[30792] in bugtraq

home help back first fref pref prev next nref lref last post

RE: Windows Update - Unsafe ActiveX control

daemon@ATHENA.MIT.EDU (Jackson, Chris)
Thu Jul 17 13:55:58 2003

Message-ID: <28BDBE0CC1D28149A5765F27757ED1D407A5D1@mystique.natasha.bridgecomtel.com>
From: "Jackson, Chris" <CJackson@bridgecom.com>
To: "'Siddhartha Jain(IT)'" <SiddharthaJ@bankmuscat.com>,
        "BUGTRAQ@SECURITYFOCUS. COM" <BUGTRAQ@securityfocus.com>
Date: Thu, 17 Jul 2003 13:35:12 -0400
MIME-Version: 1.0
Content-Type: text/plain

> "An ActiveX control on this page is not safe. Your current security
settings
> prohibit running unsafe controls on this page. As a result, this page may
> not display as intended."
> So Microsoft expects me download critical patches using an unsafe ActiveX
> control??

Safe for Scripting indicates that a control does not access files, memory,
or registers directly. The only purpose of the Windows Update control is to
access (and update) files directly, so it should not be marked as safe for
scripting.

-- 
Chris Jackson
Software Engineer
Microsoft MVP
-- 


home help back first fref pref prev next nref lref last post