Print... | Close

Security Update, January 30, 2001

Important This update upgrades your computer to build 3802 of the Microsoft VM, which includes the same vulnerability fixes as those contained in Microsoft VM build 3319. If you have already installed Microsoft VM build 3319, then your computer is not affected by the vulnerability.

This update resolves the "VM File Reading" security vulnerability in the Microsoft virtual machine (Microsoft VM). Download now to prevent a malicious Web site operator from reading – but not changing, adding, or deleting – the files on your computer or viewing the Web content inside your intranet.

Java applets (which are hosted on Web sites and run on the computers of visiting users) are run within the Microsoft VM, which uses a protected area on your computer called the "sandbox" to restrict what Java applets can do. Normally, the sandbox prevents a Java applet from performing inappropriate actions on a visiting user's computer. Through a complex series of steps, a malicious Web site operator can create a Java applet that can bypass the restrictions set by the sandbox, and read files on a visiting user's computer or view Web content within the visiting user's intranet.

For more information about this vulnerability, please read Microsoft Security Bulletin MS00-081. (This site is in English.)

This update is cumulative, and includes all fixes made in past Microsoft VM releases. For a complete list of updates included with Microsoft VM build 3802, view the list of fixes.

System Requirements

This update applies to builds of Microsoft VM numbered 3319 or earlier. (See Microsoft Security Bulletin MS00-081 for instructions for determining your Microsoft VM build number.)

Note If you are running Windows 2000, you must install Service Pack 1 before downloading this update.

How to use
Restart your computer to complete the installation.

How to uninstall
Uninstall is not available.

Print... | Close