MS04-024 and MS04-037 supersedence question

alice

Distinguished
Feb 22, 2004
185
0
18,680
Archived from groups: microsoft.public.win2000.security (More info?)

Firstly, apologies if this has already been discussed. I can't find a
definitive answer to my question so here goes:

MS04-037 bulletin originally stated it replaces MS04-024. However, this was
later changed to state that MS04-024 has not been superseded. There are also
several later hotfixes (MS05-008, MS05-016) that replace the files provided
in MS04-024, but they are not noted as replacing it.

It seems that the behaviour that is not replaced is something to do with IE
security zone settings. Could you possibly tell me what exactly is not
superseded and how MS04-024 makes this change? I take it the change must be
something that's not included in the dlls MS04-024 provides.

Thanks,
Alice
 
Archived from groups: microsoft.public.win2000.security (More info?)

Yea, MS didn't do a good job of explaining the MS04-037 not superseding
MS04-024. To be clearer, this note is specific to NT Terminal Server Edition
only, not other platforms. Additionally, it depends if Active Desktop was or
was not installed on NTSE (an option originally part of IE 4).
Take a look at this very detailed list of patches and see if this helps:

http://townsendonemedia.com/bulletInBlue/Downloads/mspatches.xls


G
 
Archived from groups: microsoft.public.win2000.security (More info?)

"GeeB" wrote:

> Yea, MS didn't do a good job of explaining the MS04-037 not superseding
> MS04-024. To be clearer, this note is specific to NT Terminal Server Edition
> only, not other platforms. Additionally, it depends if Active Desktop was or
> was not installed on NTSE (an option originally part of IE 4).
> Take a look at this very detailed list of patches and see if this helps:
>
> http://townsendonemedia.com/bulletInBlue/Downloads/mspatches.xls
>
>
> G

Thanks for the info and the link. Perhaps someone from Microsoft could
comment on why, if MS04-024 *is* superseded by MS04-037 for Windows 2000, the
security bulletin for MS04-037 doesn't mention MS04-024 at all in the FAQ
"What updates does this release replace?" section?

Alice

PS. HFNetChk and HFNetChkPro both flag MS04-024 as missing on W2K, but this
could be a mistake in the XML file.