Affected Products
Problem Description
On October 13, 2009, Microsoft released the following security bulletins:
MS09-050: Critical
Vulnerabilities in SMBv2 Could Allow Remote Code Execution (975517)
Affected Supported Software:
- Microsoft Windows Vista Enterprise Service Pack 1
MS09-051: Critical
Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution (975682)
Affected Supported Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
- Microsoft Windows Vista Enterprise Service Pack 1
MS09-052: Critical
Vulnerability in Windows Media Player Could Allow Remote Code Execution (974112)
Affected Supported Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
MS09-054: Critical
Cumulative Security Update for Internet Explorer (974455)
Affected Supported Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
- Microsoft Windows Vista Enterprise Service Pack 1
MS09-055: Critical
Cumulative Security Update of ActiveX Kill Bits (973525)
Affected Supported Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
- Microsoft Windows Vista Enterprise Service Pack 1
MS09-060: Critical
Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution (973965)
Affected Supported Software:
MS09-061: Critical
Vulnerabilities in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution (974378)
Affected Supported Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
- Microsoft Windows Vista Enterprise Service Pack 1
MS09-062: Critical
Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)
Affected Supported Software:
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
- Microsoft Windows Vista Enterprise Service Pack 1
- Microsoft SQL Server 2005 SP2
MS09-053: Important
Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution (975254)
Affected Supported Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
- Microsoft Windows Vista Enterprise Service Pack 1
MS09-056: Important
Vulnerabilities in Windows CryptoAPI Could Allow Spoofing (974571)
Affected Supported Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
- Microsoft Windows Vista Enterprise Service Pack 1
MS09-057: Important
Vulnerability in Indexing Service Could Allow Remote Code Execution (969059)
Affected Supported Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
MS09-058: Important
Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (971486)
Affected Supported Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
- Microsoft Windows Vista Enterprise Service Pack 1
MS09-059: Important
Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (975467)
Affected Supported Software:
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
- Microsoft Windows Vista Enterprise Service Pack 1
Background
Cisco evaluates Microsoft security notices and updates for potential impact to Cisco Contact Center products. The qualification process results in the application of one of three categorical ratings to an update: Impacting, Deferred, or Not Applicable. These ratings are defined in the Cisco Customer Contact software policy for using Microsoft security updates on products deployed on a retail installation of Windows operating system bulletin. The cumulative set of security patches available from Microsoft—including those marked here as Deferred—are applied to Microsoft Windows Server 2003 (current supported Service Pack) and/or the appropriate component prior to Cisco's testing of every release of the Customer Contact Business Unit (CCBU) products (major, minor, and maintenance).
For the security updates listed in the Problem Description section of this bulletin, Cisco has assigned them to the three categories as follows:
Impacting
- MS09-050: Vulnerabilities in SMBv2 Could Allow Remote Code Execution (975517)
- MS09-053: Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution (975254)
- MS09-056: Vulnerabilities in Windows CryptoAPI Could Allow Spoofing (974571)
- MS09-058: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (971486)
- MS09-059: Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (975467)
Deferred
- MS09-051: Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution (975682)
- MS09-052: Vulnerability in Windows Media Player Could Allow Remote Code Execution (974112)
- MS09-054: Cumulative Security Update for Internet Explorer (974455)
- MS09-055: Cumulative Security Update of ActiveX Kill Bits (973525)
- MS09-057: Vulnerability in Indexing Service Could Allow Remote Code Execution (969059)
- MS09-061: Vulnerabilities in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution (974378)
- MS09-062: Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)
Not Applicable
- MS09-060: Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution (973965)
Care should be taken in deciding which updates to apply to your systems. For additional information on the security measures to be considered in an ICM environment, refer to the Security Best Practices for Cisco Intelligent Contact Management Software Guide.
For the Security Updates categorized as Impacting, Cisco continues to test its products to determine if there are further potential conflicts.
Customers should follow Microsoft's guidelines regarding when and how they should apply these updates. Refer to the Microsoft website for full details of the potential exposure from the caveat, which is referenced on the Microsoft Security page.
Problem Symptoms
It is important to point out that Cisco Contact Center Support has not had any cases pertaining to these vulnerabilities recorded from our customer base as of October 15, 2009.
Workaround/Solution
Cisco has assessed and, where deemed appropriate, validated the Microsoft security patches addressed in this bulletin along with any workarounds for the problems found.
Cisco recommends that Contact Center customers separately assess all security patches released by Microsoft and install those deemed appropriate for their environments.
Cisco will continue to provide a service of separately assessing and, where necessary, validating higher severity security patches that may be relevant to the Cisco Contact Center and Self Service products.
Visit the Microsoft website to acquire the fixes. Keep in mind that you should download the appropriate fixes based on the version of the Microsoft operating system deployed in your environment and service pack level.
Additional Information
If you require further assistance, or if you have questions regarding this Impact Assessment, please contact the Cisco Systems Technical Assistance Center (TAC) by one of the following methods: