This update resolves the "Still Image Service Privilege Escalation" security vulnerability in Windows 2000 and is discussed in Microsoft Security Bulletin MS00-065. Download now to help prevent a malicious user from logging on to a Windows 2000 computer interactively and running a program that could enable the malicious user to obtain administrative privileges on the host computer.
The Still Image Service is automatically installed when a still image device (such as a digital camera or scanner) is attached to the Windows 2000 host. There is an unchecked buffer in the Still Image Service that could allow a malicious program to obtain LocalSystem privileges.For more information about these vulnerabilities, read Microsoft Security Bulletin MS00-065. (This site is in English.)