- Quick specs
- Price: Free
- Operating system: Windows 2000
- Date added: November 06, 2000
- Total Downloads: 48,916
- Downloads last week: 10
- See full specifications
- Average user rating: stars out of 4 votes
See all user reviews
Publisher's description
From Microsoft :This patch eliminates a security vulnerability in Microsoft Windows 2000. The vulnerability could allow enable a malicious user to potentially run code on another user's machine.
An ActiveX control that ships as part of Windows 2000 contains an unchecked buffer. If the control was called from a Web page or HTML mail using a specially-malformed parameter, it would be possible to cause code to execute on the machine via a buffer overrun. This could potentially enable a malicious user to take any desired action on the user's machine, limited only by the permissions of the user.
The vulnerability could only be exploited if ActiveX controls are enabled in IE, Outlook, or Outlook Express. The Security Zones feature in Internet Explorer enables customers to limit what Web sites can do, and customers who have used the feature to prevent untrusted sites from invoking ActiveX controls would be at minimal risk from the Web-based attack scenario. Customers who have applied the Outlook Security Update would be protected against the mail-borne scenario, since it moves mail into the Restricted Sites Zone, thereby preventing HTML mails from invoking ActiveX controls.
See the ActiveX Parameter Validation Vulnerability FAQ for more information.
More popular Encryption Software downloads
- 43,858 downloads 1. RoboForm
- 29,802 downloads 2. Hotspot Shield
- 26,710 downloads 3. Computer Use Reporter
- 9,031 downloads 4. Easy File Encryption
- 8,103 downloads 5. Easy Private Disk
- See all Encryption Software downloads
User reviews
- Average user rating: 0 stars Not yet available
- My rating: 0 stars Write review
-
Showing 2 of 2 user reviewsSee all 2 user reviews
This software version | All versions -
Version: Windows 2000 ActiveX Parameter Validation Vulnerability Patch (MS00-085)
-
Version: Windows 2000 ActiveX Parameter Validation Vulnerability Patch (MS00-085)
Pros: n/a
Cons: n/a
- See all 2 user reviews Write review
Submit your review
- See more CNET content tagged:
- ActiveX Control,
- Microsoft Internet Explorer,
- Microsoft Outlook,
- Microsoft Windows 2000,
- malicious user


