| PROBLEM: | A cumulative update for Internet Explorer has been released. It replaces MS05-025 (CIAC P-222) and MS05-037 (CIAC P-247) and also addresses additional security vulnerabilities. |
| PLATFORM: | Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4 Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 or on Microsoft Windows XP Service Pack 1 Internet Explorer 6 for Microsoft Windows XP Service Pack 2 Internet Explorer 6 for Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 Internet Explorer 6 for Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Millennium Edition - Review the FAQ section of this bulletin for details about this version. Internet Explorer 6 Service Pack 1 on Microsoft Windows 98, on Microsoft Windows 98 SE, or on Microsoft Windows Millennium Edition - Review the FAQ section of this bulletin for details about this version. |
| DAMAGE: | In addition to the cumulative update, new vulnerabilities addressed include: JPEG image rendering memory corruption vulnerability, web folder behaviors cross-domain vulnerability and COM object instantiation memory corruption vulnerability. |
| SOLUTION: | Apply the security updates. |
| VULNERABILITY ASSESSMENT: |
The risk is HIGH. A remote attacker who exploits the worst of these vulnerabilities may be able to take complete control of a victim’s machine. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/p-265.shtml |
| ORIGINAL BULLETIN: | http://www.microsoft.com/technet/security/bulletin/MS05-038.mspx |
| CVE/CAN: | http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CAN-2005-1988, CAN-2005-1989, CAN-2005-1990 |
REVISION HISTORY:
08/31/2005 - revised P-265 to reflect the following changes by Microsoft in
their Security Bulletin MS05-038: new packages available from the
Microsoft Download Center and updated Security Update Information
Section.
[***** Start Microsoft Security Bulletin MS05-038 *****]
Microsoft Security Bulletin MS05-038
Cumulative Security Update for Internet Explorer (896727)
Published: August 9, 2005|Updated: August 17, 2005
Version: 2.1
Summary
Who should read this document: Customers who use Microsoft Windows
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Recommendation: Customers should apply the update immediately.
Security Update Replacement This update replaces the update that is included with Microsoft Security Bulletin MS05-025. That update is also a cumulative update. This update also replaces the update that is included with Microsoft Security Bulletin MS05-037.
Caveats: Packages for this security update that were located on the Microsoft Download Center have been updated as the
initial packages were corrupt, causing some Systems Management Server (SMS) and Internet Explorere installation failures. New
packages are now available and Microsoft encourages users to re-download the packages from the links below and re-apply. Updates
downloaded from Automatic Update, Windows Update, Microsoft Update and Windows Server Update Services (WSUS), were not affected
by this issue.
Microsoft Knowledge Base Article 896727 documents the currently known issues that customers may experience when they install this security update. The article also documents recommended solutions for these issues. For more information, see Microsoft Knowledge Base Article 896727.
This update does include hotfixes that have been released since the release of MS04-004 or MS04-025, but they will only be installed on systems that need them. Customers who have received hotfixes from Microsoft or from their support providers since the release of MS04-004 or MS04-025 should review the “I have received a hotfix from Microsoft or my support provider since the release of MS04-004. Is that hotfix included in this security update?” question in the FAQ section of this bulletin to determine how you can make sure that the necessary hotfixes are installed. Microsoft Knowledge Base Article 896727 also documents this in more detail.
Tested Software and Security Update Download Locations:
Affected Software:
• Microsoft Windows 2000 Service Pack 4
• Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
• Microsoft Windows XP Professional x64 Edition
• Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
• Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with Service Pack 1 for Itanium-based Systems
• Microsoft Windows Server 2003 x64 Edition
• Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (ME) – Review the FAQ section of this bulletin for details about these operating systems.
Tested Microsoft Windows Components:
Affected Components:
• Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4 – Download the update
• Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 or on Microsoft Windows XP Service Pack 1 – Download the update
• Internet Explorer 6 for Microsoft Windows XP Service Pack 2 – Download the update
• Internet Explorer 6 for Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 – Download the update
• Internet Explorer 6 for Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems – Download the update
• Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition – Download the update
• Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition – Download the update
• Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Millennium Edition – Review the FAQ section of this bulletin for details about this version.
• Internet Explorer 6 Service Pack 1 on Microsoft Windows 98, on Microsoft Windows 98 SE, or on Microsoft Windows Millennium Edition – Review the FAQ section of this bulletin for details about this version.
The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.
Top of sectionGeneral Information