PC Tools - Essential tools for your PC
Search
 
 
Features
 
 
Newsletter
 
Security Home > Internet Explorer > Java Software

Flaw in Microsoft Virtual Machine New

A flaw exists in the Microsoft Virtual Machine (VM) which could allow attacker to execute code of their choice on the local machine by creating a malicious Java applet and inserting it into a web page or e-mail.

Issue

The Microsoft VM is a virtual machine for the Win32® operating environment. The Microsoft VM is shipped in most versions of Windows (a complete list is available in the FAQ), as well as in most versions of Internet Explorer.

The present Microsoft VM, which includes all previously released fixes to the VM, has been updated to include a fix for the newly reported security vulnerability. This new security vulnerability affects the ByteCode Verifier component of the Microsoft VM, and results because the ByteCode verifier does not correctly check for the presence of certain malicious code when a Java applet is being loaded. The attack vector for this new security issue would likely involve an attacker creating a malicious Java applet and inserting it into a web page that when opened, would exploit the vulnerability. An attacker could then host this malicious web page on a web site, or could send it to a user in e-mail.

Affected Products

  • Microsoft Virtual Machine (Microsoft VM) before build 3810

Download

Patch: http://windowsupdate.microsoft.com/

Further Details

Source: Microsoft Corporation

Reference: Microsoft Corporation

Updated: April 14, 2003

>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<

 
  Copyright © 1998-2008 PC Tools. All rights Reserved. Privacy Policy | Legal Notice