Information Disclosure Vulnerability in Microsoft Virtual Machine
A vulnerability exists in Microsoft Virtual Machine build 3802 and earlier that can result in disclosing unauthorized information.
March 5, 2002
Reported March 4, 2002, byMicrosoft.
VERSIONS AFFECTED
Microsoft Virtual Machine
DESCRIPTION
A vulnerability exists in Microsoft Virtual Machine build 3802 and earlier thatcan result in disclosing unauthorized information. Asa result of a problem in the Virtual Machine, an attacker can use a maliciousJava applet to redirect Web traffic, once the java applet has a proxy server, toa destination of the attacker’s choice. An intruder can use this vulnerabilityto send an authorized user’s Internet session to a system of the intruder'sown control without the user’s knowledge.
VENDOR RESPONSE
Thevendor, Microsoft, has released SecurityBulletin MS02-013,which addresses this vulnerability, and recommends that affected usersimmediately upgrade to build3805 or later.
CREDIT
Discovered by Harmenvan der Wal.
Read more about:
MicrosoftAbout the Author
You May Also Like