Microsoft Security Advisory 903144
A COM Object (Javaprxy.dll) Could Cause Internet Explorer to Unexpectedly Exit
Published: June 30, 2005 | Updated: July 12, 2005
Microsoft has completed the investigation into a public report of a vulnerability affecting Internet Explorer. We have issued a security bulletin to address this issue. For more information about this issue, including download links for an available security update, please review the security bulletin.
Purpose of Advisory: To provide customers with initial notification of the publicly disclosed vulnerability and the availability of security bulletin.
Advisory Status: Investigation Complete. A security bulletin has been issued.
Recommendation: Please review the released security bulletin and install the available security update.
This advisory applies to the following software.
|Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4|
|Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, or on Microsoft Windows XP Service Pack 1|
|Internet Explorer 6 for Microsoft Windows XP Service Pack 2|
|Internet Explorer 6 Service Pack 1 for Microsoft Windows XP 64-Bit Edition Service Pack 1 (Itanium)|
|Internet Explorer 6 for Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1|
|Internet Explorer 6 for Microsoft Windows Server 2003 for Itanium-based Systems, Microsoft Windows Server 2003 with SP1 for Itanium-based Systems, Microsoft Windows XP 64-Bit Edition Version 2003 (Itanium), Microsoft Windows Server 2003 x64 Edition, and Microsoft Windows XP Professional x64 Edition|
|Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Millennium Edition|
|Internet Explorer 6 Service Pack 1 on Microsoft Windows 98, on Microsoft Windows 98 SE, or on Microsoft Windows Millennium Edition|
- Please review the released security bulletin and install the available security update.
- Customers who believe they may have been affected can contact Product Support Services. You can contact Product Support Services in the United States and Canada for help with security update issues or viruses at no charge using the PC Safety line (1 866-PCSAFETY). Customers outside of the United States and Canada can locate the number for no-charge virus support by visiting the Microsoft Help and Support Web site.
All customers should apply the most recent security updates released by Microsoft to help ensure that their systems are protected from attempted exploitation. Customers who have enabled automatic updates will automatically receive all Windows Updates. For more information about security updates, visit http://www.microsoft.com/security/
- We continue to encourage customers follow our Protect Your PC guidance of enabling a firewall, getting software updates and installing antivirus software. Customers can learn more about these steps at Protect Your PC Web site.
- For more information about staying safe on the Internet, customers can visit theMicrosoft Security Home Page.
- You can provide feedback by completing the form at the following Web site.
- Customers in the U.S. and Canada can receive technical support from Microsoft Product Support Services. For more information about available support options, see the Microsoft Help and Support Web site.
- International customers can receive support from their local Microsoft subsidiaries. For more information about how to contact Microsoft for international support issues, visit the International Support Web site.
- The Microsoft TechNet Security Web site provides additional information about security in Microsoft products.
The information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.
- June 30, 2005: Advisory published
- July 1, 2005: Advisory updated with additional mitigations and workarounds
- July 5, 2005: Advisory updated with Microsoft Download Center information for the registry key update that disables Javaprxy.dll in Internet Explorer
- July 12, 2005: Advisory updated to direct customers to Security Bulletin MS05-037, “Vulnerability in JView Profiler Could Allow Remote Code Execution”.
Built at 2014-04-18T13:49:36Z-07:00