Operating System Upgrade Service Release 2003.1.5asr25 (win-OS-Upgrade-K9.2003-1-5a-sr25.exe)

Release date: 17-January-2012

Document Revision 1

Microsoft provides monthly releases of security hotfixes on the 2nd Tuesday of each month.  Cisco’s monthly OS Service Release is scheduled to post on the 3rd Tuesday of each month.

Cisco will continue to test and release Microsoft hotfixes that meet our criteria for Critical hotfixes in 1 business day.  Any applicable critical hotfix released by Microsoft will be added to the Cisco IP Telephony Operating System, SQL Server, Security Updates document with and explanation about whether or not it is critical for Cisco IP Telephony servers and when it will be released by Cisco.

Caution:  Do not apply this service release with OS version 2000.4.x or previous OS release trains.  This service release is only compatible with the OS 2003.1.5x release trains.  You should apply this service release to all servers in your cluster.  This installation causes call-processing interruptions and requires a reboot.  Close all programs before proceeding including Internet Explorer to avoid conflicts with the software being installed and/or upgraded.

General Note: If the following messages are displayed during the installation, please click “OK” and continue. These will not affect this upgrade. The causes for these messages are under investigation:
            * The Instruction at "0X0cda00dd8" referenced memory at "0X0cda00dd8". The memory could not be read. Click OK to terminate the program (CSCeb31088)
            * The Instruction at "0X000000000" referenced memory at "0X000000000". The memory could not be read. Click OK to terminate the program (CSCed45218)
            * AddAnonymousWebUserAccess failure during CallManager installations (CSCed27066)

Naming Convention Change

 For operating system, SQL Server, and Cisco IP telephony application software updates, Cisco has replaced the term, support patch, with the term, service release.  Service releases provide the same functionality as support patches; that is, they provide bug fixes, etc.  
 Review the file naming convention before you apply the software update.
 <software_name>-<software version>_<sr(x)>
 <software name> equals the name of the application; <software version> equals the maintenance release; <sr(x)> equals the version of the service release
 For example, review the following file name:
 win-OS-Upgrade-K9.2000-4-2sr2.exe
 win-OS-Upgrade indicates that this file is an operating system upgrade file; K9 indicates that you download the file from the Cisco cryptographic website; 2000-4-2 indicates the operating system maintenance release version, and sr2 indicates that this file is the first version of the operating system upgrade service release.
Contents

This document contains information on the following topics.  Click the hyperlink to go directly to the section.

This section provides information about how to receive email notifications when new updates post to Cisco Connection Online.

This section provides general information and specifies the affected Cisco IP telephony applications, supported servers, and hotfixes that are automatically installed with this software update.

This section provides procedures for installing this service release on supported servers.

This section provides a list of hotfixes that Microsoft Baseline Security Analyzer.  See this section if you want to verify which hotfixes exist on your server.

This section provides information about how to uninstall the Microsoft hotfixes.
Cisco Notification Tools
Cisco CallManager Notification Tool: Cisco has replaced the current Cisco CallManager notification tool with a new, more robust notification tool that is based on your Cisco.com profiles.  This new tool delivers email notifications for individual Cisco voice products that you select.  Follow the steps below to sign up for the Cisco Voice Technology Group Subscription Tool:
You may see this message at the bottom of the page: "Your Profile Currently Indicates that you do not wish to receive email from Cisco.”
To be able to receive information updates, you must update your email preferences.  Click on the link to update your email preferences (located in the Other Information section).  Click submit when you are done.  
If you have enabled email notification, you may exit now.  If you have not enabled email notification, then you will need to repeat the steps above.
This new software notification tool requires a valid Cisco.com login. If you do not currently have a Cisco.com password, please register with Cisco.com at: http://tools.cisco.com/RPF/register/register.do
Cisco PSIRT Advisory Notification Tool: This email service provides automatic notification of all Cisco Security Advisories that are released by the Cisco Product Security Incident Response Team (PSIRT).  Security Advisories, which describe security issues that directly impact Cisco products, provide a set of required actions to repair these products. To subscribe, click the following URL and perform the tasks as directed on the web page: http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html#SecurityInfo
 Information about This Service Release
Review the following information before you install the service release:

http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_device_support_tables_list.html

Note:  Apply this service release to all servers in your cluster.
Caution:  This installation causes call-processing interruptions and requires a reboot.  Close ALL programs before proceeding including Internet Explorer.

This service release includes the following hotfixes and defect resolutions: 
 

Table:  Hotfixes That Are Included in the Service Release

Bulletin

Knowledge Base Article

or Cisco Defect

Description

1st Released in Support Patch/Service Release:

Uninstallation
Supported

 

MS07-017

925902

Vulnerabilities in GDI Could Allow Remote Code Execution (925902)

2003.1.1sr3

Yes

MS07-012

924667

Vulnerability in Microsoft MFC Could Allow Remote Code Execution (924667)

2003.1.1sr1

Yes

MS07-017

925902

Vulnerabilities in GDI Could Allow Remote Code Execution (925902)

2003.1.1sr3

Yes

MS07-020

932168

Vulnerability in Microsoft Agent Could Allow Remote Code Execution (932168)

2003.1.1sr3

Yes

MS07-021

930178

Vulnerabilities in CSRSS Could Allow Remote Code Execution (930178)

2003.1.1sr3

Yes

MS07-022

931784

Vulnerability in Windows Kernel Could Allow Elevation of Privilege (931784)

2003.1.1sr3

Yes

 

CSCsh70353

Reinstall Hotfix- KB831877 and KB835732 error with 2000.4.4a OS Upgrade

2003.1.1sr3

N/A

MS07-031

935840

Vulnerability in the Windows Schannel Security Package Could Allow Remote Code Execution (935840):

2003.1.1sr5

Yes

MS07-034

929123

Cumulative Security Update for Outlook Express and Windows Mail (929123):

2003.1.1sr5

Yes

MS07-035

935839

Vulnerability in Win 32 API Could Allow Remote Code Execution (935839):

2003.1.1sr5

Yes

MS07-039

926122

Vulnerability in Windows Active Directory Could Allow Remote Code Execution (926122)

2003.1.2aSR1

Yes

MS07-040

931212

Vulnerabilities in .NET Framework Could Allow Remote Code Execution (931212)

2003.1.2aSR1

Yes

MS07-042

936227

Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (936227)

2003.1.2aSR2

Yes

MS07-043

921503

Vulnerability in OLE Automation Could Allow Remote Code Execution (921503)

2003.1.2aSR2

Yes

MS07-046

938829

Vulnerability in GDI Could Allow Remote Code Execution (938829)

2003.1.2aSR2

Yes

MS07-047

936782

Vulnerabilities in Windows Media Player Could Allow Remote Code Execution (936782)

2003.1.2aSR2

Yes

MS07-050

938127

Vulnerability in Vector Markup Language Could Allow Remote Code Execution (938127)

2003.1.2aSR2

Yes

 

CSCsk80526

ES/SR can abend during StopServices

2003.1.2aSR4

N/A

MS07-056

941202

Security Update for Outlook Express and Windows Mail (941202)

2003.1.2aSR4

Yes

MS07-057

939653

Cumulative Security Update for Internet Explorer (939653)

2003.1.2aSR4

Yes

MS07-058

933729

Vulnerability in RPC Could Allow Denial of Service (933729)

2003.1.2aSR4

Yes

MS07-061

943460

Vulnerability in Windows URI Handling Could Allow Remote Code Execution (943460)

2003.1.2aSR5

Yes

MS07-028

931906

Vulnerability in CAPICOM Could Allow Remote Code Execution (931906)

2003.1.2aSR6

Yes

 

CSCsl06227
936227

Security Update for MSXML 4.0 Version Component

2003.1.2aSR6

Yes

MS07-064

941568

Vulnerabilities in DirectX Could Allow Remote Code Execution (941568)

2003.1.2aSR6

Yes

MS07-067

944653

Vulnerability in Macrovision Driver Could Allow Local Elevation of Privilege (944653)

2003.1.2aSR6

Yes

MS07-068

941569

Vulnerability in Windows Media File Format Could Allow Remote Code Execution (941569 and 944275)

2003.1.2aSR6

Yes

MS07-069

942615

Cumulative Security Update for Internet Explorer (942615)

2003.1.2aSR6

Yes

 

CSCsl17246
KB925336

Error 1718: <file> was rejected by digital signature policy

2003.1.2aSR7

Yes

MS08-002

943485

Vulnerability in LSASS Could Allow Local Elevation of Privilege (943485)

2003.1.2aSR7

Yes

MS08-007

946026

Vulnerability in WebDAV Mini-Redirector Could Allow Remote Code Execution (946026)

2003.1.2aSR8

Yes

MS08-008

947890

Vulnerability in OLE Automation Could Allow Remote Code Execution (947890)

2003.1.2aSR8

Yes

MS08-010

944533

Cumulative Security Update for Internet Explorer (944533)

2003.1.2aSR8

Yes

MS08-003

946538

Vulnerability in Active Directory Could Allow Denial of Service (946538)

2003.1.2aSR8

Yes

MS08-005

942831

Vulnerability in Internet Information Services Could Allow Elevation of Privilege (942831)

2003.1.2aSR8

Yes

MS08-006

942830

Vulnerability in Internet Information Services Could Allow Remote Code Execution (942830)

2003.1.2aSR8

Yes

 

CSCsm74155

MCS-OS: c:\utils\kill.exe out of date on 2003.1.2a

2003.1.2aSR8

N/A

MS08-020

945553

Vulnerability in DNS Client Could Allow Spoofing (945553)

2003.1.2aSR10

Yes

MS08-021

948590

Vulnerabilities in GDI Could Allow Remote Code Execution (948590)

2003.1.2aSR10

Yes

MS08-022

944338

Vulnerability in VBScript and JScript Scripting Engines Could Allow Remote Code Execution (944338)

2003.1.2aSR10

Yes

MS08-023

948881

Security Update of ActiveX Kill Bits (948881)

2003.1.2aSR10

Yes

MS08-024

947864

Cumulative Security Update for Internet Explorer (947864)

2003.1.2aSR10

Yes

MS08-025

941693

Vulnerability in Windows Kernel Could Allow Elevation of Privilege (941693)

2003.1.2aSR10

Yes

 

CSCso26082

Add tzupdate.exe to OS fresh installs and upgrades

2003.1.2aSR10

N/A

 

CSCso13134

DST: MCS OS update needed for 2008 Iraq Daylight Time removal  (replaces CSCsl16516/KB942673)

2003.1.2aSR10

No

 

CSCso63866

MCS OS2000 for Australian DST does not update timezone information

2003.1.2aSR11

N/A

 

CSCso13145

DST: MCS IBM Director update needed for 2008 Iraq Daylight Time removal

2003.1.2aSR11

No

MS08-031

950759

Cumulative Security Update for Internet Explorer (950759)

2003.1.2aSR12

Yes

MS08-033

951698

Vulnerabilities in DirectX Could Allow Remote Code Execution (951698)

2003.1.2aSR12

Yes

MS08-034

948745

Vulnerability in WINS Could Allow Elevation of Privilege (948745)

2003.1.2aSR12

Yes

MS08-035

953235

Vulnerability in Active Directory Could Allow Denial of Service (953235)

2003.1.2aSR12

Yes

MS08-036

950762

Vulnerabilities in Pragmatic General Multicast (PGM) Could Allow Denial of Service (950762)

2003.1.2aSR12

Yes

MS08-032

950760

Cumulative Security Update of ActiveX Kill Bits (950760)

2003.1.2aSR12

Yes

MS08-037

951746,951748

Vulnerabilities in DNS Could Allow Spoofing (953230)

2003.1.2aSR13

Yes

MS08-040

948110

Vulnerabilities in Microsoft SQL Server Could Allow Elevation of Privilege (948110)

2003.1.2aSR13

Yes

 

CSCsr69663

SQL 2000 Hotfix KB948110 may halt upgrade on  2000.4.5b

2003.1.3sr1

N/A

 

CSCsr61830

SQL 2000 Hotfix KB948110 may fail to install intermittently

2003.1.3sr1

N/A

 

CSCsr61234

Update Hotfix Common Package for 2003.1.3

2003.1.3sr1

N/A

MS08-046

952954

Vulnerability in Microsoft Windows Image Color Management System Could Allow Remote Code Execution (952954)

2003.1.3sr1

Yes

MS08-045

953838

Cumulative Security Update for Internet Explorer (953838)

2003.1.3sr1

Yes

MS08-048

951066

Security Update for Outlook Express and Windows Mail (951066)

2003.1.3sr1

Yes

MS08-049

950974

Vulnerabilities in Event System Could Allow Remote Code Execution (950974)

2003.1.3sr1

Yes

 

953839

Cumulative Security Update of ActiveX Kill Bits

2003.1.3sr1

Yes

 

CSCsu43442

Version Error displayed when upgrading from 2003.1.3a to 2003.1.3b

2003.1.3bSR2

N/A

 

CSCsu42231

MCS OS Upgrade from MCS OS 2003.1.2a SR13 to MCS OS 2003.1.3a failed

2003.1.3bSR2

N/A

 

CSCsu43255

2003.1.3a OS upgrade breaks UCCX SQL server in HA mode

2003.1.3bSR2

N/A

MS07-042

KB933579

Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (936227)

2003.1.3bSR2

Yes

MS08-052

954593

Vulnerabilities in GDI+ Could Allow Remote Code Execution (954593)

2003.1.3bSR2

Yes

MS08-053

954156

Vulnerability in Windows Media Encoder 9 could allow remote code execution

2003.1.3bSR2

Yes

 

951702 
CSCsq23169

August 2008 cumulative time zone update for Microsoft Windows operating systems

2003.1.3bSR2

Yes

MS08-058

956390

Cumulative Security Update for Internet Explorer (956390)

2003.1.4sr1

Yes

MS08-061

954211

Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)

2003.1.4sr1

Yes

MS08-062

953155

Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155)

2003.1.4sr1

Yes

MS08-063

957095

Vulnerability in SMB Could Allow Remote Code Execution (957095)

2003.1.4sr1

Yes

MS08-064

956841

Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (956841)

2003.1.4sr1

Yes

MS08-066

956803

Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (956803)

2003.1.4sr1

Yes

 

956391

Cumulative Security Update of ActiveX Kill Bits  (replaces KB953839 and MS08-032/KB950760)

2003.1.4sr1

Yes

MS08-067

958644

Vulnerability in Server Service Could Allow Remote Code Execution (958644)

2003.1.4sr1

Yes

MS08-068

957097

Vulnerability in SMB Could Allow Remote Code Execution (957097)

2003.1.4sr1

Yes

MS08-069

955218

Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218)

2003.1.4sr1

Yes

MS08-071

956802

Vulnerabilities in GDI Could Allow Remote Code Execution (956802)

2003.1.4aSR2

Yes

MS08-073

958215

Cumulative Security Update for Internet Explorer (958215)

2003.1.4aSR2

Yes

MS08-076

959807

Vulnerabilities in Windows Media Components Could Allow Remote Code Execution (959807)

2003.1.4aSR2

Yes


CSCsw35630
948496

High non-paged pool memory usage with OS 2003.1.3b

2003.1.4aSR2

Yes

MS08-078

960714

Security Update for Internet Explorer (960714)

2003.1.4aSR3

Yes

MS09-001

958687

Vulnerabilities in SMB Could Allow Remote Code Execution (958687)

2003.1.4aSR3

Yes


CSCsw90778

TZ: Venezuelan time with Java 1.4.2 reflects GMT instead of GMT-04:30

2003.1.4aSR3

No

MS09-004

959420
960082
960083
CSCtk07151

Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (959420)

2003.1.4aSR4

Yes


960715

Update Rollup for ActiveX Kill Bits

2003.1.4aSR4

Yes


CSCsx24324

Add check for CSCsv52867 applicable systems to OS SR

2003.1.4aSR4

N/A

MS08-052

954593
938464-v2
Vulnerabilities in GDI+ Could Allow Remote Code Execution (954593)
(Microsoft reissued KB)

2003.1.4aSR5

Yes

MS09-006

958690

Vulnerabilities in Windows Kernel Could Allow Remote Code Execution (958690)

2003.1.4aSR5

Yes

MS09-007

960225

Vulnerability in SChannel Could Allow Spoofing (960225)

2003.1.4aSR5

Yes

MS09-008

962238

Vulnerabilities in DNS and WINS Server Could Allow Spoofing (962238)

2003.1.4aSR5

Yes

MS09-011

960477
923561

Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution (960477)

2003.1.4aSR6

Yes

MS09-013

960803

Vulnerabilities in Windows HTTP Services Could Allow Remote Code Execution (960803)

2003.1.4aSR6

Yes

MS09-014

963027

Cumulative Security Update for Internet Explorer (963027)

2003.1.4aSR6

Yes

MS09-010

960477

Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution (960477)

2003.1.4aSR6

Yes

MS09-012

959454
952004
956572

Vulnerabilities in Windows Could Allow Elevation of Privilege (959454)

2003.1.4aSR6

Yes

MS09-015

959426

Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (959426)

2003.1.4aSR6

Yes


969898

Update Rollup for ActiveX Killbits for Windows Server 2003 (KB969898)

2003.1.4aSR7

Yes

MS09-018

971055

Vulnerabilities in Active Directory Could Allow Remote Code Execution (971055)

2003.1.4aSR7

Yes

MS09-022

961501

Vulnerabilities in Windows Print Spooler Could Allow Remote Code Execution (961501)

2003.1.4aSR7

Yes

MS09-019

969897

Cumulative Security Update for Internet Explorer (969897)

2003.1.4aSR7

Yes

MS09-026

970238

Vulnerability in RPC Could Allow Elevation of Privilege (970238)

2003.1.4aSR7

Yes

MS09-025

968537

Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (968537)

2003.1.4aSR7

Yes

MS09-020

970483

Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483)

2003.1.4aSR7

Yes


CSCsy40419

Previous installation errors reported in current installation

2003.1.4aSR7

N/A

MS09-029

961371

Vulnerabilities in the Embedded OpenType Font Engine Could Allow Remote Code Execution (961371)

2003.1.4aSR8

Yes

MS09-028

971633

Vulnerabilities in Microsoft DirectShow Could Allow Remote Code Execution (971633) 

2003.1.4aSR8

Yes

MS09-032

973346

Cumulative Security Update of ActiveX Kill Bits (973346) 

2003.1.4aSR8

Yes


CSCsz86171

DST: MCS OS update needed for 2009 W. Australia DST removal

2003.1.4aSR9

No

MS09-034

972260

Cumulative Security Update for Internet Explorer (972260):

2003.1.5sr1

Yes

MS09-035

969706
973544

Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706)

2003.1.5sr1

Yes

MS09-029

961371-V2

Vulnerabilities in the Embedded OpenType Font Engine Could Allow Remote Code Execution (961371)

2003.1.5sr1

Yes

MS09-044

970927
958469

Vulnerabilities in Remote Desktop Connection Could Allow Remote Code Execution (970927)

2003.1.5sr1

Yes

MS09-039

969883

Vulnerabilities in WINS Could Allow Remote Code Execution (969883)

2003.1.5sr1

Yes

MS09-038

971557

Vulnerabilities in Windows Media File Processing Could Allow Remote Code Execution (971557)

2003.1.5sr1

Yes

MS09-037

973908
973354
973540
973507
973869
973815

Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)

2003.1.5sr1

Yes

MS09-041

971657

Vulnerability in Workstation Service Could Allow Elevation of Privilege (971657)

2003.1.5sr1

Yes

MS09-040

971032

Vulnerability in Message Queuing Could Allow Elevation of Privilege (971032)

2003.1.5sr1

Yes

MS09-042

960859

Vulnerability in Telnet Could Allow Remote Code Execution (960859)

2003.1.5sr1

Yes

MS09-045

971961

Vulnerability in JScript Scripting Engine Could Allow Remote Code Execution (971961)

2003.1.5sr1

Yes

MS09-047

973812

Vulnerabilities in Windows Media Format Could Allow Remote Code Execution (973812)

2003.1.5sr1

Yes

MS09-048

967723

Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (967723)

2003.1.5sr1

Yes

MS09-046

956844

Vulnerability in DHTML Editing Component ActiveX Control Could Allow Remote Code Execution (956844)

2003.1.5sr1

Yes


951531
CSCtb44910

Time drift issue - Windows time won't sync with CMOS clock

2003.1.5sr1

Yes

MS09-051

975682
954155
975025

Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution (975682)

2003.1.5sr1

Yes

MS09-052

974112

Vulnerability in Windows Media Player Could Allow Remote Code Execution (974112)

2003.1.5sr1

Yes

MS09-053

975254

Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution (975254)

2003.1.5sr1

Yes

MS09-054

974455

Cumulative Security Update for Internet Explorer (974455)

2003.1.5sr1

Yes

MS09-055

973525

Cumulative Security Update of ActiveX Kill Bits (973525)

2003.1.5sr1

Yes

MS09-056

974571

Vulnerabilities in Windows CryptoAPI Could Allow Spoofing (974571)

2003.1.5sr1

Yes

MS09-057

969059

Vulnerability in Indexing Service Could Allow Remote Code Execution (969059)

2003.1.5sr1

Yes

MS09-058

971486

Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (971486)

2003.1.5sr1

Yes

MS09-061

974378
953298

Vulnerabilities in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution (974378)

2003.1.5sr1

Yes

MS09-062

957488
958869

Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)

2003.1.5sr1

Yes

MS09-065

969947

Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947)

2003.1.5SR2

Yes

MS09-066

973309

Vulnerability in Active Directory Could Allow Denial of Service (973309)

2003.1.5SR2

Yes


CSCtb43307

MS08-069/KB954430 shows missing in MBSA report on some CRS System

2003.1.5SR2

N/A

MS09-069

974392

Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)

2003.1.5SR3

Yes

MS09-071

974318

Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)

2003.1.5SR3

Yes

MS09-072

976325

Cumulative Security Update for Internet Explorer (976325)

2003.1.5SR3

Yes

MS09-073

975539

Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)

2003.1.5SR3

Yes

MS09-074

967183

Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183)

2003.1.5SR3

Yes


CSCtd34931

7835/45-H2 - NIC driver partially upgraded

2003.1.5SR3

Yes


CSCtd90916

Available PTE on HP 7845 Servers is only 12K

2003.1.5aSR3a

No


CSCte15704

Call Resume Drops GW Call When Shared Lines on Different Nodes

2003.1.5aSR4

Yes

MS10-001

972270

Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (972270)

2003.1.5aSR4

Yes

MS10-002

978207

Cumulative Security Update for Internet Explorer (978207)

2003.1.5aSR5

Yes

MS10-005

978706

Vulnerability in Microsoft Paint Could Allow Remote Code Execution (978706)

2003.1.5aSR5

Yes

MS10-006

978251

Vulnerabilities in SMB Client Could Allow Remote Code Execution (978251)

2003.1.5aSR5

Yes

MS10-007

975713

Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (975713)

2003.1.5aSR5

Yes

MS10-008

978262

Cumulative Security Update of ActiveX Kill Bits (978262)

2003.1.5aSR5

Yes

MS10-011

978037

Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (978037)

2003.1.5aSR5

Yes

MS10-012

971468

Vulnerabilities in SMB Server Could Allow Remote Code Execution (971468)

2003.1.5aSR5

Yes

MS10-013

977935

Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (977935)

2003.1.5aSR5

Yes

MS10-014

977290

Vulnerability in Kerberos Could Allow Denial of Service (977290)

2003.1.5aSR5

Yes

MS10-015

977165

Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165)

2003.1.5aSR5

Yes

MS10-018

975416

Cumulative Security Update for Internet Explorer (980182)

2003.1.5aSR6

Yes

MS10-019

981210
978601
979309

Vulnerabilities in Windows Could Allow Remote Code Execution (981210)

2003.1.5aSR6

Yes

MS10-020

975416

Vulnerabilities in SMB Client Could Allow Remote Code Execution (980232)

2003.1.5aSR6

Yes

MS10-026

977816

Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (977816)

2003.1.5aSR6

Yes

MS10-021

979683

Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (979683)

2003.1.5aSR6

Yes

MS10-022

981169

Vulnerability in VBScript Could Allow Remote Code Execution (981169)

2003.1.5aSR6

Yes

MS10-029

978338

Vulnerabilities in Windows ISATAP Component Could Allow Spoofing (978338)

2003.1.5aSR6

Yes

MS10-030

978542

Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution (978542)

2003.1.5aSR7

Yes

MS10-033

979902
975562
978695
979482

Vulnerabilities in Media Decompression Could Allow Remote Code Execution (979902)

2003.1.5aSR8

Yes

MS10-034

980195

Cumulative Security Update of ActiveX Kill Bits (980195)

2003.1.5aSR8

Yes

MS10-035

982381

Cumulative Security Update for Internet Explorer (982381)

2003.1.5aSR8

Yes

MS10-032

979559

Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (979559)

2003.1.5aSR8

Yes

MS10-037

980218

Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Elevation of Privilege (980218)

2003.1.5aSR8

Yes

MS10-040

982666

Vulnerability in Internet Information Services Could Allow Remote Code Execution (982666)

2003.1.5aSR8

Yes

MS10-041

981343

Vulnerability in Microsoft .NET Framework Could Allow Tampering (981343)

2003.1.5aSR8

Yes


CSCtf81377
979230

WinInet HttpSendRequest calls failing with HTTP error 12029

2003.1.5aSR8

Yes


CSCtg50387

IPT-OS: Upgrade iLO2 Mgt Driver to 1.13

2003.1.5aSR8

No

MS10-042

2229593

Vulnerability in Help and Support Center Could Allow Remote Code Execution (2229593)

2003.1.5aSR9

Yes

MS10-046

2286198

Vulnerability in Windows Shell Could Allow Remote Code Execution (2286198)

2003.1.5aSR10

Yes

MS10-049

980436

Vulnerabilities in SChannel Could Allow Remote Code Execution (980436)

2003.1.5aSR10

Yes

MS10-051

2079403

Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2079403)

2003.1.5aSR10

Yes

MS10-052

2115168

Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (2115168)

2003.1.5aSR10

Yes

MS10-053

2183461

Cumulative Security Update for Internet Explorer (2183461)

2003.1.5aSR10

Yes

MS10-054

982214

Vulnerabilities in SMB Server Could Allow Remote Code Execution (982214)

2003.1.5aSR10

Yes

MS10-048

2160329

Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2160329)

2003.1.5aSR10

Yes

MS10-061

2347290

Vulnerability in Print Spooler Service Could Allow Remote Code Execution (2347290)

2003.1.5aSR11

Yes

MS10-062

975558

Vulnerability in MPEG-4 Codec Could Allow Remote Code Execution (975558)

2003.1.5aSR11

Yes

MS10-063

2320113

Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution (2320113)

2003.1.5aSR11

Yes

MS10-065

2267960

Vulnerabilities in Microsoft Internet Information Services (IIS) Could Allow Remote Code Execution (2267960)

2003.1.5aSR11

Yes

MS10-066

982802

Vulnerability in Remote Procedure Call Could Allow Remote Code Execution (982802)

2003.1.5aSR11

Yes

MS10-067

2259922

Vulnerability in WordPad Text Converters Could Allow Remote Code Execution (2259922)

2003.1.5aSR11

Yes

MS10-068

983539

Vulnerability in Local Security Authority Subsystem Service Could Allow Elevation of Privilege (983539)

2003.1.5aSR11

Yes

MS10-069

2121546

Vulnerability in Windows Client/Server Runtime Subsystem Could Allow Elevation of Privilege (2121546)

2003.1.5aSR11

Yes


CSCti88836

7835/45-I3: IPMI update required

2003.1.5aSR11

No


CSCti68522

Provide documentation for enabling TLS for RDP connections to Server

2003.1.5aSR12

N/A

MS10-070

2418042

Vulnerability in ASP.NET Could Allow Information Disclosure (2418042)

2003.1.5aSR12

Yes

MS10-071

2360131

Cumulative Security Update for Internet Explorer (2360131)

2003.1.5aSR12

Yes

MS10-076

982132

Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (982132)

2003.1.5aSR12

Yes

MS10-073

981957

Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957)

2003.1.5aSR12

Yes

MS10-078

2279986

Vulnerabilities in the OpenType Font (OTF) Format Driver Could Allow Elevation of Privilege (2279986)

2003.1.5aSR12

Yes

MS10-081

2296011

Vulnerability in Windows Common Control Library Could Allow Remote Code Execution (2296011)

2003.1.5aSR12

Yes

MS10-082

2378111

Vulnerability in Windows Media Player Could Allow Remote Code Execution (2378111)

2003.1.5aSR12

Yes

MS10-083

2405882

Vulnerability in COM Validation in Windows Shell and WordPad Could Allow Remote Code Execution (2405882)

2003.1.5aSR12

Yes

MS10-084

2360937

Vulnerability in Windows Local Procedure Call Could Cause Elevation of Privilege (2360937)

2003.1.5aSR12

Yes

MS10-074

2387149

Vulnerability in Microsoft Foundation Classes Could Allow Remote Code Execution (2387149)

2003.1.5aSR12

Yes

MS10-090

2416400

Cumulative Security Update for Internet Explorer (2416400)

2003.1.5aSR13

Yes

MS10-091

2296199

Vulnerabilities in the OpenType Font (OTF) Driver Could Allow Remote Code Execution (2296199)

2003.1.5aSR13

Yes

MS10-094

2447961

Vulnerability in Windows Media Encoder Could Allow Remote Code Execution (2447961)

2003.1.5aSR13

Yes

MS10-096

2423089

Vulnerability in Windows Address Book Could Allow Remote Code Execution (2423089)

2003.1.5aSR13

Yes

MS10-097

2443105

Insecure Library Loading in Internet Connection Signup Wizard Could Allow Remote Code Execution (2443105)

2003.1.5aSR13

Yes

MS10-098

2436673

Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2436673)

2003.1.5aSR13

Yes

MS10-099

2440591

Vulnerability in Routing and Remote Access Could Allow Elevation of Privilege (2440591)

2003.1.5aSR13

Yes

MS10-101

2207559

Vulnerability in Windows Netlogon Service Could Allow Denial of Service (2207559)

2003.1.5aSR13

Yes


2467659

Internet Explorer installation update to fix MS10-090 not showing up in MBSA scan.

2003.1.5aSR13

Yes

MS11-002

2451910
2419635

Vulnerabilities in Microsoft Data Access Components Could Allow Remote Code Execution (2451910)

2003.1.5aSR14

Yes

MS11-003

2482017

Cumulative Security Update for Internet Explorer (2482017)

2003.1.5aSR15

Yes

MS11-006

2483185

Vulnerability in Windows Shell Graphics Processing Could Allow Remote Code Execution (2483185)

2003.1.5aSR15

Yes

MS11-007

2485376

Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2485376)

2003.1.5aSR15

Yes

MS11-005

2478953

Vulnerability in Active Directory Could Allow Denial of Service (2478953)

2003.1.5aSR15

Yes

MS11-010

2476687

Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2476687)

2003.1.5aSR15

Yes

MS11-011

2393802

Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802)

2003.1.5aSR15

Yes

MS11-012

2479628

Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2479628)

2003.1.5aSR15

Yes

MS11-013

2496930
2478971

Vulnerabilities in Kerberos Could Allow Elevation of Privilege (2496930)

2003.1.5aSR15

Yes

MS11-014

2478960

Vulnerability in Local Security Authority Subsystem Service Could Allow Local Elevation of Privilege (2478960)

2003.1.5aSR15

Yes

MS11-019 2511455 Vulnerabilities in SMB Client Could Allow Remote Code Execution (2511455)
2003.1.5aSR16 Yes
MS11-020 2508429 Vulnerability in SMB Server Could Allow Remote Code Execution (2508429) 2003.1.5aSR16 Yes
MS11-029 2489979 Vulnerability in GDI+ Could Allow Remote Code Execution (2489979) 2003.1.5aSR16 Yes
MS11-031 2514666 Vulnerability in JScript and VBScript Scripting Engines Could Allow Remote Code Execution (2514666) 2003.1.5aSR16 Yes
MS11-018 2497640 Cumulative Security Update for Internet Explorer (2497640)  2003.1.5aSR16 Yes
MS11-027 2508272 Cumulative Security Update of ActiveX Kill Bits (2508272)  2003.1.5aSR16 Yes
MS11-030 2509553 Vulnerability in DNS Resolution Could Allow Remote Code Execution (2509553) 2003.1.5aSR16 Yes
MS11-032 2507618 Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2507618) 2003.1.5aSR16 Yes
MS11-024 2527308 Vulnerability in Windows Fax Cover Page Editor Could Allow Remote Code Execution (2527308) 2003.1.5aSR16 Yes
MS11-025 2500212 Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212) 2003.1.5aSR16 Yes
MS11-026 2503658 Vulnerability in MHTML Could Allow Information Disclosure (2503658)
2003.1.5aSR16 Yes
MS11-033 2485663 Vulnerability in WordPad Text Converters Could Allow Remote Code Execution (2485663)  2003.1.5aSR16 Yes
MS11-034 2506223 Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2506223) 2003.1.5aSR16 Yes
MS11-035
2524426 Vulnerability in WINS Could Allow Remote Code Execution (2524426) 2003.1.5aSR17 Yes
MS11-038 2476490 Vulnerability in OLE Automation Could Allow Remote Code Execution (2476490) 2003.1.5aSR18 Yes
MS11-042 2535512 Vulnerabilities in Distributed File System Could Allow Remote Code Execution (2535512) 2003.1.5aSR18 Yes
MS11-043 2536276 Vulnerability in SMB Client Could Allow Remote Code Execution (2536276) 2003.1.5aSR18 Yes
MS11-050 2530548 Cumulative Security Update for Internet Explorer (2530548) 2003.1.5aSR18 Yes
MS11-052 2544521 Vulnerability in Vector Markup Language Could Allow Remote Code Execution (2544521)  2003.1.5aSR18 Yes
MS11-037 2544893 Vulnerability in MHTML Could Allow Information Disclosure (2544893) 2003.1.5aSR18 Yes
MS11-046 2503665 Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2503665)  2003.1.5aSR18 Yes
MS11-025 2538242
2538243
Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212) 2003.1.5aSR18 Yes
MS11-054 2555917 Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2555917) 2003.1.5aSR19 Yes
MS11-056 2507938 Vulnerabilities in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2507938) 2003.1.5aSR19 Yes
MS11-043(v2)2536276Vulnerability in SMB Client Could Allow Remote Code Execution (2536276)2003.1.5aSR20Yes
MS11-0652570222Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (2570222)2003.1.5aSR20Yes
MS11-0572559049Cumulative Security Update for Internet Explorer (2559049)2003.1.5aSR20Yes
MS11-0582562485Vulnerabilities in DNS Server Could Allow Remote Code Execution (2562485)2003.1.5aSR20Yes
MS11-0622566454Vulnerability in Remote Access Service NDISTAPI Driver Could Allow Elevation of Privilege (2566454)2003.1.5aSR20Yes
MS11-0632567680Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2567680)2003.1.5aSR20Yes
2562937Update Rollup for ActiveX Kill Bits2003.1.5aSR20Yes
MS11-0702571621Vulnerability in WINS Could Allow Elevation of Privilege (2571621)2003.1.5aSR21Yes
MS11-0712570947Vulnerability in Windows Components Could Allow Remote Code Execution (2570947)2003.1.5aSR21Yes
MS11-0782572069Vulnerability in .NET Framework and Microsoft  Silverlight  Could Allow Remote Code Execution(2604930)2003.1.5aSR22Yes
MS11-0812586448Cumulative Secuity Update for Internet Explorer(2586448)2003.1.5aSR22Yes
MS11-0802592799Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege(2592799)2003.1.5aSR22Yes
MS11-0752564958Vulnerability in Microsoft Active Accessibility Could Allow Remote Code Execution(2623699)2003.1.5aSR22Yes
MS11-0772567053Vulnerability in Windows Kernel-mode Drivers Could Allow Remote Code Execution(2567053)2003.1.5aSR22Yes
CSCts99540
2570791
Cisco OS should implement changes in the TimeZones2003.1.5aSR22Yes
CSCts82594
2616676
Removing DigiNotar issued certificates2003.1.5aSR22Yes
MS11-0862601626Vulnerability in Active Directory Could Allow Elevation of Privilege(2630837)2003.1.5aSR23Yes
MS11-0372544893Vulnerability in MHTML Could Allow Information Disclosure(2544893)2003.1.5aSR23Yes
MS11-0872639417Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2639417)2003.1.5aSR24Yes
MS11-0902618451Cumulative Security Update of ActiveX Kill Bits (2618451)2003.1.5aSR24Yes
MS11-0932624667Vulnerability in OLE Could Allow Remote Code Execution (2624667)2003.1.5aSR24Yes
MS11-0952621146Vulnerability in Active Directory Could Allow Remote Code Execution (2640045)2003.1.5aSR24Yes
MS11-0972620712Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2620712)2003.1.5aSR24Yes
MS11-0982633171Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2633171)2003.1.5aSR24Yes
MS11-0992618444Cumulative Security Update for Internet Explorer (2618444)2003.1.5aSR24Yes
2633952December 2011 cumulative time zone update for Windows operating systems2003.1.5aSR24Yes
MS12-0012644615Vulnerability in Windows Kernel Could Allow Security Feature Bypass(2644615)2003.1.5aSR25Yes
MS12-0022603381Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381)2003.1.5aSR25Yes
MS12-0032646524Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524)2003.1.5aSR25Yes
MS12-0042598479Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391)2003.1.5aSR25Yes
MS12-0042631813Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391)2003.1.5aSR25Yes
MS12-0052584146Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146)2003.1.5aSR25Yes
MS12-0062585542Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584)2003.1.5aSR25Yes
MS12-0062638806Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584)2003.1.5aSR25Yes
MS11-1002656358Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2638420)2003.1.5aSR25Yes

Installing the Service Release
Perform the following procedure to install the service release:
1.      Disable or uninstall all virus scanning software or Intrusion Detect Software (such as CSA) prior to running this installation.
2.      Download the file to a location that you will remember.
3.      Double click the executable.
4.      To acknowledge that the server runs OS version 2003.1.5 and that you are not installing the service release through Terminal Services, click Yes.  If the server does not run OS version 2003.1.5, install it before you run this service release.
5.      Files automatically extract and install on the server.
6.      After the installation finishes, it will report the number of errors detected and ask if you want to view the logfile.
7.      If there are no errors detected, you can select “No”; otherwise click yes to view the log.  There is an ERRORS section at the very end of the logfile to assist in finding the errors.
8.      Click OK to confirm the reboot
9.      Perform this procedure on all supported servers in the cluster.
10.  If you choose to do so, you can use the Baseline Security Analyzer to verify the hotfixes that are installed on each server.  See the “Verifying HotFixes By Using Baseline Security Analyzer” section.
 
Verifying HotFixes By Using Microsoft Baseline Security Analyzer
If you want to do so, you can use the Microsoft Baseline Security Analyzer utility (run c:\utils\mbsa_scan.cmd) to verify which hotfixes are installed on the server.
Microsoft Baseline Security Analyzer (MBSA)
Make sure that you review the Reason column of the MBSA report to identify whether the hotfix should be installed.  The following table shows expected results from MBSA on a fully patched system.   
Note:  The term, Note, in the Message column indicates that the utility is not able to detect whether the hotfix is installed.  Review the information in the Reason column for more information. 

Scan date: 12/13/2011 8:57 PM
Scanned with MBSA version: 2.1.2104.0
Catalog synchronization date: 2011-12-13T03:32:07Z
Security update catalog: Microsoft Update (offline)

  Security Updates Scan Results
   
        Issue:  Developer Tools, Runtimes, and Redistributables Security Updates
       Score:  Check passed
       Result: No security updates are missing.

        Current Update Compliance
       
            | MS11-025 | Installed | Security Update for Microsoft Visual C++ 2005 Service Pack 1 Redistributable Package (KB2538242) | Important |
            | MS11-025 | Installed | Security Update for Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package (KB2538243) | Important |

        Issue:  SDK Components Security Updates
       Score:  Check passed
       Result: No security updates are missing.

        Current Update Compliance
       
            | MS07-028 | Installed | Security Update for CAPICOM (KB931906) | Critical |

        Issue:  SQL Server Security Updates
       Score:  Check passed
       Result: No security updates are missing.

        Current Update Compliance
       
            | MS06-061 | Installed | MSXML 6.0 RTM Security Update  (925673) | Critical |
            | MS09-004 | Installed | Security Update for SQL Server 2000 Service Pack 4 (KB960082) | Important |

        Issue:  Windows Security Updates
       Score:  Check failed (non-critical)
       Result: 4 service packs or update rollups are missing.

        Update Rollups and Service Packs
       
            | 890830 | Missing | Windows Malicious Software Removal Tool - December 2011 (KB890830) |  |
            | 940767 | Missing | Windows Internet Explorer 7 for Windows Server 2003 |  |
            | 951847 | Missing | Microsoft .NET Framework 3.5 Service Pack 1 and .NET Framework 3.5 Family Update (KB951847) x86 |  |
            | 944036 | Missing | Internet Explorer 8 for Windows Server 2003 |  |

        Current Update Compliance
       
            | MS09-071 | Installed | Security Update for Windows Server 2003 (KB974318) | Important |
            | MS10-097 | Installed | Security Update for Windows Server 2003 (KB2443105) | Important |
            | MS11-098 | Installed | Security Update for Windows Server 2003 (KB2633171) | Important |
            | MS10-007 | Installed | Security Update for Windows Server 2003 (KB975713) | Critical |
            | MS11-063 | Installed | Security Update for Windows Server 2003 (KB2567680) | Important |
            | MS08-046 | Installed | Security Update for Windows Server 2003 (KB952954) | Critical |
            | MS10-029 | Installed | Security Update for Windows Server 2003 (KB978338) | Moderate |
            | MS10-083 | Installed | Security Update for Windows Server 2003 (KB979687) | Important |
            | MS11-014 | Installed | Security Update for Windows Server 2003 (KB2478960) | Important |
            | MS11-005 | Installed | Security Update for Windows Server 2003 (KB2478953) | Important |
            | MS08-069 | Installed | Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB954430) | Important |
            | MS09-010 | Installed | Security Update for Windows Server 2003 (KB923561) | Important |
            | MS11-099 | Installed | Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB2618444) | Low |
            | MS10-096 | Installed | Security Update for Windows Server 2003 (KB2423089) | Important |
            | MS10-070 | Installed | Security Update for Microsoft .NET Framework 1.1 SP1, Windows Server 2003, and Windows Server 2003 R2 x86 (KB2416451) | Important |
            | MS11-078 | Installed | Security Update for Microsoft .NET Framework 1.1 SP1 on Windows Server 2003 and Windows Server 2003 R2 x86 (KB2572069) | Critical |
            | MS09-051 | Installed | Security Update for Windows Media Format Runtime 9.5 for Windows Server 2003 (KB954155) | Critical |
            | MS11-065 | Installed | Security Update for Windows Server 2003 (KB2570222) | Important |
            | MS08-007 | Installed | Security Update for Windows Server 2003 (KB946026) | Important |
            | 2633952 | Installed | Update for Windows Server 2003 (KB2633952) |  |
            | MS11-013 | Installed | Security Update for Windows Server 2003 (KB2478971) | Important |
            | MS10-082 | Installed | Security Update for Windows Server 2003 (KB2378111) | Important |
            | MS08-071 | Installed | Security Update for Windows Server 2003 (KB956802) | Critical |
            | MS11-038 | Installed | Security Update for Windows Server 2003 (KB2476490) | Critical |
            | MS09-037 | Installed | Security Update for Windows Server 2003 (KB973815) | Critical |
            | MS07-067 | Installed | Security Update for Windows Server 2003 (KB944653) | Important |
            | MS09-012 | Installed | Security Update for Windows Server 2003 (KB956572) | Important |
            | MS07-020 | Installed | Security Update for Windows Server 2003 (KB932168) | Moderate |
            | MS11-093 | Installed | Security Update for Windows Server 2003 (KB2624667) | Important |
            | MS09-041 | Installed | Security Update for Windows Server 2003 (KB971657) | Important |
            | MS09-056 | Installed | Security Update for Windows Server 2003 (KB974571) | Important |
            | MS10-013 | Installed | Security Update for Windows Server 2003 (KB975560) | Critical |
            | 914961 | Installed | Windows Server 2003 Service Pack 2 (32-bit x86) |  |
            | MS11-070 | Installed | Security Update for Windows Server 2003 (KB2571621) | Important |
            | MS08-005 | Installed | Security Update for Windows Server 2003 (KB942831) | Important |
            | MS09-046 | Installed | Security Update for Windows Server 2003 (KB956844) | Moderate |
            | MS10-019 | Installed | Security Update for Windows Server 2003 (KB979309) | Critical |
            | MS10-033 | Installed | Security Update for Windows Media Format Runtime 9.5 for Windows Server 2003 (KB978695) | Critical |
            | MS10-042 | Installed | Security Update for Windows Server 2003 (KB2229593) | Low |
            | MS10-040 | Installed | Security Update for Windows Server 2003 (KB982666) | Important |
            | MS09-057 | Installed | Security Update for Windows Server 2003 (KB969059) | Important |
            | MS09-052 | Installed | Security Update for Windows Server 2003 (KB974112) | Critical |
            | MS09-037 | Installed | Security Update for Windows Server 2003 (KB973507) | Critical |
            | MS07-017 | Installed | Security Update for Windows Server 2003 (KB925902) | Critical |
            | MS09-048 | Installed | Security Update for Windows Server 2003 (KB967723) | Important |
            | MS09-037 | Installed | Security Update for Windows Server 2003 (KB973869) | Critical |
            | MS09-073 | Installed | Security Update for Windows Server 2003 (KB973904) | Important |
            | MS10-081 | Installed | Security Update for Windows Server 2003 (KB2296011) | Important |
            | MS11-062 | Installed | Security Update for Windows Server 2003 (KB2566454) | Important |
            | MS11-037 | Installed | Security Update for Windows Server 2003 (KB2544893) | Low |
            | MS11-043 | Installed | Security Update for Windows Server 2003 (KB2536276) | Critical |
            | MS10-065 | Installed | Security Update for Windows Server 2003 (KB2124261) | Important |
            | MS11-031 | Installed | Security Update for Windows Server 2003 (KB2510587) | Critical |
            | MS10-052 | Installed | Security Update for Windows Server 2003 (KB2115168) | Critical |
            | MS10-001 | Installed | Security Update for Windows Server 2003 (KB972270) | Low |
            | MS11-032 | Installed | Security Update for Windows Server 2003 (KB2507618) | Important |
            | MS10-049 | Installed | Security Update for Windows Server 2003 (KB980436) | Critical |
            | MS08-069 | Installed | Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB954459) | Important |
            | MS11-090 | Installed | Cumulative Security Update for ActiveX Killbits for Windows Server 2003 (KB2618451) | Critical |
            | MS11-052 | Installed | Security Update for Internet Explorer 6 for Windows Server 2003 (KB2544521) | Moderate |
            | MS11-020 | Installed | Security Update for Windows Server 2003 (KB2508429) | Critical |
            | MS08-036 | Installed | Security Update for Windows Server 2003 (KB950762) | Important |
            | MS11-075 | Installed | Security Update for Windows Server 2003 (KB2564958) | Important |
            | MS10-013 | Installed | Security Update for Windows Server 2003 (KB977914) | Critical |
            | MS08-067 | Installed | Security Update for Windows Server 2003 (KB958644) | Critical |
            | MS10-033 | Installed | Security Update for Windows Server 2003 (KB975562) | Critical |
            | MS09-012 | Installed | Security Update for Windows Server 2003 (KB952004) | Important |
            | MS09-013 | Installed | Security Update for Windows Server 2003 (KB960803) | Critical |
            | MS11-011 | Installed | Security Update for Windows Server 2003 (KB2393802) | Important |
            | MS06-078 | Installed | Security Update for Windows Media Player 6.4 (KB925398) | Critical |
            | MS09-022 | Installed | Security Update for Windows Server 2003 (KB961501) | Moderate |
            | MS11-030 | Installed | Security Update for Windows Server 2003 (KB2509553) | Important |
            | MS10-033 | Installed | Security Update for Windows Server 2003 (KB979482) | Critical |
            | MS08-076 | Installed | Security Update for Windows Server 2003 (KB952069) | Important |
            | MS09-042 | Installed | Security Update for Windows Server 2003 (KB960859) | Important |
            | MS11-087 | Installed | Security Update for Windows Server 2003 (KB2639417) | Critical |
            | MS11-042 | Installed | Security Update for Windows Server 2003 (KB2535512) | Critical |
            | MS11-071 | Installed | Security Update for Windows Server 2003 (KB2570947) | Important |
            | MS07-040 | Installed | Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) | Critical |
            | MS11-029 | Installed | Security Update for Windows Server 2003 (KB2412687) | Critical |
            | MS11-097 | Installed | Security Update for Windows Server 2003 (KB2620712) | Important |
            | MS09-069 | Installed | Security Update for Windows Server 2003 (KB974392) | Important |
            | MS11-006 | Installed | Security Update for Windows Server 2003 (KB2483185) | Critical |
            | MS10-063 | Installed | Security Update for Windows Server 2003 (KB981322) | Critical |
            | MS09-040 | Installed | Security Update for Windows Server 2003 (KB971032) | Important |
            | MS11-024 | Installed | Security Update for Windows Server 2003 (KB2506212) | Important |
            | MS10-005 | Installed | Security Update for Windows Server 2003 (KB978706) | Moderate |
            | MS09-044 | Installed | Security Update for Windows Server 2003 (KB958469) | Critical |
            | MS10-019 | Installed | Security Update for Windows Server 2003 (KB978601) | Critical |
            | MS10-020 | Installed | Security Update for Windows Server 2003 (KB980232) | Critical |
            | MS10-026 | Installed | Security Update for Windows Server 2003 (KB977816) | Critical |
            | MS07-068 | Installed | Security Update for Windows Server 2003 (KB941569) | Critical |
            | MS11-033 | Installed | Security Update for Windows Server 2003 (KB2485663) | Important |
            | MS09-015 | Installed | Security Update for Windows Server 2003 (KB959426) | Moderate |
            | MS10-074 | Installed | Security Update for Windows Server 2003 (KB2387149) | Moderate |
            | MS10-062 | Installed | Security Update for Windows Server 2003 (KB975558) | Critical |
            | MS10-061 | Installed | Security Update for Windows Server 2003 (KB2347290) | Important |
            | MS11-080 | Installed | Security Update for Windows Server 2003 (KB2592799) | Important |
            | MS10-041 | Installed | Microsoft .NET Framework 1.1 SP1 Security Update for Windows Server 2003 x86 and Windows Server 2003 R2 x86 (KB979907) | Important |
            | MS10-051 | Installed | Security Update for Windows Server 2003 (KB2079403) | Moderate |
            | MS09-051 | Installed | Security Update for Windows Server 2003 (KB975025) | Critical |
            | MS09-037 | Installed | Security Update for Windows Server 2003 (KB973540) | Critical |
            | MS11-002 | Installed | Security Update for Windows Server 2003 (KB2419635) | Important |
            | MS11-095 | Installed | Security Update for Windows Server 2003 (KB2621146) | Important |
            | MS11-056 | Installed | Security Update for Windows Server 2003 (KB2507938) | Important |
            | MS08-049 | Installed | Security Update for Windows Server 2003 (KB950974) | Important |
            | MS10-084 | Installed | Security Update for Windows Server 2003 (KB2360937) | Important |
            | MS10-076 | Installed | Security Update for Windows Server 2003 (KB982132) | Critical |
            | MS07-034 | Installed | Cumulative Security Update for Outlook Express for Windows Server 2003 (KB929123) | Low |
            | MS10-099 | Installed | Security Update for Windows Server 2003 (KB2440591) | Important |
            | MS11-058 | Installed | Security Update for Windows Server 2003 (KB2562485) | Important |
            | MS09-020 | Installed | Security Update for Windows Server 2003 (KB970483) | Important |
            | MS10-030 | Installed | Security Update for Windows Server 2003 (KB978542) | Critical |

2011-12-13 20:57:56 : MBSA_Scan successfully executed
2011-12-13 20:57:56 : Successfully stopped wuauserv
[SC] ChangeServiceConfig SUCCESS
2011-12-13 20:57:56 : Success detected disabling wuauserv
2011-12-13 20:57:56 :
2011-12-13 20:57:56 : End MBSA Scan



Known Caveats


Uninstalling Hotfixes

 If you need to uninstall this OS Service Release or one of its hotfixes, follow the uninstall procedures exactly as they appear in this section.  Most hotfixes have an uninstall program provided by Microsoft, but there are caveats associated with uninstalling the hotfixes, This section provides procedures to uninstall a single hotfix and to uninstall the entire OS Service Release.

 Perform the following procedure to uninstall a single hotfix:

1.      Verify whether the hotfix can be uninstalled by checking the Uninstall Supported column of the Hotfixes That Are Included in the Service Release table.  If No displays in that column, you cannot use this procedure to uninstall the hotfix.  The only way to return the server to a state without the hotfix, is to fail back to a saved copy of the mirrored drive or rebuild the server, install the IP Telephony application, and restore the database.  If Yes displays in the Uninstall Supported column, continue with Step 2.

2.      Choose Start > Settings > Control Panel > Add/Remove Programs.  Hotfixes appear near the bottom of the Add/Remove Programs window.  Each hotfix begins with Windows 2003 Hotfix and is followed by the Microsoft Knowledge Base (KB or Q) article number.  You can use the Hotfixes That Are Included in the Service Release table to convert the security bulletin number (MS05-053) to a KB or Q number (KB896424).

3.      Select the hotfix you want to uninstall and click Change/Remove.  The Windows 2003 <hotfix number> Removal Wizard displays. 

4.      Click Next.  The steps may differ, depending on the uninstall program provided with the hotfix.  If a window appears with a message asking whether you want to uninstall the hotfix, click Yes.

5.      It’s very likely that the Inspecting Current Configuration step of the Removal Wizard will detect a list of hotfixes or programs that may be affected by removing this hotfix.  Record this list.  All the hotfixes listed will need to be re-installed and any applications listed should be checked to confirm they are still working properly.  Removing this hotfix will replace the system files it backed up with it was originally installed.  Other hotfixes or applications may be dependant on these same files.  The Removal Wizard does not know whether or not the applications or hotfixes will be affected.  It just has detected that they have been installed after the hotfix being removed was installed.  After recording the list, click Yes.

6.      Click Finish.  The server will reboots, if needed.  If you are prompted to reboot, click Yes.

7.      If the Inspecting Current Configuration step of the Removal Wizard listed any other hotfixes, reinstall those hotfixes now.  The the individual hotfix installations can be found in C:\Program Files\Cisco\Updates\2003.1.x_common.  The files will be named by their KB or Q number and should match what you have written down.  Double-click the first hotfix that is on your list of hotfixes that need to be reinstalled, and follow the prompts to install the hotfix.  Repeat this step for each hotfix you need to reinstall.  You do not need to reboot between hotfixes.  Once you have reinstalled all the hotfixes on your list, reboot the server.

8.      If the Inspecting Current Configuration step of the Removal Wizard listed any applications, confirm that they are still working properly.

 

Perform the following procedure to uninstall this entire OS Service Release:

1.      In order to determine what hotfixes need to be uninstalled, you need to determine what the OS level was before you applied this Service Release.  The minimum OS level for this Service Release is OS Upgrade 2003.1.3b so that is the starting point.  To determine what Service Releases where applied after OS Upgrade 2003.1.3b, use the History.log file.  Click Start > Cisco Install Logs  (C:\Program Files\Common Files\Cisco\Logs)

2.      Double-click History.log (or just History if known file extensions are hidden)

3.      Find OS Upgrade 2003.1.5 and search down the list for the last 2003.1.5SR# before the one you are trying to uninstall.  Record this Service Release number.

4.      Use the Hotfixes That Are Included in the Service Release table to find all the hotfixes installed after the Service Release recorded in the previous step.

5.      Choose Start > Settings > Control Panel > Add/Remove Programs.  Hotfixes appear near the bottom of the Add/Remove Programs window.  Each hotfix begins with Windows 2003 Hotfix and is followed by the Microsoft Knowledge Base (KB or Q) article number.  You can use the Hotfixes That Are Included in the Service ReleaseHotfixes That Are Included in the Service Release table to convert the security bulletin number (e.g. MS05-053) to a KB or Q number (e.g. KB896424).

6.      Select the hotfix you want to uninstall and click Change/Remove.  The Windows 2003 <hotfix number> Removal Wizard displays. 

7.      Click Next.  The steps may differ, depending on the uninstall program provided with the hotfix.  If a window appears with a message asking whether you want to uninstall the hotfix, click Yes.

8.      It’s very likely that the Inspecting Current Configuration step of the Removal Wizard will detect a list of hotfixes or programs that may be affected by removing this hotfix.  Record this list.  All the hotfixes listed will need to be re-installed and any applications listed should be checked to confirm they are still working properly.  Removing this hotfix will replace the system files it backed up with it was originally installed.  Other hotfixes or applications may be dependant on these same files.  The Removal Wizard does not know whether or not the applications or hotfixes will be affected.  It just has detected that they have been installed after the hotfix being removed was installed.  After recording the list, click Yes.

9.      Click Finish.  The server will reboots, if needed.  If you are prompted to reboot, click Yes.

10.  Follow steps 6 - 9 until all the hotfix you want to uninstall have been removed.

11.  If the Inspecting Current Configuration step of the Removal Wizard listed any other hotfixes, reinstall those hotfixes now.  The the individual hotfix installations can be found in C:\Program Files\Cisco\Updates\2003.1.x_common.  The files will be named by their KB or Q number and should match what you have written down.  Double-click the first hotfix that is on your list of hotfixes that need to be reinstalled, and follow the prompts to install the hotfix.  Repeat this step for each hotfix you need to reinstall.  You do not need to reboot between hotfixes.  Once you have reinstalled all the hotfixes on your list, reboot the server.

12.  If the Removal Wizard listed any applications in the Inspecting Current Configuration step, confirm that they are still working properly.

 

Instructions for enabling TLS for RDP connections (CSCti68522)

The following are specific instructions for a Cisco Unified Communications Manager system. (For further details on this subject matter, see MS article: KB895433 How to configure a Windows Server 2003 terminal server to use TLS for server authentication: http://support.microsoft.com/kb/895433)
  1. From Internet Explorer - go to https://hostname/CCMAdmin/Main.asp  (where hostname is the local servername)
  2. Accept the certificate
  3. Then to permanently import it, From the IE file menu, select properties, click certificates, and then click Install Certificate and follow the prompts.
  4. Bring up Terminal Services Configuration
  5. Right Click on RDP-Tcp and select Properties.
  6. On the Security Layer dropdown, select "SSL"
  7. Click Edit button next to "Certificate" box.
  8. Select Certificate, and click OK.
  9. When remotely connecting from an RDP client - the client will now request to verify the certificate. 

NOTE:  RDP 5.2 and higher clients will now be required to remotely connect to the server.  Older/incompatible RDP clients may attempt to connect and then appear to hang, or just error out.