Microsoft IE Legacy ActiveX Control Vulnerability
BID:285
Info
Microsoft IE Legacy ActiveX Control Vulnerability
| Bugtraq ID: | 285 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 1999 12:00AM |
| Updated: | May 27 1999 12:00AM |
| Credit: | This vulnerability was reported to Microsoft by Steve Loughran. |
| Vulnerable: |
Microsoft Internet Explorer 5.0 for Windows NT 4 Microsoft Internet Explorer 5.0 for Windows 98 Microsoft Internet Explorer 5.0 for Windows 95 Microsoft Internet Explorer 4.0 for Windows NT 4 Microsoft Internet Explorer 4.0 for Windows NT 3 Microsoft Internet Explorer 4.0 for Windows 95 Microsoft Internet Explorer 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft IE Legacy ActiveX Control Vulnerability
A vulnerability in a legacy ActiveX control shipped with Internet Explorer 4 and Internet Explorer 5 allows malicious web sites to steal local files. The ActiveX control was used by previous version of IE and it was shipped with IE4 and IE5 but it is used by neither.
A vulnerability in a legacy ActiveX control shipped with Internet Explorer 4 and Internet Explorer 5 allows malicious web sites to steal local files. The ActiveX control was used by previous version of IE and it was shipped with IE4 and IE5 but it is used by neither.
Exploit / POC
Microsoft IE Legacy ActiveX Control Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft IE Legacy ActiveX Control Vulnerability
Solution:
Apply the Microsoft patch available at:
http://www.microsoft.com/windows/ie/security/favorites.asp
Solution:
Apply the Microsoft patch available at:
http://www.microsoft.com/windows/ie/security/favorites.asp
References
Microsoft IE Legacy ActiveX Control Vulnerability
References:
References: