Windows 2000 Unchecked Buffer Help Security Vulnerability Patch for Windows Free Download

     
Tags
Internet Software  Video Software  System Utilities  Networking Software  Graphic Design Software  Disk & File Software  Educational & Science Software  CAD Software  Digital Photo Software  Database Management Software  Video Players  Business & Office Software  Wireless Networking Software  Developer Tools  Communication Software  3D Modeling Software  Games  Audio Software  Privacy Software & Access control  Security Software  Drivers 
Search by Category
Audio Software
Browsers
Business & Office Software
CD & DVD Software
Communication Software
Desktop Enhancements
Developer Tools
Digital Photo Software
Disk & File Software
Drivers
Educational & Science Software
Entertainment & Hobby Software
Games
Graphic Design Software
Home & Family Software
Internet Software
iTunes & iPod Software
Networking Software
Productivity Software
Screensavers
Security Software
System Utilities
Travel & Navigation Software
Video Software
Web Development Software
     




 
 
Windows 2000 Unchecked Buffer Help Security Vulnerability Patch

Windows 2000 Unchecked Buffer Help Security Vulnerability Patch
Version: MS02-055
Platforms: Windows

Categories: Security Software
Upload Date: 2 Nov 15
Developer: Microsoft
Distribution Type: Freeware
Downloads: 0
File Size: 876 Kb
Free Download Windows 2000 Unchecked Buffer Help Security Vulnerability Patch 

Rating: 1.0/5 (Total votes: 1)


 
The HTML Help facility in Windows includes an ActiveX control that provides much of its functionality. One of the functions exposed via the control contains an unchecked buffer, which could be exploited by a Web page hosted on an attacker?s site or sent to a user as an HTML mail. An attacker who successfully exploited the vulnerability would be able to run code in the security context of the user, thereby gaining the same privileges as the user on the system.

A second vulnerability exists because of flaws associated with the handling of compiled HTML Help files that contain shortcuts. Because shortcuts allow HTML Help files to take any desired action on the system, only trusted HTML Help files should be allowed to use them. Two flaws allow this restriction to be bypassed. First, the HTML Help facility incorrectly determines the Security Zone in the case where a Web page or HTML mail delivers a CHM file to the Temporary Internet Files folder and subsequently opens it. Instead of handling the CHM file in the correct zone--the one associated with the Web page or HTML mail that delivered it--the HTML Help facility incorrectly handles it in the Local Computer Zone, thereby considering it trusted and allowing it to use shortcuts. This error is compounded by the fact that the HTML Help facility doesn?t consider what folder the content resides in. Were it to do so, it could recover from the first flaw, as content within the Temporary Internet Folder is clearly not trusted, regardless of the Security Zone it renders in.

The attack scenario for this vulnerability would be complex, and involves using an HTML mail to deliver a CHM file that contains a shortcut, then making use of the flaws to open it and allow the shortcut to execute. The shortcut would be able to perform any action the user had privileges to perform on the system.

Requirements:

Windows 2000

 
Like it? Share with your friends!   
 

Other Windows Software of Developer «Microsoft»:

Office XP Service Pack 3 (SP3) for Access 2002 RuntimeOffice XP Service Pack 3 (SP3) for Access 2002 Runtime
Office XP Service Pack 3 (SP3) for Access 2002 Runtime provides the latest updates to the Access 2002 Runtime. This update contains significant security enhancements, as well as stability and performance improvements. This version is the first release on C
Outlook Live 2003 Service Pack 2 (SP2)Outlook Live 2003 Service Pack 2 (SP2)
Microsoft Office Outlook Live 2003 Service Pack 2 (SP2) provides the latest updates to Outlook Live 2003. Outlook Live 2003 Service Pack 2 contains significant security and feature enhancements, in addition to stability and performance improvements. You ca
Windows NT Multiple UNC Provider Vulnerability PatchWindows NT Multiple UNC Provider Vulnerability Patch
This update resolves the 'Unchecked buffer in the Multiple UNC Provider' security vulnerability in Windows NT 4.0 and is discussed in Microsoft Security Bulletin MS02-017. Download it now to prevent a malicious user from exploiting a buffer overflow vulner
Microsoft Dynamics CRM 2011 for Microsoft Office Outlook (32-bit)Microsoft Dynamics CRM 2011 for Microsoft Office Outlook (32-bit)
Microsoft Dynamics CRM 2011 for Microsoft Office Outlook (32-bit) enables access to the same data through Outlook as Microsoft Dynamics CRM.Requirements:Microsoft Office 2003, 2007, or 2010.
Security Update for Office 2000 (KB917152)Security Update for Office 2000 (KB917152)
A security vulnerability exists in Microsoft Office 2000 that could allow the elevation of rights. This update addresses that vulnerability. This version is the first release on CNET Download.com.What is new in this release:This version is the first releas
Telemetry Dashboard Administration ToolTelemetry Dashboard Administration Tool
Telemetry Dashboard Administration Tool is a command-line tool will help you to manage your Telemetry Dashboard database. The tool will perform tasks like archive the Telemetry Dashboard database, manage the size of the Telemetry Dashboard database, apply
Word 2003 Sample: Creating a Custom Spell Checker with Word 2003 and Visual Basic .NETWord 2003 Sample: Creating a Custom Spell Checker with Word 2003 and Visual Basic .NET
This sample file accompanies the MSDN article Creating a Custom Spell-Checker with Word 2003 and Visual Basic .NET which demonstrates using the Word object model in conjunction with Microsoft Visual Basic .NET to create a simple spell-checker whose functio
Windows NT Invalid RDP Data Vulnerability PatchWindows NT Invalid RDP Data Vulnerability Patch
This update eliminates the 'Invalid RDP Data can Cause Terminal Service Failure' vulnerability in computers running Windows 2000 and Windows NT4.0 Terminal Services Edition, and is discussed in Microsoft Security Bulletin MS01-052. Download now to prevent
Microsoft Golf 1999 Edition demoMicrosoft Golf 1999 Edition demo
Microsoft Golf 1999 lets you experience the ancient game of ball and club on your PC. Realistic graphics bring the golfing ambiance to life, from the motion of the swing to the design of the course. In fact, many holes were created by famous golf course
Mobile Internet Toolkit System.FormatException FixMobile Internet Toolkit System.FormatException Fix
The Microsoft Mobile Internet Toolkit English release, which can be installed on the Microsoft .NET Framework and Visual Studio .NET, contains an error that may cause an application with a calendar control to produce an exception. Download Mobile Internet

» show all

 
Similar Applications:

GOLock FolderGOLock Folder
GOLock Folder is a security software that can encrypt and provide a folder with a password. It is simple and easy to use and advisable to use home computers.
KoloSoft IntruderKoloSoft Intruder
From the developer: ""This highly-flexible program provides the PCs equivalent of the security camera. Each activity is logged with the date and time, keystrokes entered, what application was used along with the computer name and person who is logged on to
Ghost FileGhost File
This is novel software integrating encryption technology with decryption technology. The features of this software can be concluded as follow: Based on the encryption engine of Microsoft, the software with mandatory encryption technology can be applied to
FileMSBFileMSB
FileMSB is an encryption software on the windows platform, it can manage the password, (bulk) to encrypt / decrypt files, create self-extracting file, crushed paper, is a good helper for your office. FUNCTIONS:Password management, encryption, decryption,
Sophos Free EncryptionSophos Free Encryption
Protect your confidential files. Securely sending or storing data can be tricky if you don't have a robust security infrastructure. We make encryption easy for you with Sophos Free Encryption. This free tool lets you secure your data easily and quickly wit
Armor System 5Armor System 5
Armor System5 is a professional, easy-to-use encryption program for everyone who is serious about data security. The program includes three modules: File Encryption Module, Text Encryption Module (with built-in word processor), and E-mail Encryption Module
Snare for Lotus NotesSnare for Lotus Notes
Snare for Lotus Notes provides a remote distribution, and configuration checking tool for the Lotus Notes application, interfacing with the underlying Notes "log.nsf" file, and user/group and access control application programming interfaces. Snare for Not
Secret Data ManagerSecret Data Manager
Secret Data Manager is a tool for computer users to keep their private files in encrypted status. Secret Data Manager is simple and strong. You do not need extra training if you can use Windows. Its core feature is encryption and decryption and it supports
Invoptima ImagerInvoptima Imager
Invoptima Imager is a tool to encrypt various types of images easily. Users can simply select images and encrypt them into desire location. Once images are encrypted, they can only be decrypted with this software. Users can set passwords for encrypted ima
Portable Password ManagerPortable Password Manager
With Portable Password Manager you can setup a master password and multiple different passwords for you web accounts that you do not need to remember as you need to login to your accounts on the web. You have the option to use the quick launcher to rapidly
 

Supported Operating Systems:
Windows 2000 | 
 

Comments on Windows 2000 Unchecked Buffer Help Security Vulnerability Patch:

Comments not found

Name:


Comment:


Enter text from image below:

Turn on images!

 
 
 

Windows Software - Free Windows Downloads, Apps, Games, Freeware, Skype, Media Player, Antivirus, Gimp, Live, Starter for Windows XP, Vista, 7, 8, 10

© Pantich 2016 all rights reserved