Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Internet Explorer - MSDDS Zero Day Exploit Protection

ISC Logo The Internet Storm Center went to yellow alert for a 24 hour period to highlight the need for administrators and others to take precautions and preventative actions.  Vulernable versions might be found in Office versions earlier than Office 2003, or other older Microsoft products. 

The MSDSS.DLL version must be higher than 7.0.9064.9112 to be considered safe.  When you search, make your folder view is set to SHOW HIDDEN SYSTEM FILES and search the entire C: drive, as this isn't in the Windows directory.   To test this, find MSDDS.DLL and check the File PROPERTIES and then check the VERSION information 

As I'm using Office XP, and my version of MSDSS.DLL version was right at 7.0.9064.9112.  So, I've personally tested the ISC Killbit solution and so far so good.

IE Zero Day Exploit - Internet Storm Center returns to Yellow

Microsoft Security Advisory - MSDDS.DLL Issue

Internet Storm Center - Kill Bit for MSDDS Solution

FrSIRT MSDDS.DLL - IE Exploit Information

FrSIRT MSDDS.DLL - IE Advisory