Skip to content
View in the app

A better way to browse. Learn more.

MSFN

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Internet Explorer Critical Vulnerability

Featured Replies

There is new critical vulnerability in vgx.dll that also applies to IE on Windows 9x.

Microsoft published this Security Advisory (925568)

ZERT created an unofficial patch: http://isotf.org/zert/download.htm

I have tested that fully patched IE 6.01SP1 on Windows 98 SE will crash.

I have not tested other version of IE and other version of Windows.

The ZERT patch does not work on Windows 98 but probably it could be possible to use it on Windows 2000 and copy the patched file to Win9x.

Petr

Anyone tried this workaround advised by Microsoft?

regsvr32 -u "%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll

Doesn't work on my fully updated Win98se+IE6.0 SP1. I get a loadlibrary failed error.

Well you can simply rename or delete it, also when Windows+IE is running. A registry checker will find it missing, so the unregistering failed indeed, but that's all I have noticed so far. Perhaps that a infected site can crash a browser because of this but that's better than downloading trojans.

The test on the ZERT site says I am not vulnerable now after renaming vgx.dll, before that it didn't do anything on my system with the Maxton browser (based on IE engine), no crash just a blank page.

I must say that I expected much more response in this topic because this vulnerability is a nasty one. Just visiting a wrong site can get you into trouble. No user interference needed! The number of bad sites is rising:

http://www.techweb.com/wire/security/193004128

Microsoft denies that it is this serious but is considering to release a patch outside the normal patch-cycle anyway :)

Edited by noguru

Well you can simply rename or delete it, also when Windows+IE is running. A registry checker will find it missing, so the unregistering failed indeed, but that's all I have noticed so far. Perhaps that a infected site can crash a browser because of this but that's better than downloading trojans.

The test on the ZERT site says I am not vulnerable now after renaming vgx.dll, before that it didn't do anything on my system with the Maxton browser (based on IE engine), no crash just a blank page.

I must say that I expected much more response in this topic because this vulnerability is a nasty one. Just visiting a wrong site can get you into trouble. No user interference needed! The number of bad sites is rising:

http://www.techweb.com/wire/security/193004128

Microsoft denies that it is this serious but is considering to release a patch outside the normal patch-cycle anyway :)

I think if you must use I.E it is imperative to disable active scripting to disable javascript,vbs and activex,adding only sites you require in the trusted zone. I would also disable vbs via file association as any standard security feature. Unfortunately it seems they are going to bypass even this temporary defense shortly so use Firefox as a browser in the interim or a live cd

LinkScanner http://linkscanner.explabs.com/linkscanner/default.asp

Edited by oscardog

I am presuming that what has been released has just scratched the surface as yet

I'm not worried about this. Seriously.

Thanks for helping to circulate this unofficial IE925568 patch. I probably would have missed it in the original post. The work these "patch hackers" do is really appreciated by those of use still running 98/Me machines.

I installed the patch and checked out the test page. My IE6SP1 browser running under Windows Me passed without any problems at all.

We should have some kind of mailing list that will keep everyone in the loop when it comes to unofficial patches and upgrades.

:thumbup outstanding i grapped the vgx patch for xp from zert 2 days ago but im happy 2 see u got 9x covered u guys are awesome ,now this what a forums all about working to improve a os any os well done.

Edited by smok3yjoint

@Petr: I'm looking at it right now. It will be repackaged ASAP.

the_guy

EDIT: Microsoft also made an update to the Roots Update. Link is the same.

Edited by the_guy

Done of the update! It's at mytempdir until MDGx can host it at his site.

This update replaces 883586 for XPSP2 and 890573 for IE6SP1.

Link=here.

the_guy

Here are all official [+ unofficial 1 created using official VGX.DLL from official Win2000 SP4 fix] VGX.DLL patches:

http://www.mdgx.com/ietoy.htm#VGX

* Microsoft Internet Explorer 5.01 SP4/6.0/6.0 SP1/6.0 SP2 for Windows 98/98 SE/NT4 SP6a/2000/ME/XP/2003 Vector Markup Language (VML) VGX.DLL Security Vulnerability Fix (English):

http://www.microsoft.com/technet/security/...n/ms06-055.mspx

- MS IE 6.0 SP1 Patch for Windows 2003/2003 SP1/2003 R2 [892 KB]:

http://download.microsoft.com/download/a/3...486-x86-ENU.exe

- MS IE 6.0 SP2 Patch for Windows XP SP2 [784 KB]:

http://download.microsoft.com/download/9/b...486-x86-ENU.exe

- MS IE 6.0 SP1 Patch for Windows XP SP1 [803 KB]:

http://download.microsoft.com/download/9/d...sXP-x86-ENU.exe

- MS IE 6.0 SP1 Patch for Windows 2000 SP4 [1.42 MB]:

http://download.microsoft.com/download/3/b...000-x86-ENU.exe

- MS IE 5.01 SP4 Patch for Windows 2000 SP4 [1.22 MB]:

http://download.microsoft.com/download/c/b...sp4-x86-ENU.exe

- Unofficial MS IE 6.0/6.0 SP1 Patch for Windows 98/98 SE/NT4 SP6a/ME [1.03 MB]:

http://www.mdgx.com/files/IE925486.EXE

More info:

http://www.isotf.org/zert/

Test VML:

http://www.isotf.org/zert/testvml.htm

the_guy:

Unofficial IE925486.EXE installs on 98FE, 98SE, ME + NT4, only with MS IE 6.0 or 6.0 SP1 installed.

HTH

Edited by MDGx

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.