MS04-024: Vulnerability in Windows Shell


Recommended Posts

Microsoft Security Bulletin MS04-024

Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)

Issued: July 13, 2004

Version: 1.0

Summary

Who should read this document: Customers who use Microsoft? Windows?

Impact of Vulnerability: Remote Code ExecutionMaximum Severity Rating: Important

Recommendation: Customers should install the update at the earliest opportunity.b>

Security Update Replacement: This update replaces MS03-027 on Windows XP. This update does not replace MS03-027 on Windows NT 4.0, on Windows 2000, or on Windows Server 2003.

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

?Microsoft Windows NT? Workstation 4.0 Service Pack 6a ? Download the update

?Microsoft Windows NT Server 4.0 Service Pack 6a ? Download the update

?Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 ? Download the update

?Microsoft Windows NT? Workstation 4.0 Service Pack 6a and NT Server 4.0 Service Pack 6a with Active Desktop ? Download the update

?Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4 ? Download the update

?Microsoft Windows XP and Microsoft Windows XP Service Pack 1 ? Download the update

?Microsoft Windows XP 64-Bit Edition Service Pack 1 ? Download the update

?Microsoft Windows XP 64-Bit Edition Version 2003 ? Download the update

?Microsoft Windows Server? 2003 ? Download the update

?Microsoft Windows Server 2003 64-Bit Edition ? Download the update

?Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (Me) ? Review the FAQ section of this bulletin for details about these operating systems.

The software in this list has been tested to determine if the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support lifecycle for your product and version, visit the following Microsoft Support Lifecycle Web site.

Executive Summary:

This update resolves a newly-discovered, publicly reported vulnerability. A remote code execution vulnerability exists in the way that the Windows Shell launches applications.

If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. However, significant user interaction is required to exploit this vulnerability. Users whose accounts are configured to have fewer privileges on the system would be at less risk than uWe recommend that customers consider applying the security update.stomers consider applying the security update.

http://www.microsoft.com/technet/security/...n/MS04-024.mspx

The wierd thing is that if i go to windows update (v5 but still running SP1) it says the patch is (Security Update for Windows XP KB839645) 91.4 MB, but if i try to download it from microsofts site it is only 3.9 MB http://www.microsoft.com/downloads/details...&displaylang=en

Since im on 56k, i wonder which one i'll choose...lol

But seriously does anyone know if these updates are the same. They both say KB839645 but there is almost a 90MB file size difference

I hope its not one of those stupid web installers that want you to download additional files when you run it.

Edited by 12Iceman

Well i downloaded the update and installed it, it did not require downloading any additional files and the 91.4 MB KB839645 dissapeared from windows update which leads me to believe that the 91.4 MB is an error (windows updates are never that big except for service packs)

I would still like some clarification on this is anyone knows anything about this.

Well, it did download all 91mb for me using v5 of Windows Update, but there is a problem. This patch refuses to install and it continuously gives me a failed summary. Any reason why it's failing to install? I do have some services disabled as recommended by BlackViper, but I don't think it's that.

Here's what appears in the .txt on the Windows folder:

[KB839645.log]

***

2004/7/13 13:55:8.57

***

Exe = update.exe, Version = 5.4.1.0

***

================== Update.exe started at 7/13/2004 at 13:55: 8 ==================

***

Service Pack ??????????: -q /Z -ER

***

DoInstallation: CheckSystem Failed: 0xf001

***

?????????? Windows XP ??,??????????????????????

***

Update.exe extended error code = 0xf001

***

[KB839645.log]

***

2004/7/13 14:3:21.356

***

Exe = update.exe, Version = 5.4.1.0

***

================== Update.exe started at 7/13/2004 at 14: 3:21 ==================

***

Service Pack ??????????: -q /Z -ER

***

DoInstallation: CheckSystem Failed: 0xf001

***

?????????? Windows XP ??,??????????????????????

***

Update.exe extended error code = 0xf001

***

And yes, I do have a legal copy of XP :p

Nice, i was hoping i wouldn't have to download 90MB on 56k to patch security vulnerablilites. I'm glad i investigated this further instead of starting a 5+ hour download that would result in failure.

3.9MB linkage - http://www.microsoft.com/downloads/details...&displaylang=en

^Yes, we know, it is a known bug in v5. By the way, if you downloaded that 91mb update, make sure to delete all its downloaded files in the softwaredistribution folder under c:\windows. It's under downloads under the softwaredistribution folder.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Win11Debloat 2026.06.14 by Razvan Serea Win11Debloat is a lightweight, easy to use PowerShell script that allows you to quickly declutter and customize your Windows experience. It can remove pre-installed bloatware apps, disable telemetry, remove intrusive interface elements and much more. The script also includes many features that system administrators and power users will enjoy. Such as a powerful command-line interface, support for Windows Audit mode and the option to make changes to other Windows users. All changes made by Win11Debloat can be easily reversed, and most removed apps can be restored via the Microsoft Store. A full guide on how to undo the changes is available here. Win11Debloat features: Below is an overview of the key features and functionality offered by Win11Debloat. Please refer to the wiki for more information about the default settings preset. Remove a wide variety of preinstalled apps. Click here for more info. Disable telemetry, diagnostic data, activity history, app-launch tracking & targeted ads. Disable tips, tricks, suggestions & ads across Windows. Disable Windows location services & app location access. Disable Find My Device location tracking. Disable 'Windows Spotlight' and tips & tricks on the lock screen. Disable 'Windows Spotlight' desktop background option. Disable ads, suggestions and the MSN news feed in Microsoft Edge. Hide Microsoft 365 ads on the Settings 'Home' page, or hide the 'Home' page entirely. Disable & remove Microsoft Copilot. Disable Windows Recall. Disable Click to Do, AI text & image analysis tool. Prevent AI service (WSAIFabricSvc) from starting automatically. Disable AI Features in Edge. Disable AI Features in Paint. Disable AI Features in Notepad. Disable the Drag Tray for sharing & moving files. Restore the old Windows 10 style context menu. Turn off Enhance Pointer Precision, also known as mouse acceleration. Disable the Sticky Keys keyboard shortcut. Disable Storage Sense automatic disk cleanup. Disable fast start-up to ensure a full shutdown. ...and more. Once you’ve downloaded the Win11Debloat file (Get.ps1), just follow these quick steps: Locate the Get.ps1 script file. Right-click the file and select Run with PowerShell from the context menu. If prompted by User Account Control (UAC), select Yes to grant the script the necessary administrative permissions. Win11Debloat 2026.06.14 changes: This is a minor release that hopefully addresses the false positives in Windows Defender and Bitdefender that prevented users from downloading and/or running Win11Debloat. Refactor Get-RegFileOperations.ps1 to address false positives by @Raphire in #626 Add logging around WinGet app retrieval and increase timeout to 20s by @Raphire Download: Win11Debloat 2026.06.14 | Open Source View: Win11Debloat Home Page | Screenshots 1| 2 Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Still using Microsoft Money 2005 in 2026 here!
    • I have a couple to mention, and they still run great on Windows 11 Adobe Lightroom Version 2 Alcohol 120% CLZ Book, Comic, Game, Movie, & Music Collector (PC - No longer sold / Grandfathered in - now mobile apps/online only) DVDDecrypter ISO Buster Pro version 1.9.1 (Still supports HD-DVD too) Nero Burning Rom 8 (Only the burning software, no backup, media converter, etc)   OpenAL (Runtime) - GuildWars 1 Reforged still uses it for 3d headphone audio PowerDVD 12 Ultra SPTD (SCSI Pass through Direct Driver) UltraISO Windows Media Encoder 9 WinImage You can tell I still sport an optical drive    
    • Linux 7.1 arrives with an NTFS overhaul and major hardware performance boosts by Paul Hill The founder of the Linux kernel has just announced the availability of Linux 7.1. This is a stable version of the kernel that will now be tested by various Linux distributions before it is shipped to users through update managers. Some users, like those on Debian, for example, might not get it for a long time, if at all, while Fedora users can expect it in the near future. With Linux 7.1 out on time, the merge window for Linux 7.2 is now open, giving contributors the opportunity to send in major new features that have been waiting for the last two months. Torvalds warned that he is currently travelling and will be in another timezone, so timing for the merge window may be irregular due to timezone differences and limited internet access. Torvalds said that he has already fetched early pull requests to allow him to do some offline work, but the travel could still cause disruption. Right now, he is not planning to extend the release, but did consider it. He said he might later regret not extending, though. In terms of this last week of development for Linux 7.1, Torvalds said there were no major or alarming changes. This week consisted mostly of smaller driver updates to GPU, networking, and sound, networking fixes, trace tooling fixes, and misc minor fixes. The shortlog this week lists fixes for driver bugs, memory leaks, I/O and USB fixes, networking and RDMA fixes, DRM/graphics fixes, and tooling and verification improvements. Specific fixes include USB series heap-overflow and buffer overflow fixes, and multiple use-after-free, memory-leak, and refcount corrections across subsystems such as i2c, zram, gpio, and net. There are fixes for graphics drivers, including amdgpu, i915, and virtio, as well as hypervisor and virtualization tweaks affecting mshv, vmbus, and hyperv. According to Phoronix, anyone running Linux 7.1 should look out for the new NTFS driver, Intel FRED for improved performance on Panther Lake and future CPUs, faster graphics with Intel Arc Battlemage, and improvements for older AMD Radeon GPUs. If you are running Linux on your computer and everything is fine, then you don’t need to worry about updating to Linux 7.1 as a priority; just wait for it to be pushed to you. If you have tried Linux on hardware but it didn’t work properly, trying again with a distro that uses Linux 7.1 could cause Linux to work on your machine, thanks to the new hardware support.
    • you can also do this with this tool: PowerSettingsExplorer made by mbk1969 at 3dguru forum.. I found it by accident researching on modern standby and annoying quirks of it in 2022
  • Recent Achievements

    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
    • One Month Later
      agatameier earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      197
    3. 3
      PsYcHoKiLLa
      139
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      81
  • Tell a friend

    Love Neowin? Tell a friend!