Source:
http://www.microsoft.com/technet/sec.../MS06-040.mspx This patch DOES apply to all Windows 2000 and XP not just servers. All Windows run the server services that must be patched. I thought it was important to get this out because it has been upgraded to a level 1 threat. Code to exploit this vulnerability has already hit the Internet and a new worm is inevitable and expected by Monday. PATCH AS SOON AS POSSIBLE Vulnerability in Server Service Could Allow Remote Code Execution (921883)
Published: August 8, 2006
Version: 1.0
<SCRIPT language=javascript>sID='l1-ELB'</SCRIPT>
Summary Who Should Read this Document: Customers who use Microsoft Windows
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Recommendation: Customers should apply the update immediately
Security Update Replacement: None
Caveats: None
Tested Software and Security Update Download Locations: Affected Software:
<TABLE cellSpacing=0 cellPadding=0 border=0><TBODY><TR><TD class=listBullet vAlign=top>•</TD><TD class=listItem>Microsoft Windows 2000 Service Pack 4 —
Download the update
</TD></TR><TR><TD class=listBullet vAlign=top>•</TD><TD class=listItem>Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2 —
Download the update
</TD></TR><TR><TD class=listBullet vAlign=top>•</TD><TD class=listItem>Microsoft Windows XP Professional x64 Edition —
Download the update
</TD></TR><TR><TD class=listBullet vAlign=top>•</TD><TD class=listItem>Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 —
Download the update
</TD></TR><TR><TD class=listBullet vAlign=top>•</TD><TD class=listItem>Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems —
Download the update
</TD></TR><TR><TD class=listBullet vAlign=top>•</TD><TD class=listItem>Microsoft Windows Server 2003 x64 Edition —
Download the update
</TD></TR></TBODY></TABLE>The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the
Microsoft Support Lifecycle Web site.
Note The security updates for Microsoft Windows Server 2003, Windows Server 2003 Service Pack 1, and Windows Server 2003 x64 Edition also apply to Windows Server 2003 R2.