FREE Registration is required
Overview:
A security vulnerability exists in the Microsoft Local Troubleshooter ActiveX control. The vulnerability exists because the ActiveX control (Tshoot.ocx) contains a buffer overflow that could allow an attacker to run code of their choice on a users system. Because this control is marked "safe for scripting", an attacker could exploit this vulnerability by convincing a user to view a specially crafted HTML page that references this ActiveX control. The Microsoft Local Troubleshooter ActiveX control is installed as a default part of the operating system on Windows 2000. To exploit this vulnerability, the attacker would have to create a specially formed HTMLbased e-mail and send it to the user. Alternatively an attacker would have to host a malicious Web site that contained a Web page designed to exploit this vulnerability. In the worst case, this vulnerability could allow an attacker to load malicious code onto a user's system and then to execute the code. The code would run in the context of the user. Therefore, the code is limited to any action that the legitimate user could take on the system. Any limitations on the user's account would also limit the actions of any arbitrary code that the attacker could execute. The risk of attack from the HTML email vector can be significantly reduced if the following conditions are met: You have applied the patch included with Microsoft Security bulletin MS03-040 You are using Internet Explorer 6 or later You are using the Microsoft Outlook Email Security Update or Microsoft Outlook Express 6.0 and higher, or Microsoft Outlook 2000 or higher in their default configuration.
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Software | ||
| Date: | Oct 2003 | Version: | 826232 |
| License: | Update | Price: | $1.00 |
| Platform: | Windows | ||
| System Req: | Windows 2000 SP 2, 3, 4 |
Top results from Programming Software
![]() |
Guiffy 9.0 Build 270 (Mac) |
![]() |
AG Author 1.2 (Mac) |
![]() |
Apple Carbon Dater 1.3 (Mac) |
![]() |
Apple Game Sprockets SDK 1.7.3 (Mac) |
![]() |
Apple Help 1.2 SDK 1.0 (Mac) |
White Papers, Webcasts, and Resources
- Enterprise and Web 2.0 application support in a modern mainframe environment IBMSee how IBM WebSphere Portal software can help you develop a Web presence based on individual needs while unlocking value for customers and employees.
- Windows Phones and Unified Communications MicrosoftGain a more solid understanding of UC, why its essential for your business today, and what makes Windows phones ideal for secure UC environments.
- Building Reliable IP Telephony Systems ShoreTelDownload this white paper for a comprehensive look at IP telephony systems, including issues related to availability and considerations for selecting a VoIP system. (ShoreTel)
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Keep Up With The Latest In Document Management with The DocuMentor.
-
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
- Learn more >>
- Windows Server 2008 R2 Optimizes IT
-
See how you can optimize your IT department and save money, using Windows Server 2008 R2.

- Click to download >>
- New Online Dashboard for IT Leaders
-
Read about top issues IT decision-makers face every day, plus get cost-effective solutions to real-life IT problems.
- Learn more >>
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- How to Drive Better Business Outcomes with Exceptional Web Experiences Download the eBook
- Driving Business Agility through SOA Connectivity & Integration Read the White Paper from IBM
- Linking Decisions and Information for Organizational Performance Read the Tom Davenport study









