Security Advisory 2736233: Fixlet Request

(imported topic written by CSL2012)

Can a fixlet be provided for Microsoft Security Advisory 2736233? This patch was released (9/11/2012).

An update (KB2736233) for Microsoft Security Advisory: Update Rollup for ActiveX Kill Bits

Affected Software:

• Microsoft Windows XP

• Windows Server 2003

• Windows Vista

• Windows Server 2008

• Windows 7

• Windows Server 2008 R2

Summary:

This update sets the kill bits for the following third-party software:

Cisco Secure Desktop. The following Class Identifier relates to a request by Cisco to set a kill bit for an ActiveX control that is vulnerable. For more information regarding security issues in the Cisco Secure Desktop ActiveX control, please see the Cisco Security Advisory, Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client. The class identifiers (CLSIDs) for this ActiveX control are as listed in the Third-Party Kill Bits section of this advisory.

Cisco Hostscan. The following Class Identifier relates to a request by Cisco to set a kill bit for an ActiveX control that is vulnerable. For more information regarding security issues in the Cisco Hostscan ActiveX control, please see the Cisco Security Advisory, Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client. The class identifiers (CLSIDs) for this ActiveX control are as listed in the Third-Party Kill Bits section of this advisory.

Cisco AnyConnect Secure Mobility Client. The following Class Identifier relates to a request by Cisco to set a kill bit for an ActiveX control that is vulnerable. For more information regarding security issues in the Cisco AnyConnect Secure Mobility Client ActiveX control, please see the Cisco Security Advisory, Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client. The class identifiers (CLSIDs) for this ActiveX control are as listed in the Third-Party Kill Bits section of this advisory.

More Information: http://technet.microsoft.com/en-us/security/advisory/2736233

Windows 2003x86 - http://www.microsoft.com/en-us/download/details.aspx?id=34640

Windows 2003x64 - http://www.microsoft.com/en-us/download/details.aspx?id=34648

Windows 2008R2 - http://www.microsoft.com/en-us/download/details.aspx?id=34644

Thanks,

Chi

(imported comment written by CSL2012)

Correction to the url for the patch’s

Patch Download

Windows 2003x86

http://download.microsoft.com/download/1/1/7/117B7D96-0A78-460D-80F3-0EA6F0DE8D02/WindowsServer2003-KB2736233-x86-ENU.exe

Windows 2003x64

http://download.microsoft.com/download/7/4/3/74382B73-DA92-41AA-A174-581468888627/WindowsServer2003.WindowsXP-KB2736233-x64-ENU.exe

Windows 2008R2

http://download.microsoft.com/download/6/3/1/6319FAFC-6F64-4399-92F1-6C46A1C80F82/Windows6.1-KB2736233-x64.msu

(imported comment written by TerryWeiChao)

Hey Chi,

New Fixlet Messages:

2736233: Update Rollup for ActiveX Kill Bits - Windows Server 2008 SP2 (x64) (ID: 273623317)

2736233: Update Rollup for ActiveX Kill Bits - Windows Server 2003 SP2 (x64) (ID: 273623307)

2736233: Update Rollup for ActiveX Kill Bits - Windows Server 2008 R2 Gold/SP1 (x64) (ID: 273623325)

2736233: Update Rollup for ActiveX Kill Bits - Windows Vista SP2 (x64) (ID: 273623313)

2736233: Update Rollup for ActiveX Kill Bits - Windows 7 Gold/SP1 (x64) (ID: 273623323)

2736233: Update Rollup for ActiveX Kill Bits - Windows XP SP2 (x64) (ID: 273623303)

2736233: Update Rollup for ActiveX Kill Bits - Windows Vista SP2 (ID: 273623311)

2736233: Update Rollup for ActiveX Kill Bits - Windows Server 2003 SP2 (ID: 273623305)

2736233: Update Rollup for ActiveX Kill Bits - Windows 7 Gold/SP1 (ID: 273623321)

2736233: Update Rollup for ActiveX Kill Bits - Windows Server 2008 SP2 (ID: 273623315)

2736233: Update Rollup for ActiveX Kill Bits - Windows XP SP3 (ID: 273623301)

Reason for Update:

Microsoft released Security Advisory 2736233.

Published site version:

Patches for Windows (English), version 1655

Have a nice weekend!

-Terry

(imported comment written by CSL2012)

Thank you. Have a nice weekend.

Chi

(imported comment written by MBARTOSH)

I am having trouble with this patch. I am getting a Failed status on most of my Windows 7 machines. I manually installed it on one Win7 computer that failed in Bigfix, and it said it was already installed. Then when I run the fixlet through Bigfix, it goes to pending restart when it should have been not relevant. Then when I restart, I get a failed status. I get the same result if I run it multiple times even though the log says not relevant. It seems that the relevance check is not correct.

(imported comment written by sylviabeing)

May I have the fixlet ID and client logs?

(imported comment written by SystemAdmin)

Hi

I got the same trouble on win 2008R2 server.

any idea how to fix it?

I tried to run qna, its showing relevance 7 is true on some of the win 2008R2 machine.

when I run manual install, it pop up patch already installed.

Thanks

Sun

(imported comment written by SystemAdmin)

forgot to mention this is 273623325

(imported comment written by TerryWeiChao)

Thanks for the information. The patch itself will update several registry keys in the target platform. I am thinking the fixlet detect something missing in the registry. It would be great if you can contact our support and we can do further checking on your system.

Thanks!

(imported comment written by MBARTOSH)

This problem was fixed with the PMR I opened. The PMR number is 87720,227,000.