Microsoft KB Archive/925398

From BetaArchive Wiki
Knowledge Base


MS06-078: Vulnerability in Windows Media Format could allow remote code execution

Article ID: 925398

Article Last Modified on 10/11/2007



APPLIES TO

  • Microsoft Windows Media Player 6.4, when used with:
    • Microsoft Windows 2000 Service Pack 4
    • Microsoft Small Business Server 2000 Standard Edition
    • Microsoft Windows XP Professional x64 Edition
    • Microsoft Windows Server 2003 R2 Standard Edition (32-bit x86)
    • Microsoft Windows Server 2003 R2 Enterprise Edition (32-Bit x86)
    • Microsoft Windows Server 2003 R2 Datacenter Edition (32-Bit x86)
    • Microsoft Windows Server 2003 R2 Standard x64 Edition
    • Microsoft Windows Server 2003 R2 Enterprise x64 Edition
    • Microsoft Windows Server 2003 R2 Datacenter x64 Edition
    • Microsoft Windows Server 2003, Standard x64 Edition
    • Microsoft Windows Server 2003, Enterprise x64 Edition
    • Microsoft Windows Server 2003, Datacenter x64 Edition
    • Microsoft Windows Server 2003, Enterprise Edition
    • Microsoft Windows Server 2003, Web Edition
    • Microsoft Windows Server 2003 SP1
    • Microsoft Windows Server 2003 Service Pack 2
    • Microsoft Windows Small Business Server 2003, Standard Edition Service Pack 1 (SP1)
    • Microsoft Windows Small Business Server 2003 R2 Standard Edition
    • Microsoft Windows Small Business Server 2003 R2 Premium Edition
    • Microsoft Windows XP Service Pack 2
    • Microsoft Windows XP Tablet PC Edition 2005
    • Microsoft Windows XP Media Center Edition 2005



SUMMARY

Microsoft has released security bulletin MS06-078. The security bulletin contains all the relevant information about the security update. This information includes file manifest information and deployment options. To view the complete security bulletin, visit one of the following Microsoft Web sites:

Note As of July 10, 2007, security update for 925398 can be installed on Microsoft Windows Server 2003 Service Pack 2 to help secure Windows Media Player 6.4. This is documented in revision 3.0 of security bulletin MS06-078. Customers who did experience this known issue and who did not install this security update will be reoffered the security update that is included with security bulletin MS06-078. The security update previously did not correctly allow customers to install security update 925398 on Microsoft Windows Server 2003 Service Pack 2. MBSA and SMS will offer security update 925398 to customers with Microsoft Windows Server 2003 Service Pack 2. We recommend that customers apply the update immediately. No action is required on systems where the security update has been successfully installed. For more information, visit the following Microsoft Web site:


Additional query words: security_patch security_update bug flaw malicious attacker exploit registry unauthenticated buffer overrun overflow specially-formed scope specially-crafted denial of service DoS TSE Win2000

Author: secure; kariz
Writer: v-chsu
Tech reviewer: secure; kbsec
Editor: v-valedo

Keywords: kbbug kbfix kbsecvulnerability kbqfe kbsecurity kbsecbulletin kbpubtypekc kbwin2000presp5fix kbexpertiseinter kbexpertisebeginner KB925398