Help and Support
 

powered byLive Search

Malicious Java Applet May Be Able to Read, Write, or Delete Files on the Computer of a Web Site Visitor

Article ID:240346
Last Review:January 25, 2007
Revision:4.2
This article was previously published under Q240346

SYMPTOMS

A scenario has been identified through which a Java applet can operate outside the bounds set by the sandbox and perform normally unauthorized functions on your computer. Exploiting the vulnerability is only possible through a very carefully managed series of steps, and cannot happen accidentally. However, if a malicious Web site operator hosts a Java applet that exploits this security vulnerability, it could read, write, or delete files on your computer when you visit the site.

Back to the top

RESOLUTION

A supported fix that corrects this problem has been posted to the following Internet location:
http://www.microsoft.com/mscorp/java (http://www.microsoft.com/mscorp/java/)

Back to the top

STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article. This problem has been corrected in build 3234 of the Microsoft Virtual Machine (VM) that is included with Internet Explorer version 5.01.

NOTE: JVIEW in Windows 2000 displays the build number as 3229.

Back to the top

MORE INFORMATION

For more information, please see the following Microsoft Security Bulletin:
http://www.microsoft.com/security/bulletins/ms99-031faq.asp (http://www.microsoft.com/security/bulletins/ms99-031faq.asp)
For additional security-related information about Microsoft products, please go to:
http://www.microsoft.com/security/ (http://www.microsoft.com/security/)

Back to the top


APPLIES TO
Microsoft Internet Explorer 5.0
Microsoft Internet Explorer 4.01 Service Pack 1
Microsoft Internet Explorer 4.01 Service Pack 2
Microsoft Internet Explorer 4.0 128-Bit Edition
Microsoft Windows 98 Second Edition

Back to the top

Keywords: 
kbbug kbfix KB240346

Back to the top

Article Translations

 

Other Support Options

  • Need More Help?
    Contact a Support professional by Email, Online or Phone.
  • Customer Service
    For non-technical assistance with product purchases, subscriptions, online services, events, training courses, corporate sales, piracy issues, and more.
  • Newsgroups
    Pose a question to other users. Discussion groups and Forums about specific Microsoft products, technologies, and services.