- Quick specs
- Price: Free
- Operating system:
- Date added: December 19, 2002
- Total Downloads: 13,126
- Downloads last week: 1
- See full specifications
- Average user rating: stars out of 1 votes
See all user reviews
Publisher's description
From Microsoft :The Windows Shell is responsible for providing the basic framework of the Windows user interface experience. It is most familiar to users as the Windows Desktop, but also provides a variety of other functions to help define the user's computing session, including organizing files and folders, and providing the means to start applications.
An unchecked buffer exists in one of the functions used by the Windows Shell to extract custom attribute information from audio files. A security vulnerability results because it is possible for a malicious user to mount a buffer overrun attack and attempt to exploit this flaw.
An attacker could seek to exploit this vulnerability by creating an MP3 or a WMA file that contains a corrupt custom attribute and then host it on a Web site or on a network share, or send it via an HTML e-mail. If a user were to hover his or her mouse pointer over the icon for the file (either on a Web page or on the local disk), or open the shared folder where the file is stored, the vulnerable code would be invoked. An HTML e-mail could cause the vulnerable code to be invoked when a user opens or previews the e-mail. A successful attack could have the effect of either causing the Windows Shell to fail, or causing an attacker's code to run on the user's computer in the security context of the user.
For more information about the vulnerabilities this update addresses, read the associated Microsoft Security Bulletin.
CNET Editor's Note: This patch is for the Windows XP 32-bit edition.
More popular Encryption Software downloads
- 33,082 downloads 1. Hotspot Shield
- 8,526 downloads 2. RoboForm
- 6,764 downloads 3. Folder Lock
- 4,106 downloads 4. RAR Password Cracker
- 3,149 downloads 5. Eraser
- See all Encryption Software downloads
User reviews
- Average user rating: 0 stars Not yet available
- My rating: 0 stars Write review
-
Showing 1 of 1 user reviewSee 1 user review
This software version | All versions -
Version: Microsoft Windows XP (32-bit) Unchecked Buffer Vulnerability Patch MS02-072
Cons: Im sick and tired of YAHOO and their sneaky installation techniques.
- See 1 user review Write review
Submit your review
- See more CNET content tagged:
- HTML,
- Microsoft Corp.,
- Microsoft Windows,
- code,
- security


