MS03-008: Flaw in Windows Script Engine may allow code to run
On This PageSYMPTOMSAn attacker may exploit a vulnerability in Windows Script
Engine by constructing a Web page that, when visited by a user, runs code of
the attacker’s choice with user credentials. The attacker can host the Web page
on a Web site or send the page directly to the user by e-mail. CAUSEThis problem occurs because of a flaw in the way that
Windows Script Engine for JScript processes information. RESOLUTIONWindows XP service pack informationTo resolve this problem, obtain the latest service pack for Windows XP. For more information, click the following article number to view the article in the Microsoft Knowledge Base:322389 (http://support.microsoft.com/kb/322389/) How to obtain the latest Windows XP service pack
Update informationTo resolve this problem, you can install an update. You must install the update that corresponds to the version of operating system that you are running, and to the version of JScript that you currently have installed. To determine the version of JScript that is installed, follow these steps:
The following files are available for download from the Microsoft Download Center: Windows XP and Windows 2000 Download the 814078 package now (http://microsoft.com/downloads/details.aspx?FamilyId=824B1BD4-B4D6-49D5-8C58-199BDC731B64&displaylang=en)Windows NT 4.0 and Windows NT 4.0, Terminal Server Edition Download the 814078 package now (http://microsoft.com/downloads/details.aspx?FamilyId=C6504FD9-5E2C-45BF-9424-55D7C5D2221B&displaylang=en)Windows Millennium Edition Download the 814078 package now (http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=c6504fd9-5e2c-45bf-9424-55d7c5d2221b)Windows 98 Second Edition and Windows 98 Download the 814078 package now (http://www.microsoft.com/downloads/details.aspx?FamilyID=6c2afd66-05ea-487b-88ea-5d8fba958a57&DisplayLang=en)For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591 (http://support.microsoft.com/kb/119591/EN-US/) How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
Prerequisites
322389 (http://support.microsoft.com/kb/322389/)
How to obtain the latest Windows XP service pack
For more information about how to obtain the latest Windows 2000
service pack, click the following article number to view the article in the Microsoft Knowledge Base:
260910 (http://support.microsoft.com/kb/260910/)
How to obtain the latest Windows 2000 service pack
For more information about how to obtain the latest Windows NT 4.0 service pack, click the following article number to view the article in the Microsoft Knowledge Base: 152734 (http://support.microsoft.com/kb/152734/)
How to obtain the latest Windows NT 4.0 service pack
Installation informationThis update supports the following Setup switches.
js56nen /q /r:n To install the update with very little user intervention and silently restart without prompting the user: js56nen /q /r:s Note The updated file will not be completely installed. Therefore, the security hole will still exist until the computer has been restarted.
For more information about command line switches, click the following article number to view the article in the Microsoft Knowledge Base:
197147 (http://support.microsoft.com/kb/197147/)
Command-line switches for IExpress software update packages
Removal informationJScript is a system file and protected component and therefore cannot be removed.Restart requirementYou must restart your computer after you apply this update.Hotfix replacement informationThis update does not replace any other updates.File informationThe English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.Depending on the version of JScript installed (5.1, 5.5 or 5.6), one of the following files will be present in the %WINDIR%\System32 folder. Date Time Version Size File name ----------------------------------------------------- 13-Jan-2003 20:57 5.6.0.8513 589,881 Jscript.dll 13-Jan-2003 18:53 5.5.0.8513 553,020 Jscript.dll 14-Jan-2003 14:58 5.1.0.8513 487,481 Jscript.dll STATUS
Microsoft has confirmed that this problem may cause a degree of security vulnerability in the Microsoft products that are listed in the "Applies to" section.
Windows XPThis problem was first corrected in Microsoft Windows XP Service Pack 2.MORE INFORMATION For more information about this vulnerability, visit the
following Microsoft Web site: http://www.microsoft.com/technet/security/bulletin/MS03-008.mspx (http://www.microsoft.com/technet/security/bulletin/MS03-008.mspx) For more information about JScript, visit the following Microsoft
Web site:http://msdn.microsoft.com/library/default.asp?url=/library/en-us/script56/html/0441e1e5-34e4-4d32-b188-f7fc35613478.asp (http://msdn.microsoft.com/library/default.asp?url=/library/en-us/script56/html/0441e1e5-34e4-4d32-b188-f7fc35613478.asp) APPLIES TO
| Article Translations
|
Back to the top
