This is a bit of the latest Microsoft Security Bulletin. Received this yesterday.
From Microsoft
Web sites use cookies as a way to store information on a user's
local system. Most often, this information is used for customizing
and retaining a site's setting for a user across multiple sessions.
By design each site should maintain its own cookies on a user's
machine and be able to access only those cookies.
A vulnerability exists because it is possible to craft a URL that
can allow sites to gain unauthorized access to user's cookies and
potentially modify the values contained in them. Because some web
sites store sensitive information in a user's cookies, it is also
possible that personal information could be exposed.
Risk Rating:
============
- Internet systems: High
- Intranet systems: High
- Client systems: High
RD
|