YNOT
  • Home
  • Industry News
    • Adult Business News
    • Adult Novelty News
    • YNOT Magazine
    • EU News
    • Opinions
    • Picture Galleries
  • PR Wire
    • Adult Company News
    • Adult Retail News
    • Adult Talent News
    • Adult Videos News
  • Podcasts
  • Industry Guides
    • Adult Affiliate Guide
    • Affiliate Marketing for Beginners
    • Top Adult Traffic Networks
    • Top Adult PR Agents
    • Funding an Adult Business
  • Business Directory
    • View Categories
    • View Listings
    • Submit Listing
  • Newsletters
  • Industry Events
    • Events Calendar
    • YNOT Cam Awards | Hollywood
    • YNOT Awards | Prague
    • YNOT Cammunity
    • YNOT Summit
    • YNOT Reunion
  • Login with YNOT ID

Russian Porn Sites First to Exploit VML Vulnerability in IE

Posted On 20 Sep 2006
By : admin

CYBERSPACE – According to security software vendor Sunbelt Software, a handful of Russian porn sites are the source of the first known exploit of vulnerability present in Windows’ handling of Vector Markup Language (VML).Sunbelt posted screencaps detailing the visible behavior of the exploit Monday, and Microsoft acknowledged yesterday that the flaw was being actively targeted by attackers.

The vulnerability, which has received an “extremely critical” rating from security monitoring company Secunia, exists within the Windows component “vgx.dll,” the Microsoft Vector Graphics Rendering library file.

According to Secunia, the boundary error in the vgx.dll file “can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into viewing a malicious VML document containing an overly long ‘fill’ method inside a ‘rect’ tag with the Internet Explorer browser.”

Secunia adds in their bulleting that successful exploitation of the vulnerability “allows execution of arbitrary code with the privileges of the application using the vulnerable functionality in the library.”

In a security advisory published yesterday acknowledging the flaw, Microsoft states that the company is “aware that this vulnerability is being actively exploited.”

“A security update to address this vulnerability is now being finalized through testing to ensure quality and application compatibility,” the Microsoft advisory states. “Microsoft’s goal is to release the update on Tuesday, October 10.”

The advisory also states that Microsoft may issue the patch prior to October 10, “depending on customer needs.”

For the time being, the primary defense against the exploit is the usual set of common-sense advice given for any number of exploit types; don’t click on email attachments from senders you don’t know and trust, avoid browsing unfamiliar websites, and keep your anti-virus software up-to-date.

One work-around solution, instructions for which have been published on ZDNet.com, is to disable VML rendering until Microsoft issues the official patch, and subsequently restore the rendering once the patch has been installed.

Instructions for disabling VML rendering are available here: http://blogs.zdnet.com/Ou/index.php?p=323

For more information on the vulnerability, visit the following links:
Secunia security advisory: http://secunia.com/advisories/21989/

Microsofts advisory: http://www.microsoft.com/technet/security/advisory/925568.mspx

Sunbelt Software blog: http://sunbeltblog.blogspot.com/2006/09/seen-in-wild-zero-day-exploit-being.html

  • google-share
Previous Story

WRAAC.org Releases Free “ParentalControl Bar” Web Filter Tool

Next Story

Playboy Lures Victoria Secret Employees and Shafts Sick Kids

Leave a Reply Cancel reply

You must be logged in to post a comment.

Sponsor

YNOT Shoot Me

YNOTShootMe.com has exclusive pics from adult industry business events. Check it out!

YNOT Directory

  • MojoHost
    Website Hosting Services
  • Sexperteaze — Adult Online Marketing, SEO & Design
    Marketing Consultants
  • Vantage Video Distributor
    Distributors & Manufacturers
  • Premiere Listing

    Clickadu – Your trusted traffic souce

    More Details

RECENT

POPULAR

COMMENTS

Trans Star Tori Easton Ends Pride Month on WTF-TV

Posted On 07 Jul 2025

Beca Barbie Is Pretty in Pink in Hookup Hotshot Debut

Posted On 07 Jul 2025

Mag Numb Guests on Sex Party Podcast with Dustin Rybka

Posted On 07 Jul 2025

Vanessa, Meet Vivid

Posted On 29 Sep 2014
Laila Mickelwaite and Exodus Cry

Laila Mickelwaite, Exodus Cry and their Crusade Against Porn

Posted On 03 May 2021

Sex Toy Collective Dildo Sculptor

Posted On 19 Mar 2019

Find a good sex toy is now a problem,...

Posted On 18 Mar 2024

Thanks to the variety of sex toys, I can...

Posted On 02 Feb 2024

I understand the concerns about...

Posted On 05 Jan 2024

Sponsor

Sitemap
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.OkPrivacy Policy