MS VML patch is out

FYI...

- http://www.f-secure.com/weblog/archi....html#00000980
"Microsoft has released a patch against the VML vulnerability outside of their normal update cycle. Which is great. The patch is available right now via http://update.microsoft.com . Get it."

~or~

- http://isc.sans.org/diary.php?storyid=1738
Last Updated: 2006-09-26 19:22:11 UTC ...(Version: 3)...
"Microsoft has just released an update to address the VML (VGX) issue. The update can currently be found on Microsoft Update and is titled:

Microsoft Security Bulletin MS06-055
Vulnerability in Vector Markup Language Could Allow Remote Code Execution (925486)
> http://www.microsoft.com/technet/sec.../MS06-055.mspx
Published: September 26, 2006
Version: 1.0

It is recommended that the patch be applied immediately (after testing) unless a suitable mitigation strategy is in place.
Update: Also, note that if you applied the ACL mitigation (removing Everyone Read access from the DLL), you will need to undo that before this update will apply successfully..."

> http://blogs.technet.com/msrc/archiv...26/459194.aspx

.
Many thanks to AplusWebMaster @ CastleCops