MS12-014: Vulnerability in Indeo Codec could allow remote code execution: February 14, 2012

Support for Windows XP has ended

Microsoft ended support for Windows XP on April 8, 2014. This change has affected your software updates and security options. Learn what this means for you and how to stay protected.

Microsoft has released security bulletin MS12-014. To view the complete security bulletin, visit one of the following Microsoft websites:

How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your computer that is running Windows from viruses and malware:Virus Solution and Security Center

Local support according to your country: International Support

More information

Known issues with this security update

  • When you try to install this security update, you may receive an error message that resembles the following:

    Setup cannot continue because one or more of the requirements for the installation of KB2661637 were not met

    This issue may occur if Ligos Indeo Codecs for Windows is installed on the system. This is expected behavior. The installation of the security update is blocked in order to maintain application compatibility for Ligos Indeo Codecs for Windows. 

    Note The system is not in an unprotected state when this issue occurs. When Ligos Indeo Codecs for Windows is installed, the required .dll file is installed in the System32 folder, and the system is protected against the vulnerability that is described in Microsoft Security Bulletin MS12-014. 
The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.
  • The files that apply to a specific milestone (SPn) and service branch (QFE, GDR) are noted in the "SP requirement" and "Service branch" columns.
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. QFE service branches contain hotfixes in addition to widely released fixes.
  • In addition to the files that are listed in these tables, this software update also installs an associated security catalog file ( that is signed with a Microsoft digital signature.
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Updspapi.dll6.3.13.0382,84005-Jul-201013:16x86NoneNot Applicable
update security_patch security_update security bug flaw vulnerability malicious attacker exploit registry unauthenticated buffer overrun overflow specially-formed scope specially-crafted denial of service DoS TSE

Article ID: 2661637 - Last Review: 07/18/2012 16:58:00 - Revision: 3.0

Microsoft Windows XP Service Pack 3

  • atdownload kbbug kbexpertiseinter kbfix kbsecbulletin kbsecurity kbsecvulnerability kbsurveynew KB2661637