Description
The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-011
Scores
EPSS
0.0755
EPSS Percentile
93.9%
Details
Status
published
Products (6)
microsoft/ie
4.0 (2 CPE variants)
microsoft/ie
4.1 (2 CPE variants)
microsoft/ie
5
microsoft/ie
5.0 (2 CPE variants)
microsoft/internet_explorer
4.0
microsoft/visual_studio
6.0
Published
Feb 18, 2000
Tracked Since
Feb 18, 2026