Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

MS09-032 Installation

0 views
Skip to first unread message

Sandy Wood

unread,
Jul 15, 2009, 2:18:01 PM7/15/09
to
The security bulletin for MS09-032 fixes an ActiveX vulnerability first
described in Security Advisory 972890. We applied the workaround described
there for our XP and Windows 2003 systems. Now that the Security Bulletin is
released we're wondering what would happen should we apply MS09-032 and then
undo the fix in 927890. MS09-032 answers the question by describing a
scenario of Vista and Win 2008 systems, not XP or Win 2003. Here's the FAQ
I'm talking about:

What would happen if I install this update and then undo the workaround from
Microsoft Security Advisory 972890?

In this scenario, customers of Windows Vista and Windows Server 2008 install
this security update for defense-in-depth and then either manually undo the
workaround from Microsoft Security Advisory 972890, or use the automated
Microsoft Fix it solution in Microsoft Knowledge Base Article 972890 to
disable the workaround. Such customers will no longer prevent the Microsoft
Video ActiveX Control from running in Internet Explorer, making their systems
vulnerable. Also, such systems will not be reoffered this update since future
detection results will yield the successful installation that was undone by
workaround.
--
Sandy Wood
Orange County District Attorney

@nomail.afraid.org FromTheRafters

unread,
Jul 15, 2009, 5:09:02 PM7/15/09
to
"Sandy Wood" <sandy...@nospam.com> wrote in message
news:A3737A7F-81DA-49E0...@microsoft.com...

> The security bulletin for MS09-032 fixes an ActiveX vulnerability
> first
> described in Security Advisory 972890. We applied the workaround
> described
> there for our XP and Windows 2003 systems.

Apparently the "workaround" does the same thing that the "update" does
regarding that vulnerability. The update addresses other items though,
and should be taken advantage of.

> Now that the Security Bulletin is
> released we're wondering what would happen should we apply MS09-032
> and then
> undo the fix in 927890.

You would be "updated" but then you would be undoing that part of the
update that addresses that particular issue. You would then no longer be
offered that update because it is already installed - and remain
vulnerable do to your manual mis-configuration.

> MS09-032 answers the question by describing a
> scenario of Vista and Win 2008 systems, not XP or Win 2003. Here's the
> FAQ
> I'm talking about:
>
> What would happen if I install this update and then undo the
> workaround from
> Microsoft Security Advisory 972890?
>
> In this scenario, customers of Windows Vista and Windows Server 2008
> install
> this security update for defense-in-depth and then either manually
> undo the
> workaround from Microsoft Security Advisory 972890, or use the
> automated
> Microsoft Fix it solution in Microsoft Knowledge Base Article 972890
> to
> disable the workaround. Such customers will no longer prevent the
> Microsoft
> Video ActiveX Control from running in Internet Explorer, making their
> systems
> vulnerable. Also, such systems will not be reoffered this update since
> future
> detection results will yield the successful installation that was
> undone by
> workaround.

Clear as mud...

For people between the ages of 20 and 57, it is not a good idea to stick
your fingers in an energized lightbulb socket.


Sandy Wood

unread,
Jul 15, 2009, 5:44:01 PM7/15/09
to
So it sounds like the update does the same thing as the workaround!

--
Sandy Wood
Orange County District Attorney

@nomail.afraid.org FromTheRafters

unread,
Jul 15, 2009, 5:58:15 PM7/15/09
to
Regarding that particular vulnerability, yes.

It is still a good idea to get the update rather than to rely on only
the workaround. The update does other things as well as address that
vulnerability.

"Sandy Wood" <sandy...@nospam.com> wrote in message

news:46A498EB-F6D7-424B...@microsoft.com...

PA Bear [MS MVP]

unread,
Jul 15, 2009, 6:00:24 PM7/15/09
to
Egggzzzzactly!

Sandy Wood wrote:
> So it sounds like the update does the same thing as the workaround!
>

ET

unread,
Jul 18, 2009, 9:44:01 PM7/18/09
to
It is recommended to install the update even if you have done the work around.

--
ET
PSS

PA Bear [MS MVP]

unread,
Jul 19, 2009, 12:17:48 PM7/19/09
to
QED: Will MS09-032 be offered by Automatic Updates or Windows Update if the
work-around is in place or the now-withdrawn FixIt was applied?

ET wrote:
> It is recommended to install the update even if you have done the work
> around.
>

@nomail.afraid.org FromTheRafters

unread,
Jul 19, 2009, 4:26:31 PM7/19/09
to
The vulnerability is addressed by the registry setting (whether done
manually or automatically). The update does other things *plus* makes
the appropriate registry setting. If a user applies the"workaround" the
user should still apply the update. After applying the update, it would
be a mistake to "undo" the workaround, making the system vulnerable
again, *plus* making it so that the update is not offered again even
though the system is now vulnerable to one of the things that the update
addressed.

"ET" <e...@microsoft.com> wrote in message
news:1795F85C-CD97-4561...@microsoft.com...

PA Bear [MS MVP]

unread,
Jul 19, 2009, 7:17:54 PM7/19/09
to
> The update does other things...

Such as...?

With all due respect, MS09-032 only addresses MS Video ActiveX Control
Vulnerability - CVE-2008-0015, as does the FixIt some had used before
MS09-032 was released. See the Vulnerability Information section of
http://www.microsoft.com/technet/security/bulletin/MS09-032.mspx
--
~PA Bear

@nomail.afraid.org FromTheRafters

unread,
Jul 19, 2009, 7:54:03 PM7/19/09
to
From http://www.microsoft.com/technet/security/bulletin/MS09-032.mspx

What kill bits does this Cumulative Security Update of ActiveX Kill Bits
contain?
This Cumulative Security Update of ActiveX Kill Bits contains all kill
bits previously released in MS08-023, Security Update of ActiveX Kill
Bits; MS08-032, Cumulative Security Update of ActiveX Kill Bits; and
advisories entitled Update Rollup for ActiveX Kill Bits, Microsoft
Security Advisory 953839, Microsoft Security Advisory 956391, Microsoft
Security Advisory 960715, and Microsoft Security Advisory 969898.

"PA Bear [MS MVP]" <PABe...@gmail.com> wrote in message
news:ej7bSiMC...@TK2MSFTNGP05.phx.gbl...

PA Bear [MS MVP]

unread,
Jul 19, 2009, 8:06:29 PM7/19/09
to
Well, one assumes all of those other updates have been installed already,
doesn't one?

And if they hadn't been installed already, chances are that user's
encountered far worse problems by now. <eg>

0 new messages