Home
Up

horizontal rule

bulletMicrosoft_Security_Bulletin_Re-Release,_December_2004
bulletDecember_14,_2004
bulletMicrosoft_Security_Bulletin_Summary_for_December_2004
bulletMicrosoft_Security_Bulletin_Re-Releases,_November_2004
bulletRe-Releases,_November_2004
bulletNovember_9,_2004
bulletMicrosoft_Security_Bulletin_Summary_for_September_2004
bulletMicrosoft_Security_Bulletin_Re-Releases,_August_2004
bulletMicrosoft_Security_Bulletin_Summary_for_August_2004
bulletMicrosoft_Security_Bulletin_Summary_for_July_2004
bulletBuffer_Overflow_in_ISS_Protocol_Analysis_Module
bulletBuffer_Overrun_in_WS_FTP_Pro
bulletDenial_of_Service_in_Windows_Media_Services
bulletInformation_Disclosure_in_MSN_Messenger
bulletVulnerability_in_ISAPI_Extension_for_Windows_Media
bulletMicrosoft_Windows_Security_Bulletin_Summary_for_March_2004
bulletMicrosoft_MSN_Products_Security_Bulletin_Summary_for_March_2004
bulletMicrosoft_Office_Security_Bulletin_Summary_for_March_2004
bulletMicrosoft_Windows_Security_Bulletin_Summary February 2004
bulletMicrosoft_Macintosh_Products_Security_Bulletin

horizontal rule

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

********************************************************************
Title: Microsoft Security Bulletin Re-Release, December 2004
Issued: December 14, 2004
********************************************************************

Summary
=======
The following bulletin has undergone a major revision increment.
Please see the bulletin for more details.

* MS04-028

Bulletin Information:
=====================

* MS04-028

- http://www.microsoft.com/technet/security/bulletin/MS04-028.mspx
- Reason for revision: Bulletin updated to advise on the
availability of additional security updates. Standalone security
updates for The Microsoft .NET Framework version 1.0 Service
Pack 2 and The Microsoft .NET Framework version 1.1 are now
available. Security updates for Microsoft Visual FoxPro 8.0 and
the Microsoft Visual FoxPro 8.0 runtime are also now available.
Bulletin updated to reflect the release of Windows Messenger 5.1
that contains an updated version of the affected file. The MS04-
028 Enterprise Update Scanning Tool has been updated to detect
and deploy the additional security updates.
- Originally posted: September 14, 2004
- Updated: December 14, 2004
- Bulletin Severity Rating: Critical
- Version: 3.0

********************************************************************

Support:
========
Technical support is available from Microsoft Product Support Services at 1-866-PC SAFETY (1-866-727-2338). There is no charge for support calls associated with security updates.
International customers can get support from their local Microsoft subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx

Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
valuable information to help you protect your network. This
newsletter provides practical security tips, topical security
guidance, useful resources and links, pointers to helpful
community resources, and a forum for you to provide feedback
and ask security-related questions.
You can sign up for the newsletter at:

http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
serves as a supplement to the Security Notification Service
(this e-mail). It provides timely notification of any minor
changes or revisions to previously released Microsoft Security
Bulletins. This new service provides notifications that are
written for IT professionals and contain technical information
about the revisions to security bulletins.
Visit http://www.microsoft.com to subscribe to this service:

- Click on Subscribe at the top of the page.
- This will direct you via Passport to the Subscription center.
- Under Newsletter Subscriptions you can sign up for the
"Microsoft Security Notification Service: Comprehensive Version".

* Protect your PC: Microsoft has provided information on how you
can help protect your PC at the following locations:

http://www.microsoft.com/security/protect/

If you receive an e-mail that claims to be distributing a
Microsoft security update, it is a hoax that may be distributing a
virus. Microsoft does not distribute security updates via e-mail.
You can learn more about Microsoft's software distribution
policies here:

http://www.microsoft.com/technet/security/topics/policy/swdist.mspx


********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.
********************************************************************

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQIVAwUBQb9GQIreEgaqVbxmAQLHoA/+JCOZuYzAKfaPDsOmExWPdsiGtJVycmGZ
MgAINGzYGUD1Tfig5WNtVhOTnBj4rfStTWE+Ytl2S0GPvh9d8/5DuUcbbguD3Ox1
kDBnEQi6Wd40d0Sudvwx8zAJi8or/99tMeTXEBJCNNrLtZKrS1Fo8U58SF3x6tx/
H03ZChZnSJQT/qH8BHII2ib+1rio2UBuTFll9ptP5Tofp+ofw5cCiFlsd4LErx5H
5Dx7eiq3wRht7Scho1kc9ysPdWxeIG0Y0Nk54C9wKZTkrnjy77jP62pYidUi/95B
vqfuCLBRhga4BUCxBiCHcxDGPVYslQI5ZOVLwqGsrG5wSjouOG7Vk0M7tAp8fFVs
dRa4+tX73tKmGFNZrO56CCF89i2AwYKAY9QZe2kglY6ASjrThixRRwUhl+dtmq5R
7BRV1cmjrOOHXxeejEu/4WlLBMNFUJXkb+12HPhAoux/VjB+mDxgNhdnfNLmud7G
/pW0WiJfD45SLnRefJhIYtvbPcTi3QqGsJh67Xm3BSQX4x/nVsyt7w33VaFD4qzT
atxgWgsH9UhM7bcxkuda1ReLxXeZAGmcFrOmPVYomRQxEg+EXMUJSTz/cWD1DEAu
htcoW0FWCgdzER9kQBv/gfjk7JL5tVFomNP9P7TvVmLL6SWR6Uwg9v2lKaIHIYIs
uDGSlCQB2KI=
=c6Cw
-----END PGP SIGNATURE-----

 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

********************************************************************
Title: Microsoft Security Bulletin Summary for December 2004
Issued: December 14, 2004
Version Number: 2.0
Bulletin: http://go.microsoft.com/fwlink/?LinkId=38912
********************************************************************

Summary:
========
This advisory contains information about all security updates released this month. It is broken down by security bulletin severity.

Critical Security Bulletins
===========================

MS04-040 - Cumulative Security Update for Internet Explorer
(889293)

- Affected Software:
- Windows NT Server 4.0 Service Pack 6a
- Windows NT Server 4.0 Terminal Server Edition
Service Pack 6
- Windows 2000 Service Pack 3
- Windows 2000 Service Pack 4
- Windows XP and Windows XP Service Pack 1
- Windows XP 64-Bit Edition Service Pack 1

- Review the FAQ section of bulletin MS04-O40 for
information about these operating systems:
- Microsoft Windows 98
- Microsoft Windows 98 Second Edition (SE)
- Microsoft Windows Millennium Edition (ME)

- Impact: Remote Code Execution
- Version Number: 1.0

Note: This bulletin (MS04-040) was released on December 1, 2004.

Important Security Bulletins
============================

MS04-041 - Vulnerability in WordPad Could Allow Code
Execution (885836)

- Affected Software:
- Windows NT Server 4.0 Service Pack 6a
- Windows NT Server 4.0 Terminal Server Edition
Service Pack 6
- Windows 2000 Service Pack 3
- Windows 2000 Service Pack 4
- Windows XP Service Pack 1
- Windows XP Service Pack 2
- Windows XP 64-Bit Edition Service Pack 1
- Windows XP 64-Bit Edition Version 2003
- Windows Server 2003
- Windows Server 2003 64-Bit Edition

- Impact: Remote Code Execution
- Version Number: 1.0


MS04-042 - Vulnerability in DHCP Could Allow Remote Code
Execution and Denial of Service (885249)

- Affected Software:
- Windows NT Server 4.0 Service Pack 6a
- Windows NT Server 4.0 Terminal Server Edition
Service Pack 6

- Impact: Remote Code Execution
- Version Number: 1.0


MS04-043 - Vulnerability in HyperTerminal Could Allow Code
Execution (873339)

- Affected Software:
- Windows NT Server 4.0 Service Pack 6a
- Windows NT Server 4.0 Terminal Server Edition
Service Pack 6
- Windows 2000 Service Pack 3
- Windows 2000 Service Pack 4
- Windows XP Service Pack 1
- Windows XP Service Pack 2
- Windows XP 64-Bit Edition Service Pack 1
- Windows XP 64-Bit Edition Version 2003
- Windows Server 2003
- Windows Server 2003 64-Bit Edition

- Impact: Remote Code Execution
- Version Number: 1.0


MS04-044 - Vulnerabilities in Windows Kernel and LSASS Could
Allow Elevation of Privilege (885835)

- Affected Software:
- Windows NT Server 4.0 Service Pack 6a
- Windows NT Server 4.0 Terminal Server Edition
Service Pack 6
- Windows 2000 Service Pack 3
- Windows 2000 Service Pack 4
- Windows XP Service Pack 1
- Windows XP Service Pack 2
- Windows XP 64-Bit Edition Service Pack 1
- Windows XP 64-Bit Edition Version 2003
- Windows Server 2003
- Windows Server 2003 64-Bit Edition

- Impact: Elevation of Privilege
- Version Number: 1.0


MS04-045 - Vulnerability in WINS Could Allow Remote Code
Execution (870736)

- Affected Software:
- Windows NT Server 4.0 Service Pack 6a
- Windows NT Server 4.0 Terminal Server Edition
Service Pack 6
- Windows 2000 Service Pack 3
- Windows 2000 Service Pack 4
- Windows Server 2003
- Windows Server 2003 64-Bit Edition

- Impact: Remote Code Execution
- Version Number: 1.0


Update Availability:
===================
Updates are available to address these issues.
For additional information, including Technical Details, Workarounds, answers to Frequently Asked Questions, and Update Deployment Information please read the Microsoft Security Bulletin Summary for this month at: http://go.microsoft.com/fwlink/?LinkId=38912

Support:
========
Technical support is available from Microsoft Product Support Services at 1-866-PC SAFETY (1-866-727-2338). There is no charge for support calls associated with security updates.
International customers can get support from their local Microsoft subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx

Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
valuable information to help you protect your network. This
newsletter provides practical security tips, topical security
guidance, useful resources and links, pointers to helpful
community resources, and a forum for you to provide feedback
and ask security-related questions.
You can sign up for the newsletter at:

http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
serves as a supplement to the Security Notification Service
(this e-mail). It provides timely notification of any minor
changes or revisions to previously released Microsoft Security
Bulletins. This new service provides notifications that are
written for IT professionals and contain technical information
about the revisions to security bulletins.
Visit http://www.microsoft.com to subscribe to this service:

- Click on Subscribe at the top of the page.
- This will direct you via Passport to the Subscription center.
- Under Newsletter Subscriptions you can sign up for the
"Microsoft Security Notification Service: Comprehensive Version".

* Join Microsoft's webcast for a live discussion of the technical
details of these security bulletins and steps you can take
to protect your environment. Details about the live webcast
can be found at:

www.microsoft.com/technet/security/bulletin/summary.mspx

The on-demand version of the webcast will be available 24 hours
after the live webcast at:

www.microsoft.com/technet/security/bulletin/summary.mspx

* Protect your PC: Microsoft has provided information on how you
can help protect your PC at the following locations:

http://www.microsoft.com/security/protect/

If you receive an e-mail that claims to be distributing a
Microsoft security update, it is a hoax that may be distributing a
virus. Microsoft does not distribute security updates through
e-mail. You can learn more about Microsoft's software distribution
policies here:

http://www.microsoft.com/technet/security/topics/policy/swdist.mspx

Acknowledgments:
================
Microsoft thanks the following for working with us to protect
customers:

* Greg Jones of KPMG UK (http://www.kpmg.co.uk/)
for reporting an issue described in MS04-041.

* Lord Yup working with iDefense (http://www.idefense.com/)
for reporting an issue described in MS04-041.

* Kostya Kortchinsky (kostya.kortchinsky@renater.fr)
from CERT RENATER
for reporting the issues described in MS04-042.

* Brett Moore of Security-Assessment.com
(http://www.security-assessment.com/)
for reporting an issue described in MS04-043.

* Cesar Cerrudo of Application Security Inc.
(http://www.appsecinc.com/)
for reporting the issues described in MS04-044.

* Kostya Kortchinsky (kostya.kortchinsky@renater.fr)
from CERT RENATER
for reporting the issues described in MS04-045.


********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.
********************************************************************


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQIVAwUBQb3nD4reEgaqVbxmAQIqTg//U3viI43M1sgS2WD321N2jvph3CIDMAjA
zrmR8tuTcNR6Luyc5+xeFet4jlEkbphYU91NRT6UogfQk5r5VJsRnkH1wcoLPijK
P3Qa6NpAMcBLJf6UF6WwuLllThhJNFEPGgzUSB2Xpc/zwlpyuM1oUbGZ0raeTDQz
+1xx+LcrH5QnEwRJ8qGJHtwvt9Q4UPyzj2IV0uUBOVL+Tp8+sNDbG20x4ijK0MmC
K+06RaKM3gCKDqFhkYo0bXX6PpBb333ie4sqbaYAZL4rQQOIKyP+wPFFKwZ1aYfe
LP/E56KkQYXBm6aLcD9qgbn8HNv+nrTw8/GuZH1KWlh06IUx4HgraTqU/Mmdebvc
4dZCW8nyXLcZm9JoNb3xeRbCmP2IMQThtyPQkSDHgA6Qa42Y3HjDJe3OT3UrPwWT
/CeU+WBe7C/1MLY7oqeEIi9zAaTflKMZ1NNGTlioL5kBFGQMg+smKZDiIFuFpYhZ
zYm2bToJLVO1lJs+Nr0szvEBwVPLANTDwsFTuVCbEyWUOHO3aYNnWY/OMrAV8HnR
zs9otlObyOVjiCzINIAIRBcnqKi+rn6QCOg+WIcqi4oRXYDJpXTDCxAT7/j24Q/o
soVF5IHLtnTmj+mK7qBVKQq+oEFe9qEOTVWpUH4R5cYnjba3DECKqDquZApRyvw4
tnlXqKYbuJs=
=BlEG
-----END PGP SIGNATURE-----

 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

********************************************************************
Title: Microsoft Security Bulletin Summary for December 2004
Issued: December 1, 2004
Version Number: 1.0
Bulletin: http://go.microsoft.com/fwlink/?LinkId=38912
********************************************************************

Summary:
========
This advisory contains information about all security updates
released this month. It is broken down by security bulletin severity.

Critical Security Bulletins
===========================

   MS04-040   - Cumulative Security Update for Internet Explorer
                (889293)

              - Affected Software:
                - Windows NT Server 4.0 Service Pack 6a
                - Windows NT Server 4.0 Terminal Server Edition
                  Service Pack 6
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1

              - Review the FAQ section of bulletin MS04-O40 for
                information about these operating systems:
                - Microsoft Windows 98
                - Microsoft Windows 98 Second Edition (SE)
                - Microsoft Windows Millennium Edition (ME)

              - Impact: Remote Code Execution
              - Version Number: 1.0

Update Availability:
===================
An update is available to address these issues.
For additional information, including Technical Details,
Workarounds, answers to Frequently Asked Questions,
and Update Deployment Information please read
the Microsoft Security Bulletin Summary for this
month at: http://go.microsoft.com/fwlink/?LinkId=38912

Support:
========
Technical support is available from Microsoft Product Support
Services at 1-866-PC SAFETY (1-866-727-2338). There is no
charge for support calls associated with security updates.
International customers can get support from their local Microsoft
subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx

Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
  valuable information to help you protect your network. This
  newsletter provides practical security tips, topical security
  guidance, useful resources and links, pointers to helpful
  community resources, and a forum for you to provide feedback
  and ask security-related questions.
  You can sign up for the newsletter at:

  http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
  serves as a supplement to the Security Notification Service
  (this e-mail). It provides timely notification of any minor
  changes or revisions to previously released Microsoft Security
  Bulletins. This new service provides notifications that are
  written for IT professionals and contain technical information
  about the revisions to security bulletins.
  Visit http://www.microsoft.com to subscribe to this service:

  - Click on Subscribe at the top of the page.
  - This will direct you via Passport to the Subscription center.
  - Under Newsletter Subscriptions you can sign up for the
    "Microsoft Security Notification Service: Comprehensive Version".

* Join Microsoft's webcast for a live discussion of the technical
  details of these security bulletins and steps you can take
  to protect your environment. Details about the live webcast
  can be found at: 

  www.microsoft.com/technet/security/bulletin/summary.mspx

  The on-demand version of the webcast will be available 24 hours
  after the live webcast at:

  www.microsoft.com/technet/security/bulletin/summary.mspx

* Protect your PC: Microsoft has provided information on how you
  can help protect your PC at the following locations:

  http://www.microsoft.com/security/protect/

  If you receive an e-mail that claims to be distributing a
  Microsoft security update, it is a hoax that may be distributing a
  virus. Microsoft does not distribute security updates through
  e-mail. You can learn more about Microsoft's software distribution
  policies here:
 
http://www.microsoft.com/technet/security/topics/policy/swdist.mspx

********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQIVAwUBQa4J5oreEgaqVbxmAQIRbA//UAlMsOpy/LogdVJpZkLR4Ck+GHyJLH+r
lJ/rXC3OzV4P6zVvbivmo5p4gNm8CnuvDCR9l5PT3OA6Sw9uAmpPM2x0K7Df0cRN
cwg3opDz9FvKc69YadnRd7rzsXoNI7J9K5Ipp8nbdDtx87kdr6Mny8eCISUBjwzO
GM7vJNL4xq0pOBAx+FTkes+9hrPBEPJ3Fin/O3FSxaBphD5UTUwWjEil7rAPukB6
jDlU3NDkI+qvmMtfqnXx7Jdj5/JE4L9FRl+Sf/W0nLidmu2MthsPtu0r+ZrdWjJo
4wz331F8AyH/hc4Sm1XZG1Ey7XLjgJPkq5mroOAZCrDUn1sJ060q+NRy4Mx50oyb
DAT+7LjwZeDgt9QESgyjnmK9PTsN7Bz0j41Q1mQQNyiCSAvMR5F/Jst6NKW1yil7
pL+6Zy8ut+vU7fF2V0j2hImOQ2phSwT9JbOMN36rGbFG3P6CTfjUjMB00L8ih6SP
DyTO+jI9dUiMZxBaXE+FXT5/fLRzfWR3nYk8nIeO3WrDP/PNP3taIWP4YoNbPYZr
KfbDWHPfli7+MM3KPZZIE9I1zQMBm8p66Kp/ytRtyqzHyVBjUz/5NYOope+CdJJN
cl7YmG8Axmfaoc3hfuvVUmpxG2bCsWEWj2aIHF163+R0Hiwliuh4mI/798h8MX18
laesNUlg1HY=
=Kj+e
-----END PGP SIGNATURE-----
 

 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

********************************************************************
Title: Microsoft Security Bulletin Re-Releases, November 2004
Issued: November 16, 2004
********************************************************************

Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.

* MS04-039

Bulletin Information:
=====================

* MS04-039

  - http://www.microsoft.com/technet/security/bulletin/MS04-039.mspx
  - Reason for re-release: Bulletin updated to reflect the release
    of updated ISA Server 2000 security updates for all languages.
    These issues affected customers using ISA Server 2000 Service
    Pack 1 or using Windows 2000 Service Pack 3. The Security
    Update Replacement section has also been revised.
  - Originally posted: November 9, 2004
  - Updated: November 16, 2004
  - Bulletin Severity Rating: Important
  - Version: 3.0

********************************************************************

Support:
========
Technical support is available from Microsoft Product Support
Services at 1-866-PC SAFETY (1-866-727-2338). There is no
charge for support calls associated with security updates.
International customers can get support from their local Microsoft
subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx

Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
  valuable information to help you protect your network. This
  newsletter provides practical security tips, topical security
  guidance, useful resources and links, pointers to helpful
  community resources, and a forum for you to provide feedback
  and ask security-related questions.
  You can sign up for the newsletter at:

  http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
  serves as a supplement to the Security Notification Service
  (this e-mail). It provides timely notification of any minor
  changes or revisions to previously released Microsoft Security
  Bulletins. This new service provides notifications that are
  written for IT professionals and contain technical information
  about the revisions to security bulletins.
  Visit http://www.microsoft.com to subscribe to this service:

  - Click on Subscribe at the top of the page.
  - This will direct you via Passport to the Subscription center.
  - Under Newsletter Subscriptions you can sign up for the
    "Microsoft Security Notification Service: Comprehensive Version".

* Protect your PC: Microsoft has provided information on how you
  can help protect your PC at the following locations:

  http://www.microsoft.com/security/protect/

  If you receive an e-mail that claims to be distributing a
  Microsoft security update, it is a hoax that may be distributing a
  virus. Microsoft does not distribute security updates via e-mail.
  You can learn more about Microsoft's software distribution
  policies here:

http://www.microsoft.com/technet/security/topics/policy/swdist.mspx


********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQIVAwUBQZoqDoreEgaqVbxmAQLDgBAAl+k5P/fDc4Mq4lKgisqeX1QmrSNTw7pe
aWpF7oWu8BCIPhnz4G+fCV3Q5/ygmwsx32ZO9DUainy4jrAHS4GhG8z+YkqH/3nV
mLBKVya8CRaLMfxGKTTSCwZRRFhJMbFfMtcVCMrDSbxoW4IHAIXgwm1/ad/IKPRe
ouOU1ITr9Brxh7VyJlk1PdBVdSfU16VYCBKTzlsOugLi+BSO5nXMRQZp01BiAPnK
IYGFcfbyQ8GwsKHfgRXnJAWGMUQOj5Vg504xtnOy/I5GnidGGP8VRyztP6HS3BiT
IBKygqolUCRhNVWnuP/ZvCOiLMYhs4DMseeIkZvRDS45+eGElnfT7qjLDekpqw83
Dt0QbEr2wtnHDXEkoeTi5+w2xKlOxhQ/3yp33khdCwzMrqauqFH78I2XFTwMJzVu
3SRvhpsfcwoWs5YN2t4lRvxcT0HzKtzprmhftQu3IvV3IraMveBXGff48tqbzrlL
74P/Pgn5U2aAICVKSwJ5tkoGMVgJidl4FW4Bk7bfcLDg0wvFOloSG7tN6gNVi72N
sv3E729fPLqAEzJG0VFm8o4dMzKGdzkz7wy55QjvLw6I+NtpIkJIlDXMS4TnZ0K7
LMy+rsATtgzBbGlt9NY+s2u9N62gPFKhcbw/Qtrdxwdd6pYt5/zjkvK4+TdayFTQ
QA8DqRjeQiY=
=rINJ
-----END PGP SIGNATURE-----

 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

********************************************************************
Title: Microsoft Security Bulletin Re-Releases, November 2004
Issued: November 10, 2004
********************************************************************

Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.

* MS04-039

Bulletin Information:
=====================

* MS04-039

  - http://www.microsoft.com/technet/security/bulletin/MS04-039.mspx
  - Reason for re-release: Bulletin updated to reflect the release
    of an updated ISA Server 2000 security update for the German
    language only. This issue does not affect any other language
    version of this security update. The Security Update Replacement
    section has also been revised.
  - Originally posted: November 9, 2004
  - Updated: November 9, 2004
  - Bulletin Severity Rating: Important
  - Version: 2.0

********************************************************************

Support:
========
Technical support is available from Microsoft Product Support
Services at 1-866-PC SAFETY (1-866-727-2338). There is no
charge for support calls associated with security updates.
International customers can get support from their local Microsoft
subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx

Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
  valuable information to help you protect your network. This
  newsletter provides practical security tips, topical security
  guidance, useful resources and links, pointers to helpful
  community resources, and a forum for you to provide feedback
  and ask security-related questions.
  You can sign up for the newsletter at:

  http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
  serves as a supplement to the Security Notification Service
  (this e-mail). It provides timely notification of any minor
  changes or revisions to previously released Microsoft Security
  Bulletins. This new service provides notifications that are
  written for IT professionals and contain technical information
  about the revisions to security bulletins.
  Visit http://www.microsoft.com to subscribe to this service:

  - Click on Subscribe at the top of the page.
  - This will direct you via Passport to the Subscription center.
  - Under Newsletter Subscriptions you can sign up for the
    "Microsoft Security Notification Service: Comprehensive Version".

* Protect your PC: Microsoft has provided information on how you
  can help protect your PC at the following locations:

  http://www.microsoft.com/security/protect/

  If you receive an e-mail that claims to be distributing a
  Microsoft security update, it is a hoax that may be distributing a
  virus. Microsoft does not distribute security updates via e-mail.
  You can learn more about Microsoft's software distribution
  policies here:

http://www.microsoft.com/technet/security/topics/policy/swdist.mspx


********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQIVAwUBQZJCh4reEgaqVbxmAQJKKA//cR5ES0Bofe/5EwobsAwFzjslBdHuDm3z
colZQa/uIrczQ6rY2K40jKYMc79yBacU1uecNa9i492XHP1UXyDVPFyuw96Bxe8+
Mytb81LReRrkcbD4c/fR5aWLqUZRkADjXwvqoC+upM+KdVmeVLU7TAXZ/y943o8Q
WLavpZ7+MmVIjmjV1FO5SAyCJFf3AulM/yZ7IKv+QvG+cGlsHo27WnQb3si4XrSy
an76NwPZKz5UxchfAS4AMj96PilBSPsTmT6o0jDYy/KVLtYgZV6nTDuB5lpq9vZj
2SVuh6vYgk+3FBvzi1omz10LZgyp4IfFAk7FwoEDu13rcKkf9O35sAb/FS14Q+t7
t7Se7uRHO5rv8y6azzeK2drfrEjF7EqO6o8/EWtSTJ+/1D9lUhd9ocrwd5/HC2pl
yAkClnEVpcS7paCG6y0J7tJmXTPBB4IfGH4GHX/Vs9R6zMnQI90/4EHMP6M6ZClb
LS4UKBhrtJC2kgMtT1dIKfxNHgh3yRKadjJv6RZw82iRgmqJYJRCTGp2u2LXVi8q
Zhyd0T3VuF4iSeG+yACWuWW1YG6M0weSKBfCAFW41K2w2udnh6Y5gmCWJZhBDeLF
d/fvCjSvFMdFjo9Ax48L5TZ7AtHRJJBNcAkvarEw3gqGk9YbbcnDDj3be0/+DF/6
2WpfBKVYnOw=
=91Xo
-----END PGP SIGNATURE-----


 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

********************************************************************
Title: Microsoft Security Bulletin Summary for November 2004
Issued: November 9, 2004
Version Number: 1.0
Bulletin: http://go.microsoft.com/fwlink/?LinkId=37221
********************************************************************

Summary:
========
This advisory contains information about all security updates
released this month. It is broken down by security bulletin severity.

Important Security Bulletins
===========================

   MS04-039   - Vulnerability in ISA Server 2000 and Proxy Server
                2.0 Could Allow Internet Content Spoofing (888258)

              - Affected Software:
                - Microsoft Proxy Server 2.0 Service Pack 1
                - Microsoft Internet Security and Acceleration
                  Server 2000 Service Pack 1 and Microsoft Internet
                  Security and Acceleration Server 2000
                  Service Pack 2
                - Microsoft Small Business Server 2000 (which
                  includes Microsoft Internet Security and
                  Acceleration Server 2000)
                - Microsoft Small Business Server 2003 Premium
                  Edition (which includes Microsoft Internet
                  Security and Acceleration Server 2000)

              - Impact: Spoofing
              - Version Number: 1.0 

Update Availability:
===================
An update is available to address these issues.
For additional information, including Technical Details,
Workarounds, answers to Frequently Asked Questions,
and Update Deployment Information please read
the Microsoft Security Bulletin Summary for this
month at: http://go.microsoft.com/fwlink/?LinkId=36672

Support:
========
Technical support is available from Microsoft Product Support
Services at 1-866-PC SAFETY (1-866-727-2338). There is no
charge for support calls associated with security updates.
International customers can get support from their local Microsoft
subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx

Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
  valuable information to help you protect your network. This
  newsletter provides practical security tips, topical security
  guidance, useful resources and links, pointers to helpful
  community resources, and a forum for you to provide feedback
  and ask security-related questions.
  You can sign up for the newsletter at:

  http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
  serves as a supplement to the Security Notification Service
  (this e-mail). It provides timely notification of any minor
  changes or revisions to previously released Microsoft Security
  Bulletins. This new service provides notifications that are
  written for IT professionals and contain technical information
  about the revisions to security bulletins.
  Visit http://www.microsoft.com to subscribe to this service:

  - Click on Subscribe at the top of the page.
  - This will direct you via Passport to the Subscription center.
  - Under Newsletter Subscriptions you can sign up for the
    "Microsoft Security Notification Service: Comprehensive Version".

* Join Microsoft's webcast for a live discussion of the technical
  details of these security bulletins and steps you can take
  to protect your environment. Details about the live webcast
  can be found at:
  www.microsoft.com/technet/security/bulletin/summary.mspx

  The on-demand version of the webcast will be available 24 hours
  after the live webcast at:
  www.microsoft.com/technet/security/bulletin/summary.mspx

* Protect your PC: Microsoft has provided information on how you
  can help protect your PC at the following locations:

  http://www.microsoft.com/security/protect/

  If you receive an e-mail that claims to be distributing a
  Microsoft security update, it is a hoax that may be distributing a
  virus. Microsoft does not distribute security updates through
  e-mail. You can learn more about Microsoft's software distribution
  policies here:
 
http://www.microsoft.com/technet/security/topics/policy/swdist.mspx

Acknowledgments:
================
Microsoft thanks the following for working with us to protect
customers:

- - Martijn de Vries (martijnv@infosupport.com)of Info Support for
  discovering and Thomas de Klerk (thomask@infosupport.com) of
  Info Support for reporting an issue described in MS04-039.

********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQIVAwUBQZEDIIreEgaqVbxmAQJcgw//d3QyNdDCTju0NYF2xy9TFMf7E7F5pygl
meAUylnYnk/NkjDGR7dWUkToErf10+FbejGOGk7HO2zYiR+2QN/4WjWRgNEPKuge
RA9CJVycceIQYe7mc7s3hozPF+NN+J6aDWdHWBVMqTtVgr8ldMsxeZsflTyOW03s
50hXo+5ECmzptD5FHdqC+zUUlzx51N5CYvShdrOMiZfWxRvOVTroTacZiUxTenty
5N2Z0viRKYPnMcIzp64wPGBeED7VPNon2ORV2JYhUVB35z7T97xAKndE8i7AeWDY
/OAk0/En0wVmyV3Zdw9/AaXUIgqBHHN+3kWTmLiGtau4JnR02cLPoI+sf8/5zbQ0
YdsLu+RQSCT2WSQXfrmgOEu7yjUR4GycjBM+icr9hEf6HlzImaEWuyLkrFkaIYMd
gXsmSrNll9CM2bvSbIrh4TFpoXDVb5XKJIumYPKIOh292DvZ+3NQDslT+tf24jyq
ARH/ghDZs50b6qVPFx6TAnUs8R8hFw5AZh4hvGdf18B9pS1B36esA95B9t57BjDb
rc/sJmdVlpTrtcHSVKC5SooqZq2j58cTnUuDMlknQfzsM1AkUUXQAz1VSROICKeX
vbbhpvw5g9+sWmyZc8cOTsaXGePazozwUXbBx6LsYG8UXoOibY3VPsspj1V8//u0
7vs+wB6i0kQ=
=PCsh
-----END PGP SIGNATURE-----

 

-----BEGIN PGP SIGNED MESSAGE-----

********************************************************************
Title: Microsoft Security Bulletin Summary for September 2004
Issued: September 14, 2004
Version Number: 1.0
Bulletin: http://go.microsoft.com/fwlink/?LinkId=34846
********************************************************************

Summary:
========
This advisory contains information about all security updates
released this month. It is broken down by security bulletin severity.

Critical Security Bulletins
===========================

    MS04-028  - Buffer Overrun in JPEG Processing (GDI+) Could Allow
                Code Execution (833987)

              - Affected Software:
              
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1
                - Windows XP 64-Bit Edition Version 2003
                - Windows Server 2003
                - Windows Server 2003 64-Bit Edition

                - Office 2003
                - Office XP Service Pack 3
                - Visio 2003 (All versions)
                - Visio 2002 Service Pack 2 (All versions)
                - Project 2003 (All versions)
                - Project 2002 Service Pack 1 (All versions)

              - Review bulletin MS04-O28 for information about
                these affected operating systems and applications:

                - Windows NT Workstation 4.0 Service Pack 6a
                - Windows NT Server 4.0 Service Pack 6a
                - Windows NT Server 4.0 Terminal Server Edition
                  Service Pack 6
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4

                - The Microsoft .NET Framework, version 1.0
                - The Microsoft .NET Framework, version 1.1
                - Internet Explorer 6 Service Pack 1

                - Picture It! 2002 (All versions)
                - Greetings 2002
                - Picture It! version 7.0 (All versions)
                - Digital Image Pro version 7.0
                - Picture It! version 9 (All versions)
                  Including Picture It! Library)
                - Digital Image Pro version 9
                - Digital Image Suite version 9
                - Producer for Microsoft Office PowerPoint
                  (All versions)

                - Visual Studio 2003 .NET
                - Visual Basic .NET Standard 2003
                - Visual C# .NET Standard 2003
                - Visual C++ .NET Standard 2003
                - Visual J# .NET Standard 2003
                - Visual Studio 2002 .NET
                - Visual Basic .NET Standard 2002
                - Visual C# .NET Standard 2002
                - Visual C++ .NET Standard 2002
                - The Microsoft .NET Framework, version 1.0 SDK
                - Platform SDK Redistributable: GDI+

              - Review the FAQ section of bulletin MS04-O28 for
                information about these operating systems:

                - Microsoft Windows 98
                - Microsoft Windows 98 Second Edition (SE)
                - Microsoft Windows Millennium Edition (ME)
          
              - Impact: Remote Code Execution
              - Version Number: 1.0 


Important Security Bulletins
============================

    MS04-027  - Vulnerability in WordPerfect Converter Could
                Allow Code Execution (884933)

              - Affected Software:
                - Office 2003
                - Office XP Service Pack 3
                - Office 2000 Service Pack 3
                - Works Suite (All versions)

              - Impact: Remote Code Execution
              - Version Number: 1.0


Update Availability:
===================
An update is available to address these issues.
For additional information, including Technical Details,
Workarounds, answers to Frequently Asked Questions,
and Update Deployment Information please read
the Microsoft Security Bulletin Summary for this
month at: http://go.microsoft.com/fwlink/?LinkId=34846

Support:
========
Technical support is available from Microsoft Product Support
Services at 1-866-PC SAFETY (1-866-727-2338). There is no
charge for support calls associated with security updates.
International customers can get support from their local Microsoft
subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx
 
Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
  valuable information to help you protect your network. This
  newsletter provides practical security tips, topical security
  guidance, useful resources and links, pointers to helpful
  community resources, and a forum for you to provide feedback
  and ask security-related questions.
  You can sign up for the newsletter at:

  http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
  serves as a supplement to the Security Notification Service
  (this e-mail). It provides timely notification of any minor
  changes or revisions to previously released Microsoft Security
  Bulletins. This new service provides notifications that are
  written for IT professionals and contain technical information
  about the revisions to security bulletins.
  Visit http://www.microsoft.com to subscribe to this service:

  - Click on Subscribe at the top of the page.
  - This will direct you via Passport to the Subscription center.
  - Under Newsletter Subscriptions you can sign up for the
    "Microsoft Security Notification Service: Comprehensive Version".

* Join Microsoft's webcast for a live discussion of the technical
  details of these security bulletins and steps you can take
  to protect your environment. Details about the live webcast
  can be found at:

  http://go.microsoft.com/fwlink/?LinkId=33258

  The on-demand version of the webcast will be available 24 hours
  after the live webcast at:

  http://go.microsoft.com/fwlink/?LinkId=33258

* Protect your PC: Microsoft has provided information on how you
  can help protect your PC at the following locations:

  http://www.microsoft.com/security/protect/

  If you receive an e-mail that claims to be distributing a
  Microsoft security update, it is a hoax that may be distributing a
  virus. Microsoft does not distribute security updates through
  e-mail. You can learn more about Microsoft's software distribution
  policies here:
 
http://www.microsoft.com/technet/security/topics/policy/swdist.mspx

Acknowledgments:
================
Microsoft thanks the following for working with us to protect
customers:

- - Peter Winter-Smith of Next Generation Security Software Ltd.
     (http://www.nextgenss.com)
     for reporting the issue described in MS04-027.

- -  Nick DeBaggis
     (ndebaggis@verizon.net)
     for reporting the issue described in MS04-028.

********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQEVAwUBQUci+40ZSRQxA/UrAQHi3gf/YGQwT5AvLTlyb6Zx/fX/Kng4SGhIEkdn
ZENkK63FI0Fbs2xKotpnMCy6TCBoOVnylrMjhHC2aTQn5v/lwM9vQ4fQwo2z0kbg
JncMsC/vmBRV8daLpDm+wM2dKPOCxdtgS+bG44jBlayn+AnvPOYgVISOnpTypGWq
JZPJanf5ehwFqNa7GWalwAUuFJqu9eXH2HvRoHdZuZehOwFuZVWpKEhpLZ0KNru1
TtmpAsgk0je3bgcXq4HykJXwtztTodUEVgInz+V2C5/Hm7RPhlBm4HDKTVTOfFfo
uMQYbLxPTYC58IlFtCpflrybhqgsdF74/n/B/UGtA9fQyCQFJgO0aw==
=3skI
-----END PGP SIGNATURE-----

horizontal rule

-----BEGIN PGP SIGNED MESSAGE-----

********************************************************************
Title: Microsoft Security Bulletin Re-Releases, August 2004
Issued: August 10, 2004
********************************************************************

Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.

* MS04-020

Bulletin Information:
=====================

* MS04-020

  - http://www.microsoft.com/technet/security/bulletin/MS04-020.mspx
  - Reason for re-release: Updated to reflect an additional affected
    product - Microsoft INTERIX 2.2.
  - Originally posted: July 13, 2004
  - Updated: August 10, 2004
  - Bulletin Severity Rating: Important
  - Version: 2.0

********************************************************************

Support:
========
Technical support is available from Microsoft Product Support
Services at 1-866-PC SAFETY (1-866-727-2338). There is no
charge for support calls associated with security updates.
International customers can get support from their local Microsoft
subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx
 
Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
  valuable information to help you protect your network. This
  newsletter provides practical security tips, topical security
  guidance, useful resources and links, pointers to helpful
  community resources, and a forum for you to provide feedback
  and ask security-related questions.
  You can sign up for the newsletter at:

  http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
  serves as a supplement to the Security Notification Service
  (this e-mail). It provides timely notification of any minor
  changes or revisions to previously released Microsoft Security
  Bulletins. This new service provides notifications that are
  written for IT professionals and contain technical information
  about the revisions to security bulletins.
  Visit http://www.microsoft.com to subscribe to this service:

  - Click on Subscribe at the top of the page.
  - This will direct you via Passport to the Subscription center.
  - Under Newsletter Subscriptions you can sign up for the
    "Microsoft Security Notification Service: Comprehensive Version".

* Protect your PC: Microsoft has provided information on how you
  can help protect your PC at the following locations:

  http://www.microsoft.com/security/protect/

  If you receive an e-mail that claims to be distributing a
  Microsoft security update, it is a hoax that may be distributing a
  virus. Microsoft does not distribute security updates via e-mail.
  You can learn more about Microsoft's software distribution
  policies here:

http://www.microsoft.com/technet/security/topics/policy/swdist.mspx


********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQEVAwUBQRkdCI0ZSRQxA/UrAQEXQAf9FF2Y88agNmYiG3CA/NG8M21PeFAduG+B
0BzMsiyG1GiBCSoBn2tBd/DTeO1HbdyYAdNW2e5/jfnGBFDkESkVoGXr0NDFv30o
D6Wrq3DjxHVVxOuvO2tNL/2NA9+Il5vNQJ8MKMF1EpNZLfcRmN56+M8TTiWPmiFr
gd08CNWh0J+P+SeItbjshgy9HADM77MOIPrY2knvKeiDuJzIGd1cUwfGQLHQ6qdD
2vHAfJEwi46blZUQIZ2VWNqoRZ0AJwL1Ls3CG7skAxP+0Qt46FPAQirHpuBkRW3v
K6yf13+0cDZ8bISdHMO4xg9ifh7wG+iD61Rsa4m/hee2DfxCtfQEKQ==
=CwRl
-----END PGP SIGNATURE-----

 

-----BEGIN PGP SIGNED MESSAGE-----

********************************************************************
Title: Microsoft Security Bulletin Summary for August 2004
Issued: August 10, 2004
Version Number: 1.0
Bulletin: http://go.microsoft.com/fwlink/?LinkId=29234
********************************************************************

Summary:
========
This advisory contains information about all security updates
released this month. It is broken down by security bulletin severity.

Moderate Security Bulletins
===========================

   MS04-026 - Vulnerability in Exchange Server 5.5 Outlook Web
              Access Could Allow Cross-Site Scripting and Spoofing
              Attacks (842436)

              - Affected Software:
                - Exchange Server 5.5 Service Pack 4
              - Affected Components:
                - Outlook Web Access

Update Availability:
===================
An update is available to address these issues.
For additional information, including Technical Details,
Workarounds, answers to Frequently Asked Questions,
and Update Deployment Information please read
the Microsoft Security Bulletin Summary for this
month at: http://go.microsoft.com/fwlink/?LinkId=20833

Support:
========
Technical support is available from Microsoft Product Support
Services at 1-866-PC SAFETY (1-866-727-2338). There is no
charge for support calls associated with security updates.
International customers can get support from their local Microsoft
subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx
 
Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
  valuable information to help you protect your network. This
  newsletter provides practical security tips, topical security
  guidance, useful resources and links, pointers to helpful
  community resources, and a forum for you to provide feedback
  and ask security-related questions.
  You can sign up for the newsletter at:
  http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
  serves as a supplement to the Security Notification Service
  (this e-mail). It provides timely notification of any minor
  changes or revisions to previously released Microsoft Security
  Bulletins. This new service provides notifications that are
  written for IT professionals and contain technical information
  about the revisions to security bulletins.
  Visit http://www.microsoft.com to subscribe to this service:

  - Click on Subscribe at the top of the page.
  - This will direct you via Passport to the Subscription center.
  - Under Newsletter Subscriptions you can sign up for the
    "Microsoft Security Notification Service: Comprehensive Version".

* Join Microsoft's webcast for a live discussion of the technical
  details of these security bulletins and steps you can take
  to protect your environment. Details about the live webcast
  can be found at:  http://go.microsoft.com/fwlink/?LinkId=32590

  The on-demand version of the webcast will be available 24 hours
  after the live webcast at:

  http://go.microsoft.com/fwlink/?LinkId=32590

* Protect your PC: Microsoft has provided information on how you
  can help protect your PC at the following locations:

  http://www.microsoft.com/security/protect/

  If you receive an e-mail that claims to be distributing a
  Microsoft security update, it is a hoax that may be distributing a
  virus. Microsoft does not distribute security updates through
  e-mail. You can learn more about Microsoft's software distribution
  policies here:

http://www.microsoft.com/technet/security/topics/policy/swdist.mspx

Acknowledgments:
================
Microsoft thanks the following for working with us to protect
customers:

- - Amit Klein or Sanctum Inc.
     (http://www.sanctuminc.com)
     for reporting the issue described in MS04-026.

********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQEVAwUBQRhEGo0ZSRQxA/UrAQGpngf8COwlbpqoTHLSM8AEHVZYIpDxHLYQBXpG
lXtyPQQc1/PH/h3X9TWHzdENavtGtYzWVLyVKfr3c1YnI8hUAWUx7OlBJQ6q/0xc
QpBY62/ihrB9h+MXR460W2UJ+ZbfDZBOvPjar2Ky30Sneqg6hrNbWWeoYpyQsO5P
bdSKHa2lKN9L7A87vfE9yaHLJkAwk4MJDBBqARDFQUIDGRsMsF3FqRxjvZ0avsf2
yixSb7Q9abF0ikJxZQdVRgzQ5Tu0OljnszEtIHVqi8W5HRQ6Gj6m0Zt6kwvmwniQ
Cib7Xa1NgQ+iZzc7TFVcwumzb08HD60rcwVApc+Jv57Tt4T6xMv6vA==
=voMP
-----END PGP SIGNATURE-----

-----BEGIN PGP SIGNED MESSAGE-----

********************************************************************
Title: Microsoft Security Bulletin Summary for July 2004
Issued: July 13, 2004
Updated: July 30, 2004
Version Number: 2.0
Bulletin: http://go.microsoft.com/fwlink/?LinkId=32567
********************************************************************

Summary:
========
This advisory contains information about all security updates
released this month. It is broken down by security bulletin severity.

Critical Security Bulletins
===========================

    MS04-025  - Cumulative Security Update for Internet Explorer
                (867801)
              
              - Affected Software:
                - Windows NT Workstation 4.0 Service Pack 6a
                - Windows NT Server 4.0 Service Pack 6a
                - Windows NT Server 4.0 Terminal Server Edition
                  Service Pack 6
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1
                - Windows XP 64-Bit Edition Version 2003
                - Windows Server 2003
                - Windows Server 2003 64-Bit Edition          
                - Microsoft Windows 98
                - Microsoft Windows 98 Second Edition (SE)
                - Microsoft Windows Millennium Edition (ME)

              - Impact: Remote Code Execution
              - Version Number: 1.0

    MS04-022  - Vulnerability in Task Scheduler Could Allow Code
                Execution (841873)

              - Affected Software:
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1

      - Affected Components:
                - Internet Explorer 6 when installed on Windows
                  NT 4.0 SP6a (Workstation, Server, or Terminal
                  Server Edition)

              - Impact: Remote Code Execution
              - Version Number: 1.1 

    MS04-023  - Vulnerability in HTML Help Could Allow Code
                Execution (840315)

              - Affected Software:
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1
                - Windows XP 64-Bit Edition Version 2003
                - Windows Server 2003
                - Windows Server 2003 64-Bit Edition
             
              - Affected Components:
                - Internet Explorer 6 when installed on Windows
                  NT 4.0 SP6a (Workstation, Server, or Terminal
                  Server Edition)

              - Review the FAQ section of bulletin MS04-O23 for
                information about these operating systems:
                - Microsoft Windows 98
                - Microsoft Windows 98 Second Edition (SE)
                - Microsoft Windows Millennium Edition (ME)

              - Impact: Remote Code Execution
              - Version Number: 1.0 

Important Security Bulletins
============================

   MS04-019 - Vulnerability in Utility Manager Could Allow Code
              Execution (842526)

              - Affected Software:
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4

              - Impact: Remote Code Execution
              - Version Number: 1.0

   MS04-020 - Vulnerability in POSIX Could Allow Code
              Execution (841872)

              - Affected Software:
                - Windows NT Workstation 4.0 Service Pack 6a
                - Windows NT Server 4.0 Service Pack 6a
                - Windows NT Server 4.0 Terminal Server Edition
                  Service Pack 6
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4

              - Impact: Remote Code Execution
              - Version Number: 1.0

   MS04-021 - Security Update for IIS 4.0 (841373)

              - Affected Software:
                - Windows NT Workstation 4.0 Service Pack 6a
                - Windows NT Server 4.0 Service Pack 6a

              - Impact: Remote Code Execution
              - Version Number: 1.1

   MS04-024 - Vulnerability in Windows Shell Could Allow Remote
              Code Execution (839645)

              - Affected Software:
                - Windows NT Workstation 4.0 Service Pack 6a
                - Windows NT Server 4.0 Service Pack 6a
                - Windows NT Server 4.0 Terminal Server Edition
                  Service Pack 6
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1
                - Windows XP 64-Bit Edition Version 2003
                - Windows Server 2003
                - Windows Server 2003 64-Bit Edition

              - Review the FAQ section of bulletin MS04-O24 for
                information about these operating systems:
                - Microsoft Windows 98
                - Microsoft Windows 98 Second Edition (SE)
                - Microsoft Windows Millennium Edition (ME)

              - Impact: Remote Code Execution
              - Version Number: 1.3

Moderate Security Bulletins
===========================

    MS04-018  - Cumulative Security Update for Outlook Express
                (823353)

              - Affected Software:
                - Windows NT Workstation 4.0 Service Pack 6a
                - Windows NT Server 4.0 Service Pack 6a
                - Windows NT Server 4.0 Terminal Server Edition
                  Service Pack 6
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1
                - Windows XP 64-Bit Edition Version 2003
                - Windows Server 2003
                - Windows Server 2003 64-Bit Edition

              - Review the FAQ section of bulletin MS04-O18 for
                information about these operating systems:
                - Microsoft Windows 98
                - Microsoft Windows 98 Second Edition (SE)
                - Microsoft Windows Millennium Edition (ME)

              - Impact: Denial of Service
              - Version Number: 1.0


Update Availability:
===================
Updates are available to address these issues.
For additional information, including Technical Details,
Workarounds, answers to Frequently Asked Questions,
and Update Deployment Information please read
the Microsoft Security Bulletin Summary for this
month at: http://go.microsoft.com/fwlink/?LinkId=32567

Support:
========
Technical support is available from Microsoft Product Support
Services at 1-866-PC SAFETY (1-866-727-2338). There is no
charge for support calls associated with security updates.
International customers can get support from their local Microsoft
subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx
 
Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
  valuable information to help you protect your network. This
  newsletter provides practical security tips, topical security
  guidance, useful resources and links, pointers to helpful
  community resources, and a forum for you to provide feedback
  and ask security-related questions.
  You can sign up for the newsletter at:

  http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
  serves as a supplement to the Security Notification Service
  (this e-mail). It provides timely notification of any minor
  changes or revisions to previously released Microsoft Security
  Bulletins. This new service provides notifications that are
  written for IT professionals and contain technical information
  about the revisions to security bulletins.
  Visit http://www.microsoft.com to subscribe to this service:

  - Click on Subscribe at the top of the page.
  - This will direct you via Passport to the Subscription center.
  - Under Newsletter Subscriptions you can sign up for the
    "Microsoft Security Notification Service: Comprehensive Version".

* The on-demand version of the July security bulletins webcast
  is available at: http://go.microsoft.com/fwlink/?LinkId=30865

* Protect your PC: Microsoft has provided information on how you
  can help protect your PC at the following locations:

  http://www.microsoft.com/security/protect/

  If you receive an e-mail that claims to be distributing a
  Microsoft security update, it is a hoax that may be distributing a
  virus. Microsoft does not distribute security updates through
  e-mail. You can learn more about Microsoft's software distribution
  policies here:
 
http://www.microsoft.com/technet/security/topics/policy/swdist.mspx

Acknowledgments:
================
Microsoft thanks the following for working with us to protect
customers:

Cesar Cerrudo of Application Security Inc. for reporting an issue
described in MS04-019. (http://www.appsecinc.com)
 
Rafal Wojtczuk working with McAfee for reporting an
issue described in MS04-020. (http://www.mcafee.com)
 
Brett Moore of Security-Assessment.com for reporting an issue
described in MS04-022. (http://www.security-assessment.com)
 
Dustin Schneider for reporting an issue described in MS04-022. 
(mailto://dschn@verizon.net)
 
Peter Winter-Smith of Next Generation Security Software Ltd. for
reporting an issue described in MS04-022.
(http://www.nextgenss.com)
 
Brett Moore of Security-Assessment.com for reporting an issue
described in MS04-023. (http://www.security-assessment.com)

********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQEVAwUBQQipKI0ZSRQxA/UrAQHoxwgAkAyy+C5GoahMc2Ajy3yIDSlGwLwletTS
udlZLUzffvA/ttvuWXw0EqzOWpQDKdVxnokXzFUP0yaHsKxnRcVh81ziBL2oF/aL
vs8uFr1u2cakv4unUcyB6dOlC3XUA9VDquEjZ6EXpI+erW4p/ZKZ0W2xvGKFgb93
lhqoDsI9+grDhMKQ49JCJ4bRFozBG5mDCVNrhUvP3SU4mAFbY0ora0nUZx4AU/+L
wslIMhn3rI3QEmK6xsvKTn2Cp4W/xUmpAkMg3wIqPfHBMLej3/da+pSqjvLBx1b2
861ZJUde8F9aHRMuzdTW50LX7GgVyMOI5Mhgo84bPa6MzjNpcDRi8g==
=kh8Z
-----END PGP SIGNATURE-----
 

-----BEGIN PGP SIGNED MESSAGE-----

********************************************************************
Title: Microsoft Security Bulletin Summary for July 2004
Issued: July 13, 2004
Version Number: 1.0
Bulletin: http://go.microsoft.com/fwlink/?LinkId=32567
********************************************************************

Summary:
========
This advisory contains information about all security updates
released this month. It is broken down by security bulletin severity.

Critical Security Bulletins
===========================

    MS04-022  - Vulnerability in Task Scheduler Could Allow Code
                Execution (841873)

              - Affected Software:
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1

      - Affected Components:
                - Internet Explorer 6 when installed on Windows
                  NT 4.0 SP6a (Workstation, Server, or Terminal
                  Server Edition)

              - Impact: Remote Code Execution
              - Version Number: 1.0 

    MS04-023  - Vulnerability in HTML Help Could Allow Code
                Execution (840315)

              - Affected Software:
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1
                - Windows XP 64-Bit Edition Version 2003
                - Windows Server 2003
                - Windows Server 2003 64-Bit Edition
             
              - Affected Components:
                - Internet Explorer 6 when installed on Windows
                  NT 4.0 SP6a (Workstation, Server, or Terminal
                  Server Edition)

              - Review the FAQ section of bulletin MS04-O23 for
                information about these operating systems:
                - Microsoft Windows 98
                - Microsoft Windows 98 Second Edition (SE)
                - Microsoft Windows Millennium Edition (ME)

              - Impact: Remote Code Execution
              - Version Number: 1.0 

Important Security Bulletins
============================

   MS04-019 - Vulnerability in Utility Manager Could Allow Code
              Execution (842526)

              - Affected Software:
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4

              - Impact: Remote Code Execution
              - Version Number: 1.0

   MS04-020 - Vulnerability in POSIX Could Allow Code
              Execution (841872)

              - Affected Software:
                - Windows NT Workstation 4.0 Service Pack 6a
                - Windows NT Server 4.0 Service Pack 6a
                - Windows NT Server 4.0 Terminal Server Edition
                  Service Pack 6
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4

              - Impact: Remote Code Execution
              - Version Number: 1.0

   MS04-021 - Security Update for IIS 4.0 (841373)

              - Affected Software:
                - Windows NT Workstation 4.0 Service Pack 6a
                - Windows NT Server 4.0 Service Pack 6a

              - Impact: Remote Code Execution
              - Version Number: 1.0

   MS04-024 - Vulnerability in Windows Shell Could Allow Remote
              Code Execution (839645)

              - Affected Software:
                - Windows NT Workstation 4.0 Service Pack 6a
                - Windows NT Server 4.0 Service Pack 6a
                - Windows NT Server 4.0 Terminal Server Edition
                  Service Pack 6
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1
                - Windows XP 64-Bit Edition Version 2003
                - Windows Server 2003
                - Windows Server 2003 64-Bit Edition

              - Review the FAQ section of bulletin MS04-O24 for
                information about these operating systems:
                - Microsoft Windows 98
                - Microsoft Windows 98 Second Edition (SE)
                - Microsoft Windows Millennium Edition (ME)

              - Impact: Remote Code Execution
              - Version Number: 1.0

Moderate Security Bulletins
===========================

    MS04-018  - Cumulative Security Update for Outlook Express
                (823353)

              - Affected Software:
                - Windows NT Workstation 4.0 Service Pack 6a
                - Windows NT Server 4.0 Service Pack 6a
                - Windows NT Server 4.0 Terminal Server Edition
                  Service Pack 6
                - Windows 2000 Service Pack 2
                - Windows 2000 Service Pack 3
                - Windows 2000 Service Pack 4
                - Windows XP and Windows XP Service Pack 1
                - Windows XP 64-Bit Edition Service Pack 1
                - Windows XP 64-Bit Edition Version 2003
                - Windows Server 2003
                - Windows Server 2003 64-Bit Edition

              - Review the FAQ section of bulletin MS04-O18 for
                information about these operating systems:
                - Microsoft Windows 98
                - Microsoft Windows 98 Second Edition (SE)
                - Microsoft Windows Millennium Edition (ME)

              - Impact: Denial of Service
              - Version Number: 1.0


Update Availability:
===================
Updates are available to address these issues.
For additional information, including Technical Details,
Workarounds, answers to Frequently Asked Questions,
and Update Deployment Information please read
the Microsoft Security Bulletin Summary for this
month at: http://go.microsoft.com/fwlink/?LinkId=32567

Support:
========
Technical support is available from Microsoft Product Support
Services at 1-866-PC SAFETY (1-866-727-2338). There is no
charge for support calls associated with security updates.
International customers can get support from their local Microsoft
subsidiaries. Phone numbers for international support can be found
at: http://support.microsoft.com/common/international.aspx
 
Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
  valuable information to help you protect your network. This
  newsletter provides practical security tips, topical security
  guidance, useful resources and links, pointers to helpful
  community resources, and a forum for you to provide feedback
  and ask security-related questions.
  You can sign up for the newsletter at:

  http://www.microsoft.com/technet/security/secnews/default.mspx

* Microsoft has created a free e-mail notification service that
  serves as a supplement to the Security Notification Service
  (this e-mail). It provides timely notification of any minor
  changes or revisions to previously released Microsoft Security
  Bulletins. This new service provides notifications that are
  written for IT professionals and contain technical information
  about the revisions to security bulletins.
  Visit http://www.microsoft.com to subscribe to this service:

  - Click on Subscribe at the top of the page.
  - This will direct you via Passport to the Subscription center.
  - Under Newsletter Subscriptions you can sign up for the
    "Microsoft Security Notification Service: Comprehensive Version".

* Join Microsoft's webcast for a live discussion of the technical
  details of these security bulletins and steps you can take
  to protect your environment. Details about the live webcast
  can be found at:  http://go.microsoft.com/fwlink/?LinkId=30865

  The on-demand version of the webcast will be available 24 hours
  after the live webcast at:

  http://go.microsoft.com/fwlink/?LinkId=30865

* Protect your PC: Microsoft has provided information on how you
  can help protect your PC at the following locations:

  http://www.microsoft.com/security/protect/

  If you receive an e-mail that claims to be distributing a
  Microsoft security update, it is a hoax that may be distributing a
  virus. Microsoft does not distribute security updates through
  e-mail. You can learn more about Microsoft's software distribution
  policies here:
 
http://www.microsoft.com/technet/security/topics/policy/swdist.mspx

Acknowledgments:
================
Microsoft thanks the following for working with us to protect
customers:

Cesar Cerrudo of Application Security Inc. for reporting an issue
described in MS04-019. (http://www.appsecinc.com)
 
Rafal Wojtczuk working with McAfee for reporting an
issue described in MS04-020. (http://www.mcafee.com)
 
Brett Moore of Security-Assessment.com for reporting an issue
described in MS04-022. (http://www.security-assessment.com)
 
Dustin Schneider for reporting an issue described in MS04-022. 
(mailto://dschn@verizon.net)
 
Peter Winter-Smith of Next Generation Security Software Ltd. for
reporting an issue described in MS04-022.
(http://www.nextgenss.com)
 
Brett Moore of Security-Assessment.com for reporting an issue
described in MS04-023. (http://www.security-assessment.com)

********************************************************************
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQEVAwUBQPQrso0ZSRQxA/UrAQFPdwgAif9ch3t8TJADL43IuYvhZ64TLc4hlhou
7gGPP1twOQJv9PM+oDIw2zIsap+2ETUbzluUThZ2WYak8HjlgtbIdyjRKIoK6FfD
3qe3RdCmRGqWkBQnytP6xwngFqQDeeeN9SBnDvFeETcrsXB7UR2KkrPg8iP9wlTP
Ciq0IYak9/L8YB+r2fA3rR1ZZX5zSNDZ0oihJfP0jAA7c/IAhx1vD3INmss0DDxJ
n+jIk7OVTIkp0iXjpCrbm/5N8Y9yaJ3ymc8FEU/K6WSfR+iKIJQpLNFTCnIdxBLy
n/e/+e32ezh5i7wWZhT4oY6g7UEuDEeglF+ze6VnSuP1OP9ICn5HxA==
=/TTr
-----END PGP SIGNATURE-----



*******************************************************************

You have received this e-mail bulletin because of your subscription to the Microsoft Product Security Notification Service.  For more information on this service, please visit http://www.microsoft.com/technet/security/notify.asp.
 
To verify the digital signature on this bulletin, please download our PGP key at http://www.microsoft.com/technet/security/notify.asp.
 

 

Security Alert, March 25, 2004

Buffer Overflow in ISS Protocol Analysis Module
   eEye Digital Security discovered a buffer-overflow vulnerability
in the Internet Security Systems (ISS) Protocol Analysis Module
component for the BlackICE, Proventia, and RealSecure products. The
vulnerability results from insufficient size checks on certain
protocol fields in ICQ Instant Messaging (IM) protocol response data
and could lead to remote compromise of the vulnerable system. ISS has
released an advisory and recommends that affected customers apply the
appropriate available patch.
   http://secadministrator.com/articles/index.cfm?articleid=42099
 

Security Alert, March 24, 2004

Buffer Overrun in WS_FTP Pro
   John Layman discovered that a buffer-overrun vulnerability in
WS_FTP Pro 8.02 and earlier can cause arbitrary code execution on the
vulnerable system. If an attacker sends an ASCII mode directory data
file that exceeds 260 bytes, and the file isn't terminated by a
carriage return/line feed (CRLF), a buffer overrun results. WS_FTP Pro
8.03 isn't vulnerable to the buffer-overrun condition, so users should
consider upgrading to version 8.03.
   http://secadministrator.com/articles/index.cfm?articleid=42098
 

Security Alert, March 16, 2004

Denial of Service in Windows Media Services
   Qualsys discovered a Denial of Service (DoS) vulnerability in
Microsoft Windows Media Services 4.1. Microsoft has released security
bulletin MS04-008, "Vulnerability in Windows Media Services Could
Allow a Denial of Service (832359)," to address the vulnerability and
recommends that affected users apply the appropriate patch listed in
the bulletin.
   http://secadministrator.com/articles/index.cfm?articleid=42021
 

Security Alert, March 15, 2004

Information Disclosure in MSN Messenger
   qFox and Mephisto discovered a vulnerability in Microsoft MSN
Messenger that can result in information disclosure on the vulnerable
system. Microsoft has released security bulletin MS04-010,
"Vulnerability in MSN Messenger Could Allow Information Disclosure
(838512)," to address the vulnerability and recommends that affected
users apply the appropriate patch listed in the bulletin.
   http://secadministrator.com/articles/index.cfm?articleid=42023
 

-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------
Title:      Vulnerability in ISAPI Extension for Windows Media
Services Could Cause Code Execution (822343)

Released:   June 25, 2003
Revised:    March 9, 2003 (version 2.0)
Software:   Windows Media Services
Impact:     Remote Code Execution
Max Risk:   Important

Bulletin:   MS03-022

Microsoft encourages customers to review the Security Bulletin at: