Overview
There is a buffer overflow in the System Monitor ActiveX control that ships with Windows 2000.
Description
| The System Monitor ActiveX control (sysmon.ocx) included with Windows 2000 contains a buffer overflow. For more information, see http://www.microsoft.com/technet/security/bulletin/ms00-085.asp | 
Impact
| Intruders who can script the control (e.g. by constructing a malicious web page or email message) can execute arbitrary code with the privileges of the victim. | 
Solution
| Apply a patch as described in the Microsoft bulletin. | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
Our thanks to Microsoft and Underground Security Systems Research and for the information contained in their advisories.
This document was written by Shawn V. Hernan.
Other Information
| CVE IDs: | CVE-2000-1034 | 
| Date Public: | 2000-11-02 | 
| Date First Published: | 2002-05-23 | 
| Date Last Updated: | 2002-05-23 23:23 UTC | 
| Document Revision: | 4 |