VM File Reading Vulnerability
The Microsoft virtual machine (Microsoft VM) includes a security vulnerability that could enable a malicious Web site operator to access the files on a user's computer and, if the user is part of an intranet, to read Web content within that intranet.
Issue
The Microsoft VM allows archive files (CAB or JAR files) that are used in a Java-based <OBJECT> tag and referenced by the CABBASE, CABINETS, or ARCHIVE parameters to come from locations other than the codebase.
Affected Products
- Microsoft VM 2000 & 3000 series
Download
Patch: http://www.microsoft.com/java/vm/dl_vm40.htm
Further Details
Source: Microsoft Corporation
Reference: Microsoft Corporation
Updated: October 31, 2000
>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<
















