Critical Updates

From: avildasfriend (anonymous_at_discussions.microsoft.com)
Date: 07/29/04


Date: Wed, 28 Jul 2004 16:06:50 -0700

On a windows 2000 server, I used the web to download and
install five critical security updates. KB839645-
Vulnerability in Windows Shell could allow remote code
execution, KB840315-Vulnerability in html help could allow
code execution,KB841873-Vulnerability in Task Scheduler
could allow code execution, KB841872-Vulnerability in
POSIX could allow code execution, and KB842526-
Vulnerability in Utility Manager could allow code
execution. Concurrent with these updates, Users were
unable to log into our internal web pages, or edit public
or internal pages. Security Properties for the directory
in question included Web Anonymous User, which only had
deny "write" checked. (I do not know the
users/permissions originally set for this directory) Once
I removed the deny write, the sites/pages were functional
again. My question is: Is there anything in the updates
that made any changes to anonymous user or ADDED anonymous
user to webroot? I read the bulletins and don't see any
reference but who knows. Blame must be placed. If not
the updates, I have to figure out who oops'd (without
authority).
Thank You



Relevant Pages

  • Web Anonymous User
    ... Vulnerability in Windows Shell could allow remote code ... execution, KB840315-Vulnerability in html help could allow ... Concurrent with these updates, Users were ... that made any changes to web anonymous user or ADDED web ...
    (microsoft.public.isa.configuration)
  • Re: <<< SECURITY BULLETINS THIS MONTH>>>
    ... DON'T install the other WU recommended updates ... >> MS04-033 - Vulnerability in Microsoft Excel Could Allow Code Execution ... >> Important Bulletins: ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: <<< SECURITY BULLETINS THIS MONTH>>>
    ... DON'T install the other WU recommended updates ... >> MS04-033 - Vulnerability in Microsoft Excel Could Allow Code Execution ... >> Important Bulletins: ...
    (microsoft.public.windows.server.sbs)
  • Re: <<< SECURITY BULLETINS THIS MONTH>>>
    ... DON'T install the other WU recommended updates ... >> MS04-033 - Vulnerability in Microsoft Excel Could Allow Code Execution ... >> Important Bulletins: ...
    (microsoft.public.backoffice.smallbiz)
  • Re: Critical Updates
    ... > could allow code execution, KB841872-Vulnerability in> POSIX could allow code execution, and KB842526-> Vulnerability in Utility Manager could allow code ... Concurrent with these updates, Users were> unable to log into our internal web pages, or edit public> or internal pages. ... Security Properties for the directory> in question included Web Anonymous User, which only had> deny "write" checked. ... Is there anything in the updates> that made any changes to anonymous user or ADDED anonymous> user to webroot? ...
    (microsoft.public.inetserver.iis.security)