Microsoft KB Archive/885834

= MS05-010: Vulnerability in the License Logging service could allow code execution =

Article ID: 885834

Article Last Modified on 2/23/2007

-

APPLIES TO


 * Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
 * Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
 * Microsoft Windows Server 2003, Standard Edition (32-bit x86)
 * Microsoft Windows Server 2003, Web Edition
 * Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
 * Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
 * Microsoft Windows 2000 Advanced Server
 * Microsoft Windows 2000 Service Pack 3
 * Microsoft Windows 2000 Service Pack 3
 * Microsoft Windows 2000 Advanced Server
 * Microsoft Windows 2000 Datacenter Server
 * Microsoft Windows 2000 Service Pack 4
 * Microsoft Windows NT Server 4.0, Terminal Server Edition Service Pack 6
 * Microsoft Windows NT 4.0 Service Pack 6a

-





Microsoft has released security bulletin MS05-010. The security bulletin contains all the relevant information about the security update. This includes file manifest information and deployment options. To view the complete security bulletin, visit the following Microsoft Web site:  Consumer:

http://www.microsoft.com/athome/security/update/bulletins/default.mspx

 IT Professional:

http://www.microsoft.com/technet/security/bulletin/ms05-010.mspx



Known issues
The Microsoft Windows 2000 Service Pack 4 (SP4) update package does not include the new version of Netserv.inf. Therefore, when Windows 2000 SP4 is used to build an integrated, or slipstream, installation, it does not replace the original Netserv.inf file. In an integrated installation, the NullSessionPipes registry entry includes License Logging service remote procedure call (LLSRPC).

Note Integrating a service pack into another set of files that you want to install is known as slipstreaming.

For more information about this issue, click the following article number to view the article in the Microsoft Knowledge Base:

896658 Windows 2000 Service Pack 4 does not update the Netserv.inf file when creating a slipstream installation

Additional query words: update security_patch security_update security bug flaw vulnerability malicious attacker exploit registry unauthenticated buffer overrun overflow specially-formed scope specially-crafted denial of service DoS TSE WinNT Win2000

Keywords: kbbug kbfix kbsecvulnerability kbsecurity kbwinnt400presp7fix kbsecbulletin kbwinxppresp2fix kbwin2000presp5fix kbwinserv2003presp1fix kbhotfixserver KB885834

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.