Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

MS13-066: Description of the security update for Active Directory Federation Services 1.x: August 13, 2013


View products that this article applies to.

INTRODUCTION

Microsoft has released security bulletin MS13-066. To view the complete security bulletin, go to the following Microsoft website:

How to obtain help and support for this security update

Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals:
TechNet Security Troubleshooting and Support

Help protect your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country:
International Support

↑ Back to the top


More Information

Additional steps required to install this security update

After you install this security update, follow these steps to manually complete the installation:
  1. Make a backup copy of the customized clientlogon.aspx page in the following folder:

    %systemdrive%\Windows\SystemData\ADFS\sts\ls
    Make sure that you store the backup in a reliable storage location.

    Note All customizations to .asp files should be reliably backed up, preferably by using version control.
  2. In the backup folder, edit the Clientlogon.aspx page to add the text "autocomplete=off" for the Username and Password textboxes. To do this, follow these steps:
    1. Change the following:

      <asp:TextBox runat="server" ID="UsernameTextBox">
      To the following:

      <asp:TextBox runat="server" ID="UsernameTextBox" autocomplete="off">
    2. Change the following:

      <asp:TextBox runat="server" ID="PasswordTextBox" TextMode="Password">


      To the following:

      <asp:TextBox runat="server" ID="PasswordTextBox" TextMode="Password" autocomplete="off">
  3. Copy the updated Clientlogon.aspx page to the following folder:

    %systemdrive%\Windows\SystemData\ADFS\sts\ls

↑ Back to the top


FILE INFORMATION

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.
Windows Server 2003 file information
  • The files that apply to a specific milestone (SPn) and service branch (QFE, GDR) are noted in the "SP requirement" and "Service branch" columns.
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. QFE service branches contain hotfixes in addition to widely released fixes.
  • In addition to the files that are listed in these tables, this software update also installs an associated security catalog file (KBnumber.cat) that is signed with a Microsoft digital signature.

For all supported x64-based versions of Windows Server 2003

File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Adfsreg.exe5.2.3790.45789,21605-Jul-201301:17x64SP2SP2QFE
Ifsext.dll5.2.3790.457896,25605-Jul-201301:18x64SP2SP2QFE
Ifsfilt.dll5.2.3790.457828,67205-Jul-201301:18x64SP2SP2QFE
Ifsutils.dll5.2.3790.4578144,89605-Jul-201301:18x64SP2SP2QFE
System.web.security.singlesignon.dll5.2.3790.5190585,72805-Jul-201301:18x86SP2SP2QFE

For all supported x86-based versions of Windows Server 2003

File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Adfsreg.exe5.2.3790.45787,68024-Aug-200911:57x86SP2SP2QFE
System.web.security.singlesignon.dll5.2.3790.5190585,72804-Jul-201312:34x86SP2SP2QFE
Ifsext.dll5.2.3790.519077,82404-Jul-201312:29x86SP2SP2QFE\IA
Ifsfilt.dll5.2.3790.519020,48004-Jul-201312:29x86SP2SP2QFE\IA
Ifsutils.dll5.2.3790.5190101,37604-Jul-201312:29x86SP2SP2QFE\IA
Ifsext.dll5.2.3790.519077,82404-Jul-201312:29x86SP2SP2QFE\ID
Ifsfilt.dll5.2.3790.519020,48004-Jul-201312:29x86SP2SP2QFE\ID
Ifsutils.dll5.2.3790.5190101,37604-Jul-201312:29x86SP2SP2QFE\ID
Ifsext.dll5.2.3790.519077,82404-Jul-201312:29x86SP2SP2QFE\IS
Ifsfilt.dll5.2.3790.519020,48004-Jul-201312:29x86SP2SP2QFE\IS
Ifsutils.dll5.2.3790.5190101,37604-Jul-201312:29x86SP2SP2QFE\IS

↑ Back to the top


Windows Server 2008 file information
  • The files that apply to a specific product, milestone (SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.0.6002. 18xxxWindows Server 2008 SP2SP2GDR
    6.0.6002. 23xxxWindows Server 2008 SP2SP2LDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
Note The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.

For all supported x86-based versions of Windows Server 2008

File nameFile versionFile sizeDateTimePlatform
System.web.security.singlesignon.dll6.0.6002.18880589,82405-Jul-201316:09x86
System.web.security.singlesignon.dll6.0.6002.23152589,82405-Jul-201316:09x86

For all supported x64-based versions of Windows Server 2008

File nameFile versionFile sizeDateTimePlatform
System.web.security.singlesignon.dll6.0.6002.18880589,82405-Jul-201316:14x86
System.web.security.singlesignon.dll6.0.6002.23152589,82405-Jul-201316:14x86

↑ Back to the top


Windows Server 2008 R2 file information
  • The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.1.7601. 18xxxWindows 7 and Windows Server 2008 R2SP1GDR
    6.1.7601. 22xxxWindows 7 and Windows Server 2008 R2SP1LDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
Note The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.

For all supported x64-based versions of Windows Server 2008 R2

File nameFile versionFile sizeDateTimePlatform
System.web.security.singlesignon.dll6.1.7601.18199589,82403-Jul-201305:27x86
System.web.security.singlesignon.dll6.1.7601.22375589,82403-Jul-201305:07x86

↑ Back to the top


Keywords: kb, atdownload, kbbug, kbexpertiseinter, kbfix, kblangall, kbmustloc, kbsecbulletin, kbsecreview, kbsecurity, kbsecvulnerability, kbsurveynew

↑ Back to the top

Article Info
Article ID : 2868846
Revision : 1
Created on : 1/7/2017
Published on : 8/19/2013
Exists online : False
Views : 261