This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS Tying IE Changes In Security Patch Sparks Backlash

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/article/printableAr…_section=700028
April 12, 2006
"By packaging a functionality change for Internet Explorer with a needed security update, Microsoft has alienated some IT pros, security vendors complained Wednesday. Along with the 10 patches in Tuesday's MS06-013 security bulletin, Microsoft bundled changes to IE's handling of ActiveX controls. Those changes, which were prompted by a 2003 $521 million judgment against Microsoft in a patent lawsuit brought by Eolas Technologies Inc. and the University of California, will require users to manually activate controls on some sites… The inclusion of the ActiveX changes "makes everything a mess" for companies deploying and testing Microsoft's monthly patches, Murray said. "I've talked to some of our customers, and they're at the point where they're pulling out their hair"… Microsoft has posted a "compatibility patch*" to delay the court-mandated changes to IE until June 13, that month's scheduled bulletin release date, when the changes will be made permanent… In an alert to users of its DeepSight Threat Management System, Symantec advised enterprises to either update or consider dropping IE. "The DeepSight team strongly encourages system administrators to apply the fixes in this update as soon as possible," the alert read… Symantec and other security companies raised the alert in part because 3 of the 7 critical flaws described in the bulletin are either currently being exploited or have been the target of published proof-of-concept code…"

* http://support.microsoft.com/default.aspx/kb/917425?

:(
Posted at SWI 4.14.2006 13:08:
- http://forums.spywareinfo.com/index.php?sh…=0&#entry393996

"There are already reports of this update breaking programs that use IE behind the scenes… see …
http://support.microsoft.com/newsgroups/ne…a4-a509246944ff
… for one such report."

(Posted at microsoft.com/newsgroups/ 4/14/2006 10:28 AM PST: "…I just finished a 2 hour call to Microsoft Support and confirmed that KB908531 is the problem child and with the help of the support tech we narrowed it down to conflict with an HP Scanjet scanner 4470c software. I installed an updated HP driver 3.14 which still did not solve the problem.
He then had me add an entry to the Registry (really long) and this has resolved my problem with the three Imaging sofware packages that would hang on startup. Although I was skeptical at first, the support fellow as really good and I believe an updated Update will be available soon to fix the problem with KB908531. Hope this helps others…")

[The report pointed to KB908531 (MS06-015), which was a patch for "Windows Explorer";
…the IE Cumulative/patch was KB912812 (MS06-013).
'Could very well be related, though ("Which came first - chicken or egg?").]

:( ???
FYI…

- http://news.com.com/2102-1002_3-6061597.ht…g=st.util.print
Last modified Fri Apr 14 17:47:54 PDT 2006
"An Internet Explorer update released earlier this week can interfere with some applications, including Google's Toolbar, according to PatchLink, a maker of patch management software. Other applications affected by the Web browser patch include business software from Oracle's Siebel customer relationship management unit and certain Web applications that use specific versions of Java, PatchLink said Friday. The problems arise because of changes Microsoft made to how the Web browser handles Web programs called ActiveX controls… While the Google Desktop error appears to occur only in some instances, Siebel 7 users face a bigger problem. After installing the IE patch, users must click several times to be able to use the Siebel customer relationship management program, one time for each ActiveX control in the program, PatchLink said. Oracle is working with Microsoft to address the issue, a representative for the Redwood Shores, Calif.-based Oracle said. "In May, we anticipate issuing fixes to address this Microsoft problem for Siebel 7 users," the representative said in an e-mailed statement. Microsoft's patch can also affect ActiveX controls that use Java Platform, Standard Edition 1.3 or 1.4, PatchLink said. Users will have to click twice to be able to use such a Web program if it uses the affected Java versions, the patch management specialist said. A newer version of Java, 1.5, is not affected, it said…"

:(
FYI…

Patch Tuesday Fallout
- http://isc.sans.org/diary.php?storyid=1267
Last Updated: 2006-04-16 00:56:49 UTC
"Microsoft published a knowledge base article* about issues with MS06-015. The two main culprits appear to be HP's "Share-to-Web" software and Kerio Personal Firewall. In order to implement the MS06-015 fix, Microsoft created a special binary (VERCLSID.EXE) which will validate extensions before the windows shell or explorer is able to instantiate them. If VERCLSID.EXE fails to run, many functions are disructed (e.g. open files in applications using the 'File'->'Open' menu).
More stories about patch MS06-013 can be found in a recent Inforworld article**. This patch was expected to cause issues due to the changes in ActiveX functionality. Again, see the respective Microsoft statement***. Let us know if you experience any issues. So far, everything appears to center around 'Siebel 7'. Given the lack of outcries so far, I don't expect a lot of problems with other applications."

* http://support.microsoft.com/kb/918165

** http://ww6.infoworld.com/products/print_fr…Niepatch_1.html

*** http://support.microsoft.com/kb/912812

:(
FYI…

- http://www.microsoft.com/technet/security/…n/ms06-015.mspx
Updated April 15, 2006
"…Caveats: Microsoft Knowledge Base Article 918165 documents the currently known issues that customers may experience when they install this security update. The article also documents recommended solutions for these issues. For more information, see Microsoft Knowledge Base Article 918165*.
• V1.1 (April 15, 2006): Bulletin revised: “Caveats” section updated due to new issues discovered with the security update. Users may experience issues in Windows Explorer or the Windows shell after installing the update. Security Update Information revised to reflect correct file version information for Microsoft Windows XP and Microsoft Windows 2000…"

* http://support.microsoft.com/default.aspx/kb/918165
"…RESOLUTION
• Hewlett-Packard's Share-to-Web software. The MS06-015 (908531) ( http://www.microsoft.com/technet/security/…n/ms06-015.mspx ) security update includes a "white list"; VERCLSID.EXE will not scan any extension that appears on this list. Adding the HP shell extension corrects the problem. Manually edit the registry:
1. Log on to the computer with an account with administrator privileges.
2. Click the Start button and then click Run.
3. Type Regedit and then click OK.
4. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
5. Right-click "Cached", point to New, click "DWORD Value", and then enter:
{A4DF5659-0801-4A60-9607-1C48695EFDA9} {000214E6-0000-0000-C000-000000000046} 0x401
6. Set the Data of this value to 1
7. Close the Registry Editor.
8. Use Task Manager to end the Verclsid.exe process or restart the computer.
Note: If other third-party COM controls or shell extensions are determined to cause this issue, the same method must be used to add the appropriate shell extension.
• VERCLSID.EXE process flagged by Sunbelt Kerio Personal Firewall. Kerio Personal Firewall Users can configure Kerio to allow VERCLSID.EXE to execute without prompting.
It has not been determined if there are other third-party COM controls or shell extensions that may also cause this problem. If the steps above do not resolve your issue, contact Microsoft Product Support Services…" (1-866-PCSafety)

.
FYI…

Update to the MS06-015 issue
- http://blogs.technet.com/msrc/default.aspx
posted Tuesday, April 18, 2006 1:43 AM by stepto
"Hi everyone, Mike Reavey here again. I wanted to follow up with the results of our investigation into some issues with security update MS06-015. Turns out that under certain circumstances, changes introduced in MS06-015 could cause an application to stop responding during specific interactions with older versions of Hewlett Packard’s “Share-to-web” software utility, or older NVIDIA video card drivers. In the case of the Hewlett Packard software, their new version known as “HP Image Zone Version 5” is not affected. Neither are the most recent NVIDIA graphics card drivers. So customers running these more recent versions are not affected by this issue. The current versions of the Hewlett Packard and NVIDIA software are available from the manufacturer websites.
To give you some idea of the scope of the problem, so far out of over 120 million successful installations of the MS06-015 update, the number of calls related to this issue is currently well under a thousand. Of course, even one customer having a problem is too many and that’s why we’ve been working on investigating this and determining solutions. We are also continuing to monitor the situation to measure scope and impact.
We’ve updated security bulletin MS06-015 to document this issue. In addition, we published knowledge base article 918165*, which details the older software this issue affects. We’ll be updating that soon to provide locations to the updated software that is unaffected by this issue. We’re working directly with the manufactures of the affected software to assist customers.
So to be clear, customers who are running the latest NVIDIA drivers, or who are running the current version of the Hewlett Packard Image Zone software are not impacted. Customers who believe they are affected should upgrade to the latest versions of the affected software, or they can contact Microsoft Product Support Services for assistance. Contact Product Support Services in North America for help with security update issues at no charge using the PC Safety line (1-866-PCSAFETY) and international customers by using any method found at this location: http://support.microsoft.com/security.
Meanwhile we're still looking at the best way to assist customers who may have been impacted by this and I encourage everyone to review KB article 918165* or contact us using the number above if they think they are having the problem…"

* http://support.microsoft.com/kb/918165/en-us

:(
FYI…

Latest Microsoft Security Glitch Limited
- http://www.internetnews.com/security/article.php/3599756
April 18, 2006
"UPDATED: Microsoft said a limited range of consumer software is to blame for its latest security update unintentionally backfiring on Office and IE users. The update was among five the company released last week. Some analysts say the software giant's solution doesn't go far enough and is courting disaster. Digital photography software from HP and a personal firewall from Sunbelt Software rejected a new file Microsoft introduced as part of a security fix for a flaw in Windows Explorer. The glitch causes Office to stop saving and opening files and prevents IE from visiting Web pages. The problems reported appear limited to consumer-oriented software, Microsoft stresses on its security blog. MS06-015 included a new file, VERCLSID.EXE, which validates shell extensions before being used by Windows Explorer or Windows Shell. A vulnerability in Windows Explorer, which Microsoft deemed "important," allowed remote attackers to convince the shell to start HTML applications, thereby gaining total system control. However, the solution seems to be creating problems for some applications.
In explaining the glitch, Microsoft said HP's Share-to-Web software causes VERCLSID.EXE to stop responding. The software, used by HP's PhotoSmart software, HP DeskJet printers that include a card reader, HP cameras and scanners, as well as some HP CD-DVD burners, can also cause trouble for Windows Explorer and IE, according to Microsoft. Windows users may lose access to their "My Documents" and "My Pictures" folders. Office could stop opening or saving files in "My Documents". Attempting to open or save a document could cause Office to stop responding, according to Microsoft. Additionally, the problem causes typing an address into IE to have no effect. Also, users of Sunbelt's Kerio Personal Firewall will need to reconfigure that application to recognize the new Microsoft file. Without the change, the file is flagged and waits for user approval.
To resolve the issue, Microsoft is suggesting HP users manually edit the Windows registry "white list" included with the security update. The edit will instruct VERCLSID.EXE to not scan the HP shell extension. Microsoft had no comment beyond the blog posting, according to Pete Voss, a company spokesman. HP did not return a request for comment by press time. Although the software giant gives instructions, analysts warn the process isn't for the faint of heart.
Joe Wilcox, analyst with JupiterResearch, said a misstep could make Windows unusable. Although Microsoft says the scope of the glitch is limited to consumers, Wilcox said the type of applications –- digital imaging and security –- are more important. While a couple of applications are known today, many more could be found to be affected tomorrow, according to the analyst. "The possible interactions are immeasurable," Wilcox said. Still, Microsoft has made much of its new-found focus on security and editing the Windows registry is not enough in this case. "You have to release an updated patch," said Wilcox."

:(
FYI…re-release available:

Microsoft Security Bulletin MS06-015
Vulnerability in Windows Explorer Could Allow Remote Code Execution (908531)
- http://www.microsoft.com/technet/security/…n/ms06-015.mspx
Updated: April 25, 2006
What updates does this release replace?
This security update replaces several prior security updates. The security bulletin IDs and affected operating systems are listed in the following table.
Bulletin ID … Windows 2000… Windows XP… Windows Server 2003
MS05-016 …..Not Replaced…… Replaced……. Replaced
MS05-008 …..Replaced………… Replaced……. Replaced
Does this update contain any security-related changes to functionality?
Yes. Besides the changes that are listed in the "Vulnerability Details" section of this bulletin, this update includes the following changes in security functionality:
• This security update introduces a new file, Verclsid.exe. Verclsid.exe is used to verify a COM object before it is instantiated by Windows Explorer.
• This security update includes a Defense in Depth change which ensures that prompting occurs consistently in Internet zone drag and drop scenarios…
Version: 2.0…
• V2.0 (April 25, 2006): Bulletin revised: This bulletin has been re-released to advise customers that revised versions of the security update are available for all products listed in the “Affected Software” section. Customers who have already applied the MS06-015 update who are not experiencing the problem need take no action. For additional information, see “Why did Microsoft reissue this bulletin on April 25, 2006.” in "Frequently asked questions (FAQ) related to this security update" section…"

:ph34r:
FYI…

MS Update to MS06-015 and a Separate Fix for AEC.SYS Issue
- http://isc.sans.org/diary.php?storyid=1286
Last Updated: 2006-04-26 23:10:42 UTC
"…Microsoft has also released a completely separate patch to fix an error associated with KB900485*, which fixes, and I quote:
"Date last published: 4/25/2006
Install this update to prevent an issue in which you may receive a 'stop 0x7e in AEC.SYS' error message on a computer that is running Windows XP Service Pack 2. The error may occur during startup, or after the system has started. AEC.SYS is the acoustic echo canceling driver. After you install this item, you may have to restart your computer."

Microsoft has told us that this patch is associated with the following:
"This is the ACE reliability update. It has been available via download center for several months; when people do hit the crash the Watson/OCA site refers them to the download. For non-security updates, especially things like this reliability update, we do try to have them posted on www.microsoft.com/downloads and available through Watson/OCA or other means for some period of time before pushing out through WU. This gives us additional confidence in the quality of the update before pushing out to several hundred million users.
This specific fix is a random timing bugcheck that can happen when using two-way audio (e.g. netmeeting, messenger, etc.) It is a random event that could happen at any time. If you hit it, and reboot, you might not ever hit it again; or you might hit it next month, or in a few months, or the next day.
We monitor the Watson/OCA crash data, and when we have a higher-volume hit in a Windows component that we can fix, we do so, and post it on download center. Over time, we then move the higher-volume cases to Windows Update. This is just one such case. Installing this update helps prevent people from crashing in the future."

Interesting insights into how things work inside the magic curtain…"

* http://support.microsoft.com/kb/900485
Last Review: April 26, 2006
Revision: 2.0

:scratch: :huh: