OFF97: Forms 2.0 (Fm20*.dll) ActiveX Control Security Fix

ID: Q214757


The information in this article applies to:
  • Microsoft Office 97 for Windows


SUMMARY

This article contains information about how to download and install the Forms 2.0 ActiveX Control security fix.


MORE INFORMATION

Why Is a Security Fix Needed?

Microsoft has determined that a security vulnerability may occur when the Forms 2.0 Control (Fm20*.dll) is available on your system. Forms 2.0 is an ActiveX component that allows text to be pasted from your Clipboard into a TextBox or ComboBox. This control is installed as a part of any of the programs listed later in this article. A malicious hacker could cause the Forms 2.0 Control to read or export text from your clipboard when you visit a Web site set up by the malicious hacker, or open an HTML e-mail created by the malicious hacker.

To prevent others from being able to view the contents of your clipboard, Microsoft has updated two ActiveX control files: Fm20.dll and Fm20enu.dll. These files are included in a downloadable security patch called Fm2paste.exe. This patch prevents a hacker from exploiting the vulnerability described earlier. If you install the patch, you will not lose any functionality and you will still have the ability to paste content from the Clipboard to a Web page or other document.

Developers who have built solutions using the Forms 2.0 Control should rely on native controls for pasting to TextBoxes and ComboBoxes.

Who Should Download and Install the Security Fix?

You should download the security fix if you have any of the following programs installed on your computer:
  • Microsoft Excel 97


  • Microsoft Word 97


  • Microsoft Access 97


  • Microsoft PowerPoint 97


  • Microsoft Outlook 97 or Microsoft Outlook 98


  • Microsoft Project 98


  • Any program that includes Microsoft Visual Basic for Applications (VBA) 5.0
Note that you can safely download and install the security fix even if you do not have any of these programs installed on your computer, or if you are not sure if they are installed.
To determine whether you need to download and install the security fix, right-click the Fm20.dll file in your Windows\System folder and click Properties on the shortcut menu. If the file date of your Fm20.dll file is earlier than January 11, 1999 (1/11/1999), you should download and install the security fix.

How Do I Download and Install the Security Fix?

To download the security fix, use your Web browser to go to the following Web site:
http://officeupdate.microsoft.com/downloaddetails/fm2paste.htm
Click "Download Now!", and save the executable file to a folder on your computer's hard disk.

To install the security fix, close all running programs, and then simply double-click the Fm2paste.exe file. After the new files are installed, you can run your programs as before.

Note that the security fix will install correctly whether you are using base level Microsoft Office 97, Microsoft Office 97 Service Release 1 (SR-1), or Microsoft Office 97 Service Release 2 (SR-2).

Additional query words: OFF97 XL97 WD97 AC97 PP97 OL97 OL98

Keywords : kbdta
Version : WINDOWS:97
Platform : WINDOWS
Issue type : kbbug


Last Reviewed: May 25, 1999
© 2000 Microsoft Corporation. All rights reserved. Terms of Use.