Help and Support

MS07-021: Vulnerability in Windows CSRSS could allow remote code execution

Article ID:930178
Last Review:March 14, 2008
Revision:3.1
On This Page

SUMMARY

Microsoft has released security bulletin MS07-021. The security bulletin contains all the relevant information about the security update. This information includes file manifest information and deployment options. To view the complete security bulletin, visit one of the following Microsoft Web sites:
Home users:
http://www.microsoft.com/athome/security/update/bulletins/200704.mspx (http://www.microsoft.com/athome/security/update/bulletins/200704.mspx)
IT professionals:
http://www.microsoft.com/technet/security/bulletin/ms07-021.mspx (http://www.microsoft.com/technet/security/bulletin/ms07-021.mspx)

Back to the top

Known issues

You may experience one or more of the following symptoms after you apply security update 930178 (MS07-021):
Consider the following scenario. On a Windows XP SP2-based computer or on a Windows 2000 SP4-based computer, you use the Certificate Import Wizard to import a certificate into the Trusted Root Certification Authorities Certificates store. In this scenario, a blank message appears. The message contains a Yes button and a No button. If you click Yes, the certificate is installed successfully. Instead of a blank message, you expect to receive the following confirmation message:
You are about to install a certificate from a certification authority (CA) claiming to represent: CAName Certificate_Information Do you want to install this certificate?

Note In this message, CAName is a placeholder for the name of the certification authority, and Certificate_Information is a placeholder for the information about the particular certificate.

You experience this problem if you run the Certificate Import Wizard by using an account that does not have Administrator rights.
You log on to a Windows XP SP2-based portable computer by using an account that does not have Administrator rights. Then, even though the battery power is low, the text balloon warning for Low Battery Alarm does not appear in the notification area. You may still receive a yellow triangle exclamation point in the notification area. However, you may not receive the text balloon warning.
You experience slow performance on a Windows XP SP2-based portable computer. Additionally, the computer may stop responding when the Low Battery Alarm warning occurs. This symptom occurs when the following conditions are true:
You log on to the computer by using an account that does not have Administrator rights.
You log on to the computer by using the Switch User option.
For more information, click the following article number to view the article in the Microsoft Knowledge Base:
940275 (http://support.microsoft.com/kb/940275/) Several problems may occur after you apply security update 930178 (MS07-021) on a Windows XP SP2-based computer or on a Windows 2000 SP4-based computer

Back to the top


APPLIES TO
Windows Vista Home Basic
Windows Vista Home Premium
Windows Vista Ultimate
Windows Vista Business
Windows Vista Enterprise
Windows Vista Starter
Windows Vista Home Basic 64-bit Edition
Windows Vista Home Premium 64-bit Edition
Windows Vista Ultimate 64-bit Edition
Windows Vista Business 64-bit Edition
Windows Vista Enterprise 64-bit Edition
Microsoft Windows Server 2003 R2 Standard Edition (32-bit x86)
Microsoft Windows Server 2003 R2 Standard x64 Edition
Microsoft Windows Server 2003 R2 Enterprise x64 Edition
Microsoft Windows Server 2003 Service Pack 2, when used with:
  Microsoft Windows Server 2003, Standard Edition (32-bit x86)
  Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
  Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
  Microsoft Windows Server 2003, Web Edition
  Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
  Microsoft Windows Server 2003, Standard x64 Edition
  Microsoft Windows Server 2003, Enterprise x64 Edition
  Microsoft Windows Server 2003, Datacenter x64 Edition
  Microsoft Windows Server 2003 R2 Standard Edition (32-bit x86)
  Microsoft Windows Server 2003 R2 Enterprise Edition (32-Bit x86)
  Microsoft Windows Server 2003 R2 Datacenter Edition (32-Bit x86)
  Microsoft Windows Server 2003 R2 Standard x64 Edition
  Microsoft Windows Server 2003 R2 Enterprise x64 Edition
  Microsoft Windows Server 2003 R2 Datacenter x64 Edition
Microsoft Windows Server 2003 Service Pack 1, when used with:
  Microsoft Windows Server 2003, Standard Edition (32-bit x86)
  Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
  Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
  Microsoft Windows Server 2003, Web Edition
  Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
  Microsoft Windows Small Business Server 2003 Standard Edition
Microsoft Windows XP Tablet PC Edition 2005
Microsoft Windows XP Media Center Edition 2005
Microsoft Windows XP Professional x64 Edition
  Microsoft Windows XP Home Edition
  Microsoft Windows XP Professional
  Microsoft Windows XP Professional x64 Edition
Microsoft Small Business Server 2000 Standard Edition
Microsoft Windows 2000 Service Pack 4, when used with:
  Microsoft Windows 2000 Professional Edition
  Microsoft Windows 2000 Server
  Microsoft Windows 2000 Advanced Server
  Microsoft Windows 2000 Datacenter Server

Back to the top

Keywords: 
kbvistasp1fix kbexpertiseinter kbexpertisebeginner kbqfe kbsecurity kbsecbulletin kbsecvulnerability kbbug kbfix kbwin2000presp5fix kbpubtypekc KB930178

Back to the top

Article Translations

 

Other Support Options

  • Contact Microsoft
    Phone Numbers, Support Options and Pricing, Online Help, and more.
  • Customer Service
    For non-technical assistance with product purchases, subscriptions, online services, events, training courses, corporate sales, piracy issues, and more.
  • Newsgroups
    Pose a question to other users. Discussion groups and Forums about specific Microsoft products, technologies, and services.