Article ID: 322924 - Last Review: February 1, 2007 - Revision: 4.12 MS02-023: Patch Available for Local Information Disclosure Through HTML Element VulnerabilityThis article was previously published under Q322924 On This PageSYMPTOMS
An information-disclosure vulnerability exists in Internet Explorer. An attacker who successfully exploits this vulnerability can view files on the user's local computer. An attacker can try to exploit this vulnerability by building a Web page that contains a specific object. In constructing the page, the attacker must specify the name and location of the file to read. The attacker can then either send the page as an HTML e-mail message, or post it on a Web site. When the user views the Web page, either by opening the mail or by viewing it in a browser, the page can exploit the vulnerability. This vulnerability is subject to a number of significant mitigating factors:
CAUSE
This vulnerability occurs because of incorrect handling when a particular HTML object calls a file on the local computer.
RESOLUTIONInternet Explorer 6To resolve this problem, obtain the latest service pack for Internet Explorer 6. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:328548
(http://support.microsoft.com/kb/328548/EN-US/
)
How to Obtain the Latest Internet Explorer 6 Service Pack
The update for this problem is included in the "May 15, 2002, Cumulative Patch for Internet Explorer." For additional information about how to obtain this patch, click the article number below
to view the article in the Microsoft Knowledge Base:
321232
(http://support.microsoft.com/kb/321232/EN-US/
)
MS02-023: May 15, 2002, Cumulative Patch for Internet Explorer
Internet Explorer 5.5 Service Pack 2The update for this problem is included in the "May 15, 2002, Cumulative Patch for Internet Explorer." For additional information about how to obtain this patch, click the article number below to view the article in the Microsoft Knowledge Base:321232
(http://support.microsoft.com/kb/321232/EN-US/
)
MS02-023: May 15, 2002, Cumulative Patch for Internet Explorer
Internet Explorer 5.5 Service Pack 1The update for this problem is included in the "May 15, 2002, Cumulative Patch for Internet Explorer." For additional information about how to obtain this patch, click the article number below to view the article in the Microsoft Knowledge Base:321232
(http://support.microsoft.com/kb/321232/EN-US/
)
MS02-023: May 15, 2002, Cumulative Patch for Internet Explorer
Internet Explorer 5.01 Service Pack 2 (on Microsoft Windows 2000 and Microsoft Windows NT 4.0 only)This update is only for customers running Internet Explorer 5.01 Service Pack 2 (http://support.microsoft.com/kb/267954) on Windows 2000 Service Pack 2 (http://support.microsoft.com/kb/260910) or Windows NT 4.0 Service Pack 6a (http://support.microsoft.com/kb/152734) . If you are running Internet Explorer 5.01 on any other version of Windows, upgrade to Internet Explorer 5.5 Service Pack 2 (http://support.microsoft.com/kb/276369) or later (http://www.microsoft.com/windows/ie) , and then apply this update.The update for this problem is included in the "May 15, 2002, Cumulative Patch for Internet Explorer." For additional information about how to obtain this patch, click the article number below to view the article in the Microsoft Knowledge Base: 321232
(http://support.microsoft.com/kb/321232/EN-US/
)
MS02-023: May 15, 2002, Cumulative Patch for Internet Explorer
STATUSInternet Explorer 6Microsoft has confirmed that this problem may cause a degree of security vulnerability in Microsoft Internet Explorer 6. This problem was first corrected in Internet Explorer 6 Service Pack 1.Internet Explorer 5.5Microsoft has confirmed that this problem may cause a degree of security vulnerability in Microsoft Internet Explorer 5.5.Internet Explorer 5.01Microsoft has confirmed that this problem may cause a degree of security vulnerability in Microsoft Internet Explorer 5.01.MORE INFORMATION
For more information about this vulnerability, visit the following Microsoft Web site:
http://www.microsoft.com/technet/security/bulletin/MS02-023.mspx
(http://www.microsoft.com/technet/security/bulletin/MS02-023.mspx)
APPLIES TO
| Article Translations
|
Back to the top
