Microsoft Security Updates for Community Connect 3 - October 2006 [HFXCC3173]
Published Date : 13 Nov 2006��
Last Updated : 13 Feb 2020��
Content Ref: DWN780909��
Operating System
Community Connect 3 SR4, Community Connect 3 SR5, RM Smart-Tools 3 SR4, RM Smart-Tools 3 SR5
Part No
(none)
Summary
Community Connect 3 Security Update to apply critical Microsoft Security Updates to servers and workstations.
Description
Any references to Community Connect™ 3 in this document apply equally to RM Smart-Tools 3.
Microsoft� has released significant Security Updates for Windows�. HFXCC3173 contains these Updates in a format easily applied to Community Connect 3 networks.
We recommend that you apply this Security Update without delay.
Important: This Security Update can be installed on to Community Connect 3 networks with HFXCC3110B or equivalent, ie RM AppAgent version 1.37.3.0 or greater.
Before installing any Software Update, please refer to TEC90813 and DWN59018 in the Other Useful Articles section below. These articles detail RM's recommendations regarding Software Update installation and support.
Known issues
At the time of writing there are no known issues related to HFXCC3173.
Requirements
HFXCC3173 should be installed on Community Connect 3 networks with Service Release 4 (SR4) or above, and HFXCC3110B or equivalent.
This Security Update should be installed on to all Community Connect 3 servers.
Note: All servers and workstations will need to be restarted in order to install this Security Update completely. You should therefore plan to install the Security Update out-of-hours to minimise disruption to your network.
What will the Security Update change?
HFXCC3173 contains the following Microsoft� Security Updates:
MS06-056: Vulnerability in ASP.NET 2.0 Could Allow Information Disclosure (922770).
MS06-057: Vulnerability in Windows Explorer Could Allow Remote Execution (923191).
MS06-058: Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (924163).
MS06-059: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (924164).
MS06-060: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (924554).
MS06-062: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (922581).
MS06-063: Vulnerability in Server Service Could Allow Denial of Service and Remote Code Execution (923414).
MS06-064: Vulnerabilities in TCP/IP IPv6 Could Allow Denial of Service (922819).
MS06-065: Vulnerability in Windows Object Packager Could Allow Remote Execution (924496).
More information on the issues resolved by these Updates is available from the Microsoft� Web site: (http://www.microsoft.com/)
Note: HFXCC3173 may not contain all the Security Updates released by Microsoft� in October 2006. Please read the More Information section below for further details.
The Updates provided in HFXCC3173 supersedes a previously-released Microsoft� Security Update; as such, the following Community Connect 3 workstation package will be removed from networks (if it is present) during this Security Update's installation:
Windows XP Security Update KB917159.
Windows XP Security Update KB921398.
Who should install this Security Update?
If you are running a Community Connect 3 network, you should apply this Security Update without delay.
HFXCC3173 should be applied to all Community Connect 3 servers including all domain controllers and all Member Servers (such as DAMMS and MIS servers, or servers running Microsoft�Exchange). It does not need to be applied to Community Connect 3 workstations directly, but all servers and workstations will need to be restarted for the Microsoft� Security Updates to be applied fully.
Download Instructions
Click the HFXCC3173.exe file link below to download the Security Update.
Choose to Save the file, browse to the temporary location you wish to save it to (for example D:\temp) and click Save.
When it has downloaded, follow the Installation Instructions below to install the Security Update.
Download
Filename
File Size
Download
HFXCC3173.exe
84.37 Mb
Installation Instructions
Important: During the installation of HFXCC3173, the Station Manager HealthCheck and the allocation of new Microsoft� Security Update packages must be done manually. Please ensure that you fully complete all steps in the Installation Instructions. If you previously started to install the Security Update but cancelled the operation, follow the installation instructions in the 'Installing after cancelling a previous install' section below.
Download HFXCC3173.
Log on to your first Community Connect 3 domain controller as Administrator (not SystemAdmin) and copy the Security Update to a temporary location (for example D:\temp).
Run the Security Update by double-clicking the self-extracting executable file (HFXCC3173.exe). The Security Update will extract files automatically and run the RM Installation Assistant to begin the installation.
When prompted, click Continue.
The installation will proceed automatically. When prompted that the RM Installation Assistant has finished, click Finish.
Note: After installation at a server, the server will need to be rebooted for the Microsoft� Security Updates to be applied fully. Ensure the server has rebooted successfully before continuing.
Repeat steps 2-5 at all your other Community Connect 3 domain controllers.
Repeat steps 2-5 at any Member Servers (eg DAMMS or MIS servers) on the network.
Note: After installation at a server, the server will need to be rebooted for the Microsoft� Security Updates to be applied fully. It is recommended that you ensure each domain controller has rebooted successfully before applying the Software Update to the next server.
When all Community Connect 3 domain controllers have had HFXCC3173 applied, log in to the first Community Connect 3 domain controller server in each site as the Administrator user (not SystemAdmin). Run Windows� Explorer� and browse to D:\RMNetwork\RMManage\Station Manager. Double-click on the file Healthcheck.exe, and select OK to start the health check, and OK again when it has completed.
HFXCC3173 provides new workstation packages but does not automatically allocate them. You should allocate these new packages to all your workstations at your earliest convenience. Note: If you choose to allocate the packages at a later time, you must still complete all of steps 1 to 8 above now, including running the Station Manager health check.
The new Security Packages are listed as available packages as follows in the RM Management Console:
System packages
Windows XP Security Update KB924496.
Windows XP Security Update KB923414.
Windows XP Security Update KB923191.
Windows XP Security Update KB922819.
Windows XP Security Update KB922770.
Note: KB922770 needs to be applied only on those workstations where ASP.NET 2.0 is installed. If it is applied to workstations which do not have ASP.NET 2.0 installed, the package will fail to install.
Application Packages
Note: There are no update removal procedures for the following application updates. Please allocate these only if you have the packages installed on your workstations.
Microsoft Word 2003 Security Update KB924554.
Microsoft Word 2002 Security Update KB924554.
Microsoft Word 2000 Security Update KB924554.
Microsoft PowerPoint 2003 Security Update KB924163.
Microsoft PowerPoint 2002 Security Update KB924163.
Microsoft PowerPoint 2000 Security Update KB924163.
Microsoft Office XP SP3 Security Update KB922581.
Microsoft Office 2000 SP3 Security Update KB922581.
Microsoft Office 2003 SP1 and SP2 Security Update KB922581.
Microsoft Excel 2002 Security Update KB924164.
Microsoft Excel 2000 Security Update KB924164.
Microsoft Excel 2003 Security Update KB924164.
Once you have allocated the packages to workstations, restart the workstations for the Microsoft� Security Update to be installed.
Installing after cancelling a previous install
Browse to D:\RMNetwork\RMManage\RM Hotfixes\HFXCC3173_extracted and double-click the file RM Installation Assistant.exe. Note: If this folder or its contents does not exist, re-run the HFXCC3173.exe file downloaded from the RM Support Web site as in step 1 of the Installation Instructions section above.
Follow the procedures from step 4 in the Installation Instructions section above.
Important - interaction with RM Service Releases
The components of HFXCC3173 are included in RM Service Release 6 for Community Connect 3.
The Security Update can be installed on to networks running Community Connect 3 with Service Release 4 or above, and HFXCC3110B or equivalent.
HFXCC3173 is not included in Service Release 4 or 5. It will not need to be re-applied if originally installed before Service Release 5 is installed.
Note: The application software updates will need to be re-applied if the related Microsoft� application is installed or re-installed after the software updates were applied.
Download File Contents
See the Description section for full list. HFXCC3173 contains new relevant workstation and server Microsoft� Security Updates.
More Information
HFXCC3173 does not contain the following security bulletins released by Microsoft� in October 2006:
MS06-061: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (924191).