Update available for Office 2000 UA Control vulnerability (262767)
The information in this article applies to:
- Microsoft Project 2000
- Microsoft Excel 2000
- Microsoft Access 2000
- Microsoft FrontPage 2000
- Microsoft Outlook 2000
- Microsoft PowerPoint 2000
- Microsoft Publisher 2000
- Microsoft Word 2000
- Microsoft Works Suite 2000
- Microsoft PhotoDraw 2000
This article was previously published under Q262767 SUMMARY
Microsoft has released an update that eliminates a security vulnerability in Microsoft Office 2000 and all of the programs listed at the beginning of this article. The vulnerability could allow a malicious Web site operator or e-mail author to take inappropriate action on the computer of a user who visited the operator's Web site or opened the HTML e-mail message.
An ActiveX control that is included with Office 2000 is incorrectly marked as "safe for scripting". This control, the Office 2000 UA Control (Ouactrl.ocx), is used by the "Show Me" function in Office Help and allows Office functions to be scripted. A malicious Web site operator or e-mail author could use the control to carry out Office functions on the computer of a user who visited the Web site or opened the HTML e-mail message.
This update removes this unsafe functionality, with the result that the "Show Me" and pop-up window definition functions are turned off in Office 2000.
For example, in Microsoft Excel 2000, any hyperlink that has the javascript:HelpPopup property does not function.
NOTE: The Office 2000 UA Control is not included in Microsoft Office 2000 Service Release 1a (SR-1a).
Modification Type: | Minor | Last Reviewed: | 1/10/2005 |
---|
Keywords: | kbdownload kbbug kbfix KB262767 |
---|
|