What's this bulletin about?
Microsoft Security Bulletin MS00-074 announces the availability of a patch that eliminates a vulnerability in Microsoft® WebTV for Windows. Microsoft is committed to protecting customers' information, and is providing the bulletin to inform customers of the vulnerability and what they can do about it.
What's the scope of the vulnerability?
This is a Denial of Service vulnerability. A malicious user could use the vulnerability to crash either the operating system or the WebTV for Windows application.
By default, WebTV for Windows is not automatically installed on Windows 98, 98Se, or Windows Me operating systems, and only customers who have installed it would be at risk from this vulnerability. The vulnerability could be used to crash the WebTV for Windows application and/or the host operating system, but could not be used for any broader attack - that is, it could not be used to compromise data on an affected system or usurp administrative control.
The WebTV for Windows application could be restored on an affected machine by restarting the application.
What causes the vulnerability?
A flaw in the WebTV for Windows application may cause either the application or the operating system to fail when provided with a particular malformed input string from a malicious client machine.
What is WebTV for Windows
WebTV for Windows is an add-in application that ships with Windows 98, 98SE and Windows Me Operating Systems. The application works in conjunction with a TV tuner card to display TV programming on the computer.
What's the problem with the WebTV for Windows application?
The WebTV for Windows application does not correctly handle a particular kind of malformed input string that could be sent to it from a client. If such a string were received by an affected system, it would cause the application and/or operating system to fail.
Who could exploit this vulnerability?
Any malicious user who could send data to an affected machine could exploit the vulnerability. If an affected machine were directly connected to the Internet, the vulnerability could be exploited by a malicious user on the Internet.
Does this have anything to do with WebTV?
No. WebTV (www.webtv.com) is a service that provides Internet services to users via their television. WebTV for Windows is an unrelated product that enables users to view TV programs on their computer.
Who should use the patch?
Microsoft recommends that users who have installed WebTV for Windows consider installing the patch.
What does the patch do?
The patch eliminates the vulnerability by causing the WebTV for Windows application to process the string at issue correctly.
How do I use the patch?
Knowledge Base article 274113 (available soon) contains detailed instructions for applying the patch to your site
Where can I get the patch?
The download location for the patch is provided in the "Patch Availability" section of the security bulletin .
How can I tell if I installed the patch correctly?
The Knowledge Base article 274113 (available soon) provides a manifest of the files in the patch package.The easiest way to verify that you've installed the patch correctly is to verify that these files are present on your computer, and have the same sizes and creation dates as shown in the KB article
What is Microsoft doing about this issue?
| • | Microsoft has delivered a patch that eliminates the vulnerability. |
| • | Microsoft has provided a security bulletin and this FAQ to provide customers with a detailed understanding of the vulnerability and the procedure to eliminate it. |
| • | Microsoft has sent copies of the security bulletin to all subscribers to the Microsoft Product Security Notification Service, a free e-mail service that customers can use to stay up to date with Microsoft security bulletins. |
| • | Microsoft has issued a Knowledge Base article (available soon) explaining the vulnerability and procedure in more detail. |
Where can I learn more about best practices for security?
The Microsoft TechNet Security web site is the best to place to get information about Microsoft security.
How do I get technical support on this issue?
Microsoft Product Support Services can provide assistance with this or any other product support issue.
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.