MSFN Forum: Internet Explorer Critical Vulnerability - MSFN Forum

Jump to content



  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Internet Explorer Critical Vulnerability Critical Vulnerability in vgx.dll Rate Topic: -----

#1 User is offline   Petr 

  • Friend of MSFN
  • PipPipPipPipPip
  • Group: Members
  • Posts: 981
  • Joined: 15-April 05
  • OS:98SE
  • Country: Country Flag

Posted 22 September 2006 - 04:43 PM

There is new critical vulnerability in vgx.dll that also applies to IE on Windows 9x.

Microsoft published this Security Advisory (925568)

ZERT created an unofficial patch: http://isotf.org/zert/download.htm

I have tested that fully patched IE 6.01SP1 on Windows 98 SE will crash.

I have not tested other version of IE and other version of Windows.

The ZERT patch does not work on Windows 98 but probably it could be possible to use it on Windows 2000 and copy the patched file to Win9x.

Petr


#2 User is offline   noguru 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 307
  • Joined: 24-February 06

Posted 22 September 2006 - 04:52 PM

Anyone tried this workaround advised by Microsoft?

regsvr32 -u "%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll


Doesn't work on my fully updated Win98se+IE6.0 SP1. I get a loadlibrary failed error.

#3 User is offline   Fredledingue 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,139
  • Joined: 10-February 05
  • OS:98SE
  • Country: Country Flag

Posted 22 September 2006 - 05:10 PM

me too.

What happens if you delete vgx.dll (instead of simply unregistering it)?

#4 User is offline   noguru 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 307
  • Joined: 24-February 06

Posted 23 September 2006 - 04:38 AM

Well you can simply rename or delete it, also when Windows+IE is running. A registry checker will find it missing, so the unregistering failed indeed, but that's all I have noticed so far. Perhaps that a infected site can crash a browser because of this but that's better than downloading trojans.

The test on the ZERT site says I am not vulnerable now after renaming vgx.dll, before that it didn't do anything on my system with the Maxton browser (based on IE engine), no crash just a blank page.

I must say that I expected much more response in this topic because this vulnerability is a nasty one. Just visiting a wrong site can get you into trouble. No user interference needed! The number of bad sites is rising:

http://www.techweb.c...urity/193004128

Microsoft denies that it is this serious but is considering to release a patch outside the normal patch-cycle anyway :)

This post has been edited by noguru: 23 September 2006 - 04:57 AM


#5 User is offline   oscardog 

  • Member
  • PipPip
  • Group: Members
  • Posts: 234
  • Joined: 29-June 06

Posted 23 September 2006 - 06:21 AM

View Postnoguru, on Sep 23 2006, 11:38 AM, said:

Well you can simply rename or delete it, also when Windows+IE is running. A registry checker will find it missing, so the unregistering failed indeed, but that's all I have noticed so far. Perhaps that a infected site can crash a browser because of this but that's better than downloading trojans.

The test on the ZERT site says I am not vulnerable now after renaming vgx.dll, before that it didn't do anything on my system with the Maxton browser (based on IE engine), no crash just a blank page.

I must say that I expected much more response in this topic because this vulnerability is a nasty one. Just visiting a wrong site can get you into trouble. No user interference needed! The number of bad sites is rising:

http://www.techweb.c...urity/193004128

Microsoft denies that it is this serious but is considering to release a patch outside the normal patch-cycle anyway :)

I think if you must use I.E it is imperative to disable active scripting to disable javascript,vbs and activex,adding only sites you require in the trusted zone. I would also disable vbs via file association as any standard security feature. Unfortunately it seems they are going to bypass even this temporary defense shortly so use Firefox as a browser in the interim or a live cd
LinkScanner http://linkscanner.e...ner/default.asp

This post has been edited by oscardog: 23 September 2006 - 06:53 AM


#6 User is offline   eidenk 

  • MSFN Addict
  • PipPipPipPipPipPipPip
  • Group: Banned
  • Posts: 1,527
  • Joined: 28-March 05

Posted 23 September 2006 - 06:54 PM

And what about simply a killbit for vgx.dll ?

#7 User is offline   oscardog 

  • Member
  • PipPip
  • Group: Members
  • Posts: 234
  • Joined: 29-June 06

Posted 23 September 2006 - 07:17 PM

I am presuming that what has been released has just scratched the surface as yet

#8 User is offline   LLXX 

  • MSFN Junkie
  • PipPipPipPipPipPipPipPipPip
  • Group: Banned
  • Posts: 3,399
  • Joined: 04-December 05

Posted 26 September 2006 - 12:08 AM

I'm not worried about this. Seriously.

#9 User is offline   MDGx 

  • 98SE2ME + 98MP10
  • Group: Super Moderator
  • Posts: 2,677
  • Joined: 22-November 04
  • OS:none specified
  • Country: Country Flag

Posted 26 September 2006 - 10:05 AM

Official VGX.DLL fix ported to 98FE, 98SE, ME + NT4:
http://www.mdgx.com/ietoy.htm#VGX

Listed here:
http://www.msfn.org/...showtopic=46581

HTH

This post has been edited by MDGx: 26 September 2006 - 11:38 PM


#10 User is offline   sam13484 

  • Member
  • PipPip
  • Group: Members
  • Posts: 102
  • Joined: 20-October 04

Posted 26 September 2006 - 12:11 PM

Thanks for helping to circulate this unofficial IE925568 patch. I probably would have missed it in the original post. The work these "patch hackers" do is really appreciated by those of use still running 98/Me machines.

I installed the patch and checked out the test page. My IE6SP1 browser running under Windows Me passed without any problems at all.

We should have some kind of mailing list that will keep everyone in the loop when it comes to unofficial patches and upgrades.

#11 User is offline   Petr 

  • Friend of MSFN
  • PipPipPipPipPip
  • Group: Members
  • Posts: 981
  • Joined: 15-April 05
  • OS:98SE
  • Country: Country Flag

Posted 26 September 2006 - 04:15 PM

Microsoft has released the official patch:
http://blogs.technet.../26/459194.aspx
http://www.microsoft.com/technet/security/...n/MS06-055.mspx

Windows 2000 patches contain:
IE5.01 SP4 contains VGX.DLL 5.00.3845.1800
IE6.0 SP1 contains VGX.DLL 6.00.2800.1580

The patch has to be re-packaged for Windows 9x.

Petr

#12 User is offline   smok3yjoint 

  • Group: Banned
  • Posts: 6
  • Joined: 24-February 04

Posted 26 September 2006 - 04:18 PM

:thumbup outstanding i grapped the vgx patch for xp from zert 2 days ago but im happy 2 see u got 9x covered u guys are awesome ,now this what a forums all about working to improve a os any os well done.

This post has been edited by smok3yjoint: 26 September 2006 - 04:19 PM


#13 User is offline   the_guy 

  • Creator of the Windows ME Service Pack
  • PipPipPipPipPip
  • Group: Members
  • Posts: 901
  • Joined: 15-July 05
  • OS:ME
  • Country: Country Flag

Posted 26 September 2006 - 04:20 PM

@Petr: I'm looking at it right now. It will be repackaged ASAP.

the_guy

EDIT: Microsoft also made an update to the Roots Update. Link is the same.

This post has been edited by the_guy: 26 September 2006 - 04:27 PM


#14 User is offline   the_guy 

  • Creator of the Windows ME Service Pack
  • PipPipPipPipPip
  • Group: Members
  • Posts: 901
  • Joined: 15-July 05
  • OS:ME
  • Country: Country Flag

Posted 26 September 2006 - 06:00 PM

Done of the update! It's at mytempdir until MDGx can host it at his site.

This update replaces 883586 for XPSP2 and 890573 for IE6SP1.

Link=here.

the_guy

#15 User is offline   MDGx 

  • 98SE2ME + 98MP10
  • Group: Super Moderator
  • Posts: 2,677
  • Joined: 22-November 04
  • OS:none specified
  • Country: Country Flag

Posted 26 September 2006 - 08:22 PM

Here are all official [+ unofficial 1 created using official VGX.DLL from official Win2000 SP4 fix] VGX.DLL patches:
http://www.mdgx.com/ietoy.htm#VGX

* Microsoft Internet Explorer 5.01 SP4/6.0/6.0 SP1/6.0 SP2 for Windows 98/98 SE/NT4 SP6a/2000/ME/XP/2003 Vector Markup Language (VML) VGX.DLL Security Vulnerability Fix (English):
http://www.microsoft.com/technet/security/...n/ms06-055.mspx
- MS IE 6.0 SP1 Patch for Windows 2003/2003 SP1/2003 R2 [892 KB]:
http://download.microsoft.com/download/a/3...486-x86-ENU.exe
- MS IE 6.0 SP2 Patch for Windows XP SP2 [784 KB]:
http://download.microsoft.com/download/9/b...486-x86-ENU.exe
- MS IE 6.0 SP1 Patch for Windows XP SP1 [803 KB]:
http://download.microsoft.com/download/9/d...sXP-x86-ENU.exe
- MS IE 6.0 SP1 Patch for Windows 2000 SP4 [1.42 MB]:
http://download.microsoft.com/download/3/b...000-x86-ENU.exe
- MS IE 5.01 SP4 Patch for Windows 2000 SP4 [1.22 MB]:
http://download.microsoft.com/download/c/b...sp4-x86-ENU.exe
- Unofficial MS IE 6.0/6.0 SP1 Patch for Windows 98/98 SE/NT4 SP6a/ME [1.03 MB]:
http://www.mdgx.com/files/IE925486.EXE
More info:
http://www.isotf.org/zert/
Test VML:
http://www.isotf.org/zert/testvml.htm

the_guy:
Unofficial IE925486.EXE installs on 98FE, 98SE, ME + NT4, only with MS IE 6.0 or 6.0 SP1 installed.

HTH

This post has been edited by MDGx: 27 September 2006 - 02:10 AM


#16 User is offline   PsycoUnc 

  • Member
  • PipPip
  • Group: Members
  • Posts: 236
  • Joined: 03-April 05

Posted 27 September 2006 - 02:00 AM

-hey, has anybody noticed that the unofficial IE 6.0+ VGX.DLL file subs just fine into IE 5.5sp2?
...
I unregistered the old one (located in Program Files), replaced it, re-registered, and voila, the test page displays just fine (it bombed before this "fix", as is proper for unprotected systems)...
...
-granted, I've only tested it w/the one test page, have no idea if it's "fully" compatible... anybody know of any other test pages, or ways to test it?

#17 User is offline   Petr 

  • Friend of MSFN
  • PipPipPipPipPip
  • Group: Members
  • Posts: 981
  • Joined: 15-April 05
  • OS:98SE
  • Country: Country Flag

Posted 27 September 2006 - 03:03 AM

View PostPsycoUnc, on Sep 27 2006, 10:00 AM, said:

-hey, has anybody noticed that the unofficial IE 6.0+ VGX.DLL file subs just fine into IE 5.5sp2?


IE5.5SP2 uses VGX.DLL 5.50.4133.200 or hotfix version 5.50.4909.1000.
IE6.0 uses VGX.DLL 6.00.2600.0000
IE6.0SP1 uses 6.00.2800.1106 (first release), 6.00.2800.1265 (re-release and KB826940), 6.00.2800.1411 (KB833989 security update), 6.00.2800.1461 (KB883586 hotfix), 6.00.2800.1488 (KB890573 hotfix)

Original Microsoft VGX fixes install on systems with IE 6.0 SP1 only (6.00.2800.1106-6.00.2800.9999) , I have no idea if the 6.0SP1 version of VGX.DLL can be used with IE6.0 or IE5.5SP2.

Petr

#18 User is offline   PsycoUnc 

  • Member
  • PipPip
  • Group: Members
  • Posts: 236
  • Joined: 03-April 05

Posted 28 September 2006 - 08:41 AM

-it's ver. 6.00.2800.1580, from MDGx's "Unofficial MS IE 6.0/6.0 SP1 Patch" file...
manual install/register of that file seems to work fine in IE5.5sp2 (at least on that one test page), but it'll need more testing of course to insure compatibility...
>;]

This post has been edited by PsycoUnc: 28 September 2006 - 08:57 AM


#19 User is offline   bacon_boy 

  • Newbie
  • Group: Members
  • Posts: 12
  • Joined: 30-September 06

Posted 30 September 2006 - 07:38 PM

View PostPsycoUnc, on Sep 28 2006, 09:41 AM, said:

-it's ver. 6.00.2800.1580, from MDGx's "Unofficial MS IE 6.0/6.0 SP1 Patch" file...
manual install/register of that file seems to work fine in IE5.5sp2 (at least on that one test page), but it'll need more testing of course to insure compatibility...
>;]


Thanks for that valuable bit of info, the page now displays correctly for me as well :)

#20 User is offline   noguru 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 307
  • Joined: 24-February 06

Posted 01 October 2006 - 08:39 AM

ZERT also made a patch for Win98/2Ksp3/XPsp0

http://isotf.org/zert/download.htm

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2011 msfn.org
Privacy Policy