Help and Support
 

powered byLive Search

MS08-022: Vulnerability in the VBScript and JScript scripting engines could allow remote code execution

Article ID:944338
Last Review:August 15, 2008
Revision:4.0
On This Page

INTRODUCTION

Microsoft has released security bulletin MS08-022. The security bulletin contains all the relevant information about the security update. This information includes file manifest information and deployment options. To view the complete security bulletin, visit one of the following Microsoft Web sites:
Home users:
http://www.microsoft.com/protect/computer/updates/bulletins/200804.mspx (http://www.microsoft.com/protect/computer/updates/bulletins/200804.mspx)
Skip the details: Download the updates for your home computer or laptop from the Microsoft Update Web site now:
http://update.microsoft.com/microsoftupdate/ (http://update.microsoft.com/microsoftupdate/)
IT professionals:
http://www.microsoft.com/technet/security/bulletin/ms08-022.mspx (http://www.microsoft.com/technet/security/bulletin/ms08-022.mspx)

Back to the top

How to obtain help and support for this security update

For home users, no-charge support is available by calling 1-866-PCSAFETY in the United States and Canada or by contacting your local Microsoft subsidiary. For more information about how to contact your local Microsoft subsidiary for support issues with security updates, visit the Microsoft International Support Web site:
http://support.microsoft.com/common/international.aspx?rdpath=4 (http://support.microsoft.com/common/international.aspx?rdpath=4)
North American customers can also obtain instant access to unlimited no-charge e-mail support or to unlimited individual chat support by visiting the following Microsoft Web site:
http://support.microsoft.com/oas/default.aspx?&prid=7552 (http://support.microsoft.com/oas/default.aspx?&prid=7552)
For enterprise customers, support for security updates is available through your usual support contacts.

Back to the top

Known issues with this security update

Back to the top

Issue 1

Symptoms

You install this security update on a Microsoft Windows 2000-based computer that is running a version of Microsoft Internet Explorer that is earlier than Microsoft Internet Explorer 5.5. When you do this, a script that uses features from VBScript 5.0 or a later version of VBScript does not work.

For example, you run a script that uses a feature that is provided by VBScript 5.0 or a later version of VBScript, such as RegExp. When you do this, you may receive an error message that resembles the following error message:
Library is not registered.

Cause

This issue occurs because the installer file for this security update does not add a registry entry that is associated with the new VBScript.dll file.

Workaround

To work around this issue, open a command prompt, type the following command, and then press ENTER:
Regsvr32 vbscript.dll

Back to the top

Issue 2

A setup issue was causing the update for VBScript 5.6 and JScript 5.6 to not be offered, and not installed, if Windows Internet Explorer 7 is installed on the system. The solution is a detection change to this security update. Customers who have successfully updated their systems do not need to reinstall this update.

Back to the top

File information

The English (United States) version of this security update has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

For all supported editions of Microsoft Windows 2000 Service Pack 4

File nameFile versionFile sizeDateTimePlatform
Jscript.dll5.6.0.8835458,75205-Jan-200811:05x86
Vbscript.dll5.6.0.8835401,40805-Jan-200811:05x86

For all supported 32-bit versions of Windows XP

File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Jscript.dll5.6.0.8835450,56018-Dec-200714:40x86SP2SP2GDR
Vbscript.dll5.6.0.8835417,79218-Dec-200714:40x86SP2SP2GDR
Jscript.dll5.6.0.8835450,56018-Dec-200714:32x86SP2SP2QFE
Vbscript.dll5.6.0.8835417,79218-Dec-200714:32x86SP2SP2QFE

For all supported x64-based versions of Windows XP Professional

File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Jscript.dll5.6.0.8835998,91214-Dec-200722:58x64SP1SP1GDR
Vbscript.dll5.6.0.8835662,01614-Dec-200722:58x64SP1SP1GDR
Wjscript.dll5.6.0.8835458,75214-Dec-200722:58x86SP1SP1GDR\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200722:58x86SP1SP1GDR\WOW
Jscript.dll5.6.0.8835999,42414-Dec-200722:58x64SP1SP1QFE
Vbscript.dll5.6.0.8835662,52814-Dec-200722:58x64SP1SP1QFE
Wjscript.dll5.6.0.8835458,75214-Dec-200722:58x86SP1SP1QFE\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200722:58x86SP1SP1QFE\WOW
Jscript.dll5.6.0.8835999,93614-Dec-200723:10x64SP2SP2GDR
Vbscript.dll5.6.0.8835663,04014-Dec-200723:10x64SP2SP2GDR
Wjscript.dll5.6.0.8835458,75214-Dec-200723:10x86SP2SP2GDR\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200723:10x86SP2SP2GDR\WOW
Jscript.dll5.6.0.8835999,93614-Dec-200722:58x64SP2SP2QFE
Vbscript.dll5.6.0.8835663,04014-Dec-200722:58x64SP2SP2QFE
Wjscript.dll5.6.0.8835458,75214-Dec-200722:58x86SP2SP2QFE\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200722:58x86SP2SP2QFE\WOW

For all supported 32-bit versions of Windows Server 2003

File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Jscript.dll5.6.0.8835458,75214-Dec-200708:34x86SP1SP1GDR
Vbscript.dll5.6.0.8835401,40814-Dec-200708:34x86SP1SP1GDR
Jscript.dll5.6.0.8835458,75214-Dec-200708:00x86SP1SP1QFE
Vbscript.dll5.6.0.8835401,40814-Dec-200722:54x86SP1SP1QFE
Jscript.dll5.6.0.8835458,75214-Dec-200708:34x86SP2SP2GDR
Vbscript.dll5.6.0.8835401,40814-Dec-200708:34x86SP2SP2GDR
Jscript.dll5.6.0.8835458,75214-Dec-200708:41x86SP2SP2QFE
Vbscript.dll5.6.0.8835401,40814-Dec-200708:41x86SP2SP2QFE

For all supported x64-based versions of Windows Server 2003

File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Jscript.dll5.6.0.8835998,91214-Dec-200722:58x64SP1SP1GDR
Vbscript.dll5.6.0.8835662,01614-Dec-200722:58x64SP1SP1GDR
Wjscript.dll5.6.0.8835458,75214-Dec-200722:58x86SP1SP1GDR\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200722:58x86SP1SP1GDR\WOW
Jscript.dll5.6.0.8835999,42414-Dec-200722:58x64SP1SP1QFE
Vbscript.dll5.6.0.8835662,52814-Dec-200722:58x64SP1SP1QFE
Wjscript.dll5.6.0.8835458,75214-Dec-200722:58x86SP1SP1QFE\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200722:58x86SP1SP1QFE\WOW
Jscript.dll5.6.0.8835999,93614-Dec-200723:10x64SP2SP2GDR
Vbscript.dll5.6.0.8835663,04014-Dec-200723:10x64SP2SP2GDR
Wjscript.dll5.6.0.8835458,75214-Dec-200723:10x86SP2SP2GDR\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200723:10x86SP2SP2GDR\WOW
Jscript.dll5.6.0.8835999,93614-Dec-200722:58x64SP2SP2QFE
Vbscript.dll5.6.0.8835663,04014-Dec-200722:58x64SP2SP2QFE
Wjscript.dll5.6.0.8835458,75214-Dec-200722:58x86SP2SP2QFE\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200722:58x86SP2SP2QFE\WOW

For all supported Itanium-based versions of Windows Server 2003

File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Jscript.dll5.6.0.88351,304,57614-Dec-200722:58IA-64SP1SP1GDR
Vbscript.dll5.6.0.88351,116,16014-Dec-200722:58IA-64SP1SP1GDR
Wjscript.dll5.6.0.8835458,75214-Dec-200722:58x86SP1SP1GDR\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200722:58x86SP1SP1GDR\WOW
Jscript.dll5.6.0.88351,306,62414-Dec-200723:00IA-64SP1SP1QFE
Vbscript.dll5.6.0.88351,116,67214-Dec-200723:00IA-64SP1SP1QFE
Wjscript.dll5.6.0.8835458,75214-Dec-200723:00x86SP1SP1QFE\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200723:00x86SP1SP1QFE\WOW
Jscript.dll5.6.0.88351,306,62414-Dec-200723:09IA-64SP2SP2GDR
Vbscript.dll5.6.0.88351,116,67214-Dec-200723:09IA-64SP2SP2GDR
Wjscript.dll5.6.0.8835458,75214-Dec-200723:09x86SP2SP2GDR\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200723:09x86SP2SP2GDR\WOW
Jscript.dll5.6.0.88351,306,62414-Dec-200723:00IA-64SP2SP2QFE
Vbscript.dll5.6.0.88351,116,67214-Dec-200723:00IA-64SP2SP2QFE
Wjscript.dll5.6.0.8835458,75214-Dec-200723:00x86SP2SP2QFE\WOW
Wvbscript.dll5.6.0.8835401,40814-Dec-200723:00x86SP2SP2QFE\WOW

Back to the top


APPLIES TO
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Datacenter Server
Microsoft Windows XP Service Pack 2, when used with:
  Microsoft Windows XP Home Edition
  Microsoft Windows XP Professional
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003, Datacenter x64 Edition
Microsoft Windows Server 2003, Enterprise x64 Edition
Microsoft Windows Server 2003, Standard x64 Edition
Microsoft Windows Server 2003 Service Pack 1, when used with:
  Microsoft Windows Server 2003, Web Edition
  Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
  Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
  Microsoft Windows Server 2003, Standard Edition (32-bit x86)
  Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
  Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
Microsoft Windows Server 2003 Service Pack 2, when used with:
  Microsoft Windows XP Professional x64 Edition
  Microsoft Windows Server 2003, Web Edition
  Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
  Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
  Microsoft Windows Server 2003, Standard Edition (32-bit x86)
  Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
  Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  Microsoft Windows Server 2003, Datacenter x64 Edition
  Microsoft Windows Server 2003, Enterprise x64 Edition
  Microsoft Windows Server 2003, Standard x64 Edition

Back to the top

Keywords: 
kbexpertiseinter kbexpertisebeginner kbqfe kbsecurity kbsecbulletin kbsecvulnerability kbbug kbfix kbpubtypekc KB944338

Back to the top

Article Translations

 

Other Support Options

  • Need More Help?
    Contact a Support professional by E-mail, Online or Phone.
  • Customer Service
    For non-technical assistance with product purchases, subscriptions, online services, events, training courses, corporate sales, piracy issues, and more.
  • Newsgroups
    Pose a question to other users. Discussion groups and Forums about specific Microsoft products, technologies, and services.