MS10-022 still relevant after installation

(imported topic written by jonaserlundhammarback91)

Hi

On some servers with OS Windows 2008 Standard SP2 server x86 the fixlet “ID: 1002229 MS10-022: Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution - VBScript 5.7 - Windows Server 2008 Gold/SP2” is still valid after the installation.

Installation proceed without any problems.

After reboot BigFix is still reporting that the fixlet is missing and needs to be installed.

The hotfix KB981349 is already installed on the server so it can not be re-installed/updated.

If I uninstall KB981349 the vbscript.dll becomes version 5.7.0.18005

and then run BigFix it will install it again and the fileversion is once again 5.7.6002.18222 ,

but BigFix still wants to install it’s fixlet “ID: 1002229 MS10-022: Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution - VBScript 5.7 - Windows Server 2008 Gold/SP2”

The relevance for this fixlet checks for version 5.7.6002.18440 in this specific case.

The version 5.7.6002.18222 should be valid according to http://support.microsoft.com/?kbid=981349

Anyone who as an idea how to solve this. Is this an error in the relevance expression?

BR

Jonas Erlund Hammarbäck

(imported comment written by liuhoting91)

The relevance on this particular Fixlet (as well as the Vista one) was slightly tweaked just yesterday. If you try again now it should work.