Microsoft KB Archive/928139

= FIX: You may experience several security-related issues in Microsoft XML components in Windows CE 6.0 =

Article ID: 928139

Article Last Modified on 5/10/2007

-

APPLIES TO


 * Windows Embedded CE 6.0

-



SYMPTOMS
You may experience the following security-related issues in Microsoft XML (MSXML) components in Microsoft Windows CE 6.0:
 * A cross-site scripting vulnerability exists.
 * An MSXML component may enter an infinite loop.
 * MSXML crashes.



Software update information
The fixes in this Windows CE 6.0 software update have been converted from the desktop Microsoft Windows version of MSXML code to Windows CE 6.0.

A supported software update is now available from Microsoft as Windows CE 6.0 Platform Builder Monthly Update (December 2006). You can confirm this by scrolling to the &quot;File information&quot; section of this article. The package file name contains the product version, date, Knowledge Base article number, and processor type. The package file name format is:

Product version-yymmdd-kbnnnnnn-processor type

For example: Wincepb50-060503-kb917590-armv4i.msi is the ARMV4i Windows CE 5.0 Platform Builder fix that is documented in KB article 917590 and that is contained in the May 2006 monthly update. To resolve this problem immediately, click the following article number for information about obtaining Windows CE Platform Builder and core operating system software updates:

837392 How to locate core operating system fixes for Microsoft Windows CE Platform Builder products

Prerequisites
This update is supported only if all previously issued updates for this product have also been installed.

Restart requirement
After you install this update, you must perform a clean build of the whole platform. To clean the platform, click Clean on the Build menu. To build the platform, click Build Platform on the Build menu. You do not have to restart your computer after you apply this update.

Update replacement information
This update does not replace any other updates.

File information
The English version of this package has the file attributes (or later file attributes) that are listed in the following table.

The English version of this update has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.



STATUS
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the &quot;Applies to&quot; section.



MORE INFORMATION
For more information about an MSXML security-related update for Microsoft Windows CE .NET 4.2, click the following article number to view the article in the Microsoft Knowledge Base:

916644 FIX: Update for several MSXML security issues in Windows CE .NET 4.2

For more information about a MSXML security-related update for Microsoft Windows CE 5.0, click the following article number to view the article in the Microsoft Knowledge Base:

918456 FIX: You may experience security-related problems when you use MSXML components in Windows CE 5.0

For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:

824684 Description of the standard terminology that is used to describe Microsoft software updates

Additional query words: cross-site scripting crashing MSXML infinite loops

Keywords: kbpubtypekc kbqfe kbhotfixserver kbfix kbbug KB928139

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.