Launch Printer Friendly Page Security TechCenter > Security Bulletins > Microsoft Security Bulletin MS03-041

Microsoft Security Bulletin MS03-041

Vulnerability in Authenticode Verification Could Allow Remote Code Execution (823182)

Issued: October 15, 2003
Updated: November 17, 2003
Version Number: 1.2

See all Windows bulletins released October, 2003

Summary

Who Should Read This Document:
Customers using Microsoft® Windows®

Impact of Vulnerability:
Remote Code Execution

Maximum Severity Rating:
Critical

Recommendation:
Customers should apply the patch immediately

Patch Replacement:
None

Caveats:
None

Tested Software and Patch Download Locations:

Affected Software:

Non Affected Software:

  • Microsoft Windows Millennium Edition

The software listed above has been tested to determine if the versions are affected. Other versions are no longer supported, and may or may not be affected.

General Information

Technical Details

Workarounds

Frequently Asked Questions

Security Patch Information

Other Information

Obtaining other security patches:

Patches for other security issues are available from the following locations:

  • Security patches are available from the Microsoft Download Center, and can be most easily found by doing a keyword search for "security_patch".
  • Patches for consumer platforms are available from the Windows Update web site

Support:

Security Resources:

Disclaimer:

The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions:

  • V1.0 October 15, 2003: Bulletin published.
  • V1.1 October 22, 2003: Updated "File Information" in the "Windows 2000" section of "Security Patch Information."
  • V1.2 November 17, 2003: Updated "File Information" for all platforms in the "Security Patch Information" sections.