X

Join or Sign In

Sign in to add and modify your software

Continue with email

By joining Download.com, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy.

Microsoft XML 3.0 Core Services Vulnerability Patch

By Microsoft Free

Download.com has removed the direct-download link and offers this page for informational purposes only.

Download.com has chosen not to provide a direct-download link for this product and offers this page for informational purposes only.

Developer's Description

Microsoft XML Core Services (MSXML) includes the XMLHTTP ActiveX control, which allows web pages rendering in the browser to send or receive XML data via HTTP operations such as POST, GET, and PUT. The control provides security measures designed to restrict web pages so they can only use the control to request data from remote data sources.

A flaw exists in how the XMLHTTP control applies IE security zone settings to a redirected data stream returned in response to a request for data from a web site. A vulnerability results because an attacker could seek to exploit this flaw and specify a data source that is on the user's local system. The attacker could then use this to return information from the local system to the attacker's web site. An attacker would have to entice the user to a site under his control to exploit this vulnerability. It cannot be exploited by HTML email. In addition, the attacker would have to know the full path and file name of any file he would attempt to read. Finally, this vulnerability does not give an attacker any ability to add, change or delete data.

Full Specifications

What's new in version MS02-008

General

Release December 5, 2008
Date Added March 1, 2002
Version MS02-008

Operating Systems

Operating Systems Windows, Windows NT, Windows 2000
Additional Requirements Windows NT/2000

Popularity

Total Downloads 62,629
Downloads Last Week 0
Report Software

Related Software

AVG Antivirus Business Edition

Free to try
AVG Antivirus Business Edition

Pulse Secure for Windows 10

Free
Pulse Secure for Windows 10

Metasploit

Free
Metasploit

Trusteer Rapport

Purchase
Trusteer Rapport

User Reviews

3.2/5
9 User Votes
5 Star
4 Star
3 Star
2 Star
1 Star