27 September 2006

Security advisory

Microsoft has released a security update between its monthly security update schedule. This is unusual, and expresses the seriousness of the vulnerability that is solved by this update.

This is a critical update for the so-called "Vector Markup Language vulnerability", which can allow remote code execution. Note that several pieces of malicious software that utilize this vulnerability are seen in the wild recently.

Critical is Microsoft’s highest vulnerability rating.

More detailed information is available in Microsoft's Security Bulletin MS06-055.

An update that fixes the vulnerability is available from Windows automatic update mechanism for systems that support this. Alternatively, one may download the update from http://windowsupdate.microsoft.com.  

Norman advices all affected users to download this security update as soon as possible, to be protected from potential exploits.