The information in this article applies to:
SYMPTOMSTaskpads is a feature that allows users to view and run Windows management tools through an HTML page rather than the Windows control. A vulnerability has been discovered in Taskpads that lets Web sites invoke executables on a user's workstation. CAUSEThis vulnerability results because certain methods provided by Taskpads are incorrectly marked as "safe for scripting." RESOLUTION
A patch is available for this issue that removes the Taskpads functionality, which is rarely used. http://support.microsoft.com/support/supportnet/default.asp Windows 98 Resource Kit and Windows 98 Resource Kit SamplerThis patch has been posted to the following Internet location:ftp://ftp.microsoft.com/reskit/win98/taskpads/ BackOffice Resource Kit, Second EditionThis patch has been posted to the following Internet locations:x86: Alpha: STATUSMicrosoft has confirmed this problem could result in some degree of security vulnerability in Taskpads included with the Windows 98 Resource Kit, the Windows 98 Resource Kit Sampler, and the BackOffice Resource Kit, second edition. MORE INFORMATIONTaskpads is included with:
Additional query words: 4.00 98 95 rkit reskit ms99-007 Patch Available for TaskPad Scripting Vulnerability
Keywords : |
Last Reviewed: November 9, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |