Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Description of the security update for Windows XP and Windows Server 2003: June 13, 2017


View products that this article applies to.

Summary

Windows olecnv32.dll remote code execution vulnerability

A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input. An attacker could exploit the vulnerability to execute malicious code.

To exploit the vulnerability, an attacker would have to convince a user to open either a specially crafted file or a program from either a webpage or an email message.

The update addresses the vulnerability by correcting how Windows OLE validates user input.

The following table contains links to the standard entry for each vulnerability in the Common Vulnerabilities and Exposures list:

Vulnerability title

CVE number

Publicly disclosed

Exploited

Windows olecnv32.dll Remote Code Execution Vulnerability

CVE-2017-8487

Yes

Yes

 

Mitigating Factors

Microsoft has not identified any mitigating factors for this vulnerability.

Workarounds

Microsoft has not identified any workarounds for this vulnerability.

↑ Back to the top


More Information

Important
 
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

↑ Back to the top


How to obtain and install the update

Method 1: Microsoft Update Catalog

To get the stand-alone package for this update, go to the Microsoft Update Catalog website.

Method 2: Microsoft Download Center

The following files are available for download from the Microsoft Download Center.



For all x86-based versions of Windows Server 2003

Download the package now



For all x64-based versions of Windows Server 2003

Download the package now



For all x86-based versions of Windows XP

Download the package now



For all x64-based versions of Windows XP

Download the package now



For all versions of Windows XP Embedded

Download the package now

Release Date: June 13, 2017

For more information about how to download Microsoft support files, click the following article number to go to the article in the Microsoft Knowledge Base:



Virus-scan claim

Microsoft scanned this file for viruses by using the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help prevent any unauthorized changes to it.

↑ Back to the top


Deployment information

For deployment details for this security update, go to the following article in the Microsoft Knowledge Base:

↑ Back to the top


More Information

How to obtain help and support for this security update
Help for installing updates: Windows Update: FAQ

Security solutions for IT professionals: TechNet Security Support and Troubleshooting

Help for protecting your Windows-based computer from viruses and malware: Microsoft Secure

Local support according to your country: International Support

↑ Back to the top


File Information

File hash information
File name SHA1 hash SHA256 hash
WindowsServer2003-KB4025218-x64-custom-ENU.exe C58EA3F1A4E71FCF141A4D45A058AE6640F73C11 6F43F4407BFF6B54623F5CD47FB89098CC7EF0A889E49394CB2437A946BC95F2
WindowsServer2003-KB4025218-x86-custom-ENU.exe 9405EE1A1EBBD332BA9E993C7A75A73414167B36 8C411D8C06D147B93A1BD420B57A532CF7B496E71B6353F51FE66AC26F341CF1


File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables.

For all supported x64-based versions
File name File version File size Date Time Platform
Olecnv32.dll 5.2.3790.6113 56,832 07-Jun-2017 09:29 x64 SP2
Wolecnv32.dll 5.2.3790.6113 38,912 07-Jun-2017 09:29 x86 SP2
Updspapi.dll 6.3.4.1 462,128 07-Jun-2017 09:31 x64

 

For all supported x86-based versions
File name File version File size Date Time Platform
Olecnv32.dll 5.2.3790.6113 38,912 07-Jun-2017 19:26 x86
Updspapi.dll 6.3.4.1 379,184 16-May-2014 03:14 x86

↑ Back to the top


Keywords: atdownload, kbbug, kbexpertiseinter, kbfix, kblangall, kbmustloc, kbsecbulletin, kbsecreview, kbsecurity, kbsecvulnerability, kbsurveynew, kb

↑ Back to the top

Article Info
Article ID : 4025218
Revision : 24
Created on : 4/13/2020
Published on : 4/13/2020
Exists online : False
Views : 404