Help and Support

FIX: Security Issue Allows Access to Files on User's Computer

Article ID:277014
Last Review:June 14, 2006
Revision:4.0
This article was previously published under Q277014

SYMPTOMS

The Microsoft virtual machine (Microsoft VM) includes a security vulnerability that could enable a malicious Web site operator to access the files on a user's computer and, if the user is part of an intranet, to read Web content within that intranet.

This affects the following builds of the Microsoft VM:
All builds in the 3000 series.

Back to the top

CAUSE

The Microsoft VM allows archive files (CAB or JAR files) that are used in a Java-based <OBJECT> tag and referenced by the CABBASE, CABINETS, or ARCHIVE parameters to come from locations other than the codebase.

Back to the top

RESOLUTION

To resolve this problem, install build 3319 or later of the Microsoft VM. For more information, visit the following Microsoft Web site:
http://www.microsoft.com/mscorp/java/ (http://www.microsoft.com/mscorp/java/)
WARNING: After you install the updated Microsoft VM, you cannot uninstall it.
2000-series builds are no longer supported
Customers should upgrade to the latest 3000-series build.
3000-series Microsoft VM customers
Customers should upgrade to build 3319 or later.

Back to the top

STATUS

Microsoft has confirmed that this is a bug in the Microsoft products that are listed at the beginning of this article.

This bug was corrected in the Microsoft VM build 3319.

Back to the top

REFERENCES

For more information, please see Microsoft Security Bulletin MS00-081 at the following Microsoft Web site:
http://www.microsoft.com/technet/security/bulletin/MS00-081.mspx (http://www.microsoft.com/technet/security/bulletin/MS00-081.mspx)
For additional security-related information about Microsoft products, please refer to the following Microsoft Web site:
http://www.microsoft.com/technet/security/ (http://www.microsoft.com/technet/security/)
For support information about Visual J++ and the SDK for Java, visit the following Microsoft Web site:
http://www.microsoft.com/java (http://www.microsoft.com/java)

Back to the top


APPLIES TO
Microsoft Java Virtual Machine

Back to the top

Keywords: 
kbbug kbfix kbjava kbjavavm33xxfix kbsechack kbsecurity kbsecvulnerability KB277014

Back to the top

Article Translations

 

Other Support Options

  • Contact Microsoft
    Phone Numbers, Support Options and Pricing, Online Help, and more.
  • Customer Service
    For non-technical assistance with product purchases, subscriptions, online services, events, training courses, corporate sales, piracy issues, and more.
  • Newsgroups
    Pose a question to other users. Discussion groups and Forums about specific Microsoft products, technologies, and services.