Join or Sign In

Sign in to add and modify your software

Continue with email

By joining Download.com, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy.

Windows 2000 ActiveX Parameter Validation Vulnerability Patch

By Microsoft Free

Download.com has removed the direct-download link and offers this page for informational purposes only.

Download.com has chosen not to provide a direct-download link for this product and offers this page for informational purposes only.

Developer's Description

This patch eliminates a security vulnerability in Microsoft Windows 2000. The vulnerability could allow enable a malicious user to potentially run code on another user's machine.

An ActiveX control that ships as part of Windows 2000 contains an unchecked buffer. If the control was called from a Web page or HTML mail using a specially-malformed parameter, it would be possible to cause code to execute on the machine via a buffer overrun. This could potentially enable a malicious user to take any desired action on the user's machine, limited only by the permissions of the user.

The vulnerability could only be exploited if ActiveX controls are enabled in IE, Outlook, or Outlook Express. The Security Zones feature in Internet Explorer enables customers to limit what Web sites can do, and customers who have used the feature to prevent untrusted sites from invoking ActiveX controls would be at minimal risk from the Web-based attack scenario. Customers who have applied the Outlook Security Update would be protected against the mail-borne scenario, since it moves mail into the Restricted Sites Zone, thereby preventing HTML mails from invoking ActiveX controls.

See the ActiveX Parameter Validation Vulnerability FAQ for more information.

Full Specifications

What's new in version (MS00-085)


Release December 5, 2008
Date Added November 7, 2000
Version (MS00-085)

Operating Systems

Operating Systems Windows, Windows 2000
Additional Requirements None


Total Downloads 54,603
Downloads Last Week 0
Report Software

Related Software

Vpn One Click

Free to try
Vpn One Click

Protected Folder

Free to try
Protected Folder

Random Password Generator

Random Password Generator



User Reviews

4 User Votes
5 Star
4 Star
3 Star
2 Star
1 Star