Microsoft KB Archive/917283

= MS06-033: A vulnerability in ASP.NET could allow information disclosure =

Article ID: 917283

Article Last Modified on 10/11/2007

-

APPLIES TO

 Microsoft .NET Framework 2.0, when used with:  Microsoft Windows 2000 Service Pack 4

 Microsoft Windows XP Service Pack 1

 Microsoft Windows XP Service Pack 2

 Microsoft Windows XP Professional x64 Edition</li></ul>

 Microsoft Windows XP Tablet PC Edition</li></ul>

 Microsoft Windows XP Media Center Edition 2002</li></ul>

 Microsoft Windows Server 2003 SP1</li></ul>

 Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems</li></ul>

 Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems</li></ul>

 Microsoft Windows Server 2003, Standard x64 Edition</li></ul> </li> Microsoft .NET Framework 2.0 x64 Edition</li> Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems</li> Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems</li> Microsoft Windows Server 2003 SP1, when used with: <ul> <li>Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems</li></ul>

<ul> <li>Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems</li></ul> </li></ul>

-

<div class="notice_section">

<div class="summary_section">

Microsoft has released security bulletin MS06-033. The security bulletin contains all the relevant information about the security update. This includes file manifest information and deployment options. To view the complete security bulletin, visit the following Microsoft Web sites. <ul> <li>Home users:

http://www.microsoft.com/athome/security/update/bulletins/200607.mspx

</li> <li>IT professionals:

http://www.microsoft.com/technet/security/bulletin/ms06-033.mspx

</li></ul>

<div class="moreinformation_section">

Known issues
<ul> <li>To install this security update, you must have Microsoft Windows Installer 3.1 installed on your computer. To obtain the latest Windows Installer for your computer, visit the following Microsoft Web site:

http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c

</li> <li>For more information about installation issues with Microsoft .NET Framework 2.0, click the following article number to view the article in the Microsoft Knowledge Base:

923100 When you try to install a security update for the .NET Framework 2.0, the computer may stop responding, or you may receive a &quot;0x643&quot; error code

</li> <li>For more information about installation issues with x64-based versions of Microsoft Windows Server 2003, click the following article number to view the article in the Microsoft Knowledge Base:

923101 Error message when you try to install a security update for the .NET Framework 2.0 on a computer that is running Windows Server 2003 x64 Edition: &quot;Error 1324. The folder 'Program Files' contains an invalid character&quot;

</li> <li>For more information about issues after you install an update for the .NET Framework 2.0, click the following article number to view the article in the Microsoft Knowledge Base:

929110 A file system that was case sensitive becomes case insensitive after you install an update for the .NET Framework 2.0

</li></ul>

For more information about the security update for the ASP.NET development platform, click the following article number to view the article in the Microsoft Knowledge Base:

922481 Description of the security update for the ASP.NET development platform

Additional query words: update security_patch security_update security bug flaw vulnerability malicious attacker exploit registry unauthenticated buffer overrun overflow specially-formed scope specially-crafted denial of service DoS TSE WinNT Win2000

Keywords: kbbug kbfix kbsecvulnerability kbqfe kbsecurity kbwinnt400presp7fix kbsecbulletin kbwinxppresp2fix kbpubtypekc kbwin2000presp5fix kbwinserv2003presp1fix KB917283

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.