Description of the security update for Windows XP and Windows Server 2003: June 13, 2017

Applies to: Windows XPMicrosoft Windows XP ProfessionalMicrosoft Windows XP Home Edition More

Summary


WebDAV remote code execution vulnerability

A vulnerability exists in IIS when WebDAV improperly handles objects in memory, which could allow an attacker to run arbitrary code on the user’s system. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user.

To exploit this vulnerability, an attacker would have to send a specially crafted HTTP request to the affected system.

The update addresses the vulnerability by changing how WebDAV handles objects in memory. The following table contains links to the standard entry for each vulnerability in the Common Vulnerabilities and Exposures list:

Vulnerability title

CVE number

Publicly disclosed

Exploited

WebDAV Remote Code Execution Vulnerability

CVE-2017-7269

Yes

Yes

Mitigating Factors

Mitigating Factors

Microsoft has not identified any mitigating factors for this vulnerability.

Workarounds

Microsoft has not identified any workarounds for this vulnerability.

More Information


Important
 
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

How to obtain and install the update


Method 1: Microsoft Update Catalog

To get the stand-alone package for this update, go to the Microsoft Update Catalog website.

Method 2: Microsoft Download Center

The following files are available for download from the Microsoft Download Center.



For all x86-based versions of Windows Server 2003

Download the package now



For all x64-based versions of Windows Server 2003

Download the package now



For all x86-based versions of Windows XP

Download the package now



For all x64-based versions of Windows XP

Download the package now



For all versions of Windows XP Embedded

Download the package now



For all versions of Windows Embedded POS Ready 2009

Download the package now

Release Date: June 13, 2017

For more information about how to download Microsoft support files, click the following article number to go to the article in the Microsoft Knowledge Base:



Virus-scan claim

Microsoft scanned this file for viruses by using the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help prevent any unauthorized changes to it.

Deployment information


For deployment details for this security update, go to the following article in the Microsoft Knowledge Base:

More Information


File Information



File information
The English (United States) version of this software update installs files that have the attributes that are listed in the following tables.