Microsoft KB Archive/890046

= MS05-032: Vulnerability in Microsoft agent could allow spoofing =

Article ID: 890046

Article Last Modified on 10/11/2007

-

APPLIES TO

 Microsoft Windows Server 2003, Datacenter Edition (32-bit x86) Microsoft Windows Server 2003, Enterprise Edition Microsoft Windows Server 2003, Standard Edition (32-bit x86) Microsoft Windows Server 2003, Web Edition Microsoft Windows Server 2003, 64-Bit Enterprise Edition Microsoft Windows Server 2003, 64-Bit Datacenter Edition Microsoft Windows Server 2003, Enterprise x64 Edition Microsoft Windows Server 2003, Standard x64 Edition</li> Microsoft Windows Server 2003, Datacenter x64 Edition</li> Microsoft Windows Server 2003 SP1, when used with: <ul> Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)</li></ul>

<ul> Microsoft Windows Server 2003, Enterprise Edition</li></ul>

<ul> Microsoft Windows Server 2003, Standard Edition (32-bit x86)</li></ul>

<ul> Microsoft Windows Server 2003, Web Edition</li></ul>

<ul> Microsoft Windows Server 2003, 64-Bit Datacenter Edition</li></ul>

<ul> Microsoft Windows Server 2003, 64-Bit Enterprise Edition</li></ul> </li> Microsoft Windows XP Service Pack 1, when used with: <ul> Microsoft Windows XP Home Edition</li></ul>

<ul> Microsoft Windows XP Professional</li></ul>

<ul> Microsoft Windows XP Media Center Edition 2002</li></ul>

<ul> Microsoft Windows XP Tablet PC Edition</li></ul>

<ul> Microsoft Windows XP Professional for Itanium-based systems</li></ul> </li> Microsoft Windows XP Service Pack 2, when used with: <ul> Microsoft Windows XP Home Edition</li></ul>

<ul> <li>Microsoft Windows XP Professional</li></ul>

<ul> <li>Microsoft Windows XP Media Center Edition 2002</li></ul>

<ul> <li>Microsoft Windows XP Tablet PC Edition</li></ul> </li> <li>Microsoft Windows XP Professional for Itanium-based systems</li> <li>Microsoft Windows XP Professional x64 Edition</li> <li>Microsoft Windows 2000 Advanced Server</li> <li>Microsoft Windows 2000 Datacenter Server</li> <li>Microsoft Windows 2000 Advanced Server</li> <li>Microsoft Windows 2000 Service Pack 3</li> <li>Microsoft Windows 2000 Service Pack 3</li> <li>Microsoft Windows 2000 Professional Edition</li></ul>

-

<div class="notice_section">

<div class="notice_section">

Technical updates
August 9, 2005:
 * Microsoft updated this bulletin on August 9, 2005 to advise customers that a revised version of the security update is available for the following systems:
 * Microsoft Windows Server 2003 for Itanium-based Systems
 * Microsoft Windows Server 2003 with Service Pack 1 (SP1) for Itanium-based Systems
 * Microsoft Windows Server 2003 x64 Edition
 * Microsoft Windows XP Professional x64 Edition
 * The original security update successfully addressed the vulnerabilities that are described in this security bulletin for non-64-bit systems. No additional action is required for non-64-bit customers. However, on 64-bit systems, the kill bit that is documented in the “Does this update contain any security-related changes to functionality?” FAQ is not correctly enabled when you use a 32-bit version of Microsoft Internet Explorer. The kill bit is correctly enabled for 64-bit versions of Internet Explorer. We recommend that you install the revised security update even if you have installed the earlier version. The revised security update will be available through Windows Update and through Software Update Services (SUS) as appropriate. The revised security update will be recommended by the Microsoft Baseline Security Analyzer (MBSA). You do not have to uninstall the prior security update before you install the revised security update.

<div class="summary_section">

Microsoft has released security bulletin MS05-032. The security bulletin contains all the relevant information about the security update. This information includes file manifest information and deployment options. To see the security bulletin, visit the following Microsoft Web sites: <ul> <li>Home users:

http://www.microsoft.com/athome/security/update/bulletins/default.mspx

</li> <li>IT professionals:

http://www.microsoft.com/technet/security/bulletin/MS05-032.mspx

</li></ul>

For more information about the latest service pack for Windows Server 2003, click the following article number to view the article in the Microsoft Knowledge Base:

889100 How to obtain the latest service pack for Windows Server 2003

Additional query words: update security_patch security_update security bug flaw vulnerability malicious attacker exploit unauthenticated buffer overrun overflow specially-formed scope specially-crafted denial of service Win2000

Keywords: kbbug kbfix kbsecvulnerability kbqfe kbsecurity kbsecbulletin kbpubtypekc kbwin2000presp5fix kbwinserv2003presp1fix kbwinxppresp3fix kbhotfixserver kbwinserv2003sp2fix KB890046

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.