Who should read this document: Customers who use
Microsoft Windows
Impact of Vulnerability: Remote Code
Execution
Maximum Severity Rating: Critical
Recommendation: Customers should apply the update
immediately.
Security Update Replacement: This update replaces the
update that is included with Microsoft Security Bulletin
MS05-052. That update is also a cumulative update.
Caveats:
Microsoft Knowledge Base Article 905915 documents the
currently known issues that customers may experience when they
install this security update. The article also documents
recommended solutions for these issues. For more information,
see
Microsoft Knowledge Base Article 905915.
This update does include hotfixes that have been released
since the release of
MS04-004 and
MS04-025, but they will only be installed on systems that
need them. Customers who have received hotfixes from Microsoft
or from their support providers since the release of
MS04-004 or
MS04-025 should review the “I have received a hotfix from
Microsoft or my support provider since the release of MS04-004.
Is that hotfix included in this security update?” question in
the FAQ section of this bulletin to determine how you can make
sure that the necessary hotfixes are installed.
Microsoft Knowledge Base Article 905915 also documents this
in more detail.
Tested Software and Security Update Download Locations:
Affected Software:
| • |
Microsoft Windows 2000 Service Pack
4 |
| • |
Microsoft Windows XP Service Pack 1
and Microsoft Windows XP Service Pack 2 |
| • |
Microsoft Windows XP Professional
x64 Edition |
| • |
Microsoft Windows Server 2003 and
Microsoft Windows Server 2003 Service Pack 1 |
| • |
Microsoft Windows Server 2003 for
Itanium-based Systems and Microsoft Windows Server 2003
with Service Pack 1 for Itanium-based Systems |
| • |
Microsoft Windows Server 2003 x64
Edition family |
| • |
Microsoft Windows 98, Microsoft
Windows 98 Second Edition (SE), and Microsoft Windows
Millennium Edition (ME) – Review the FAQ section of this
bulletin for details about these operating systems. |
Note The security updates for Microsoft Windows Server
2003, Microsoft Windows Server 2003 Service Pack 1, and
Microsoft Windows Server 2003 x64 Edition also apply to
Microsoft Windows Server 2003 R2.
For the FULL Microsoft Security
Bulletin, including update download links
click here.