Launch Printer Friendly Page Security TechCenter > Security Bulletins > Microsoft Security Bulletin MS03-015

Microsoft Security Bulletin MS03-015

Cumulative Patch for Internet Explorer (813489)

Originally posted: April 23, 2003

Summary

Who should read this bulletin: 
Customers using Microsoft® Internet Explorer.

Impact of vulnerability: 
Four new vulnerabilities, the most serious of which could enable an attacker to execute arbitrary code on a user's system if the user either browsed to a hostile web site or opened a specially crafted HTML email message.

Maximum Severity Rating: 
Critical

Recommendation: 
System administrators should install the patch immediately

Affected Software:

  • Microsoft Internet Explorer 5.01
  • Microsoft Internet Explorer 5.5
  • Microsoft Internet Explorer 6.0

General Information

Technical details

Frequently asked questions

Patch availability

Other information:

Acknowledgments

Microsoft thanks the following for working with us to protect customers:

Mark Litchfield of Next Generation Security Software Ltd. for reporting the PLUGIN.OCX issue to us.

Andreas Sandblad, Sweden for reporting the showhelp issue to us.

Jouko Pynnönen of Oy Online Solutions Ltd, Finland for reporting the URLMON.DLL Buffer Overrun issue to us.

Support:

Security Resources: The Microsoft TechNet Security Web Site provides additional information about security in Microsoft products.

Disclaimer:

The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions:

  • V1.0 April 23, 2003: Bulletin Created.
  • V1.1 May 1, 2003: Updated mitigating factors and Frequently Asked Questions to note that the URLMON.DLL buffer overrun vulnerability is not blocked from the HTML email vector by the Outlook Email Security Update or the default settings of Outlook 2002 and Outlook Express 6.0.