OCBob
VIPER POWERED
There is a new exploit for internet explorer and outlook. It is a new 0 day exploit. It allows any kind of malware to be loaded onto your machine without your knowledge, so it is very dangerous. It can come from a website or an email. The best bet is not to use IE, use Mozilla instead, but if you do there is a registry hack that can mitigate this exploit. I have added that info below. If you use Outlook, do not use the preview pane, this can be launched there without you even opening the email. We have seen a very large number of our customers that have been exposed to this already.
This is what we sent to our managed customers:
There is an unpatched "Zero Day" exploit for all current versions of Microsoft Internet Explorer and Outlook, which is being exploited by a wide array of sites on the Internet. Exploitation of this vulnerability can lead to execution of arbitrary code on affected hosts.
VeriSign MSS is currently tracking four versions of the exploit in the wild, and has witnessed the attack on a wide array of our customer base.
We cannot underscore enough the serious impact that exploitation of this vulnerability may have on your network, therefore VeriSign is recommending the following mitigation steps:
1.) Unregister the VML DLL, with either:
regsvr32 -u "%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll"
regsvr32 /u "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"
This is the most effective way of mitigating the threat.
While you are working to implement this workaround, please also do the following:
2.) Cease use of Microsoft Internet Explorer completely and make use of another browser if at all possible.
3.) Disable the Preview Pane in Microsoft Outlook, as it is possible to exploit this vulnerability using HTML email automatically through the preview pane.
4.) Do not open any email from unknown sources, or any email you are not expecting.
5.) Make sure your Antivirus software is up to date.
This is what we sent to our managed customers:
There is an unpatched "Zero Day" exploit for all current versions of Microsoft Internet Explorer and Outlook, which is being exploited by a wide array of sites on the Internet. Exploitation of this vulnerability can lead to execution of arbitrary code on affected hosts.
VeriSign MSS is currently tracking four versions of the exploit in the wild, and has witnessed the attack on a wide array of our customer base.
We cannot underscore enough the serious impact that exploitation of this vulnerability may have on your network, therefore VeriSign is recommending the following mitigation steps:
1.) Unregister the VML DLL, with either:
regsvr32 -u "%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll"
regsvr32 /u "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"
This is the most effective way of mitigating the threat.
While you are working to implement this workaround, please also do the following:
2.) Cease use of Microsoft Internet Explorer completely and make use of another browser if at all possible.
3.) Disable the Preview Pane in Microsoft Outlook, as it is possible to exploit this vulnerability using HTML email automatically through the preview pane.
4.) Do not open any email from unknown sources, or any email you are not expecting.
5.) Make sure your Antivirus software is up to date.