Recommended Posts

i just came across something interesting. anyone skipping non-critical updates must read this!

- the critical update KB917734 released in june 2006 fixes a critical vulnerability in the windows media player.

- the non-critical update KB921134 released a couple of weeks later fixes a non-critical bug, also in the windows media player.

both updates contain just one updated file. its the same file in both, but different versions.

in the july 2006 xp release im curently putting together, KB921134 fully replaces the KB917734 update because it has a newer copy of the file KB917734 has, and so KB917734 will be removed and KB921134 added.

now, if someone were to use the autopatcher july 2006 release to update a system that KB917734 hadnt been installed on, and they skipped the 'non-critical' KB921134 update, they would be vulnerable to a serious security hole.

so next time anyone decides to skip a non-critical update, think twice!!

Link to comment
https://www.neowin.net/forum/topic/479242-every-windows-user-read-this/
Share on other sites

^ well possibly, but then what about all the other times it may have occured, this is the first time ive realised that it happens

leave it i guess, i know if i see a bug fixing update for something i use i'll install it, if you go to windows update does it ask to install both? how about installing both in ap? (critical one goes first obviously)

I have 917734 installed, not 921134. Just checked Microsoft Updates, custom; it does not offer 921134.

Also KB921134 article does say: only install if you have the problem.... So IMO it is not one that should be included in AP, as per previous posts I read you did not include hotfixes that say only install if...

PS I do have WMP10, not sure if that makes a difference.

PPS Just tried installing 921134, but it refuses to do so (not compatible with WMP 10 installed on this computer). My WMP is 10.00.00.4036. I'm in the UK, so it's probably a UK localised version?

The file I downloaded was windowsmedia10-kb921134-x86-intl.exe from the KB article page.

In fact I've seen several posts in other forums saying they could not install it.

So my suggestion is, please include 917734 in AP in the critical list, and if you want, 921134 in the optional list.

Edited by JRosenfeld
  • 2 weeks later...

Hi,

I have just tested KB921134 on my PC here (Window XP Professional SP2 UK with WMP 10 installed).

If you have either Outlook Express, Explorer or WMP open when it installing this update it will warn you that these applications are open and then wait for them to close.

Alternatively you can let the update install when these applicastions are open and then reboot once it's completed.

I wonder if the unattended installation masks this behavior and prevents successful installation?

At least one install from APXP opens an IE window (Macromedia Shockwave I believe) so this may prevent this update from installing if it installs after Shockwave.

Anyway I had no issues installing this update on my PC here but this was not via APXP.

Kind Regards

Simon

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft finally admits its default Windows 11 25H2, 24H2 action broke key legacy component by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. So far the company has acknowledged two known issues that have popped up after the release which include bugged-out Office apps as well as the Recycle Bin; though there could be more at play too. Speaking of bugs and issues, Microsoft seems to have finally acknowledged a problem that probably has been around for close to a year. That's because back in July of 2025 the company made a default change to the latest Windows 11 versions, wherein it switched to JScript9Legacy on Windows 11 24H2 and later releases. Hence following the release of version 25H2 in October 2025, JScript9Legacy also remained default-enabled. As a result there has been a compatibility issue ever since then. For those wondering, by switching to JScript9Legacy Microsoft intended to improve the security of modern Windows PCs by reducing vulnerabilities tied to legacy scripting like cross-site scripting (XSS), among others. XSS exploits can allow cyber-attackers to attach malicious code onto legitimate websites and use them to execute the code when a potential victim loads such a website. Hence the new JScript9Legacy engine enforced stricter execution policies and improved object handling, which should help mitigate such attacks. Microsoft today has published a new support article detailing the problem. Neowin spotted it while browsing. The company says that JScript global definitions and execution context may fail to persist across scripts, potentially breaking older dependent apps and web-based components that relied on this legacy behavior. In the article Microsoft has confirmed that the issue stems from its move away from the older jscript9.dll engine in favor of jscript9legacy.dll. As mentioned above, while the newer engine was designed to address vulnerabilities and strengthen security it also changes how JScript handles execution context. As a result functions and definitions loaded by one script could no longer remain available to subsequent scripts once execution ended. The company notes that some applications worked correctly on earlier Windows versions because the older JScript engine automatically retained global definitions and execution state between scripts. Under the newer model though that behavior is disabled by default causing certain legacy workloads and polyfill-dependent scripts to fail. Microsoft says it addressed the problem via the KB5077241 update though the fix had not been enabled automatically in the following updates. As such admins must explicitly turn on persistent JScript execution context using a Registry setting that the tech giant shared today. The configuration can be applied to individual processes or system-wide through the FEATURE_ENABLE_PERSISTENCE registry key. The steps have been outlined below: Run the following command to create the feature control registry key: reg add "HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PERSISTENCE" Under this key, create a new DWORD (32-bit) value. Configure the value as follows: To enable persistence for specific processes only: Set the value to 1 for each target process name. To enable persistence for all processes: Add * as the key name and set its value to 1. You can find the official support article here on Microsoft's website.
    • The possibility that milk gathers back into a glass implies that gravity can be 'reversed'.
    • VidCoder 12.20 by Razvan Serea  VidCoder is a DVD/Blu-ray ripping and video transcoding application for Windows. It uses HandBrake as its encoding engine. Calling directly into the HandBrake library gives it a more rich UI than the official HandBrake Windows GUI. VidCoder can rip DVDs but does not defeat the CSS encryption found in most commercial DVDs. You’ll need the NET 8 Desktop Runtime. If you don’t have it, VidCoder will prompt you to download and install it. The Portable version is self-contained and does not require any .NET Runtime to be installed. You do not need to install HandBrake for VidCoder to work. Feature list: Multi-threaded MP4, MKV containers Completely integrated encoding pipeline: everything is in one process and no huge intermediate temporary files H.264, H.265, MPEG-4, MPEG-2, VP8, Theora video Hardware-accelerated encoding with AMD VCE, Nvidia NVENC and Intel QuickSync AAC, MP3, Vorbis, AC3, FLAC audio encoding and AAC/AC3/MP3/DTS/DTS-HD passthrough Target bitrate, size or quality for video 2-pass encoding Decomb, detelecine, deinterlace, rotate, reflect, chroma smooth, colorspace filters Powerful batch encoding with simultaneous encodes Customizable Pickers to automatically pick audio and subtitle tracks, destination, titles and more Instant source previews Creates small encoded preview clips Pause, resume encoding VidCoder 12.20 changes: Updated HandBrake core to 1.11.2. Download: VidCoder 12.20 | 47.0 MB (Open Source) Download: Portable VidCoder 12.19 | 89.3 MB Link: VidCoder Home Page | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      590
    2. 2
      +Edouard
      185
    3. 3
      PsYcHoKiLLa
      76
    4. 4
      Michael Scrip
      73
    5. 5
      Steven P.
      66
  • Tell a friend

    Love Neowin? Tell a friend!