Article ID: 970483 - Last Review: June 9, 2009 - Revision: 1.0

MS09-020: Vulnerabilities in Internet Information Services (IIS) could allow elevation of privilege

On This Page

Expand all | Collapse all

INTRODUCTION

Microsoft has released security bulletin MS09-020. To view the complete security bulletin, visit one of the following Microsoft Web sites:

How to obtain help and support for this security update

For home users, no-charge support is available by calling 1-866-PCSAFETY in the United States and Canada or by contacting your local Microsoft subsidiary. For more information about how to contact your local Microsoft subsidiary for support issues with security updates, visit the Microsoft International Support Web site:
http://support.microsoft.com/common/international.aspx?rdpath=4 (http://support.microsoft.com/common/international.aspx?rdpath=4)
North American customers can also obtain instant access to unlimited no-charge e-mail support or to unlimited individual chat support by visiting the following Microsoft Web site:
http://support.microsoft.com/oas/default.aspx?&prid=7552 (http://support.microsoft.com/oas/default.aspx?&prid=7552)
For enterprise customers, support for security updates is available through your usual support contacts.

FILE INFORMATION

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.

Windows 2000 file information

For all supported editions of Microsoft Windows 2000 Service Pack 4

Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatform
Httpext.dll5.0.2195.7290247,05625-Apr-200911:09x86

Windows XP and Windows Server 2003 file information

  • The files that apply to a specific milestone (RTM, SPn) and service branch (QFE, GDR) are noted in the "SP requirement" and "Service branch" columns.
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. QFE service branches contain hotfixes in addition to widely released fixes.
  • In addition to the files that are listed in these tables, this software update also installs an associated security catalog file (KBnumber.cat) that is signed with a Microsoft digital signature.

For all supported x86-based versions of Windows XP

Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Httpext.dll6.0.2600.3574268,28821-May-200918:19x86SP2SP2GDR
Httpext.dll6.0.2600.3574268,28821-May-200918:01x86SP2SP2QFE
Httpext.dll6.0.2600.5817268,28821-May-200918:46x86SP3SP3GDR
Httpext.dll6.0.2600.5817268,28821-May-200918:09x86SP3SP3QFE

For all supported x64-based versions of Windows Server 2003 and of Windows XP Professional x64 edition

Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Httpext.dll6.0.3790.4518492,03226-May-200904:41x64SP2SP2GDR
Whttpext.dll6.0.3790.4518241,66426-May-200904:41x86SP2SP2GDR\WOW
Httpext.dll6.0.3790.4518492,03226-May-200904:38x64SP2SP2QFE
Whttpext.dll6.0.3790.4518241,66426-May-200904:38x86SP2SP2QFE\WOW

For all supported x86-based versions of Windows Server 2003

Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Httpext.dll6.0.3790.4518241,66425-May-200915:56x86SP2SP2GDR
Httpext.dll6.0.3790.4518241,66425-May-200915:49x86SP2SP2QFE

For all supported IA-64-based versions of Windows Server 2003

Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Httpext.dll6.0.3790.4518846,33626-May-200904:40IA-64SP2SP2GDR
Whttpext.dll6.0.3790.4518241,66426-May-200904:40x86SP2SP2GDR\WOW
Httpext.dll6.0.3790.4518845,82426-May-200904:38IA-64SP2SP2QFE
Whttpext.dll6.0.3790.4518241,66426-May-200904:38x86SP2SP2QFE\WOW

APPLIES TO
  • Microsoft Windows Server 2003 Service Pack 2, when used with:
    • Microsoft Windows Server 2003, Standard Edition (32-bit x86)
    • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
    • Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
    • Microsoft Windows Server 2003, Web Edition
    • Microsoft Windows Server 2003, Datacenter x64 Edition
    • Microsoft Windows Server 2003, Enterprise x64 Edition
    • Microsoft Windows Server 2003, Standard x64 Edition
    • Microsoft Windows XP Professional x64 Edition
    • Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
    • Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  • Microsoft Windows XP Service Pack 2, when used with:
    • Microsoft Windows XP Home Edition
    • Microsoft Windows XP Professional
  • Microsoft Windows XP Service Pack 3, when used with:
    • Microsoft Windows XP Home Edition
    • Microsoft Windows XP Professional
  • Microsoft Windows 2000 Service Pack 4, when used with:
    • Microsoft Windows 2000 Advanced Server
    • Microsoft Windows 2000 Datacenter Server
    • Microsoft Windows 2000 Professional Edition
    • Microsoft Windows 2000 Server
Keywords: 
atdownload kbbug kbexpertiseinter kbfix kbsecbulletin kbsecurity kbsecvulnerability kbsurveynew KB970483
 

Article Translations