ZERT VML patch for old Windows versions
Results 1 to 7 of 7

Thread: ZERT VML patch for old Windows versions

  1. #1
    Join Date
    Apr 2005
    Location
    Maryland, USA
    Posts
    17,806

    ZERT VML patch for old Windows versions

    http://news.zdnet.com/2100-1009_22-6...=zdfd.newsfeed
    By Joris Evers, CNET News.com
    Published on ZDNet News: September 30, 2006, 10:32 AM PT

    A group of security professionals has released a patch to repair a serious flaw in older Windows versions for which Microsoft no longer provides security updates.

    The group, which calls itself the Zeroday Emergency Response Team, or ZERT, created the patch so users of Windows versions that are no longer officially supported can protect their PCs against increasing attacks that utilize a recently disclosed Windows flaw.

    The vulnerability, first reported last week, lies in a Windows component called "vgx.dll." This component supports Vector Markup Language (VML) graphics in the operating system. Malicious software can be loaded, unbeknownst to the user, onto a vulnerable PC when the user clicks on a malicious link on a Web site or an e-mail message.

    Microsoft rushed out a "critical" fix for Windows on Tuesday to address the problem, two weeks before its regularly scheduled patch day. Microsoft's updates are available for Windows 2000 with Service Pack 4, Windows XP with Service Pack 1 or later, Microsoft Windows XP Professional x64 Edition, and Windows Server 2003.

    But Microsoft no longer provides updates for its older operating systems. ZERT sought to fill that void. "A ZERT patch has just been made available for unsupported system versions," the group said on its Web site. The patch has been tested on Windows 98, Windows 98 Second Edition, Windows Millennium Edition, Windows 2000 and Windows 2000 with Service Pack 3, the group said.

    ZERT is made up of security professionals from around the world who volunteer their time. Last week the group crafted a patch to plug the VML flaw ahead of Microsoft's fix, so IE users can protect themselves while Microsoft worked on an official patch.

    Meanwhile, there are several other security vulnerabilities in Microsoft products waiting to be fixed. Some of these flaws are already being used in cyberattacks, though not as widespread as the VML flaw, according to security experts.

    A word of caution is always warranted when it comes to third-party fixes, ZERT has noted. The group does test its fixes, but does not have the same resources Microsoft does when it produces patches. ZERT does provide the source code of its fix, allowing people to validate what it does.

    ZERT stresses on its Web site that its fix has no warranties.
    ZERT Download Information for ZERT2006-02:
    Buffer overflow in Vector Markup Language (VML) library file used by Microsoft Internet Explorer and Outlook
    .
    For Windows 9x to 2000 SP3 and XP SP0
    http://www.isotf.org/zert/download.htm

    VML Vulnerability Test Page:
    If you can see the two colored boxes on this page and your browser doesn't crash, you are not vulnerable.
    http://www.isotf.org/zert/testvml.htm

  2. #2
    Join Date
    Oct 2000
    Location
    OH USA
    Posts
    2,945
    SpywareDr this is a great find. Thanks.

    I used it succesfully on my W98SE.

    I think the mods should make this a 'sticky' in the appropriate forums.

  3. #3
    Join Date
    Apr 2005
    Location
    Maryland, USA
    Posts
    17,806
    You're welcome.

    'So far so good' on two old 98SE machines at the office here too.

  4. #4
    Join Date
    Feb 2002
    Location
    London, England
    Posts
    234
    I have downloaded this patch but I am afraid that I find the instructions for installation incomprehensible. Would some kind person spell out in simple steps how I ought to proceed?

    I am using WIN98SE.

  5. #5
    Join Date
    Apr 2005
    Location
    Maryland, USA
    Posts
    17,806
    After extracting the ZIP file, run the ZVGPatcher.exe program.

  6. #6
    Join Date
    Feb 2002
    Location
    London, England
    Posts
    234
    Thanks a lot! It has worked.

  7. #7
    Join Date
    Apr 2005
    Location
    Maryland, USA
    Posts
    17,806
    You're more than welcome ... and thanks for posting back.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •