Skip to content
View in the app

A better way to browse. Learn more.

Thailand News and Discussion Forum | ASEANNOW

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Critical Vulnerability

Featured Replies

hi'

here is an alert dating yesterday, and it may affect a lot of PC's ...

here it is :

Critical vulnerability in a COM component of Windows

(18/08/05)

SUMMARY:

A vulnerability was discovered in certain versions of

the Microsoft component DDS Library Shape Control

(Msdds.dll) of Windows. This fault allows a hostile

individual to run of the remote code on the computer of

his(her) victim during the consultation of a Web page

trapped via the browser Internet Explorer. The

vulnerable file is not present default in Windows but

can have been installed by an application Office or

.NET.

SOFTWARE CONCERNED:

Considering the nasty character(typeface) of the

disclosure of this fault, at the moment there is no

reliable list of the applications susceptible to install

a vulnerable version of the component COM. Certain

averagely recent versions of Microsoft Office and Visual

Studio .Net should be a part of it.

CORRECTIVE:The discoverer of the fault having chosen not to

cooperate with the publisher before publishing his

discovery, for the moment there does not exist official

corrective and the risk of hostile exploitation is

maximal because the detail of the code allowing to run

(exploit) this fault was made public. To know if they

are for risk, the concerned users can simply launch a

search for the file Msdds.dll on their hard disk:

* If this file is not present, the computer is not

vulnerable. No supplementary action is necessary;

* If this file is present in its vulnerable or

doubtful version (right click on the file > "Properties"

> tab "Version"), 7.0.9064.9112 or subordinate in

7.10.x, besides the attentiveness towards the links and

not sure HTML files, by waiting for the availability of

an official corrective the users can also download and

run the utility KillBit of the internet Storm Center to

deactivate the coverage of the vulnerable component in

the browser Internet Explorer (to click "Yes" if the

indicated status is " currently UNSET " and "No."

otherwise). It is possible finally possibly to delete

the file Msdds.dll, but if it is used by certain

applications their functioning will be

disrupted(perturbed) keep at least a copy of the file or

do not empty the Windows dustbin to be able to restore

it in case of problem.

check asap!

francois

Please read the link from Crossy before you get too excited as only two versions seem to be at risk. What I have is not one of them and I suspect that is probably the case with a lot of people (if not most).

The affected versions of Msdds.dll are 7.0.9064.9112 and 7.0.9446.0. Customers who have Msdds.dll with version 7.0.9955.0, 7.10.3077.0, or higher on their systems are not affected by this vulnerability.
  • Author
Merci M. Francois :o

cv

hi'

you're welcome :D

I have read again the alert and whatever version of this dll you have you should run the tool, I don't have any of these dll versions, my system is clean!

if you have one of them check with the tool and apply if needed :D

francois

ps;prevent before having the need to cure :D

Thanks Francois.

I have checked and do not have that DLL

Running XP Pro

I did a check and I FOUND the msdds.dll file on my PC. The file version is 7.0.9064.9112 and it is located in the C:\Program Files\Common Files\Microsoft Shared\MSDesigners7 folder. I run Win XP Pro SP2.

I went to the Microsoft page that Crossy mentioned but I must say that I don't understand much of it.

What should I do? Which is this 'tool' that I should apply and where to find it?

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.