Information Disclosure Vulnerability in Microsoft Virtual Machine

A vulnerability exists in Microsoft Virtual Machine build 3802 and earlier that can result in disclosing unauthorized information.

Ken Pfeil

March 5, 2002

1 Min Read
ITPro Today logo

Reported March 4, 2002, byMicrosoft.

VERSIONS AFFECTED

  • Microsoft Virtual Machine

DESCRIPTION
A vulnerability exists in Microsoft Virtual Machine build 3802 and earlier thatcan result in disclosing unauthorized information. Asa result of a problem in the Virtual Machine, an attacker can use a maliciousJava applet to redirect Web traffic, once the java applet has a proxy server, toa destination of the attacker’s choice. An intruder can use this vulnerabilityto send an authorized user’s Internet session to a system of the intruder'sown control without the user’s knowledge.

VENDOR RESPONSE

Thevendor, Microsoft, has released SecurityBulletin MS02-013,which addresses this vulnerability, and recommends that affected usersimmediately upgrade to build3805 or later.

CREDIT
Discovered by Harmenvan der Wal.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like