Mr N Manager Support Online Demo Site [359918]
Logout(Remember Me)
Support
RM Home
Support
Sections
My Support Calls
Search Library
Drivers and Downloads
Guide to Support Online
FAQs
Events
Technical Rating:�
Support Home PageSupport
Print This PagePrint This Page
Add to 'My Library' Add to 'My Library'

Microsoft Security Updates for Community Connect 3 - January 2006 [HFXCC3148]
Published Date : 20 Jan 2006�� Last Updated : 13 Feb 2020�� Content Ref: DWN569738��





Description

Any references to Community Connect� 3 in this document apply equally to RM Smart-Tools 3.

Microsoft� have released significant security updates for Microsoft Windows�.  HFXCC3148 contains these updates in a format easily applied to Community Connect 3 networks.

We strongly recommend that you apply this Security Update.

Important:  This Security Update can be installed on to Community Connect 3 networks with HFXCC3110B or equivalent, i.e. RM AppAgent version 1.37.3.0 or greater.

Before installing any software update, please refer to TEC90813 and DWN59018 in the Other Useful Articles section below. These articles detail RM's recommendations regarding software update installation and support.


Known issues

At the time of writing there are no known issues related to HFXCC3148.


Requirements
  • HFXCC3148 should be installed on Community Connect 3 networks with Service Release 4 (SR4) or above, and HFXCC3110B or equivalent.
  • This Security Update should be installed on all Community Connect 3 servers.
  • HFXCC3148 also provides a security update for Microsoft Exchange� 2000 but does not install it automatically. Please refer to the Installation Instructions below for more information.

Note:  All servers and workstations will need to be restarted in order to install this Security Update completely. You should therefore plan to install the Security Update out-of-hours to minimise disruption to your network.


What will the Security Update change?

HFXCC3148 contains the following Microsoft� security updates:

 

1.      MS06-001: Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution (912919);

2.      MS06-002: Vulnerability in Embedded Web Fonts Could Allow Remote Code Execution (908519);

3.      MS06-003: Vulnerability in TNEF Decoding in Microsoft Outlook� and Microsoft Exchange could allow Remote Code Execution (902412) - for Microsoft Exchange 2000. Please refer to the Installation Instructions below and the More Information section.

 

More information on the issues resolved by these updates is available from the Microsoft Web site http://www.microsoft.com.


Who should install this Security Update?

If you are running a Community Connect 3 network, you should apply this Security Update without delay.

HFXCC3148 should be applied to all Community Connect 3 servers including all domain controllers and all Member Servers (such as DAMMS and MIS servers, or servers running Microsoft Exchange).  It does not need to be applied to Community Connect 3 workstations directly but all servers and workstations will need to be restarted for the Microsoft security updates to be applied fully.



Download Instructions

1.      Click the HFXCC3148.exe file link to download the Security Update.

2.      Choose to Save the file, browse to the temporary location you wish to save it to and click Save.

3.      When it has downloaded, follow the installation instructions below to install the Security Update.



Download

FilenameFile SizeDownload
HFXCC3148.exe6.78 Mb Download


Installation Instructions

Important: During the installation of HFXCC3148, the Station Manager HealthCheck and the allocation of new Microsoft security update packages must be done manually. Please ensure that you fully complete all steps in the Installation Instructions.

 

If you previously started to install the security update but cancelled the operation, follow the installation instructions in the 'Installing after cancelling a previous install' section below.

 

1.      Download HFXCC3148.

2.      Log on to your first Community Connect 3 domain controller as Administrator and copy the Security Update to a temporary location (for example D:\temp).

3.      Run the Security Update by double-clicking the self-extracting executable file (HFXCC3148.exe).  The Security Update will extract files automatically and run the RM Installation Assistant to begin the installation.

4.      When prompted, click Continue.

5.      The installation will proceed automatically.  When prompted that the RM Installation Assistant has finished, click Finish.

6.    Reboot the server and wait for the logon screen to appear before continuing with Step 7.

7.       Repeat Steps 2-6 at all your other Community Connect 3 domain controllers.

8.      Also repeat steps 2-6 at any member servers (e.g. DAMMS or MIS servers) on the network. 

9.      When all Community Connect 3 domain controllers have had HFXCC3148 applied, log in to the first Community Connect 3 domain controller server in each site as the administrator user. Run Microsoft� Windows� Explorer and browse to D:\RMNetwork\RMManage\Station Manager. Double-click on the file Healthcheck.exe, and select OK to start the Healthcheck, and OK again when it has completed.

10.    HFXCC3148 provides new workstation packages but does not automatically allocate them. You should allocate these new packages to all your workstations at your earliest convenience. Note: If you choose to allocate the packages at a later time, you must still complete all of steps 1 to 8 above now, including running the Station Manager health check.  

The new security packages are listed as available packages as follows in the RM Management Console:

 

SYSTEM PACKAGES

        Windows XP Security Update KB912919

        Windows XP Security Update KB908519

11.  Once you have allocated the package to workstations, restart the workstations for the Microsoft� security update to be installed.


Microsoft Exchange 2000

If you have one or more servers running Microsoft Exchange 2000, there is an additional security update which you should install manually on each Exchange server. Follow the procedure below.

 

Important: This Microsoft Exchange 2000 security update requires the Update Rollup Pack for Microsoft Exchange 2000 to be installed first. This Update Rollup (KB870540) is available via DWN403550 in the Other Useful Articles section below and it is important that this has been installed before continuing with the steps detailed below.

 

1.      Log on to the Exchange 2000 server as an administrator.

2.      Browse to D:\RMNetwork\RMManage\RM Hotfixes\HFXCC3148_extracted\Utilities\Server Updates\v1.12.0.0 and double-click the file Exchange2000-KB894689-x86-ENU.exe. (If this location does not exist you can copy the file from any Community Connect 3 server which has had HFXCC3148 installed.)

3.      At the Security Update for Exchange 2000 Server (KB894689) Setup Wizard screen, choose Next.

4.      Choose I Agree at the License Agreement screen, then choose Next.

5.      The security update will install. If prompted that services will be stopped and re-started, choose Continue.

6.      When the installation has completed, choose Finish.

7.      It is recommended that you restart the server to ensure that the security update has been fully installed.

8.      Repeat steps 1-7 at any other Microsoft� Exchange� 2000 servers.


Installing after cancelling a previous install

1.      Browse to D:\RMNetwork\RMManage\RM Hotfixes\HFXCC3148_extracted and double-click the file RM Installation Assistant.exe. (If this folder or its contents does not exist, re-run the HFXCC3148.exe file downloaded from the RM Support website).

2.   Follow the procedures in 'How to install the Security Update' from step 4 in the main installation instructions above.


Important: Interaction with RM Service Releases

The components of HFXCC3148 are included in RM Service Release 6 for Community Connect 3.

The Security Update can be installed on networks running Community Connect 3 with Service Release 4 or above, and HFXCC3110B or equivalent.

HFXCC3148 is not included in Service Release 4 or 5. It will not need to be re-applied if originally installed before Service Release 5 is installed.



Download File Contents

See the Description section for full list.  HFXCC3148 contains two new workstation packages and a component to update servers with the relevant Microsoft security updates. It also includes a security update for Microsoft Exchange 2000 servers which must be installed manually.



More Information

MS06-003: Security bulletin MS06-003, Vulnerability in TNEF Decoding in Microsoft Outlook and Microsoft Exchange Could Allow Remote Code Execution (902412), provides additional updates for various version of Microsoft Outlook and Microsoft Office. These are not provided in HFXCC3148. They may be provided in future updates to Microsoft Office packages supplied by RM.


FEEDBACK
Did the information in this article help answer your question?
�Yes
�No
Please add any comments about this article in the box below. If you answered No then it is important you tell us why so that we can change the article if required. We can only respond if you log in to the RM Support website or provide your contact details. Note: If you need help with a technical query, please log a call online or telephone our support team.
Thank you for your feedback, which is sent directly to the RM Knowledge team. We address every message received with the intention of improving our Knowledge Library articles. If you have an unresolved technical issue, please contact RM Support.


If this article has not helped provide a solution then it is also possible to log a call...



Document Keywords:�windows, 2000, service release 4, windows server 2003, xp, sp1a, sp1, sp2, critical, bulletin, hfxcommunity connect 3, hfx148, 148, hotfix 148, hfxcommunity connect 3148, community connect 3hfx148, ms06-001, ms06-002, ms06-003, wmf, windows metafile, graphics rendering engine, 912919, kb912919, 908519, kb908519, 902412, kb902412, 894689, kb894689, embedded web fonts, tnef decoding


Please read - important disclaimer information.
http://www.rm.com/_RMVirtual/Includes/csredirect.asp?cref=&title=Standard Content Disclaimer


Top Of PageTop of page