Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Security update for the information disclosure vulnerability in Windows Server 2008: September 12, 2017


View products that this article applies to.

Summary

An information disclosure vulnerability exists in the Microsoft Common Console Document (.msc) when it improperly parses XML input that contains a reference to an external entity. An attacker who successfully exploits this vulnerability could read arbitrary files via an XML external entity (XXE) declaration.

To learn more about the vulnerability, see  CVE-2017-8710.

↑ Back to the top


More Information

Important
 
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

↑ Back to the top


How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Windows Update: FAQ.

Method 2: Microsoft Update Catalog

To get the stand-alone package for this update, go to the Microsoft Update Catalog website.

↑ Back to the top


Deployment information

For deployment details for this security update, go to the following article in the Microsoft Knowledge Base:

↑ Back to the top


More Information

How to obtain help and support for this security update
Help for installing updates: Windows Update: FAQ

Security solutions for IT professionals: TechNet Security Support and Troubleshooting

Help for protecting your Windows-based computer from viruses and malware: Microsoft Secure

Local support according to your country: International Support

↑ Back to the top


File Information

File hash information
File name SHA1 hash SHA256 hash
Windows6.0-KB4039038-x86.msu 8601160898D5E7C6CD20305A73698F3A59A7756C BE15C873EBEDB02969DDAF09C2FE4A77AEC9C8E2C9AA4BD9AE60745379CCFC6A
Windows6.0-KB4039038-x64.msu AF469E3FF72EF6B6A4FA5C86086AB2A00F10D172 7EF22D00FA504C8CA62649CA200F9471FC1347E85F73E3AD9A6AD067A61C2A00
Windows6.0-KB4039038-ia64.msu BCC597D382E7F618096FA52C70C739B476B25C1A 69C40BEC32BFE5E2F4577B83E03DD19837641BC01F6D1257375C101F3640BEF7


File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time together with your current daylight-saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.

Windows Server 2008 file information

For all supported x86-based versions
File name File version File size Date Time Platform
Cic.dll 6.0.6002.19858 171,520 11-Aug-2017 03:03 x86
Mmc.exe 6.0.6002.19858 1,793,024 11-Aug-2017 00:16 x86
Mmc.mof Not applicable 698 18-Sep-2006 21:26 Not applicable
Mmcbase.dll 6.0.6002.19858 301,056 11-Aug-2017 03:03 x86
Mmcshext.dll 6.0.6002.19858 127,488 11-Aug-2017 03:03 x86
Cic.dll 6.0.6002.24180 171,520 13-Aug-2017 19:35 x86
Mmc.exe 6.0.6002.24180 1,793,024 13-Aug-2017 14:35 x86
Mmc.mof Not applicable 698 07-Mar-2016 23:34 Not applicable
Mmcbase.dll 6.0.6002.24180 301,056 13-Aug-2017 19:36 x86
Mmcshext.dll 6.0.6002.24180 127,488 13-Aug-2017 19:36 x86
Mmcndmgr.dll 6.0.6002.19858 2,167,808 11-Aug-2017 03:03 x86
Mmcndmgr.dll 6.0.6002.24180 2,167,808 13-Aug-2017 19:36 x86
For all supported x64-based versions
File name File version File size Date Time Platform
Cic.dll 6.0.6002.19858 206,848 11-Aug-2017 02:05 x64
Mmc.exe 6.0.6002.19858 2,716,160 11-Aug-2017 00:33 x64
Mmc.mof Not applicable 698 18-Sep-2006 21:24 Not applicable
Mmcbase.dll 6.0.6002.19858 349,696 11-Aug-2017 02:06 x64
Mmcshext.dll 6.0.6002.19858 127,488 11-Aug-2017 02:06 x64
Cic.dll 6.0.6002.24180 206,848 13-Aug-2017 19:32 x64
Mmc.exe 6.0.6002.24180 2,716,160 13-Aug-2017 14:44 x64
Mmc.mof Not applicable 698 07-Mar-2016 23:34 Not applicable
Mmcbase.dll 6.0.6002.24180 349,696 13-Aug-2017 19:33 x64
Mmcshext.dll 6.0.6002.24180 127,488 13-Aug-2017 19:33 x64
Mmcndmgr.dll 6.0.6002.19858 3,262,464 11-Aug-2017 02:06 x64
Mmcndmgr.dll 6.0.6002.24180 3,262,464 13-Aug-2017 19:33 x64
Cic.dll 6.0.6002.19858 171,520 11-Aug-2017 03:03 x86
Mmc.exe 6.0.6002.19858 1,793,024 11-Aug-2017 00:16 x86
Mmc.mof Not applicable 698 18-Sep-2006 21:26 Not applicable
Mmcbase.dll 6.0.6002.19858 301,056 11-Aug-2017 03:03 x86
Mmcshext.dll 6.0.6002.19858 127,488 11-Aug-2017 03:03 x86
Cic.dll 6.0.6002.24180 171,520 13-Aug-2017 19:35 x86
Mmc.exe 6.0.6002.24180 1,793,024 13-Aug-2017 14:35 x86
Mmc.mof Not applicable 698 07-Mar-2016 23:34 Not applicable
Mmcbase.dll 6.0.6002.24180 301,056 13-Aug-2017 19:36 x86
Mmcshext.dll 6.0.6002.24180 127,488 13-Aug-2017 19:36 x86
Mmcndmgr.dll 6.0.6002.19858 2,167,808 11-Aug-2017 03:03 x86
Mmcndmgr.dll 6.0.6002.24180 2,167,808 13-Aug-2017 19:36 x86
For all supported ia64-based versions
File name File version File size Date Time Platform
Cic.dll 6.0.6002.19858 401,920 11-Aug-2017 01:39 IA-64
Mmc.exe 6.0.6002.19858 5,194,240 11-Aug-2017 00:21 IA-64
Mmc.mof Not applicable 698 03-Jan-2008 18:37 Not applicable
Mmcbase.dll 6.0.6002.19858 521,728 11-Aug-2017 01:40 IA-64
Mmcshext.dll 6.0.6002.19858 219,648 11-Aug-2017 01:40 IA-64
Cic.dll 6.0.6002.24180 401,920 13-Aug-2017 19:34 IA-64
Mmc.exe 6.0.6002.24180 5,194,240 13-Aug-2017 14:38 IA-64
Mmc.mof Not applicable 698 07-Mar-2016 23:34 Not applicable
Mmcbase.dll 6.0.6002.24180 521,728 13-Aug-2017 19:35 IA-64
Mmcshext.dll 6.0.6002.24180 219,648 13-Aug-2017 19:35 IA-64
Mmcndmgr.dll 6.0.6002.19858 5,696,000 11-Aug-2017 01:40 IA-64
Mmcndmgr.dll 6.0.6002.24180 5,696,000 13-Aug-2017 19:35 IA-64
Cic.dll 6.0.6002.19858 171,520 11-Aug-2017 03:03 x86
Mmc.exe 6.0.6002.19858 1,793,024 11-Aug-2017 00:16 x86
Mmc.mof Not applicable 698 18-Sep-2006 21:26 Not applicable
Mmcbase.dll 6.0.6002.19858 301,056 11-Aug-2017 03:03 x86
Mmcshext.dll 6.0.6002.19858 127,488 11-Aug-2017 03:03 x86
Cic.dll 6.0.6002.24180 171,520 13-Aug-2017 19:35 x86
Mmc.exe 6.0.6002.24180 1,793,024 13-Aug-2017 14:35 x86
Mmc.mof Not applicable 698 07-Mar-2016 23:34 Not applicable
Mmcbase.dll 6.0.6002.24180 301,056 13-Aug-2017 19:36 x86
Mmcshext.dll 6.0.6002.24180 127,488 13-Aug-2017 19:36 x86
Mmcndmgr.dll 6.0.6002.19858 2,167,808 11-Aug-2017 03:03 x86
Mmcndmgr.dll 6.0.6002.24180 2,167,808 13-Aug-2017 19:36 x86

↑ Back to the top


Keywords: kb, atdownload, kbbug, kbexpertiseinter, kbfix, kblangall, kbmustloc, kbsecbulletin, kbsecreview, kbsecurity, kbsecvulnerability, kbsurveynew

↑ Back to the top

Article Info
Article ID : 4039038
Revision : 21
Created on : 9/14/2017
Published on : 9/14/2017
Exists online : False
Views : 204