The information in this article applies to:
SYMPTOMS
Microsoft has made an update available that addresses a potential security issue in which an HTTP redirect to a javascript:url can be used to compromise security. This issue could allow a malicious Web site operator to read files on the local computer, although the intruder would have to know the name and location of the file. The vulnerability does not allow the malicious user to list the contents of folders, create, modify or delete files.
RESOLUTIONTo obtain this update, download and install the appropriate Q244357.exe file for your computer from the following Microsoft site:
Note that if you try to install this update on any version of Internet Explorer other than Internet Explorer 5, you receive a message that says "This update does not need to be installed on this system" when in fact the computer may be vulnerable. For additional information about Internet Explorer 4.01, click the article number below to view the article in the Microsoft Knowledge Base: Q244356 Update for "Javascript Redirect" Vulnerability in Internet Explorer 4.01 STATUSThis issue is fixed in Internet Explorer 5.01. Additional query words:
Keywords : kbtool msiew95 msient msiew98 |
Last Reviewed: November 19, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |