Microsoft Affected

Notified:  March 22, 2001 Updated: March 26, 2001

Status

Affected

Vendor Statement

Microsoft has published a security bulletin describing this issue at: http://www.microsoft.com/technet/security/bulletin/MS01-017.asp

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Netscape Not Affected

Notified:  March 22, 2001 Updated: March 26, 2001

Status

Not Affected

Vendor Statement

Netscape takes all security and privacy issues very seriously. The Netscape browser does not allow the execution of ActiveX controls, signed or unsigned, and therefore Netscape users are not vulnerable to exploits which rely on signed ActiveX. In the unlikely event that Netscape users are presented with signed content from Microsoft requesting enhanced privileges, Netscape users can protect themselves by denying permission to any such request.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.