Blocking VML with ISA 2004 & ISA 2006 discusses a vulnerability in the VML parsing dll which can result in an unpleasant experience. discusses a methodology by which you can use ISA 2004 or ISA 2006 to block HTTP-based attacks targeted against this vulnerability.

Finally, automates the process of creating the proper HTTP Filter settings for you.

Tim's report was accurate (see my comments). I've updated the script to version 1.2 and reposted it. Many thanx to Tim for his discovery.

Jim Harrison (ISA Sustained Engineering)