Home > Support > Global Security Advisor 

Vulnerability Detail

Microsoft Windows HCP URL validation vulnerability

Date Discovered:
12 Apr 2004

Date Published:
13 Apr 2004

Last Updated:
6 Dec 2006

Threat Assessment

Overall Risk:  High
Popularity : High
Impact:  Critical
Simplicity:  Medium

Characteristics

Vulnerability ID:  27890
Discovered By:  iDefense and Jouko Pynn÷nen

Exploitable Locally:  No
Exploitable Remotely:  Yes

Impact:  Remote attackers can execute arbitrary code.

Root Cause:  Software Vulnerability

 

Description

Microsoft Windows contains a vulnerability that can allow an attacker to execute arbitrary code. The vulnerability is due to the way HCP URL validation is performed. An attacker can create a HCP URL containing quotes to pass arbitrary command line arguments to HelpCtr.exe and execute arbitrary code.

Back to top

Recommendations

Apply the patch provided by the vendor.



Microsoft Windows XP and Microsoft Windows XP SP 1(WindowsXP-KB835732-x86-ENU):

http://www.microsoft.com/downloads/details.aspx?FamilyId=3549EA9E-DA3F-43B9-A4F1-AF243B6168F3&displaylang=en



Microsoft Windows XP 64-Bit Edition SP 1(WindowsXP-KB835732-IA64-ENU):

http://www.microsoft.com/downloads/details.aspx?FamilyId=C6B55EF2-D9FE-4DBE-AB7D-73A20C82FF73&displaylang=en



Microsoft Windows XP 64-Bit Edition Version 2003(WindowsServer2003-KB835732-IA64-ENU):

http://www.microsoft.com/downloads/details.aspx?FamilyId=C207D372-E883-44A6-A107-6CD2D29FC6F5&displaylang=en



Microsoft Windows Server 2003(WindowsServer2003-KB835732-x86-ENU):

http://www.microsoft.com/downloads/details.aspx?FamilyId=EAB176D0-01CF-453E-AE7E-7495864E8D8C&displaylang=en



Microsoft Windows Server 2003 64-Bit Edition(:

http://downloads/details.aspx?FamilyId=C207D372-E883-44A6-A107-6CD2D29FC6F5&displaylang=en



Alternatively, use the following vendor recommended workaround solution:



1. Disable the HCP Protocol



Start -> Run -> regedit -> HKEY_CLASSES_ROOT -> delete the HCP key



2. If applicable, install the Outlook E-mail Security Update.



3. Use plain text to read e-mail messages.



Vendor advisory:

MS04-011

835732Apply the patch provided by the vendor.



Microsoft Windows XP and Microsoft Windows XP SP 1(WindowsXP-KB835732-x86-ENU):

http://www.microsoft.com/downloads/details.aspx?FamilyId=3549EA9E-DA3F-43B9-A4F1-AF243B6168F3&displaylang=en



Microsoft Windows XP 64-Bit Edition SP 1(WindowsXP-KB835732-IA64-ENU):

http://www.microsoft.com/downloads/details.aspx?FamilyId=C6B55EF2-D9FE-4DBE-AB7D-73A20C82FF73&displaylang=en



Microsoft Windows XP 64-Bit Edition Version 2003(WindowsServer2003-KB835732-IA64-ENU):

http://www.microsoft.com/downloads/details.aspx?FamilyId=C207D372-E883-44A6-A107-6CD2D29FC6F5&displaylang=en



Microsoft Windows Server 2003(WindowsServer2003-KB835732-x86-ENU):

http://www.microsoft.com/downloads/details.aspx?FamilyId=EAB176D0-01CF-453E-AE7E-7495864E8D8C&displaylang=en



Microsoft Windows Server 2003 64-Bit Edition(:

http://downloads/details.aspx?FamilyId=C207D372-E883-44A6-A107-6CD2D29FC6F5&displaylang=en



Alternatively, use the following vendor recommended workaround solution:



1. Disable the HCP Protocol



Start -> Run -> regedit -> HKEY_CLASSES_ROOT -> delete the HCP key



2. If applicable, install the Outlook E-mail Security Update.



3. Use plain text to read e-mail messages.



Vendor advisory:

MS04-011

835732



-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: WindowsServer2003-KB835732-x86
If you have: Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 FR

Download:
http://download.windowsupdate.com/msdownload/update/v3-19990518/cabpool/WindowsServer2003-KB835732-x86-FRA_ea11d01f27dc5805a4c033f9254064d.EXE

If you have: Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 IT

Download:
http://download.windowsupdate.com/msdownload/update/v3-19990518/cabpool/WindowsServer2003-KB835732-x86-ITA_92ac50fea7973ac6bc69c0265191fff.EXE

If you have: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 DE

Download:
http://download.windowsupdate.com/msdownload/update/v3-19990518/cabpool/WindowsServer2003-KB835732-x86-DEU_30429c0cc197343602642fe7d6c4671.EXE

If you have: Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 EN

Download:
http://download.windowsupdate.com/msdownload/update/v3-19990518/cabpool/WindowsServer2003-KB835732-x86-ENU_9c2348f833ade0cca439ec6b2a92179.EXE

If you have: Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 ES

Download:
http://download.windowsupdate.com/msdownload/update/v3-19990518/cabpool/WindowsServer2003-KB835732-x86-ESN_1c6f3c577b5e0a8ffaf01993ecc4538.EXE


-------------------------------------------------------------------------------
For: Microsoft Windows XP Professional SP1 x86 32 DE, Microsoft Windows XP Professional SP1 x86 32 EN, Microsoft Windows XP Professional SP1 x86 32 ES, Microsoft Windows XP Professional SP1 x86 32 FR, Microsoft Windows XP Professional SP1 x86 32 IT
Apply: WindowsXP-KB835732-x86
If you have: Microsoft Windows XP Professional SP1 x86 32 EN, Microsoft Windows XP Professional x86 32 EN

Download:
http://download.microsoft.com/download/6/1/5/615a50e9-a508-4d67-b53c-3a43455761bf/WindowsXP-KB835732-x86-ENU.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 DE, Microsoft Windows XP Professional x86 32 DE

Download:
http://download.microsoft.com/download/4/c/d/4cda48a2-28e8-46fb-b332-2dcc618e6b0b/WindowsXP-KB835732-x86-DEU.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 ES, Microsoft Windows XP Professional x86 32 ES

Download:
http://download.microsoft.com/download/a/b/2/ab2f3bb1-e6ec-498f-b391-82c5a4c9cc4c/WindowsXP-KB835732-x86-ESN.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 FR, Microsoft Windows XP Professional x86 32 FR

Download:
http://download.microsoft.com/download/6/2/e/62e5a992-b54b-4d86-88ed-ea06852c5c46/WindowsXP-KB835732-x86-FRA.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 IT, Microsoft Windows XP Professional x86 32 IT

Download:
http://download.microsoft.com/download/4/2/9/42988565-9dc5-4027-b4c4-fcbea69e2e5e/WindowsXP-KB835732-x86-ITA.EXE


-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: Microsoft Windows Server 2003 Standard Edition SP1 x86 32 FR

Upgrade to Windows Server 2003 SP1 from the vendor.

http://support.microsoft.com/kb/889100

-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: Microsoft Windows Server 2003 Enterprise Edition SP1 x86 32 DE

Upgrade to Windows Server 2003 SP1 from the vendor. http://support.microsoft.com/kb/889100

-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: Microsoft Windows Server 2003 Enterprise Edition SP1 x86 32 ES

Upgrade to Windows Server 2003 SP1 from the vendor. http://support.microsoft.com/kb/889100

-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: Microsoft Windows Server 2003 Enterprise Edition SP1 x86 32 IT

Upgrade to Windows Server 2003 SP1 from the vendor. http://support.microsoft.com/kb/889100

-------------------------------------------------------------------------------
For: Microsoft Windows XP Home Edition SP1 x86 32 DE, Microsoft Windows XP Home Edition SP1 x86 32 EN, Microsoft Windows XP Home Edition SP1 x86 32 ES, Microsoft Windows XP Home Edition SP1 x86 32 FR, Microsoft Windows XP Home Edition SP1 x86 32 IT
Apply: WindowsXP-KB835732-x86
If you have: Microsoft Windows XP Professional SP1 x86 32 EN, Microsoft Windows XP Professional x86 32 EN

Download:
http://download.microsoft.com/download/6/1/5/615a50e9-a508-4d67-b53c-3a43455761bf/WindowsXP-KB835732-x86-ENU.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 DE, Microsoft Windows XP Professional x86 32 DE

Download:
http://download.microsoft.com/download/4/c/d/4cda48a2-28e8-46fb-b332-2dcc618e6b0b/WindowsXP-KB835732-x86-DEU.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 ES, Microsoft Windows XP Professional x86 32 ES

Download:
http://download.microsoft.com/download/a/b/2/ab2f3bb1-e6ec-498f-b391-82c5a4c9cc4c/WindowsXP-KB835732-x86-ESN.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 FR, Microsoft Windows XP Professional x86 32 FR

Download:
http://download.microsoft.com/download/6/2/e/62e5a992-b54b-4d86-88ed-ea06852c5c46/WindowsXP-KB835732-x86-FRA.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 IT, Microsoft Windows XP Professional x86 32 IT

Download:
http://download.microsoft.com/download/4/2/9/42988565-9dc5-4027-b4c4-fcbea69e2e5e/WindowsXP-KB835732-x86-ITA.EXE


-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: Microsoft Windows Server 2003 Enterprise Edition SP1 x86 32 EN

Upgrade to Windows Server 2003 SP1 from the vendor.



http://www.microsoft.com/downloads/details.aspx?familyid=22CFC239-337C-4D81-8354-72593B1C1F43&displaylang=en



Additional details:

http://support.microsoft.com/kb/889100

-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: Microsoft Windows Server 2003 Standard Edition SP1 x86 32 EN

Upgrade to Windows Server 2003 SP1 from the vendor.



http://www.microsoft.com/downloads/details.aspx?familyid=22CFC239-337C-4D81-8354-72593B1C1F43&displaylang=en



Additional details:

http://support.microsoft.com/kb/889100



-------------------------------------------------------------------------------
For: Microsoft Windows XP Professional x86 32 DE, Microsoft Windows XP Professional x86 32 EN, Microsoft Windows XP Professional x86 32 ES, Microsoft Windows XP Professional x86 32 FR, Microsoft Windows XP Professional x86 32 IT
Apply: WindowsXP-KB835732-x86
If you have: Microsoft Windows XP Professional SP1 x86 32 EN, Microsoft Windows XP Professional x86 32 EN

Download:
http://download.microsoft.com/download/6/1/5/615a50e9-a508-4d67-b53c-3a43455761bf/WindowsXP-KB835732-x86-ENU.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 DE, Microsoft Windows XP Professional x86 32 DE

Download:
http://download.microsoft.com/download/4/c/d/4cda48a2-28e8-46fb-b332-2dcc618e6b0b/WindowsXP-KB835732-x86-DEU.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 ES, Microsoft Windows XP Professional x86 32 ES

Download:
http://download.microsoft.com/download/a/b/2/ab2f3bb1-e6ec-498f-b391-82c5a4c9cc4c/WindowsXP-KB835732-x86-ESN.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 FR, Microsoft Windows XP Professional x86 32 FR

Download:
http://download.microsoft.com/download/6/2/e/62e5a992-b54b-4d86-88ed-ea06852c5c46/WindowsXP-KB835732-x86-FRA.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 IT, Microsoft Windows XP Professional x86 32 IT

Download:
http://download.microsoft.com/download/4/2/9/42988565-9dc5-4027-b4c4-fcbea69e2e5e/WindowsXP-KB835732-x86-ITA.EXE


-------------------------------------------------------------------------------
For: Microsoft Windows XP Home Edition x86 32 DE, Microsoft Windows XP Home Edition x86 32 EN, Microsoft Windows XP Home Edition x86 32 ES, Microsoft Windows XP Home Edition x86 32 FR, Microsoft Windows XP Home Edition x86 32 IT
Apply: WindowsXP-KB835732-x86
If you have: Microsoft Windows XP Professional SP1 x86 32 EN, Microsoft Windows XP Professional x86 32 EN

Download:
http://download.microsoft.com/download/6/1/5/615a50e9-a508-4d67-b53c-3a43455761bf/WindowsXP-KB835732-x86-ENU.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 DE, Microsoft Windows XP Professional x86 32 DE

Download:
http://download.microsoft.com/download/4/c/d/4cda48a2-28e8-46fb-b332-2dcc618e6b0b/WindowsXP-KB835732-x86-DEU.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 ES, Microsoft Windows XP Professional x86 32 ES

Download:
http://download.microsoft.com/download/a/b/2/ab2f3bb1-e6ec-498f-b391-82c5a4c9cc4c/WindowsXP-KB835732-x86-ESN.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 FR, Microsoft Windows XP Professional x86 32 FR

Download:
http://download.microsoft.com/download/6/2/e/62e5a992-b54b-4d86-88ed-ea06852c5c46/WindowsXP-KB835732-x86-FRA.EXE

If you have: Microsoft Windows XP Professional SP1 x86 32 IT, Microsoft Windows XP Professional x86 32 IT

Download:
http://download.microsoft.com/download/4/2/9/42988565-9dc5-4027-b4c4-fcbea69e2e5e/WindowsXP-KB835732-x86-ITA.EXE


-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: Microsoft Windows Server 2003 Standard Edition SP1 x86 32 IT

Upgrade to Windows Server 2003 SP1 from the vendor. http://support.microsoft.com/kb/889100

-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: Microsoft Windows Server 2003 Standard Edition SP1 x86 32 ES

Upgrade to Windows Server 2003 SP1 from the vendor. http://support.microsoft.com/kb/889100

-------------------------------------------------------------------------------
For: Microsoft Windows XP Professional SP1 x86 32 DE, Microsoft Windows XP Professional SP1 x86 32 EN, Microsoft Windows XP Professional SP1 x86 32 ES, Microsoft Windows XP Professional SP1 x86 32 FR, Microsoft Windows XP Professional SP1 x86 32 IT, Microsoft Windows XP Professional x86 32 DE, Microsoft Windows XP Professional x86 32 EN, Microsoft Windows XP Professional x86 32 ES, Microsoft Windows XP Professional x86 32 FR, Microsoft Windows XP Professional x86 32 IT
Apply: Microsoft Windows XP Professional SP2 x86 32 EN

Upgrade to Windows XP SP2 from the vendor.



Vendor reference:

http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/winxpsp2.mspx



-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: Microsoft Windows Server 2003 Enterprise Edition SP1 x86 32 FR

Upgrade to Windows Server 2003 SP1 from the vendor. http://support.microsoft.com/kb/889100

-------------------------------------------------------------------------------
For: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition x86 32 IT, Microsoft Windows Server 2003 Standard Edition x86 32 DE, Microsoft Windows Server 2003 Standard Edition x86 32 EN, Microsoft Windows Server 2003 Standard Edition x86 32 ES, Microsoft Windows Server 2003 Standard Edition x86 32 FR, Microsoft Windows Server 2003 Standard Edition x86 32 IT, Microsoft Windows Server 2003 Web Edition x86 32 DE, Microsoft Windows Server 2003 Web Edition x86 32 EN, Microsoft Windows Server 2003 Web Edition x86 32 ES, Microsoft Windows Server 2003 Web Edition x86 32 FR, Microsoft Windows Server 2003 Web Edition x86 32 IT
Apply: Microsoft Windows Server 2003 Standard Edition SP1 x86 32 DE

Upgrade to Windows Server 2003 SP1 from the vendor. http://support.microsoft.com/kb/889100

Back to top

Affected Technologies

Microsoft: Microsoft Windows Server 2003 Enterprise Edition x64 64 EN
Microsoft: Microsoft Windows Server 2003 Enterprise Edition x86 32 DE
Microsoft: Microsoft Windows Server 2003 Enterprise Edition x86 32 EN
Microsoft: Microsoft Windows Server 2003 Enterprise Edition x86 32 ES
Microsoft: Microsoft Windows Server 2003 Enterprise Edition x86 32 FR
Microsoft: Microsoft Windows Server 2003 Enterprise Edition x86 32 IT
Microsoft: Microsoft Windows Server 2003 Standard Edition x86 32 DE
Microsoft: Microsoft Windows Server 2003 Standard Edition x86 32 EN
Microsoft: Microsoft Windows Server 2003 Standard Edition x86 32 ES
Microsoft: Microsoft Windows Server 2003 Standard Edition x86 32 FR
Microsoft: Microsoft Windows Server 2003 Standard Edition x86 32 IT
Microsoft: Microsoft Windows Server 2003 Web Edition x86 32 DE
Microsoft: Microsoft Windows Server 2003 Web Edition x86 32 EN
Microsoft: Microsoft Windows Server 2003 Web Edition x86 32 ES
Microsoft: Microsoft Windows Server 2003 Web Edition x86 32 FR
Microsoft: Microsoft Windows Server 2003 Web Edition x86 32 IT
Microsoft: Microsoft Windows XP Home Edition SP1 x86 32 DE
Microsoft: Microsoft Windows XP Home Edition SP1 x86 32 EN
Microsoft: Microsoft Windows XP Home Edition SP1 x86 32 ES
Microsoft: Microsoft Windows XP Home Edition SP1 x86 32 FR
Microsoft: Microsoft Windows XP Home Edition SP1 x86 32 IT
Microsoft: Microsoft Windows XP Home Edition x86 32 DE
Microsoft: Microsoft Windows XP Home Edition x86 32 EN
Microsoft: Microsoft Windows XP Home Edition x86 32 ES
Microsoft: Microsoft Windows XP Home Edition x86 32 FR
Microsoft: Microsoft Windows XP Home Edition x86 32 IT
Microsoft: Microsoft Windows XP Professional SP1 x86 32 DE
Microsoft: Microsoft Windows XP Professional SP1 x86 32 EN
Microsoft: Microsoft Windows XP Professional SP1 x86 32 ES
Microsoft: Microsoft Windows XP Professional SP1 x86 32 FR
Microsoft: Microsoft Windows XP Professional SP1 x86 32 IT
Microsoft: Microsoft Windows XP Professional x86 32 DE
Microsoft: Microsoft Windows XP Professional x86 32 EN
Microsoft: Microsoft Windows XP Professional x86 32 ES
Microsoft: Microsoft Windows XP Professional x86 32 FR
Microsoft: Microsoft Windows XP Professional x86 32 IT
Microsoft: Windows XP 64-bit Edition
Microsoft: Windows XP 64-bit Edition SP1

Back to top

References

Microsoft: MS04-011
Mitre CVE: CAN-2003-0907

Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All
 
 
Page Tools