Security Advisory
Microsoft Security Advisory 906267
Published: August 18, 2005 | Updated: February 21, 2006
Microsoft has completed the investigation into a public report of a vulnerability affecting Internet Explorer. We have issued a security bulletin to address this issue. For more information about this issue, including download links for an available security update, please review the security bulletin.
Purpose of Advisory: To provide customers with initial notification of the publicly disclosed vulnerability and the availability of security bulletin.
Advisory Status: Investigation Complete. A security bulletin has been issued.
Recommendation: Please review the released security bulletin and install the available security update.
References | Identification |
---|---|
Security Bulletin | MS05-052 |
CERT Reference | VU#740372 |
CVE Reference | CAN-2005-2127 |
Microsoft Knowledge Base Article | 906267 |
This advisory discusses the following software.
Related Software |
Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4 |
Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 or on Microsoft Windows XP Service Pack 1 |
Internet Explorer 6 for Microsoft Windows XP Service Pack 2 |
Internet Explorer 6 Service Pack 1 for Microsoft Windows XP 64-Bit Edition Service Pack 1 (Itanium) |
Internet Explorer 6 for Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 |
Internet Explorer 6 for Microsoft Windows Server 2003 for Itanium-based Systems, Microsoft Windows Server 2003 with SP1 for Itanium-based Systems, Microsoft Windows XP 64-Bit Edition Version 2003 (Itanium), Microsoft Windows Server 2003 x64 Edition, and Microsoft Windows XP Professional x64 Edition |
Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Millennium Edition |
Internet Explorer 6 Service Pack 1 on Microsoft Windows 98, on Microsoft Windows 98 SE, or on Microsoft Windows Millennium Edition |
- Please review the released security bulletin and install the available security update.
- Customers who believe they may have been affected can contact Product Support Services. You can contact Product Support Services in the United States and Canada for help with security update issues or viruses at no charge using the PC Safety line (1 866-PCSAFETY). Customers outside of the United States and Canada can locate the number for no-charge virus support by visiting the Microsoft Help and Support Web site.
All customers should apply the most recent security updates released by Microsoft to help ensure that their systems are protected from attempted exploitation. Customers who have enabled automatic updates will automatically receive all Windows Updates. For more information about security updates, visit https: - We continue to encourage customers follow our Protect Your PC guidance of enabling a firewall, getting software updates and installing antivirus software. Customers can learn more about these steps at Protect Your PC Web site.
- For more information about staying safe on the Internet, customers can visit theMicrosoft Security Home Page.
Resources:
- You can provide feedback by completing the form by visiting the following Web site.
- Customers in the U.S. and Canada can receive technical support from Microsoft Product Support Services. For more information about available support options, see the Microsoft Help and Support Web site.
- International customers can receive support from their local Microsoft subsidiaries. For more information about how to contact Microsoft for international support issues, visit the International Support Web site.
- The Microsoft TechNet Security Web site provides additional information about security in Microsoft products.
Disclaimer:
The information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.
Revisions:
- August 18, 2005: Advisory published
- August 19, 2005: Advisory updated to include additional mitigating factors and also to include steps on how to restrict Web sites to only your trusted Web sites in the “Workarounds section”.
- August 25, 2005: Advisory updated to include additional mitigating factors. Msdds.dll file versions have also been revised: updated file version from 7.0.9446.0 to 7.0.9466.0 and added file version 7.0.9064.9143.
- February 21, 2006: Advisory updated to direct customers to Security Bulletin MS05-052, “Cumulative Security Update for Internet Explorer”.
Built at 2014-04-18T13:49:36Z-07:00 </https:>