Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Description of the security update for Windows XP and Windows Server 2003: June 13, 2017


View products that this article applies to.

Summary

WebDAV remote code execution vulnerability

A vulnerability exists in IIS when WebDAV improperly handles objects in memory, which could allow an attacker to run arbitrary code on the user’s system. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user.

To exploit this vulnerability, an attacker would have to send a specially crafted HTTP request to the affected system.

The update addresses the vulnerability by changing how WebDAV handles objects in memory. The following table contains links to the standard entry for each vulnerability in the Common Vulnerabilities and Exposures list:

Vulnerability title

CVE number

Publicly disclosed

Exploited

WebDAV Remote Code Execution Vulnerability

CVE-2017-7269

Yes

Yes

Mitigating Factors

Mitigating Factors

Microsoft has not identified any mitigating factors for this vulnerability.

Workarounds

Microsoft has not identified any workarounds for this vulnerability.

↑ Back to the top


More Information

Important
 
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

↑ Back to the top


How to obtain and install the update

Method 1: Microsoft Update Catalog

To get the stand-alone package for this update, go to the Microsoft Update Catalog website.

Method 2: Microsoft Download Center

The following files are available for download from the Microsoft Download Center.



For all x86-based versions of Windows Server 2003

Download the package now



For all x64-based versions of Windows Server 2003

Download the package now



For all x86-based versions of Windows XP

Download the package now



For all x64-based versions of Windows XP

Download the package now



For all versions of Windows XP Embedded

Download the package now



For all versions of Windows Embedded POS Ready 2009

Download the package now

Release Date: June 13, 2017

For more information about how to download Microsoft support files, click the following article number to go to the article in the Microsoft Knowledge Base:



Virus-scan claim

Microsoft scanned this file for viruses by using the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help prevent any unauthorized changes to it.

↑ Back to the top


Deployment information

For deployment details for this security update, go to the following article in the Microsoft Knowledge Base:

↑ Back to the top


More Information

How to obtain help and support for this security update
Help for installing updates: Windows Update: FAQ

Security solutions for IT professionals: TechNet Security Support and Troubleshooting

Help for protecting your Windows-based computer from viruses and malware: Microsoft Secure

Local support according to your country: International Support

↑ Back to the top


File Information

File hash information
File name SHA1 hash SHA256 hash
WindowsServer2003-KB3197835-x64-custom-ENU.exe 8E98E29D5EC7BE84A2F68F654C983847A8504D27 1D4C6D290EF276F2EB4A5C6363940B73B75A5F0A94F88FF141F85093A2C9A568
WindowsServer2003-KB3197835-x86-custom-ENU.exe 3C4A7783A9823543F4E79CC1E21239A97EDBF045 8FE0B742950105FCD802A112E47023EF0FB881C20DFC887260E6AB35968AA126


File information
The English (United States) version of this software update installs files that have the attributes that are listed in the following tables.

For all supported x64-based versions
File name File version File size Date Time Platform
Httpext.dll 6.0.3790.5955 492,544 07-Oct-2016 05:16 x64
Whttpext.dll 6.0.3790.5955 241,664 07-Oct-2016 05:16 x86
Updspapi.dll 6.3.4.1 462,128 07-Oct-2016 05:19 x64

 

For all supported x86-based versions
File name File version File size Date Time Platform
Httpext.dll 6.0.3790.5955 241,664 07-Oct-2016 20:08 x86
Updspapi.dll 6.3.4.1 379,184 16-May-2014 02:29 x86

↑ Back to the top


Keywords: atdownload, kbbug, kbexpertiseinter, kbfix, kblangall, kbmustloc, kbsecbulletin, kbsecreview, kbsecurity, kbsecvulnerability, kbsurveynew, kb

↑ Back to the top

Article Info
Article ID : 3197835
Revision : 24
Created on : 4/13/2020
Published on : 4/13/2020
Exists online : False
Views : 563