Select the product you need help with
MS02-048: Flaw in Certificate Enrollment Control May Cause Digital Certificates to Be DeletedArticle ID: 323172 - View products that this article applies to. This article was previously published under Q323172 On This PageSYMPTOMS
The versions of Microsoft Windows that are listed in the "Applies to" section of this article include an ActiveX control that is known as the Certificate Enrollment control. This control is located in the Xenroll.dll binary. Windows uses this control to allow Web-based certificate enrollments and to submit PKCS #10-compliant certificate requests. When this control receives the requested certificate, it stores the certificate in the user's local certificate store, which is part of the user profile. The Certificate Enrollment control contains a flaw that may allow a Web page, by using an extremely complex process, to run the control in a way that deletes the certificates on a user's system. An attacker who successfully exploits this vulnerability may be able to delete trusted root certificates, EFS encryption certificates, e-mail signing certificates, and any other certificates on the computer, thereby preventing the user from using these features. An attack may be carried out in either of the following scenarios:
Mitigating Factors
RESOLUTION
Microsoft has released an update that prevents the flawed control from being called from Web pages and installs new versions of the control. The client update includes a registry change that turns off the earlier version of the control and installs the new version of the control. Because a common version of the Certificate Enrollment control must be provided to all supported clients, a dependency on CryptoAPI is created. The new Certificate Enrollment control is dependent on the functionality that is only available with Microsoft Internet Explorer 5.0 or later. Therefore, this update is not installed on computers that are not running Internet Explorer 5 or later. If you are not using Internet Explorer 5 or later, you receive the following error message:
This update is not designed for your version of Internet Explorer. Press OK to exit.
For more information about how to resolve this vulnerability, click any of the following links to review the section that applies to your operating system.
Windows XP (All Versions)To resolve this problem, obtain the latest service pack for Windows XP. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:322389
(http://support.microsoft.com/kb/322389/EN-US/
)
How to Obtain the Latest Windows XP Service Pack
Windows XP Pre-SP1 Download InformationIf you have not applied Windows XP Service Pack 1 (SP1) or later, apply the appropriate patch to resolve this problem. The following files are available for download from the Microsoft Download Center:Windows XP Professional and Windows XP Home: English (US): Windows XP 64-Bit Edition:
Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=en)
Arabic: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=ar)
Chinese (Simplified): Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=zh-cn)
Chinese (Traditional): Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=zh-tw)
Czech: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=cs)
Danish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=da)
Dutch: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=nl)
Finnish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=fi)
French: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=fr)
German: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=de)
Greek: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=el)
Hebrew: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=he)
Hungarian: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=hu)
Italian: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=it)
Japanese: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=ja)
Korean: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=ko)
Norwegian: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=no)
Polish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=pl)
Portuguese: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=pt-pt)
Portuguese (Brazil): Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=pt-br)
Russian: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=ru)
Spanish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=es)
Swedish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=sv)
Turkish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=d82c3aa2-2130-4e58-b8e0-41c30590f857&DisplayLang=tr)
English (US):
Release Date: August 28, 2002Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=9a30f025-9ce0-454c-ae39-3fdc3464f540&DisplayLang=en)
French: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=9a30f025-9ce0-454c-ae39-3fdc3464f540&DisplayLang=fr)
German: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=9a30f025-9ce0-454c-ae39-3fdc3464f540&DisplayLang=de)
Japanese: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=9a30f025-9ce0-454c-ae39-3fdc3464f540&DisplayLang=ja)
For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
Installation InformationBefore you apply this update, close all programs, Internet Explorer browser sessions, and Web services.To apply this update on a Windows XP-based client, the user who is logged on must be a member of the local Power Users group or the Administrators group. You must restart your computer after you apply this update. This update supports the following Setup switches:
filename -u -q -z WARNING: Your computer is vulnerable until you restart it.
File InformationThe English version of this fix has the file attributes (or later) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (also known as Universal Time Coordinate [UTC]). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.Date Version Size File name ------------------------------------------------ 09-Jul-2002 5.131.3659.0 172,664 Xenroll.dll Windows 2000 (All Versions) Service Pack InformationTo resolve this problem, obtain the latest service pack for Microsoft Windows 2000. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:260910
(http://support.microsoft.com/kb/260910/EN-US/
)
How to Obtain the Latest Windows 2000 Service Pack
Windows 2000 (All Versions) Hotfix InformationA supported fix is now available from Microsoft, but it is only intended to correct the problem that is described in this article. Apply it only to computers that you determine are at risk of attack. Evaluate your computer's physical accessibility, network and Internet connectivity, and other factors to determine the degree of risk to your computer. See the associated Microsoft Security Bulletin
(http://www.microsoft.com/technet/security/bulletin/MS02-048.mspx)
to help determine the degree of risk. This fix may receive additional testing. If your computer is sufficiently at risk, Microsoft recommends that you apply this fix now. Otherwise, wait for the next Windows 2000 service pack that contains this fix.To resolve this problem immediately, download the fix by following the instructions later in this article or contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information about support costs, visit the following Microsoft Web site: http://support.microsoft.com/default.aspx?scid=fh;EN-US;CNTACTMS NOTE: In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The usual support costs will apply to additional support questions and issues that do not qualify for the specific update in question.
(http://support.microsoft.com/default.aspx?scid=fh;en-us;cntactms)
Download InformationThe following file is available for download from the Microsoft Download Center:All Languages: Release Date: August 28, 2002Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=e8e33441-b6f4-4ee3-aff6-7cfc19b3354e&DisplayLang=en)
For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591 Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on secure servers that prevent any unauthorized changes to the file.
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online ServicesInstallation InformationBefore you apply this update, close all programs, Internet Explorer browser sessions, and Web services.To apply this update on a Windows 2000-based client, the user who is logged on must be a member of the local Power Users group or the Administrators group. Downloads of the Certificate Enrollment control (Xenroll.dll) to Alpha-based client computers from Windows 2000 that has certificate services installed is no longer supported. You must restart your computer after you apply this update. This update supports the following Setup switches:
filename -u -q -z WARNING: Your computer is vulnerable until you restart it.
File InformationThe English version of this fix has the file attributes (or later) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.Date Version Size File name --------------------------------------------------- 09-Jul-2002 5.131.3659.0 172,664 Xenroll.dll 05-Aug-2002 5.131.2195.5938 48,568 Scrdenrl.dll Windows NT 4.0 (All Versions)A supported hotfix is now available from Microsoft, but it is only intended to correct the problem that this article describes. Apply it only to systems that you determine are at risk of attack. Evaluate the computer's physical accessibility, network and Internet connectivity, and other factors to determine the degree of risk to the computer. See the associated Microsoft Security Bulletin
(http://www.microsoft.com/technet/security/bulletin/MS02-048.mspx)
to help determine the degree of risk. This hotfix may receive additional testing. If the computer is sufficiently at risk, we recommend that you apply this hotfix now. To resolve this problem immediately, download the hotfix by following the instructions later in this article or contact Microsoft Product Support Services to obtain the hotfix. For a complete list of Microsoft Product Support Services telephone numbers and information about support costs, visit the following Microsoft Web site: http://support.microsoft.com/contactus/?ws=support Note In special cases, charges that are ordinarily incurred for support calls may be canceled, if a Microsoft Support Professional determines that a specific update will resolve your problem. The usual support costs will apply to additional support questions and issues that do not qualify for the specific update in question.
(http://support.microsoft.com/contactus/?ws=support)
Download InformationThe following files are available for download from the Microsoft Download Center:Windows NT 4.0 English: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&displaylang=en)
Arabic: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=ar)
Chinese (Simplified): Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=zh-cn)
Chinese (Traditional): Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=zh-tw)
Chinese (Hong Kong): Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=zh-tw)
Czech: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=cs)
Danish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=da)
Dutch: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=nl)
Finnish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=fi)
French: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=fr)
German: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=de)
Hebrew: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=he)
Hungarian: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=hu)
Italian: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=it)
Japanese: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=ja)
Korean: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=ko)
Norwegian: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=no)
Polish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=pl)
Portuguese (Brazilian): Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=pt-br)
Russian: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=ru)
Spanish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=es)
Swedish: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=9A64851A-05AE-4912-9967-3AA3B4D5A76F&DisplayLang=sv)
Thai: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?displaylang=th&FamilyID=9a64851a-05ae-4912-9967-3aa3b4d5a76f)
Release Date: August 28, 2002 For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591 Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on secure servers that prevent any unauthorized changes to the file.
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online ServicesInstallation InformationBefore you apply this update, close all programs, Internet Explorer browser sessions, and Web services.To apply this update on a Windows NT 4.0 client, the user who is logged on must be a member of the local Power Users group or the Administrators group. Downloads of the Certificate Enrollment control (Xenroll.dll) to Alpha-based client computers from Windows NT 4.0 Server that has certificate services installed is no longer supported. You must restart your computer after you apply this update. This update supports the following Setup switches:
filename -q -z WARNING: Your computer is vulnerable until you restart it.
File InformationThe English version of this fix has the file attributes (or later) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.Date Version Size File name ------------------------------------------------ 09-Jul-2002 5.131.3659.0 172,664 Xenroll.dll Windows Millennium Edition, Windows 98 Second Edition, and Windows 98A supported fix is now available from Microsoft, but it is only intended to correct the problem that is described in this article. Apply it only to computers that you determine are at risk of attack. Evaluate your computer's physical accessibility, network and Internet connectivity, and other factors to determine the degree of risk to your computer. See the associated Microsoft Security Bulletin
(http://www.microsoft.com/technet/security/bulletin/MS02-048.mspx)
to help determine the degree of risk. This fix may receive additional testing. If your computer is sufficiently at risk, Microsoft recommends that you apply this fix now.To resolve this problem immediately, download the fix by clicking the download link later in this article or contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information about support costs, please visit the following Microsoft Web site: http://support.microsoft.com/default.aspx?scid=fh;EN-US;CNTACTMS NOTE: In special cases, charges that are ordinarily incurred for support calls may be canceled, if a Microsoft Support Professional determines that a specific update will resolve your problem. The usual support costs will apply to additional support questions and issues that do not qualify for the specific update in question.
(http://support.microsoft.com/default.aspx?scid=fh;en-us;cntactms)
Download InformationThe following files are available for download from the Microsoft Download Center:Windows Millennium Edition: English (US): Windows 98 and Windows 98 Second Edition:
Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/en-us/323172usam.exe)
Arabic: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/ar/323172larm.exe)
Enabled Arabic: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421ear/winme/en-us/323172earm.exe)
Chinese (Simplified): Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/cn/323172chsm.exe)
Chinese (Traditional): Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/tw/323172chtm.exe)
Czech: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/cs/323172czem.exe)
Danish: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/da/323172danm.exe)
Dutch: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/nl/323172dutm.exe)
Finnish: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/fi/323172finm.exe)
French: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/fr/323172frnm.exe)
German: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/de/323172germ.exe)
Greek: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/el/323172grkm.exe)
Hebrew: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/he/323172lhem.exe)
Enabled Hebrew: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421ehe/winme/en-us/323172ehem.exe)
Hungarian: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/hu/323172hunm.exe)
Italian: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/it/323172itnm.exe)
Japanese: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/ja/323172jpnm.exe)
Korean: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/ko/323172korm.exe)
Norwegian: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/no/323172norm.exe)
Polish: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/pl/323172polm.exe)
Portuguese: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/pt/323172porm.exe)
Portuguese (Brazil): Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/pt-br/323172brzm.exe)
Russian: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/ru/323172rusm.exe)
Slovak: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/sk/323172svkm.exe)
Slovenian: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/sl/323172slom.exe)
Spanish: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/es/323172spam.exe)
Swedish: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/sv/323172swem.exe)
Thai: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/th/323172tham.exe)
Turkish: Collapse this image ![]()
(http://download.microsoft.com/download/winme/patch/24421/winme/tr/323172trkm.exe)
All Languages: Release Date: August 28, 2002Collapse this image ![]()
(http://support.microsoft.com/ph/1139)
For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591 Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on secure servers that prevent any unauthorized changes to the file.
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online ServicesInstallation InformationBefore you apply this update, close all programs, Internet Explorer browser sessions, and Web services.File InformationThe English version of this fix has the file attributes (or later) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.Date Version Size File name ------------------------------------------------ 09-Jul-2002 5.131.3659.0 172,664 Xenroll.dll STATUSWindows XP (All Versions)Microsoft has confirmed that this problem may cause a degree of security vulnerability in the Microsoft products that are listed at the beginning of this article. This problem was first corrected in Windows XP Service Pack 1.Windows 2000 (All Versions)Microsoft has confirmed that this problem may cause a degree of security vulnerability in the Microsoft products that are listed at the beginning of this article. This problem was first corrected in Microsoft Windows 2000 Service Pack 4.Windows NT 4.0 (All Versions)Microsoft has confirmed that this problem may cause a degree of security vulnerability in the Microsoft products that are listed at the beginning of this article.Windows Millennium Edition, Windows 98 Second Edition, and Windows 98Microsoft has confirmed that this problem may cause a degree of security vulnerability in the Microsoft products that are listed at the beginning of this article.MORE INFORMATIONClient InformationAfter you apply this update to a client computer, the client cannot enroll with a Web server for which the update has not been applied. If you are using this client, you may experience Web pages that stop responding, you may receive error messages that state the ActiveX Control could not be downloaded, or enrollment may not be successful.When a client computer for which the updated control has not been applied tries to enroll with a Web server that has been updated, the Web server downloads the updated control to the client computer. IMPORTANT: Even if a Web site has been updated and client enrollment is successful, you must update the client computer to remove this vulnerability. Netscape browsers do not use the Certificate Enrollment control when enrolling with a Microsoft Windows Certificate Server; however, the client computers must be updated to remove this vulnerability. Server InformationIf you operate a Web site that uses the Certificate Enrollment control, you must make minor revisions to your Web programs to use the new control. Both Windows NT 4.0-based servers and Windows 2000-based servers that host Certificate Services Web enrollment pages must be updated with the new Certificate Enrollment control and the Smartcard Enrollment control. If a Windows certification authority (CA) also has Web enrollment services installed on separate Internet Information Services (IIS)-based servers, you must also apply the server update to those Web sites. Third-party Web sites that use either of these controls must also update any Web pages that use these controls. The Web site must refer to the new class identifier (ID) and version of Xenroll.dll and Scrdenrl.dll:
The Smartcard Enrollment control is only used with Windows 2000 CAs. This control does not apply to Windows NT 4.0, Windows 98, Windows 98 Second Edition, or Windows Millennium Edition. The following Web pages are updated on a Windows 2000 CA:
Certdat.inc
To manually patch a Windows NT 4.0-based server that has Certificate Services installed, follow these steps:
Certsgcl.inc Certsces.asp
Downloading ActiveX Control
An Active control on this page might be unsafe to interact with other parts of the page. Do you want to allow this interaction yes/no?
If the Web server is not listed in the trusted sites in Internet Explorer, you receive the following error message:
The proper version of the ActiveX Control failed to download and install. You may not have sufficient permissions. Please ask your system administrator for assistance.
328595
For more information about this vulnerability, visit the following Microsoft Web site:
(http://support.microsoft.com/kb/328595/EN-US/
)
Problems Installing Certificate Services After you Apply the Q323172 Patch
http://www.microsoft.com/technet/security/bulletin/MS02-048.mspx For additional information about Windows Millennium Edition hotfixes, click the article number below
to view the article in the Microsoft Knowledge Base:
(http://www.microsoft.com/technet/security/bulletin/MS02-048.mspx)
295413 For additional information about Windows 98 and Windows 98 Second Edition hotfixes, click the article number below
to view the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/295413/EN-US/
)
General Information About Windows Millennium Edition Hotfixes
206071
(http://support.microsoft.com/kb/206071/EN-US/
)
General Information on Windows 98 and SE Hotfixes
PropertiesArticle ID: 323172 - Last Review: December 1, 2007 - Revision: 7.3 APPLIES TO
| Article Translations
|



Back to the top








