Description of the security update of Windows XP and Windows Server 2003: June 13, 2017

Applies to: Windows XPMicrosoft Windows XP ProfessionalMicrosoft Windows XP Home Edition More

Summary


Remote desktop protocol remote code execution vulnerability


A remote code execution vulnerability exists in Remote Desktop Protocol (RDP) if the RDP server has Smart Card authentication enabled. An attacker who successfully exploited this vulnerability could execute code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

To exploit this vulnerability, an attacker would need to run a specially crafted application against an RDP server which has Smart Card authentication enabled. Smart Card authentication is a non-default configuration; systems without it enabled are not vulnerable.

The security update addresses the vulnerability by correcting how Remote Desktop Protocol handles requests. The following table contains links to the standard entry for each vulnerability in the Common Vulnerabilities and Exposures list:

Vulnerability title

CVE number

Publicly disclosed

Exploited

Remote Desktop Protocol Remote Code Execution Vulnerability

CVE-2017-0176

Yes

Yes

 

Mitigating Factors

Microsoft has not identified any mitigating factors for this vulnerability.

Workarounds

Microsoft has not identified any workarounds for this vulnerability.

More Information


Important
 
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

How to obtain and install the update


Method 1: Microsoft Update Catalog

To get the stand-alone package for this update, go to the Microsoft Update Catalog website.

Method 2: Microsoft Download Center

The following files are available for download from the Microsoft Download Center.



For all x86-based versions of Windows Server 2003

Download the package now



For all x64-based versions of Windows Server 2003

Download the package now



For all x86-based versions of Windows XP

Download the package now



For all x64-based versions of Windows XP

Download the package now



For all versions of Windows XP Embedded

Download the package now

Release Date: June 13, 2017

For more information about how to download Microsoft support files, click the following article number to go to the article in the Microsoft Knowledge Base:



Virus-scan claim

Microsoft scanned this file for viruses by using the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help prevent any unauthorized changes to it.

Deployment information


For deployment details for this security update, go to the following article in the Microsoft Knowledge Base:

More Information


File Information



File information


The English (United States) version of this software update installs files that have the attributes that are listed in the following tables.

Windows XP file information