Close but no cigar.
<QP>
Why are there two places to get this update?
These updates are available in two places due to the way the updates were
originally offered. The updates that were offered in Microsoft Knowledge
Base Article 953252 were not available from automatic updating (including
Automatic Updates, Windows Update, and Windows Server Update Services) and
therefore required users to manually find these updates and install them.
The updates that are offered in Microsoft Knowledge Base Article 967715
contain the same updates that correctly respect the registry keys values to
disable Autorun as in Microsoft Knowledge Base Article 953252, but are being
distributed via automatic updating.
</QP>
Source:
http://www.microsoft.com/technet/sec...ry/967940.mspx (FAQ)
<QP>
Does this update contain any security-related changes to functionality?
Yes. Besides the changes that are listed in the “Vulnerability Details”
section of this bulletin, this security update also resolves a publicly
known issue with Autorun functionality in Windows Vista and Windows Server
2008 systems. The update correctly disables the right-click and double-click
behavior controlled by the NoDriveTypeAutorun registry key. This corrects
the issue identified in CVE-2008-0951 on Windows Vista and Windows Server
2008. For more information on the usage of this registry key, see Microsoft
Knowledge Base Article 953252.
</QP>
Source:
http://www.microsoft.com/technet/sec.../ms08-038.mspx
(FAQ)
While MS08-038 (AKA KB950582) was NOT offered to WinXP, Win2003, or Win2000,
KB950585 is and always has been available for these OSS at the Download
Center (e.g.,
http://www.microsoft.com/downloads/d...4-1721D7B8DAA5).
For all intents and purposes, KB953252 and KB967715 are identical except for
the fact that KB967715 offered to WinXP, Win2003, and Win2000 via AU/WU/MU.
Why didn't MS just re-release MS08-038 (KB950585) for WinXP, Win2003 and
Win2000? Who knows?
Yes, it's all /very/ confusing.
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Client - since 2002
AumHa VSOP & Admin
http://aumha.net
DTS-L
http://dts-l.net/
Gis Bun wrote:
> If I got it right, the story goes that this update replaced a previous
> update. For Vista/Server 2008, it was offered as a security update but for
> XP/Server 2003 it was just an update. For XP/Server 2003, since it was
> just
> a plain update, it wasn't offered as a critical update for WU/AU/MU/WSUS.
> Since then the Conflickr worm has spread around and MS decided to release
> it to WU/AU/MU/WSUS.
>
> So for those who installed the original update (don't remember the KB but
> should be in the KB for this one), this is not needed.
<snip>