This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Ms04-040 Cumulative Security Update For Ie

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.microsoft.com/technet/security/…n/ms04-040.mspx
December 1, 2004
"Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Caveats: Microsoft Knowledge Base Article 889293 documents the currently known issues that customers may experience when they install this security update. The article also documents recommended solutions for these issues.
- http://support.microsoft.com/kb/889293

Important: This update may not include hotfixes that have been released since the release of MS04-004 or MS04-038. Customers who have received hotfixes from Microsoft or from their support providers since the release of MS04-004 or MS04-038 should not install this update. Instead customers should deploy update 889669.

This update contains several functionality and security changes which are documented in the FAQ section for this update…"

Updates for consumer platforms are available from the Windows Update Web site …"

:oops:
Additional info:

- http://www.techweb.com/article/printableAr…_section=700028
"…"Microsoft is releasing this security bulletin outside of its monthly security-bulletin release cycle to provide customers with a quality security update as soon as possible," a company spokesperson said.
The patch fixes the IFRAME vulnerability in Internet Explorer (IE) 6.0 that allowed hackers to create a buffer overflow, then gain control of the system. A working exploit has been available to attackers for nearly a month. In the interim, several attacks–including the Bofra worm and a six-hour-long stretch where a European ad-serving vendor directed innocent surfers to malicious Web sites–exploited the IFRAME vulnerability…

>>> Also on Wednesday, Microsoft corrected a problem in Windows Update, the primary patch-delivery service for individuals. "We discovered that customers running Windows XP SP1 have not been offered the updates that apply to their computer from the October monthly release," said the Microsoft spokesperson. "This is due to the fact that these updates are already included in Windows XP SP2, and this is the update that Windows Update and Automatic Updates presents to these users."

:blink: :blink:
FYI…from the Internet Storm Center:

- http://isc.sans.org/diary.php?date=2004-12-02
Updated December 3rd 2004 10:12 UTC
"MS04-040.
MS04-040 seems to have generated some discussion. Some readers have reported that the update did not install correctly, or did not mitigate the IFRAME vulnerability. Other conversations have involved the timing of the update release…

I installed it via WindowsUpdate and then checked the DLL versions after a reboot. Lo and behold they were not the correct versions. There are reports the PoC code may in fact still work. I manually downloaded and installed the patch and it seems to have worked…"

:blink: :(