MS05-032: Vulnerability in Microsoft agent could allow spoofing (890046)



The information in this article applies to:

  • Microsoft Windows Server 2003, Datacenter Edition
  • Microsoft Windows Server 2003, Enterprise Edition
  • Microsoft Windows Server 2003, Standard Edition
  • Microsoft Windows Server 2003, Web Edition
  • Microsoft Windows Server 2003, 64-Bit Enterprise Edition
  • Microsoft Windows Server 2003, 64-Bit Datacenter Edition
  • Microsoft Windows Server 2003, Enterprise x64 Edition
  • Microsoft Windows Server 2003, Standard x64 Edition
  • Microsoft Windows Server 2003, Datacenter x64 Edition
  • Microsoft Windows Server 2003 SP1, when used with:
    • Microsoft Windows Server 2003, Datacenter Edition
    • Microsoft Windows Server 2003, Enterprise Edition
    • Microsoft Windows Server 2003, Standard Edition
    • Microsoft Windows Server 2003, Web Edition
    • Microsoft Windows Server 2003, 64-Bit Datacenter Edition
    • Microsoft Windows Server 2003, 64-Bit Enterprise Edition
  • Microsoft Windows XP Service Pack 1, when used with:
    • Microsoft Windows XP Home Edition
    • Microsoft Windows XP Professional
    • Microsoft Windows XP Media Center Edition
    • Microsoft Windows XP Tablet PC Edition
    • Microsoft Windows XP 64-Bit Edition Version 2003
  • Microsoft Windows XP Service Pack 2, when used with:
    • Microsoft Windows XP Home Edition
    • Microsoft Windows XP Professional
    • Microsoft Windows XP Media Center Edition
    • Microsoft Windows XP Tablet PC Edition
  • Microsoft Windows XP 64-Bit Edition Version 2003
  • Microsoft Windows XP Professional x64 Edition
  • Microsoft Windows 2000 Advanced Server SP3
  • Microsoft Windows 2000 Datacenter Server SP4
  • Microsoft Windows 2000 Advanced Server SP4
  • Microsoft Windows 2000 Datacenter Server SP3
  • Microsoft Windows 2000 Professional SP3
  • Microsoft Windows 2000 Professional SP4

Technical updates

August 9, 2005:
  • Microsoft updated this bulletin on August 9, 2005 to advise customers that a revised version of the security update is available for the following systems:
    • Microsoft Windows Server 2003 for Itanium-based Systems
    • Microsoft Windows Server 2003 with Service Pack 1 (SP1) for Itanium-based Systems
    • Microsoft Windows Server 2003 x64 Edition
    • Microsoft Windows XP Professional x64 Edition
  • The original security update successfully addressed the vulnerabilities that are described in this security bulletin for non-64-bit systems. No additional action is required for non-64-bit customers. However, on 64-bit systems, the kill bit that is documented in the "Does this update contain any security-related changes to functionality?" FAQ is not correctly enabled when you use a 32-bit version of Microsoft Internet Explorer. The kill bit is correctly enabled for 64-bit versions of Internet Explorer. We recommend that you install the revised security update even if you have installed the earlier version. The revised security update will be available through Windows Update and through Software Update Services (SUS) as appropriate. The revised security update will be recommended by the Microsoft Baseline Security Analyzer (MBSA). You do not have to uninstall the prior security update before you install the revised security update.
Microsoft has released security bulletin MS05-032. The security bulletin contains all the relevant information about the security update. This information includes file manifest information and deployment options. To see the security bulletin, visit the following Microsoft Web sites:


Modification Type:MinorLast Reviewed:7/26/2006
Keywords:kbHotfixServer kbQFE kbWinServ2003preSP1fix kbWinXPpreSP3fix kbSecurity KbSECBulletin KbSECVulnerability kbBug kbfix kbWin2000preSP5fix kbpubtypekc KB890046 kbAudEndUser kbAudITPRO