What would happen if I install this update and then undo the workaround from
Microsoft Security Advisory 972890?
In this scenario, customers of Windows Vista and Windows Server 2008 install
this security update for defense-in-depth and then either manually undo the
workaround from Microsoft Security Advisory 972890, or use the automated
Microsoft Fix it solution in Microsoft Knowledge Base Article 972890 to
disable the workaround. Such customers will no longer prevent the Microsoft
Video ActiveX Control from running in Internet Explorer, making their systems
vulnerable. Also, such systems will not be reoffered this update since future
detection results will yield the successful installation that was undone by
workaround.
--
Sandy Wood
Orange County District Attorney
Apparently the "workaround" does the same thing that the "update" does
regarding that vulnerability. The update addresses other items though,
and should be taken advantage of.
> Now that the Security Bulletin is
> released we're wondering what would happen should we apply MS09-032
> and then
> undo the fix in 927890.
You would be "updated" but then you would be undoing that part of the
update that addresses that particular issue. You would then no longer be
offered that update because it is already installed - and remain
vulnerable do to your manual mis-configuration.
> MS09-032 answers the question by describing a
> scenario of Vista and Win 2008 systems, not XP or Win 2003. Here's the
> FAQ
> I'm talking about:
>
> What would happen if I install this update and then undo the
> workaround from
> Microsoft Security Advisory 972890?
>
> In this scenario, customers of Windows Vista and Windows Server 2008
> install
> this security update for defense-in-depth and then either manually
> undo the
> workaround from Microsoft Security Advisory 972890, or use the
> automated
> Microsoft Fix it solution in Microsoft Knowledge Base Article 972890
> to
> disable the workaround. Such customers will no longer prevent the
> Microsoft
> Video ActiveX Control from running in Internet Explorer, making their
> systems
> vulnerable. Also, such systems will not be reoffered this update since
> future
> detection results will yield the successful installation that was
> undone by
> workaround.
Clear as mud...
For people between the ages of 20 and 57, it is not a good idea to stick
your fingers in an energized lightbulb socket.
It is still a good idea to get the update rather than to rely on only
the workaround. The update does other things as well as address that
vulnerability.
"Sandy Wood" <sandy...@nospam.com> wrote in message
news:46A498EB-F6D7-424B...@microsoft.com...
Sandy Wood wrote:
> So it sounds like the update does the same thing as the workaround!
>
--
ET
PSS
ET wrote:
> It is recommended to install the update even if you have done the work
> around.
>
"ET" <e...@microsoft.com> wrote in message
news:1795F85C-CD97-4561...@microsoft.com...
Such as...?
With all due respect, MS09-032 only addresses MS Video ActiveX Control
Vulnerability - CVE-2008-0015, as does the FixIt some had used before
MS09-032 was released. See the Vulnerability Information section of
http://www.microsoft.com/technet/security/bulletin/MS09-032.mspx
--
~PA Bear
What kill bits does this Cumulative Security Update of ActiveX Kill Bits
contain?
This Cumulative Security Update of ActiveX Kill Bits contains all kill
bits previously released in MS08-023, Security Update of ActiveX Kill
Bits; MS08-032, Cumulative Security Update of ActiveX Kill Bits; and
advisories entitled Update Rollup for ActiveX Kill Bits, Microsoft
Security Advisory 953839, Microsoft Security Advisory 956391, Microsoft
Security Advisory 960715, and Microsoft Security Advisory 969898.
"PA Bear [MS MVP]" <PABe...@gmail.com> wrote in message
news:ej7bSiMC...@TK2MSFTNGP05.phx.gbl...
And if they hadn't been installed already, chances are that user's
encountered far worse problems by now. <eg>