Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Microsoft Security Bulletin MS04-024 - Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)

Reply
Thread Tools Display Modes

Microsoft Security Bulletin MS04-024 - Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)

 
 
Emily F [MSFT]
Guest
Posts: n/a

 
      07-13-2004
Microsoft Security Bulletin MS04-024
Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)
http://www.microsoft.com/technet/sec.../ms04-024.mspx
Issued: July 13, 2004
Version: 1.0
Executive Summary:
This update resolves a newly-discovered, publicly reported vulnerability. A
remote code execution vulnerability exists in the way that the Windows Shell
launches applications.
If a user is logged on with administrative privileges, an attacker who
successfully exploited this vulnerability could take complete control of an
affected system, including installing programs; viewing, changing, or
deleting data; or creating new accounts with full privileges. However,
significant user interaction is required to exploit this vulnerability.
Users whose accounts are configured to have fewer privileges on the system
would be at less risk than users who operate with administrative privileges.
We recommend that customers consider applying the security update.
Summary
Who should read this document: Customers who use Microsoft® Windows®
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Important
Recommendation: Customers should install the update at the earliest
opportunity.
Security Update Replacement: This update replaces MS03-027 on Windows XP.
This update does not replace MS03-027 on Windows NT 4.0, on Windows 2000, or
on Windows Server 2003.
Caveats: None
Tested Software and Security Update Download Locations:
Affected Software:
..Microsoft Windows NT® Workstation 4.0 Service Pack 6a - Download the update
..Microsoft Windows NT Server 4.0 Service Pack 6a - Download the update
..Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 -
Download the update
..Microsoft Windows NT® Workstation 4.0 Service Pack 6a and NT Server 4.0
Service Pack 6a with Active Desktop - Download the update
..Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack
3, Microsoft Windows 2000 Service Pack 4 - Download the update
..Microsoft Windows XP and Microsoft Windows XP Service Pack 1 - Download the
update
..Microsoft Windows XP 64-Bit Edition Service Pack 1 - Download the update
..Microsoft Windows XP 64-Bit Edition Version 2003 - Download the update
..Microsoft Windows ServerT 2003 - Download the update
..Microsoft Windows Server 2003 64-Bit Edition - Download the update
..Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and
Microsoft Windows Millennium Edition (Me) - Review the FAQ section of this
bulletin for details about these operating systems.

The software in this list has been tested to determine if the versions are
affected. Other versions either no longer include security update support or
may not be affected. To determine the support lifecycle for your product and
version, visit the following Microsoft Support Lifecycle Web site.


 
Reply With Quote
 
 
 
 
Paul.
Guest
Posts: n/a

 
      07-13-2004
"Emily F [MSFT]" wrote the following

> Microsoft Security Bulletin MS04-024
> Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)
> http://www.microsoft.com/technet/sec.../ms04-024.mspx
> Issued: July 13, 2004
> Version: 1.0

<snipped>

91.4MB!!!!

Is this for real? What sort of update is this?

Paul


 
Reply With Quote
 
Scott Harding - MS MVP
Guest
Posts: n/a

 
      07-13-2004
Ummm...your looking at the wrong numbers......the NT update is only 464kb
and windows 2000 is only 1433kb and the XP update is only 3905 kb. Are you
looking at the version number?

--
Scott Harding
MCSE, MCSA, A+, Network+
Microsoft MVP - Windows NT Server


"Paul." <> wrote in message
news:%...
> "Emily F [MSFT]" wrote the following
>
> > Microsoft Security Bulletin MS04-024
> > Vulnerability in Windows Shell Could Allow Remote Code Execution

(839645)
> > http://www.microsoft.com/technet/sec.../ms04-024.mspx
> > Issued: July 13, 2004
> > Version: 1.0

> <snipped>
>
> 91.4MB!!!!
>
> Is this for real? What sort of update is this?
>
> Paul
>
>



 
Reply With Quote
 
Scott Harding - MS MVP
Guest
Posts: n/a

 
      07-13-2004
Your looking at the wrong numbers....

--
Scott Harding
MCSE, MCSA, A+, Network+
Microsoft MVP - Windows NT Server

"Paul." <> wrote in message
news:%...
> "Emily F [MSFT]" wrote the following
>
> > Microsoft Security Bulletin MS04-024
> > Vulnerability in Windows Shell Could Allow Remote Code Execution

(839645)
> > http://www.microsoft.com/technet/sec.../ms04-024.mspx
> > Issued: July 13, 2004
> > Version: 1.0

> <snipped>
>
> 91.4MB!!!!
>
> Is this for real? What sort of update is this?
>
> Paul
>
>



 
Reply With Quote
 
Paul.
Guest
Posts: n/a

 
      07-13-2004
"Scott Harding - MS MVP" wrote the following
....
> Ummm...your looking at the wrong numbers......the NT update is only 464kb
> and windows 2000 is only 1433kb and the XP update is only 3905 kb. Are you
> looking at the version number?
>


This is what is displayed on the choose updates to install:

Size: 91.4 MB

A security issue has been identified that could allow an attacker to
compromise a computer running Windows and gain control over it. You can help
protect your computer by installing this update from Microsoft. After you
install this item, you may have to restart your computer.
More information for this update can be found at
http://go.microsoft.com/fwlink/?LinkId=30585

I have not touched XP SP2(rc1 or 2) on this my main PC but I did notice that
I seem to be running V5 of windows update. I do remember seeing this update
to run the newer version of win update and didn't think anything of it. Is
this the problem?

Thanks.

Paul




 
Reply With Quote
 
Hilary Karp
Guest
Posts: n/a

 
      07-13-2004
The download for XP is only 3.81 mb. Not sure what you are looking at.

Paul. wrote:

> "Emily F [MSFT]" wrote the following
>
>
>>Microsoft Security Bulletin MS04-024
>>Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)
>>http://www.microsoft.com/technet/sec.../ms04-024.mspx
>>Issued: July 13, 2004
>>Version: 1.0

>
> <snipped>
>
> 91.4MB!!!!
>
> Is this for real? What sort of update is this?
>
> Paul
>
>


 
Reply With Quote
 
Jone Doe
Guest
Posts: n/a

 
      07-13-2004

"Hilary Karp" <> wrote in message
news:...
> The download for XP is only 3.81 mb. Not sure what you are looking at.
>
> Paul. wrote:
>
> > "Emily F [MSFT]" wrote the following
> >
> >
> >>Microsoft Security Bulletin MS04-024
> >>Vulnerability in Windows Shell Could Allow Remote Code Execution

(839645)
> >>http://www.microsoft.com/technet/sec.../ms04-024.mspx
> >>Issued: July 13, 2004
> >>Version: 1.0

> >
> > <snipped>
> >
> > 91.4MB!!!!
> >
> > Is this for real? What sort of update is this?
> >
> > Paul
> >
> >

>

Using a dial up connection, it took about 11 minutes, and installed
flawlessly as usual



---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.719 / Virus Database: 475 - Release Date: 7/12/2004


 
Reply With Quote
 
Paul.
Guest
Posts: n/a

 
      07-13-2004
"Hilary Karp" wrote the following

> The download for XP is only 3.81 mb. Not sure what you are looking at.
>


See my reply to Scott.

Paul.


 
Reply With Quote
 
Scott Harding - MS MVP
Guest
Posts: n/a

 
      07-13-2004
Are you just installing this single update or many? Do you have Sp1 yet?

--
Scott Harding
MCSE, MCSA, A+, Network+
Microsoft MVP - Windows NT Server

"Paul." <> wrote in message
news:%...
> "Hilary Karp" wrote the following
>
> > The download for XP is only 3.81 mb. Not sure what you are looking at.
> >

>
> See my reply to Scott.
>
> Paul.
>
>



 
Reply With Quote
 
Hilary Karp
Guest
Posts: n/a

 
      07-13-2004
The point is the download is only 3.81 mb.

Paul. wrote:

> "Hilary Karp" wrote the following
>
>
>>The download for XP is only 3.81 mb. Not sure what you are looking at.
>>

>
>
> See my reply to Scott.
>
> Paul.
>
>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Update - Internet Explorer cannot display webpage - XP SP3 paulderdash Windows Update 14 07-25-2009 06:28 PM
Re: Windows Update Error Code 80070246 PA Bear [MS MVP] Windows Update 1 07-24-2009 05:49 PM
Re: 2008 Trend Micro Internet Security is NOT is compatible withWindows Vista SP1 and Windows XP SP3 Theo Windows 64 Bit 0 02-01-2008 07:40 PM
16 Bit Application Support in WinXP x64 Savage Windows 64 Bit 60 01-24-2007 07:27 PM
Re: Microsoft Security Bulletin for June 05 Torrey Lauer Windows 64 Bit 4 06-15-2005 12:19 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59