Re: Alert: Microsoft Security Bulletin - MS03-013 - Windows 2000 Warning

From: Russ (Russ.Cooper@RC.ON.CA)
Date: 04/17/03

  • Next message: brett hill: "Interactive logons and MS03-013"
    Date:         Wed, 16 Apr 2003 19:32:18 -0400
    From: Russ <Russ.Cooper@RC.ON.CA>
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Thanks to Bronek Kozicki for bringing this to my attention.

    The Windows 2000 version of MS03-013 contains numerous files not listed in the manifest supplied in KB 811493. In addition to the kernel files supplied in the other OS patches, the following files are also included;

    gdi32.dll v5.0.2195.5907
    kernel32.dll v5.0.2195.6011
    msgina.dll v5.0.2195.4733
    ntdll.dll v5.0.2195.6685
    rdpwd.sys v5.0.2195.6692
    user32.dll v5.0.2195.6000
    userenv.dll v5.0.2195.5968
    win32k.sys v5.0.2195.6003
    winlogon.exe v5.0.2195.6013
    winsrv.dll v5.0.2195.5935

    A brief check shows all to be post-SP3 versions.

    The problem here is that by including NTDLL.DLL in MS03-013, it is definitely applying MS03-007. As has been previously reported, there are definitely problems installing MS03-007 on systems which had previously applied a PSS supplied hotfix, check the archives for more details.

    If Microsoft has somehow fixed the problems with MS03-007, they've never said so. The version of NTDLL.DLL included in MS03-013 is the same as that included in MS03-007, however as Bronek points out;

    "Binary compare between MS03-007 and MS03-013 version of NTDLL.DLL reveals six different bytes (file offset 0x8-0xA and 0x128-0x12A)"

    Its also difficult to determine whether the inclusion of all of these other files will cause some other problems for Windows 2000 systems. Let me know if you encounter any.

    Meanwhile, I would strongly suggest you avoid applying MS03-013 unless you are able to test it in a non-production environment, and possibly wait until Microsoft provides some form of clarification. Both the Security Bulletin and its KB article are incorrect in stating they do not supercede any other hotfix as clearly this is not the case for Windows 2000 systems.

    More information when Microsoft decide to publish it.

    Trustworthy Computing just took another big hit today.

    Cheers,
    Russ - NTBugtraq Editor

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Have you discovered a security vulnerability related to Windows or a
    commercial product which runs on Windows?

    Need assistance crafting the format or translating your advisory to English?

    Need to verify it, or having problems contacting the Vendor?

    Contact mailto:Advisories@NTBugtraq.com

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo


  • Next message: brett hill: "Interactive logons and MS03-013"

    Relevant Pages

    • Re: Microsoft Sucks!
      ... Children want attention, why do you? ... If your 1.3 MHz is struggling with Windows XP, ... If you can not see the differences in Microsoft OSs other than resources, ... > And XP is not really a new Operating System. ...
      (microsoft.public.windowsxp.general)
    • Re: Windows to Mac
      ... The Windows computer here which I use on the public ... Nobody goes on any weird sites, but gradually the pop-ups start ... the Mac world. ... MS's lack of attention to detail. ...
      (rec.video.desktop)
    • Re: Windows to Mac
      ... The Windows computer here which I use on the public ... A virus program should be standard, even for you Mac folks, elsewise you wander down the path of false security. ... If the share the connection with a wireless router, they too have simple firewalls. ... MS's lack of attention to detail. ...
      (rec.video.desktop)
    • Re: Seat belt survey
      ... It leaves me with less need to concentrate on these basic and much more time to concentrate on the road and more time to keep an eye on my automatic responses to ensure they behave. ... Anyone who suggests they do none of their driving action automatically is either new to driving and needs to let it take up a lot of their attention or telling porkies. ... How many times have you swapped from a manual wind windows vehicle, to one with electric windows and found yourself trying to wind the window down via a none existent winder? ...
      (uk.rec.driving)
    • Re: rebooting problem
      ... Remove the checkmark from 'Automatically Restart' in 'System Failure' section. ... Pay particular attention to these messages as they may provide clues to ... I created a windows 98 start up disk and can get to the C prompt and the ...
      (microsoft.public.windowsxp.general)