Security update 958469 updates the following binaries:
Binary name | Standard locations |
Mstscax.dll | a) %Windir%\System32 b) %SystemDrive%\Program Files\Remote Desktop |
Mstsc.exe | a) %Windir%\System32 b) %SystemDrive%\Program Files\Remote Desktop |
Msrdp.ocx | %Windir%\Download Program Files |
Msrdp.cab | a) %Windir%\Web\Tsweb b) Install path under "hklm\software\microsoft\TS Web Clients" under value "InstallDir" c) %SystemDrive%\Inetpub\Remote
|
Note The files are updated only if the files were already present on the client computer.
Security update 958469 updates the following binaries on the following operating systems:
| Mstscax.dll | Msrdp.ocx | Msrdp.cab | Mstsc.exe |
---|
Windows Server 2003 | Yes | Yes | Yes | No |
Windows XP | Yes | No | No | Yes |
Note that in specific deployments on out-of-box versions of the RDP client, files may be renamed during installation. The file names listed in the "File information" in this article are the original names prior to installation.
Platform | RDP version | Name of the binary carried in the package | Name of the binary after installation |
---|
Windows XP Professional with Service Pack 1, Service Pack 2, or Service Pack 3 | 5.2 | 2k3mstscax.dll and 2k3mstsc.exe | mstscax.dll and mstsc.exe |
Windows XP Service Pack 2 | 5.2 | 2k3mstscax.dll and 2k3mstsc.exe | mstscax.dll and mstsc.exe |
Known issues with this security update
After you install this update, gridlines may be visible in a terminal session window when you use Remote Desktop Client (RDC) to connect to a terminal server and then scroll up and down in a Web page in the terminal session.
For more information about how to resolve this issue, click the following article numbers to view the articles in the Microsoft Knowledge Base:
975153
A hotfix is available for Remote Desktop Client (RDC) 5.1 to fix a drawing failure after you apply the security update 958470 (MS09-044) on a computer that is running Windows XP Service Pack 2
975158 A hotfix is available for Remote Desktop Client (RDC) 5.2 to fix a drawing failure after you apply the security update 958470 (MS09-044) on a computer that is running Windows XP Service Pack 3 or Windows Server 2003 Service Pack 2
Frequently asked questions
Question If I have an application that deploys the Remote Desktop Web Connection binaries in non-default locations, will this security update patch my installation?
Answer This update updates the Microsoft Remote Desktop Web Connection binaries in standard locations. If your redistributed Microsoft Remote Desktop Web Connection binaries are in a custom location, you will have to update the custom location with the updated Microsoft Remote Desktop Web Connection binaries.
Question Before I installed the security update, I had the RDC 5.1 version of Msrdp.ocx. After I installed the security update, I do not see the RDC 5.1 version of Msrdp.ocx. Why?
Answer After you install this security update, the RDC 5.1 version of Msrdp.ocx is upgraded to the RDC 5.2 version of Msrdp.ocx.
Question I installed the security update, and now if I try to use ActiveX component of MSTSC (Msrdp.ocx), I cannot connect. Why?
Answer The scenario is broken (see Figure 1) because server is not updated. Therefore, the server is still pushing the vulnerable Msrdp.ocx file to the clients. Before you install the security update, the client computer does not have the ActiveX control (Msrdp.ocx). After you install the security update, the vulnerable ActiveX ClassIds were blocked. Therefore, if you try to use the vulnerable ActiveX Msrdp.ocx by using Internet Explorer, you cannot connect until the client computer receives the new Msrdp.ocx file.
To resolve the problem, follow these steps:
- Reinstall the security update on the client workstation to update the older version of the Msrdp.ocx file that was downloaded from the server.
Note The Msrdp.ocx file is updated only in the standard locations.
- Ask your Web server administrators to update the server-side Msrdp.cab file by using the security update. Administrators should be aware that the update updates only Msrdp.cab files that are found in the standard locations. To update Msrdp.cab files that are in custom locations, follow these steps:
- Extract the update (KB) by using the KB /x:<path> command.
- Copy the Msrdp.cab from <location> to the custom path.
Figure 1: The Remote Desktop Web connection will not work until the client receives an updated Msrdp.ocx file. Note that Windows Update will offer the update automatically if the vulnerable Msrdp.ocx file is available in the standard location on the computer. For more information, visit the following Microsoft Web site:
* This scenario works if you have RDC 6.0 or a later version installed on the client (workstation) computer.