Windows 2000 ActiveX Parameter Validation Vulnerability Patch (MS00-085)
Windows 2000 ActiveX Parameter Validation Vulnerability Patch (MS00-085) Ranking & Summary
Windows 2000 ActiveX Parameter Validation Vulnerability Patch (MS00-085) description
Windows 2000 ActiveX Parameter Validation Vulnerability Patch (MS00-085) is launched as an important and useful patch which can remove a security vulnerability in Microsoft Windows 2000. The vulnerability could allow enable a malicious user to potentially run code on another user's machine.
An ActiveX control that ships as part of Windows 2000 contains an unchecked buffer. If the control was called from a Web page or HTML mail using a specially-malformed parameter, it would be possible to cause code to execute on the machine via a buffer overrun. This could potentially enable a malicious user to take any desired action on the user's machine, limited only by the permissions of the user.
The vulnerability could only be exploited if ActiveX controls are enabled in IE, Outlook, or Outlook Express. The Security Zones feature in Internet Explorer enables customers to limit what Web sites can do, and customers who have used the feature to prevent untrusted sites from invoking ActiveX controls would be at minimal risk from the Web-based attack scenario. Customers who have applied the Outlook Security Update would be protected against the mail-borne scenario, since it moves mail into the Restricted Sites Zone, thereby preventing HTML mails from invoking ActiveX controls.
Windows 2000 ActiveX Parameter Validation Vulnerability Patch (MS00-085) Screenshot
Windows 2000 ActiveX Parameter Validation Vulnerability Patch (MS00-085) Keywords
Bookmark Windows 2000 ActiveX Parameter Validation Vulnerability Patch (MS00-085)
Windows 2000 ActiveX Parameter Validation Vulnerability Patch (MS00-085) Copyright
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com
- CST Odometer ActiveX Control 3.6
- Microsoft Windows 2000 Update Dump FSMO Roles
- Microsoft Windows 2000 Patch: UDP
- Microsoft Windows 2000 Patch: LSA Memory Loss
- Microsoft Windows 2000 Update: NetDiag
- Microsoft Windows 2000 Patch: AOL Image Support
- Microsoft Security Bulletin (MS00-082) 2.0
- Microsoft Windows 2000 1.2
- Microsoft Internet Explorer Active Setup Control Vulnerability patch 0
- Microsoft Office 2000 Service Release 2 (SR-2) (German Edition) 11-28-00
- Microsoft VM File Reading Vulnerability patch 1
- Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1
- Microsoft IIS Malformed Extension Data in URL Vulnerability patch MS00-030
- Microsoft Win2000 Protected Store Key Length vulnerability patch 6-8-2000
- Microsoft Internet Explorer HTML Help File Code Execution Vulnerability patch 6-8-2000
- Microsoft Internet Explorer SSL Certificate Validation Vulnerabilities patch 6-10-2000
- Internet Explorer 5.5 Scriptlet Rendering Vulnerability Patch
- Personal Web Server File Access Vulnerability Patch (FrontPage 98)
- Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) 5.131.3659.0
- Microsoft Office 2000 SR-1 Update: Web Client Secu Update
- Microsoft Office 2000 Security Update: HTML Data
- Microsoft Windows 2000 Patch: Protected Store Key
- Microsoft Office 2000 SR-1 Update: Web Client Security MS01-001
- Microsoft PowerPoint 2000 SR-1 Update: Extended Pa