Microsoft Security Advisory (2749655)

Compatibility Issues Affecting Signed Microsoft Binaries

Published: | Updated:

Version: 2.0

General Information

Executive Summary

Microsoft is aware of an issue involving specific digital certificates that were generated by Microsoft without proper timestamp attributes. These digital certificates were later used to sign some Microsoft core components and software binaries. This could cause compatibility issues between affected binaries and Microsoft Windows. While this is not a security issue, because the digital signature on files produced and signed by Microsoft will expire prematurely, this issue could adversely impact the ability to properly install and uninstall affected Microsoft components and security updates.

As a pre-emptive action to assist customers, Microsoft is providing a non-security update for supported releases of Microsoft Windows. This update helps to ensure compatibility between Microsoft Windows and affected software binaries. For more information about the update, please see Microsoft Knowledge Base Article 2749655.

In addition, Microsoft is providing updates as they become available for products affected by this issue. These updates may be provided as part of rereleased updates, or included in other software updates, depending on customer needs.

Recommendation. Microsoft recommends that customers apply the KB2749655 update and any rereleased updates addressing this issue immediately, either by using update management software or by checking for updates using the Microsoft Update service. Please see the List of available rereleases and the Suggested Actions sections of this advisory for more information.

List of available rereleases

In some cases, to best meet customer needs, Microsoft is addressing this issue by rereleasing affected updates.

  • On October 9, 2012, Microsoft rereleased the KB723135 update for Windows XP. For more information, see MS12-053.
  • On October 9, 2012, Microsoft rereleased the KB2705219 update for Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. For more information, see MS12-054.
  • On October 9, 2012, Microsoft rereleased the KB2731847 update for Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. For more information, see MS12-055.
  • On October 9, 2012, Microsoft rereleased the updates for Microsoft Exchange Server 2007 Service Pack 3 (KB2756496), Microsoft Exchange Server 2010 Service Pack 1 (KB2756497), and Microsoft Exchange Server 2010 Service Pack 2 (KB2756485). For more information, see MS12-058.
  • On October 9, 2012, Microsoft rereleased the KB2661254 update for Windows XP. For more information, see Microsoft Security Advisory 2661254.
  • On November 13, 2012, Microsoft replaced the KB2598361 update with the KB2687626 update for Microsoft Office 2003 Service Pack 3. For more information, see MS12-046.
  • On December 11, 2012, Microsoft replaced the KB2687324 update with the KB2687627 update for Microsoft XML Core Services 5.0 when installed on Microsoft Office 2003 Service Pack 3, and replaced the KB2596679 update with the KB2687497 update for Microsoft XML Core Services 5.0 when installed with all affected editions of Microsoft Groove 2007, Microsoft Groove Server 2007, and Microsoft Office SharePoint Server 2007. For more information, see MS12-043.
  • On December 11, 2012, Microsoft replaced the KB2553260 and KB2589322 updates with the KB2687501 and KB2687510 updates respectively for all affected editions of Microsoft Office 2010. For more information, see MS12-057.
  • On December 11, 2012, Microsoft replaced the KB2597171 update with the KB2687508 update for all affected editions of Microsoft Visio 2010. For more information, see MS12-059.
  • On December 11, 2012, Microsoft replaced the KB2687323 update with the KB2726929 update for Windows common controls on all affected variants of Microsoft Office 2003, Microsoft Office 2003 Web Components, and Microsoft SQL Server 2005. For more information, see, and MS12-060.

Note regarding the impact of not installing a rereleased update 
Customers who installed the original updates are protected from the vulnerabilities addressed by the updates. However, because improperly signed files, such as executable images, would not be considered correctly signed after the expiration of the CodeSign certificate used in the signing process of the original updates, Microsoft Update may not install some security updates after the expiration date. Other effects include, for example, that an application installer may display an error message. Third-party application whitelisting solutions may also be impacted. Installing the rereleased updates remediates the issue for the affected updates.

Advisory Details

Issue References

For more information about this issue, see the following references:

ReferencesIdentification
Microsoft Knowledge Base Articles2749655 
2756872

Affected Software

The update associated with this advisory applies to the following software.

Affected Software
Operating System
Windows XP Service Pack 3
(KB2749655)
Windows XP Professional x64 Edition Service Pack 2
(KB2749655)
Windows Server 2003 Service Pack 2
(KB2749655)
Windows Server 2003 x64 Edition Service Pack 2
(KB2749655)
Windows Server 2003 with SP2 for Itanium-based Systems
(KB2749655)
Windows Vista Service Pack 2
(KB2749655)
Windows Vista x64 Edition Service Pack 2
(KB2749655)
Windows Server 2008 for 32-bit Systems Service Pack 2
(KB2749655)
Windows Server 2008 for x64-based Systems Service Pack 2
(KB2749655)
Windows Server 2008 for Itanium-based Systems Service Pack 2
(KB2749655)
Windows 7 for 32-bit Systems
(KB2749655)
Windows 7 for 32-bit Systems Service Pack 1
(KB2749655)
Windows 7 for x64-based Systems
(KB2749655)
Windows 7 for x64-based Systems Service Pack 1
(KB2749655)
Windows Server 2008 R2 for x64-based Systems
(KB2749655)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
(KB2749655)
Windows Server 2008 R2 for Itanium-based Systems
(KB2749655)
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
(KB2749655)
Windows 8 for 32-bit Systems
(KB2756872)
Windows 8 for 64-bit Systems
(KB2756872)
Windows Server 2012
(KB2756872)
Server Core installation option
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
(KB2749655)
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
(KB2749655)
Windows Server 2008 R2 for x64-based Systems (Server Core installation)
(KB2749655)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
(KB2749655)
Windows Server 2012 (Server Core installation)
(KB2756872)

 

Frequently Asked Questions

Suggested Actions

Other Information

Feedback

Support

Disclaimer

The information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions

  • V1.0 (October 9, 2012): Advisory published.
  • V1.1 (October 9, 2012): Clarified that the updates for Windows 8 and Window Server 2012 associated with this advisory are included in the "Windows 8 Client and Windows Server 2012 General Availability Cumulative Update" (KB2756872). This is an informational change only. See advisory FAQ for details.
  • V1.2 (November 13, 2012): Added the KB2687626 update, described in MS12-046, to the list of available rereleases.
  • V2.0 (December 11, 2012): Added the KB2687627 and KB2687497 updates described in MS12-043, the KB2687501 and KB2687510 updates described in MS12-057, the KB2687508 update described in MS12-059, and the KB2726929 update described in MS12-060 to the list of available rereleases.