False Positive? Is MS11-051 included in the 2008r2 Convenience Rollup Package?

I have several Windows 2008 R2 servers running Certificate Services, all showing relevant for Fixlet 1105109 “MS11-051: Vulnerability in Active Directory Certificate Services Web Enrollment … Windows Server 2008 R2 Gold/SP1 (x64)”. The Fixlet fails, the wusa.exe command returns -2145124329.

When I try to install manually, wusa says “The update is not applicable to your computer”.

The article at https://technet.microsoft.com/en-us/library/security/ms11-051.aspx makes no mention of this being superseded.

The article at https://support.microsoft.com/en-us/help/2518295/ms11-051-vulnerability-in-active-directory-certificate-services-web-enrollment-could-allow-elevation-of-privilege-june-14,-2011 has broken link to the “File attributes tables for security update 2518295.csv”.

I’m wondering whether the Convenience Rollup Package (which is installed on my hosts) contained this update. The article at https://support.microsoft.com/en-us/help/3125574/convenience-rollup-update-for-windows-7-sp1-and-windows-server-2008-r2-sp1 links a CSV of all updated files and their versions, and does include a lot of “likely” candidates - certenroll.dll, certutil.exe, certarc.asp, certcert.inc, certser.asp, and literally hundreds of other cert* files are included in the Convenience Rollup Package.

But the Fixlet Relevance for MS11-051 does not include a file versions check, and I can’t retrieve the file versions from the MS11-051 article, so … does anyone know if MS11-051 is included in KB3125574 Convenience Rollup? And, if so, can the MS11-051 Fixlets be updated to include a relevance check on the rollup?

My Windows 2008 R2 is not running certificate services, and so does not have any of the files.

  • certckpn.asp
  • certrqbi.asp
  • certrqma.asp
  • certrqxt.asp
  • certrsis.asp
  • certrspn.asp

If yours does, can you check to see if any of them have Version?
I strongly suspect they do not.

You might spot check date modified to see if it is before or after June 2011 (when MS11-051 was released)

1 Like

Correct, none have versions.

certckpn.asp Fri, 25 Mar 2016
certrqbi.asp Thu, 05 May 2011
certrqma.asp Thu, 05 May 2011
certrqxt.asp Thu, 05 May 2011
certrsis.asp Thu, 05 May 2011
certrspn.asp Sun, 21 Nov 2010

So, the certrspn.asp gives me pause, as it has an older date. The others look like they line up with the right time for MS11-051 (released June 2011), and certckpn.asp was updated much more recently. I’m having some difficulty finding from the MSU file just what binaries are provided in the MS11-051 update :frowning:

Hi JasonWalker,

MS11-051 is not included in KB3125574. MS11-051 (KB2518295) is not superseded by any newer patch either.

Reference:
http://www.catalog.update.microsoft.com/ScopedViewInline.aspx?updateid=6147e6c1-663b-41bc-9582-9579343857d9
http://www.catalog.update.microsoft.com/ScopedViewInline.aspx?updateid=d11a857d-fea5-419c-a7dd-3b6e38d055bc

error code -2145124329 means WU_E_NOT_APPLICABLE:
Operation was not performed because there are no applicable updates.

It is a possible false positive case. You may want to open a PMR with IBM support and provide any debugging info you have.

Regards,
Sylvia

Thank you very much!

Jason, did you ever get this squared away? I found your post via Google… We don’t use BigFix (bummer) but a Retina scan showed we need this patch on a server and the server says it is not applicable…

Just wondering what you found out with it…

Thanks

I’m afraid I never followed up on this, but it’s on my to-do list.