days from time of first report to patch is pretty fast for Microsoft, and is almost two weeks ahead of their normal patch schedule. This security flaw was being aggressively exploited out in the wild.
Related Stories
[+]
Technology: Zero-Day IE Exploit In the Wild 239 comments
Eric Sites writes to tell us that a new zero-day IE exploit has been found in the wild. It looks to be a bug in VML in IE. The Sunbelt blog notes, "This exploit can be mitigated by turning off Javascripting."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
this patch was released before patch day? (Score:5, Funny)
Re: (Score:1)
Well just guessing but:
A) These people who write these patches, and the people who work on the DRM and probably not the same.
B) This probably has alot more code that needed to be changed then the DRM fix.
Re: (Score:2)
Re: (Score:2)
What the surprise here is they DID release it early. This has happened only twice before, once with the Windows Meta File (back at the start of the year, http://www.informationweek.com/windows/showArticle
Vendor Reviews... (Score:3, Funny)
Not a bad turnaround (Score:2, Interesting)
Re:Not a bad turnaround (Score:5, Insightful)
The virus/worm writers are the ones releasing the exploit into the wild the day after patch Tuesday.
That way they are more likely to have it expand for an entire month before MS patches it and messes up their fun.
Security researchers generally want things secure. Virus/Worm writers don't.
Parent
Re: (Score:2)
Disclosing vulnerabilities at the least convenient time for Microsoft accomplishes this - in the long run - by discouraging Microsoft from continuing their inane scheduling. If every security researcher published straight after Patch Tuesday, Microsoft would have no option but to give it up.
Re: (Score:3, Insightful)
Firefox not vulnerable because VML not supported? (Score:4, Informative)
W3C's introduction to VML: http://www.w3.org/TR/NOTE-VML [w3.org]
Microsoft's brief introduction to VML: http://msdn.microsoft.com/workshop/author/vml/def
Interestingly, the MS page includes a demo "oval with red background" which doesn't work in my Firefox browser.
Re:Firefox not vulnerable because VML not supporte (Score:3, Insightful)
Some clarification. (Score:5, Informative)
It isn't a standard, it was a submission to the W3C for consideration, by Microsoft and some of its useful idiots (HP, Macromedia, Autodesk, Visio). Submissions don't automagically get the thumbs up from the W3C. According to Wikipedia, Adobe, Sun and others submitted a proposal for a competing technology called PGML. Best features of the two technologies were then merged and improved upon to produce:
SVG: http://www.w3.org/TR/SVG10/ [w3.org]
SVG became a W3C recommendation on September 4, 2001. Later versions of Opera, Firefox and some other browsers implement at least limited support for SVG. It's also a standard vector graphics creation/exchange format for many open source graphic apps like Inkscape and Scribus. Adobe Illustrator and CorelDraw also support SVG fairly capably. Guess whose browser pointedly doesn't support SVG?
http://en.wikipedia.org/wiki/Vector_Markup_Languag e [wikipedia.org] Check out the code samples. The SVG code is quite a bit more compact than its VML equivalent.
Folks on SVG-rendering browsers (Firefox 1.5.x, Opera 8 and above) will possibly enjoy this little demonstration: http://isthis4real.com/orbit.xml [isthis4real.com]
* * * * *
It's a small world, but I wouldn't want to have to paint it.
—Stephen Wright
Parent
And even Flash isn't fool-proof. (Score:2)
I think Opera is way ahead of the Mozilla folks on the SVG implementation. That being said, I understand Firefox 2.x will implement SVG 1.1 stuff, like scripting. How well will it implement the new features? Pretty poorly at first, I'm sure. My needs are for basic multimedia implementations, like getting SVG to animate and sync with an audio file. Which is why I'm particularly
if browserid NOT Equal TO IEXP, mangle.page .. (Score:2)
Interesting enough the page layout is displayed correctly if Firefox changes User Agent ID to Internet Explorer 6. Under default Firefox ID it displays as a drap one page layout. Why does Microsoft mangle its own pages if viewed under a non MS browser.
if ($browserid!=IEXP) { mangle.page(); else display.page(); }
was: Firefox not vulnerable because VML not supported?
SVG not ignored by Firefox (Score:2, Informative)
HTH
Re: (Score:2)
Could this have something to do with... (Score:5, Insightful)
Probably not (Score:5, Insightful)
You might not agree with the policy but that's how it is, and there are reasons for doing it that way. People already whine about patches breaking systems when at present it's an extremely rare occurrence (in all the cases I've encountered, said system was spywared and that was the problem). If they rushed patches out without testing and they ended up breaking things, it could easily get to a state where people refused to patch because they were more scared of the patch than the problem.
We are dealing with non-technical users here, remember. A patch can't include a page of instructions of things you need to check first, nor can it be assumed that if it causes a problem the user can troubleshoot and fix it. It pretty much has to work straight off, and has to do so on literally tens of millions of permutations of software and hardware configurations.
Personally I'd like to see a compromise where they'd release an unofficial, untested patch for power users as soon as they could and the full patch later after testing. However the likely problem would be the unofficial patch would get in the wild, people would tout it as the official MS patch, something would go wrong, and they'd get blamed anyhow.
Parent
Re: (Score:2)
that's already the case, even if they HAVE improved in recent years. there's still the stigma associated with patches that seriously broke systems in nt4 and 2k
the only reason i don't worry about patches breaking my (windows) systems is because they're not critical enough to warrant it just let the auto update do its job. my linux servers, on the other hand, get tested thoroughly before
Maybe they should have tested it more... (Score:3, Informative)
Re: (Score:3, Funny)
Microsoft Patches IE Browser Flaw (Score:2, Funny)
Re: (Score:2)
I see by your ID (over 1 million, congrats
Re: (Score:2)
Good for them. (Score:2)
It's kind of funny how the security bulleting reads "Vulnerability in Vector Markup Language Could Allow Remote Code Execution". We're not saying that it does, but we think it's possible.
Gee. Ya think?
Re: (Score:2)
XP SP2 problems (Score:5, Informative)
What a pain in the ass. Is everybody seeing the same trouble?
Re: (Score:2, Interesting)
What's the name of your organization. I'd like to make sure I don't have any of your stock.
Re: (Score:2)
You don't have any stock in us [irs.gov].
Why do we have any left at SP1? I could be flip and say it's because we relied on Tivoli to update them, but I won't go there. Basically, we updated about 100K machines and are hunting down the last few hundred, mostly laptops belonging to people who spend all their time in the field and try to never come into the office where they can be updated. (Among our old-timers, it's a real badge of honor to brag that they haven't been in the office in 6 months.) Internal politics
Re: (Score:2)
We *finally* got a GateKeeper system up and running on our VPN for AV and critical patches. Took an act of the CIO to get the traders to agree to this...
Now please don't audit me
Re: (Score:2)
The other is a little program named M2 that runs at startup, checks a list in a specified directory, compares it to a local server, and applies anything available on the server that applies to your type of machine. You don't start work until it finishes. Works like a charm. Solid as a rock. Cost us nothing because it was written by o
Re: (Score:2, Insightful)
The only trouble I am seeing is why it has taken you so long to put SP2 on [some of] your machines.
Re: (Score:2)
In fact, here is a script that will not only splipstream in SP2, but all critical updates automatically:
http://smithii.com/?q=node/12 [smithii.com]
It's NOT! 10/10/2006! (Score:3, Insightful)
Change the icon please (Score:3, Funny)
Cant install this or a few other patches..help? (Score:2)
Security Update for Windows XP (KB917344)
Cumulative Security Update for Internet Explorer for Windows XP (KB918899)
Security Update for Windows XP (KB925486)
If only... (Score:2)
Quietly? (Score:2, Insightful)
VML's real name (Score:2)
Re: (Score:2)
Re: (Score:2, Informative)
What's even cooler is that one of the browsers he mentions (Koqueror) is just as much "embedded into the OS" (i.e. uses shared libraries that if removed affect other userland programs) and IE.
Ten bucks says he still gets modded up for it.
Re: (Score:2, Insightful)
Re: (Score:2)
Re: (Score:2, Interesting)
Which is part of the window manager which according to this image from microsoft.com [microsoft.com] has been run in kernel mode since NT 4.0 (Article ref [microsoft.com]). If that weren't the case, then Explorer could not hang the window manager (which it sometimes does).
Re: (Score:2)
Re: (Score:2)
I've looked @ the nonadmin site (yours????) before and I don't see the dll security setting you reference (to neuter IE).
Would you mind spoon feeding me?
Thanks,
Re: (Score:2)
Actually, the Administrator is a highly priveleged account but it doesn't have unlimited access (e.g. cannot get into the SAM part of the registry). The account with the most privileges (and the closest equivalent to root on UNX/Linux) is the NTAuthority/System account. Keep this in mind when checking which account services are running under. Think about e.g. your web server running with more access to the system than e
Re: (Score:2)
I think Microsoft is partly to blame for this misconception - the way they claimed in their anti-trust case that IE was part of the OS wasn't exactly helpful. (However, note that all the libraries that Konqueror uses that if removed affect other parts of KDE are in a completely separate package - kdelibs - and have
Re: (Score:2)
Wow, ur so kewl 2! You can point out when someone is making an obvious point, but then completely blow it when you refer to running windows as if the OP had commented on it being a Windows-only vulnerability... when the OP only referred to other browsers, not other OSs.
Flame on, if you like, but having something more useful or amusing to add
the first rule of slashdot (Score:2)
if you don't have a girlfriend, mention that you used to have an 8-bit computer