Post by DFH » Sat Feb 15, 2020 7:54 pm

Background: https://news.softpedia.com/news/microsoft-s-zero-day-bug-fix-causes-windows-bug-528973.shtml
Having read of the recently reported zero day vulnerability of jscript.dll in Windows,
and the fact that Microsoft has described only a mitigation workaround for Windows 7 users after extended support ended in January 2020,
it occurs to me that as TextPipe has a special filter for running JScript language,
to ask whether this uses the vulnerable jscript.dll or the non-vulnerable jscript9.dll ?

If the latter, there should be no serious consequences.

If the former, it would likely be the case that Windows 7 users that implemented the Microsoft workaround
may encounter unexpected issues when seeking to use a filter that runs JScript.

If this were the case, then TextPipe ought to be updated to use jscript9.dll and not jscript.dll

Re: TextPipe use of jscript.dll ?

Post by DataMystic Support » Mon Feb 17, 2020 9:49 pm

Hi David,

We don't directly call any jscript DLL by name. We call it by its COM registration name, which will be the patched or unpatched DLL as the case may be,

