MS04-024: Vulnerability in Windows Shell


Recommended Posts

Microsoft Security Bulletin MS04-024

Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)

Issued: July 13, 2004

Version: 1.0

Summary

Who should read this document: Customers who use Microsoft? Windows?

Impact of Vulnerability: Remote Code ExecutionMaximum Severity Rating: Important

Recommendation: Customers should install the update at the earliest opportunity.b>

Security Update Replacement: This update replaces MS03-027 on Windows XP. This update does not replace MS03-027 on Windows NT 4.0, on Windows 2000, or on Windows Server 2003.

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

?Microsoft Windows NT? Workstation 4.0 Service Pack 6a ? Download the update

?Microsoft Windows NT Server 4.0 Service Pack 6a ? Download the update

?Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 ? Download the update

?Microsoft Windows NT? Workstation 4.0 Service Pack 6a and NT Server 4.0 Service Pack 6a with Active Desktop ? Download the update

?Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4 ? Download the update

?Microsoft Windows XP and Microsoft Windows XP Service Pack 1 ? Download the update

?Microsoft Windows XP 64-Bit Edition Service Pack 1 ? Download the update

?Microsoft Windows XP 64-Bit Edition Version 2003 ? Download the update

?Microsoft Windows Server? 2003 ? Download the update

?Microsoft Windows Server 2003 64-Bit Edition ? Download the update

?Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (Me) ? Review the FAQ section of this bulletin for details about these operating systems.

The software in this list has been tested to determine if the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support lifecycle for your product and version, visit the following Microsoft Support Lifecycle Web site.

Executive Summary:

This update resolves a newly-discovered, publicly reported vulnerability. A remote code execution vulnerability exists in the way that the Windows Shell launches applications.

If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. However, significant user interaction is required to exploit this vulnerability. Users whose accounts are configured to have fewer privileges on the system would be at less risk than uWe recommend that customers consider applying the security update.stomers consider applying the security update.

http://www.microsoft.com/technet/security/...n/MS04-024.mspx

The wierd thing is that if i go to windows update (v5 but still running SP1) it says the patch is (Security Update for Windows XP KB839645) 91.4 MB, but if i try to download it from microsofts site it is only 3.9 MB http://www.microsoft.com/downloads/details...&displaylang=en

Since im on 56k, i wonder which one i'll choose...lol

But seriously does anyone know if these updates are the same. They both say KB839645 but there is almost a 90MB file size difference

I hope its not one of those stupid web installers that want you to download additional files when you run it.

Edited by 12Iceman

Well i downloaded the update and installed it, it did not require downloading any additional files and the 91.4 MB KB839645 dissapeared from windows update which leads me to believe that the 91.4 MB is an error (windows updates are never that big except for service packs)

I would still like some clarification on this is anyone knows anything about this.

Well, it did download all 91mb for me using v5 of Windows Update, but there is a problem. This patch refuses to install and it continuously gives me a failed summary. Any reason why it's failing to install? I do have some services disabled as recommended by BlackViper, but I don't think it's that.

Here's what appears in the .txt on the Windows folder:

[KB839645.log]

***

2004/7/13 13:55:8.57

***

Exe = update.exe, Version = 5.4.1.0

***

================== Update.exe started at 7/13/2004 at 13:55: 8 ==================

***

Service Pack ??????????: -q /Z -ER

***

DoInstallation: CheckSystem Failed: 0xf001

***

?????????? Windows XP ??,??????????????????????

***

Update.exe extended error code = 0xf001

***

[KB839645.log]

***

2004/7/13 14:3:21.356

***

Exe = update.exe, Version = 5.4.1.0

***

================== Update.exe started at 7/13/2004 at 14: 3:21 ==================

***

Service Pack ??????????: -q /Z -ER

***

DoInstallation: CheckSystem Failed: 0xf001

***

?????????? Windows XP ??,??????????????????????

***

Update.exe extended error code = 0xf001

***

And yes, I do have a legal copy of XP :p

Nice, i was hoping i wouldn't have to download 90MB on 56k to patch security vulnerablilites. I'm glad i investigated this further instead of starting a 5+ hour download that would result in failure.

3.9MB linkage - http://www.microsoft.com/downloads/details...&displaylang=en

^Yes, we know, it is a known bug in v5. By the way, if you downloaded that 91mb update, make sure to delete all its downloaded files in the softwaredistribution folder under c:\windows. It's under downloads under the softwaredistribution folder.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Anyway to download these versions without being on the Experimental builds?
    • Nothing is stopping you from continuing with your testing cadence. If updates are released every 2 weeks instead of 4, and you test once every 4 weeks, the exact same amount of patches will still be available for you in those 4 weeks. For example: Before 4th week - patch 1, 2, 3, 4 After 2nd week - patch 1 and 2 4th week - patch 3 and 4 Still the same amount after 4.
    • Everyone else has said it. I'm gonna say it - you don't know what you're talking about. I do. I have two laptops. One work, one personal. I have access to two more laptops - both personal. At home I manually update my personal laptop when I see on Neowin that there is an update - I carry on and only apply the updates when I am ready. My work one only updates when my workplace decides to send it - I carry on and only apply the updates (when they actually arrive, which is usually days after the release) when I switch off the laptop at the end of the day as usual. The two other personal laptops only get updated when I get to it which is rarely - the people who own them carry on using them until I get to it and update them. All of the browsers on all laptops are configured to restore the tabs when launched. Google and Microsoft have changed from 6 weeks to 4, and it looks like it's going to move to 2. None of these changes affect how any of these browsers on the laptops are used. Not one jot. My advice to you is stop panicking whenever you see an update. Just carry on with what you're doing. This even benefits you in a way - from your comment you sound like you don't like the changes or the frivolous new features - great - then carry on as before!
    • AMAZON needs to take total accountability for this.
    • Server Summit had a heap of announcements, ADCS changes are baller.
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      509
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      138
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      80
  • Tell a friend

    Love Neowin? Tell a friend!