Home > Evolution of the VML flaw
Special News Coverage:
EMAIL THIS LICENSING & REPRINTS

Evolution of the VML flaw

28 Sep 2006 | David Nielson, Assistant Site Editor

Advice for securing Windows
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Evolution of the September VML flaw

Just days after Patch Tuesday, Microsoft announced a new Internet Explorer flaw that could potentially allow attackers to crash or take control of a system. The high danger level of the flaw, which affects vector markup language, caused the company to release an out-of-cycle fix for the vulnerability this past week. While the release marked only the second time this year Microsoft has made a patch available outside of Patch Tuesday, it is hardly the first circumstance of a patch emergency involving Web applications such as Internet Explorer.

Early recommendations suggested that IT admins mitigate the flaw by only allowing trusted Web sites to run ActiveX controls until a formal patch was issued later. Microsoft originally planned to release a fix this upcoming Patch Tuesday (October 10th). However, attacks against the flaw continued to grow and Microsoft was forced to release the out-of-cycle patch earlier this week.

Prepare yourself for Web vulnerabilities

Since the beginning of 2006, IE and other Web applications have certainly received their share of time in the patching spotlight. In fact, the only other out-of-cycle patch release from Microsoft this year dealt with an exploit targeting Windows Metafile Format files that users accessed in Internet Explorer. So what about Web applications makes them so dangerous that they receive such special attention? Prepare for the next time a vulnerability arises in your Web applications by checking out this series of Web security tips and guides.


Web vulnerability defense
Tip 1: Web Browser Security Learning Guide
Tip 2: Security risks in IE 6
Tip 3: Understanding IPsec identity and authentication options
Tip 4: Adjusting security settings in Internet Explorer 6.0
Tip 5: Step-by-Step Guide: Securing Web servers
Tip 6: Running Web Applications in ISA Server
Tip 7: Upgrading and patching Firefox


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Internet Explorer (IE) security
Internet Explorer security settings and controls
Windows Vista tips and expert responses
Internet Explorer 7 and its security issues
Pop-ups in IE are hijacking my homepage
Windows can remember your passwords
Top Web security tips of 2006
Tips on surviving with IE6
Run a secure IE6 after downgrading from IE7
Microsoft scrutinized for IE 7 flaw and broken Vista promises
New exploits target Microsoft PowerPoint, IE

Microsoft Windows Patch Management
Revised hotfix for 'animated-cursor exploit' released
Excel, Office '07 affected by patch updates; Vista left alone
IE6 vulnerability included in Patch Tuesday update
Use patching to protect your network from threats
Patch management: Are off-cycle, third-party patches trustworthy?
Microsoft delivers 10 patches and tool update
Standalone patch management vendors under siege
Patch Tuesday will see the release of 13 security updates
Third-party patches appear for new Internet Explorer flaw
Developing a Windows patch methodology
Microsoft Windows Patch Management Research

Hardening
ActiveX security improves with Internet Explorer 8's security features
Web security features of Internet Explorer 8
How can I use Process Explorer as a Web security tool?
New Windows security tool protects users from keyloggers: XecureCK
Cross-site scripting 101: XSS attacks plague Web browsers
What's hot in Windows security? New Microsoft Office Security Guide
Data protection on the Web: Windows SSL security and other myths
What's hot in Windows security: Updating Windows Update; new IE scare
Web security tactics that harden Windows networks
What do you know about Microsoft Internet security?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
patch management  (SearchWindowsSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts