Customized permissions that are applied to DNS records are reset to the default value when these records are deleted and tombstoned on a Windows Server 2003-based DNS server
You create an Active Directory-integrated DNS zone on a
Windows Server 2003-based DNS server.
You control
which users or computers can create, change,
or delete DNS records in this zone.
A DNS record in
this DNS zone is deleted. However, the
deleted record still exists as
a tombstoned
record in the DNS zone.
In this scenario, a user or computer that does not have
permission to create DNS records in this zone can create a new DNS record that
has the same
name as
the deleted DNS record. You expect this action to be denied.
This problem occurs because, when a DNS record with
customized permissions becomes tombstoned, the permissions on the record are
reset to the default value. Therefore,
an unauthorized user can
modify and re-enable the tombstoned DNS record before
it is removed
from the DNS zone.
A
supported hotfix is available from Microsoft. However, this hotfix is intended
to correct only the problem that is described in this article. Apply this
hotfix only to systems that are experiencing this specific problem. This hotfix
might receive additional testing. Therefore, if you are not severely affected
by this problem, we recommend that you wait for the next software update that
contains this hotfix.
If the hotfix is available for download, there
is a "Hotfix download available" section at the top of this Knowledge Base
article. If this section does not appear, contact Microsoft Customer Service
and Support to obtain the hotfix.
Note If additional issues occur or if any troubleshooting is required,
you might have to create a separate service request. The usual support costs
will apply to additional support questions and issues that do not qualify for
this specific hotfix. For a complete list of Microsoft Customer Service and
Support telephone numbers or to create a separate service request, visit the
following Microsoft Web site:
Note The "Hotfix download available" form displays the languages for
which the hotfix is available. If you do not see your language, it is because a
hotfix is not available for that language.
Prerequisites
To apply this hotfix, you must have Windows Server 2003 Service
Pack 1 (SP1) or Windows Server 2003 Service Pack 2 (SP2) installed on the DNS
server. For more information, click the
following article number to view the article in the Microsoft Knowledge Base:
How to obtain the latest service pack for Windows Server 2003
Restart requirement
You do not have to restart the computer after you apply this
hotfix. However, you must restart the DNS server service.
Hotfix replacement information
This hotfix does not replace any other hotfixes.
File information
The English version of this hotfix has the file
attributes (or later file attributes) that are listed in the following table.
The dates and times for these files are listed in Coordinated Universal Time
(UTC). When you view the file information, it is converted to local time. To
find the difference between UTC and local time, use the Time
Zone tab in the Date and Time item in Control
Panel.
Windows Server 2003 with Service Pack 1, x86-based versions
Collapse this tableExpand this table
File name
File version
File
size
Date
Time
Platform
SP requirement
6to4svc.dll
5.2.3790.2771
99,840
16-Aug-2006
14:01
x86
SP1
Afd.sys
5.2.3790.3161
152,576
20-Jun-2008
10:38
x86
SP1
Dns.exe
5.2.3790.3184
448,000
31-Jul-2008
09:21
x86
SP1
Mswsock.dll
5.2.3790.3161
258,048
20-Jun-2008
19:36
x86
SP1
Tcpip.sys
5.2.3790.3161
394,752
20-Jun-2008
10:38
x86
SP1
Tcpip6.sys
5.2.3790.3161
225,984
20-Jun-2008
10:04
Not
Applicable
SP1
W03a2409.dll
5.2.3790.3184
30,208
31-Jul-2008
09:17
x86
SP1
Windows Server 2003 with Service Pack 2, x86-based versions
Collapse this tableExpand this table
File name
File version
File
size
Date
Time
Platform
SP requirement
Afd.sys
5.2.3790.4318
150,528
20-Jun-2008
11:02
x86
SP2
Dns.exe
5.2.3790.4345
448,000
31-Jul-2008
11:32
x86
SP2
Mswsock.dll
5.2.3790.4318
257,024
20-Jun-2008
19:01
x86
SP2
Tcpip.sys
5.2.3790.4318
390,656
20-Jun-2008
11:01
x86
SP2
Tcpip6.sys
5.2.3790.4318
234,496
20-Jun-2008
10:19
Not
Applicable
SP2
Windows Server 2003 with Service Pack 1, Itanium-based versions
Collapse this tableExpand this table
File name
File version
File
size
Date
Time
Platform
SP
requirement
Service branch
6to4svc.dll
5.2.3790.3184
362,496
31-Jul-2008
14:13
IA-64
SP1
Not
Applicable
Afd.sys
5.2.3790.3184
584,192
31-Jul-2008
14:13
IA-64
SP1
Not
Applicable
Dns.exe
5.2.3790.3184
1,140,736
31-Jul-2008
14:13
IA-64
SP1
Not
Applicable
Mswsock.dll
5.2.3790.3184
784,896
31-Jul-2008
14:13
IA-64
SP1
Not
Applicable
Tcpip.sys
5.2.3790.3184
1,308,672
31-Jul-2008
14:13
IA-64
SP1
Not
Applicable
Tcpip6.sys
5.2.3790.3184
737,024
31-Jul-2008
14:13
Not
Applicable
SP1
Not Applicable
W03a2409.dll
5.2.3790.3184
29,184
31-Jul-2008
14:13
IA-64
SP1
Not
Applicable
W6to4svc.dll
5.2.3790.3184
99,840
31-Jul-2008
14:13
x86
SP1
WOW
Wdns.exe
5.2.3790.3184
448,000
31-Jul-2008
14:13
x86
SP1
WOW
Wmswsock.dll
5.2.3790.3184
233,472
31-Jul-2008
14:13
x86
SP1
WOW
Ww03a2409.dll
5.2.3790.3184
30,208
31-Jul-2008
14:13
x86
SP1
WOW
Windows Server 2003 with Service Pack 2, Itanium-based versions
Collapse this tableExpand this table
File name
File version
File
size
Date
Time
Platform
SP
requirement
Service branch
Afd.sys
5.2.3790.4345
584,192
31-Jul-2008
14:54
IA-64
SP2
Not
Applicable
Dns.exe
5.2.3790.4345
1,140,736
31-Jul-2008
14:54
IA-64
SP2
Not
Applicable
Mswsock.dll
5.2.3790.4345
789,504
31-Jul-2008
14:54
IA-64
SP2
Not
Applicable
Tcpip.sys
5.2.3790.4345
1,310,720
31-Jul-2008
14:54
IA-64
SP2
Not
Applicable
Tcpip6.sys
5.2.3790.4345
764,416
31-Jul-2008
14:54
Not
Applicable
SP2
Not Applicable
Wmswsock.dll
5.2.3790.4345
234,496
31-Jul-2008
14:54
x86
SP2
WOW
Windows Server 2003 with Service Pack 1, x64-based versions
Collapse this tableExpand this table
File name
File version
File
size
Date
Time
Platform
SP
requirement
Service branch
6to4svc.dll
5.2.3790.2771
124,416
31-Jul-2008
14:14
x64
SP1
Not
Applicable
Afd.sys
5.2.3790.3161
299,520
31-Jul-2008
14:14
x64
SP1
Not
Applicable
Dns.exe
5.2.3790.3184
770,560
31-Jul-2008
14:14
x64
SP1
Not
Applicable
Mswsock.dll
5.2.3790.3161
491,520
31-Jul-2008
14:14
x64
SP1
Not
Applicable
Tcpip.sys
5.2.3790.3161
829,952
31-Jul-2008
14:14
x64
SP1
Not
Applicable
Tcpip6.sys
5.2.3790.3161
363,136
31-Jul-2008
14:14
x64
SP1
Not
Applicable
W03a2409.dll
5.2.3790.3184
30,720
31-Jul-2008
14:14
x64
SP1
Not
Applicable
W6to4svc.dll
5.2.3790.2771
99,840
31-Jul-2008
14:14
x86
SP1
WOW
Wdns.exe
5.2.3790.3184
448,000
31-Jul-2008
14:14
x86
SP1
WOW
Wmswsock.dll
5.2.3790.3161
233,472
31-Jul-2008
14:14
x86
SP1
WOW
Ww03a2409.dll
5.2.3790.3184
30,208
31-Jul-2008
14:14
x86
SP1
WOW
Windows XP with Service Pack 2, x64-based versions