Security Update, November 29, 2000
Published: December 11, 2000
Read This First
This update resolves the "Browser Print Template," "File Upload via Form," and "Frame Domain Verification" security vulnerabilities in Internet Explorer. Under certain conditions, a malicious Web site operator can use Print Templates or Web forms to run code or view files on a visiting user's computer. Download now to help prevent a malicious Web site operator from reading files or taking other unauthorized action on your computer.
This update eliminates the "Browser Print Template" vulnerability by ensuring that Web sites cannot execute Print Templates without user permission. The "File Upload via Form" vulnerability is eliminated by preventing Web forms from uploading files through specific HTML coding. In addition, this update eliminates a new variant of the "Frame Domain Verification" vulnerability by ensuring that all known Web page functions perform appropriate domain checking before granting access to any data.
For more information on these vulnerabilities, please read Microsoft Security Bulletin MS00-093.
How to download and install
Select your language and browser version from the table below.
This update applies to computers that are running:
| • | Internet Explorer 5.01 Service Pack 1 |
| • | Internet Explorer 5.5 |
| • | Internet Explorer 5.5 Service Pack 1 |
How to uninstall
Uninstall is not available.