Critical Hotfix for Microsoft security updates - December 2004 and January 2005 [HFXCC3098]
Published Date : 02 Feb 2005��
Last Updated : 13 Feb 2020��
Content Ref: DWN351842��
Operating System
Community Connect 3 SR3, Community Connect 3 SR4, RM Smart-Tools 3 SR3, RM Smart-Tools 3 SR4
Part No
(none)
Summary
Community Connect 3 hotfix to apply critical Microsoft security updates to servers and workstations.
Description
Any references to Community Connect 3 in this document apply equally to RM Smart-Tools 3.
Microsoft have released significant security updates for Microsoft Windows. HFXCC3098 contains these updates in a format easily applied to Community Connect 3 networks.
We recommend that you apply this hotfix without delay.
Before installing any hotfix, please refer to TEC90813 and DWN59018 in the Other Useful Articles section below. These articles detail RM's recommendations regarding hotfix installation and support.
This hotfix can be installed on Community Connect networks running Service Release 3 or above.
Requirements
HFXCC3098 can be installed on Community Connect 3 networks with Service Release 3 or above.
This hotfix should be installed on to all Community Connect 3 servers.
Important: All servers will need to be restarted in order to install this hotfix completely. You should therefore plan to install the hotfix out-of-hours to minimise disruption to your network.
What will the Hotfix change?
HFXCC3098 contains the following Microsoft security updates:
1.MS04-040: Cumulative Security Update for Internet Explorer (889293) - for Community Connect 3 servers;
2.MS04-041: Vulnerability in WordPad Could Allow Code Execution (885836) - for Community Connect 3 servers and workstations;
3.MS04-043: Vulnerability in HyperTerminal Could Allow Code Execution (873339) - for Community Connect 3 servers and workstations;
4.MS04-044: Vulnerabilities in Windows Kernel and LSASS Could Allow Elevation of Privilege (885835) - for Community Connect 3 servers and workstations;
5.MS05-001: Vulnerability in HTML Help Could Allow Code Execution (890175) - for Community Connect 3 servers and workstations;
6.MS05-002: Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution (891711) - for Community Connect 3 servers;
7.MS05-003: Vulnerability in the Indexing Service Could Allow Remote Code Execution (871250) - for Community Connect 3 servers.
More information on the issues resolved by these updates is available from Microsoft's website (http://www.microsoft.com).
Notes: The cumulative security update for Internet Explorer (889293), MS04-040, is actually provided by Update Rollup KB889669 for Internet Explorer SP1. Once installed, KB889669 will display in Add/Remove Programs on Community Connect 3 servers running Windows 2000 Server.
MS04-040, MS05-002 and MS05-003 are also applicable to Windows XP Service Pack 1, however these updates will be provided for workstations in the next Microsoft security update hotfix for Community Connect 3. Windows XP Service Pack 2 workstations are not affected by the vulnerabilities addressed by MS04-040, MS05-002 and MS05-003.
Who should install this Hotfix?
You should apply this hotfix without delay if you are running a Community Connect 3 network.
HFXCC3098 should be applied to all Community Connect 3 servers including all domain controllers and all Member Servers (such as DAMMS and MIS servers). It does not need to be applied to Community Connect 3 workstations directly but all servers and workstations will need to be restarted for the updates to be applied fully.
Download Instructions
1.Click the HFXCC3098.exe file link to download the hotfix.
2.Choose to Save the file, browse to the temporary location you wish to save it to (e.g. D:\temp) and click Save.
3.When it has downloaded, follow the installation instructions below to install the hotfix.
Download
Filename
File Size
Download
HFXCC3098.exe
20.31 Mb
Installation Instructions
IMPORTANT: During the installation of HFXCC3098, the Update Package List procedure, Station Manager HealthCheck and the allocation of new Microsoft security update packages must be done manually. Please ensure that you fully complete ALL steps in the How to install the Hotfix section of this article.
Note: If you previously started to install the hotfix but cancelled the operation, follow the installation instructions in the 'Installing after cancelling a previous install' section below.
1.Download HFXCC3098.
2.Log on to your first Community Connect 3 domain controller as Administrator (not SystemAdmin) and copy the hotfix to a temporary location (e.g. D:\temp).
3.Run the hotfix by double-clicking the self-extracting executable file (HFXCC3098.exe).The hotfix will extract files automatically and run the RM Installation Assistant to install the hotfix.
4.When prompted, click Continue.
5.The installation will proceed automatically and may take several minutes to complete.When prompted that the RM Installation Assistant has finished, click Finish.
Note: After installation at a server, the server will need to be rebooted for the hotfix to be applied fully.
6.Repeat Steps 2-5 at all your other Community Connect 3 domain controllers.
7.Also repeat steps 2-5 at any member servers (e.g. DAMMS or MIS servers) on the network.
Note: After installation at a server, the server will need to be rebooted for the hotfix to be applied fully.
8.When all Community Connect 3 servers have had the hotfix applied, open the RM Management Console at a domain controller or a workstation.
9.In the RM Management Console, expand Workstations, right-click on Main Site and choose to Update Package List. Click Yes to confirm this action. Note: If you have a multi-site network, run this hotfix on every server at all sites and then update the package list once per site only.
10.Log in to the first Community Connect 3 domain controller server in each site as the administrator user (not SystemAdmin). Run Windows Explorer and browse to D:\RMNetwork\RMManage\Station Manager. Double-click on the file Healthcheck.exe, and select OK to start the Healthcheck, and OK again when it has completed.
11.HFXCC3098 provides new workstation packages but does not automatically allocate them. You should allocate these new packages to all your workstations at your earliest convenience. Note: If you choose to allocate the packages at a later time, you must still complete all of steps 1-10 above now, including running the Update Package List and the Station Manager health check. The simplest way to do this is to allocate all the packages at Main Site level. If you prefer to allocate them at a lower location, ensure that you do so for all workstations. The new security packages are listed as RM system packages as follows:
�HTML Help Security Update KB890175;
�HyperTerminal Security Update KB873339;
�Windows Kernel and LSASS Security Update KB885835;
�Wordpad Security Update KB885836.
12.Once you have allocated the packages to workstations, restart the workstations for the hotfixes to be installed.
Installing after cancelling a previous install
1.Browse to D:\RMNetwork\RMManage\RM Hotfixes\HFXCC3098_extracted and double-click the file RM Installation Assistant.exe. (If this folder or its contents does not exist, re-run the HFXCC3098.exe file downloaded from the RM Support website).
2.The RM Installation Assistant will initialise; click Continue to proceed with the installation.
3.The installation should proceed automatically; click Finish when prompted.
4.Follow the procedures in 'How to install the Hotfix' from step 5 above.
IMPORTANT - Interaction with RM Service Releases
The components of HFXCC3098 will be included in a future Community Connect 3 Service Release or Microsoft Service Packs validated by RM.
The hotfix can be installed on to networks running Community Connect 3 with Service Release 3 or above.
HFXCC3098 is not included in CC3 SR4 or CC3 XPSP2.
If this article has not helped provide a solution then it is also possible to
log a call...