Launch Printer Friendly Page Security TechCenter > Security Bulletins > Microsoft Security Bulletin MS09-062

Microsoft Security Bulletin MS09-062 - Critical

Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)

Published: | Updated:

Version: 2.2

General Information

Executive Summary

This security update resolves several privately reported vulnerabilities in Microsoft Windows GDI+. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using affected software or browsed a Web site that contains specially crafted content. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

This security update is rated Critical for all supported editions of Windows XP and Windows Server 2003; Windows Vista and Windows Vista Service Pack 1; Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1; Windows Server 2008 for 32-bit Systems, Windows Server 2008 for x64-based Systems, and Windows Server 2008 for Itanium-based Systems; Microsoft Internet Explorer 6 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4, SQL Server 2000 Reporting Services Service Pack 2, all supported editions of SQL Server 2005, Microsoft Report Viewer 2005 Service Pack 1 Redistributable Package, Microsoft Report Viewer 2008 Redistributable Package, and Microsoft Report Viewer 2008 Redistributable Package Service Pack 1.

This security update is rated Important for all supported editions of Microsoft .NET Framework 1.1 and Microsoft .NET Framework 2.0 on Microsoft Windows 2000; Microsoft Office XP; Microsoft Office 2003; all affected Office Viewer software for Microsoft Office 2003; 2007 Microsoft Office System; all affected Office Viewer software for 2007 Microsoft Office System; Microsoft Office Compatibility Pack; Microsoft Office Project 2002; Microsoft Visio 2002; Microsoft Works 8.5; and Microsoft Forefront Client Security 1.0.

For more information, see the subsection, Affected and Non-Affected Software, in this section.

The security update addresses the vulnerabilities by introducing proper data validations within GDI+ when rendering WMF images; modifying the way that GDI+ manages a heap buffer when reading a PNG file; modifying the way that GDI+ allocates a buffer used when reading TIFF files; modifying the way that GDI+ manages buffers when certain .NET API calls are made; modifying the way that GDI+ calculates the required size of a buffer while parsing a PNG image; and modifying the way that Microsoft Office opens specially crafted files. For more information about the vulnerabilities, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.

Recommendation. Microsoft recommends that customers apply the update immediately.

Known Issues. Microsoft Knowledge Base Article 957488 documents the currently known issues that customers may experience when installing this security update. The article also documents recommended solutions for these issues.

Affected and Non-Affected Software

The following software have been tested to determine which versions or editions are affected. Other versions or editions are either past their support life cycle or are not affected. To determine the support life cycle for your software version or edition, visit Microsoft Support Lifecycle.

Microsoft Windows and Components

Operating SystemComponentMaximum Security ImpactAggregate Severity RatingBulletins Replaced by this Update
Microsoft Windows
Windows XP Service Pack 2 and Windows XP Service Pack 3
(KB958869)
Not applicableRemote Code ExecutionCriticalMS08-052
Windows XP Professional x64 Edition Service Pack 2
(KB958869)
Not applicableRemote Code ExecutionCriticalMS08-052
Windows Server 2003 Service Pack 2
(KB958869)
Not applicableRemote Code ExecutionCriticalMS08-052
Windows Server 2003 x64 Edition Service Pack 2
(KB958869)
Not applicableRemote Code ExecutionCriticalMS08-052
Windows Server 2003 with SP2 for Itanium-based Systems
(KB958869)
Not applicableRemote Code ExecutionCriticalMS08-052
Windows Vista and Windows Vista Service Pack 1
(KB958869)
Not applicableRemote Code ExecutionCriticalMS08-052
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1
(KB958869)
Not applicableRemote Code ExecutionCriticalMS08-052
Windows Server 2008 for 32-bit Systems*
(KB958869)
Not applicableRemote Code ExecutionCriticalMS08-052
Windows Server 2008 for x64-based Systems*
(KB958869)
Not applicableRemote Code ExecutionCriticalMS08-052
Windows Server 2008 for Itanium-based Systems
(KB958869)
Not applicableRemote Code ExecutionCriticalMS08-052
Internet Explorer
Microsoft Windows 2000 Service Pack 4Microsoft Internet Explorer 6 Service Pack 1
(KB958869)
Remote Code ExecutionCriticalMS08-052
Microsoft .NET Framework
Microsoft Windows 2000 Service Pack 4Microsoft .NET Framework 1.1 Service Pack 1
(KB971108)

Microsoft .NET Framework 2.0 Service Pack 1
(KB971110)
Remote Code ExecutionImportantMS08-052
Microsoft Windows 2000 Service Pack 4Microsoft .NET Framework 2.0 Service Pack 2
(KB971111)
Remote Code ExecutionImportantNone

*Server Core installation not affected. The vulnerabilities addressed by this update do not affect supported editions of Windows Server 2008 or Windows Server 2008 R2 as indicated, when installed using the Server Core installation option. For more information on this installation option, see the MSDN articles, Server Core and Server Core for Windows Server 2008 R2. Note that the Server Core installation option does not apply to certain editions of Windows Server 2008 and Windows Server 2008 R2; see Compare Server Core Installation Options.

Microsoft Office

Office Suite and Other SoftwareMaximum Security ImpactAggregate Severity RatingBulletins Replaced by this Update
Microsoft Office Suites
Microsoft Office XP Service Pack 3
(KB974811)*
Remote Code ExecutionImportantMS08-052
Microsoft Office 2003 Service Pack 3
(KB972580)**
Remote Code ExecutionImportantMS08-052
2007 Microsoft Office System Service Pack 1
(KB972581)***
Remote Code ExecutionImportantMS08-052
2007 Microsoft Office System Service Pack 2
(KB972581)***
Remote Code ExecutionImportantNone
Other Office Software
Microsoft Office Project 2002 Service Pack 1
(KB974811)*
Remote Code ExecutionImportantMS08-052
Microsoft Visio 2002 Service Pack 2
(KB975365)
Remote Code ExecutionImportantMS08-052
Microsoft Word Viewer 2003 Service Pack 3 and Microsoft Office Excel Viewer 2003 Service Pack 3
(KB972580)**
Remote Code ExecutionImportantMS08-052
Microsoft Office Excel Viewer Service Pack 2, Microsoft Office Visio Viewer 2007 Service Pack 1, and Microsoft Office Visio Viewer 2007 Service Pack 2
(KB972581)***
Remote Code ExecutionImportantMS08-052
PowerPoint Viewer 2007 Service Pack 2
(KB972581)***
Remote Code ExecutionImportantNone
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1
(KB972581)***
Remote Code ExecutionImportantMS08-052
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2
(KB972581)***
Remote Code ExecutionImportantNone
Microsoft Works 8.5
(KB973636)
Remote Code ExecutionImportantMS09-024

*These updates are identical.

**These updates are identical.

***These updates are identical.

Note Office Communicator 2005 and Office Communicator 2007 distribute a copy of gdiplus.dll that contains the affected code. However, Microsoft's analysis has shown that there are no reliable attack vectors exposed in these products.

Microsoft SQL Server

Depending on your software version or edition, you may need to choose between GDR and QFE software update links below in order to manually install your update from the Microsoft Download Center. For more information on determining which update to install on your system, see the Frequently Asked Questions (FAQ) Related to This Security Update subsection, in this section.

GDR Software UpdatesQFE Software UpdatesMaximum Security ImpactAggregate Severity RatingBulletins Replaced by this Update
Not applicableSQL Server 2000 Reporting Services Service Pack 2
(KB970899)
Remote Code ExecutionCriticalMS08-052
SQL Server 2005 Service Pack 2
(KB970895)*
SQL Server 2005 Service Pack 2
(KB970896)*
Remote Code ExecutionCriticalMS09-004
SQL Server 2005 x64 Edition Service Pack 2
(KB970895)*
SQL Server 2005 x64 Edition Service Pack 2
(KB970896)*
Remote Code ExecutionCriticalMS09-004
SQL Server 2005 for Itanium-based Systems Service Pack 2
(KB970895)*
SQL Server 2005 for Itanium-based Systems Service Pack 2
(KB970896)*
Remote Code ExecutionCriticalMS09-004
SQL Server 2005 Service Pack 3
(KB970892)**
SQL Server 2005 Service Pack 3
(KB970894)**
Remote Code ExecutionCriticalNone
SQL Server 2005 x64 Edition Service Pack 3
(KB970892)**
SQL Server 2005 x64 Edition Service Pack 3
(KB970894)**
Remote Code ExecutionCriticalNone
SQL Server 2005 for Itanium-based Systems Service Pack 3
(KB970892)**
SQL Server 2005 for Itanium-based Systems Service Pack 3
(KB970894)**
Remote Code ExecutionCriticalNone

*SQL Server 2005 Service Pack 2 customers with a Reporting Services SharePoint dependency are also required to install the Microsoft SQL Server 2005 Reporting Services Add-in for Service Pack 2 from the Microsoft Download Center.

**SQL Server 2005 Service Pack 3 customers with a Reporting Services SharePoint dependency are also required to install the Microsoft SQL Server 2005 Reporting Services Add-in for Service Pack 3 from the Microsoft Download Center.

Developer Tools

SoftwareMaximum Security ImpactAggregate Severity RatingBulletins Replaced by this Update
Microsoft Visual Studio .NET 2003 Service Pack 1
(KB971022)
NoneNone[1]MS08-052
Microsoft Visual Studio 2005 Service Pack 1
(KB971023)
NoneNone[1]MS08-052
Microsoft Visual Studio 2008
(KB972221)
NoneNone[1]MS08-052
Microsoft Visual Studio 2008 Service Pack 1
(KB972222)
NoneNone[1]None
Microsoft Report Viewer 2005 Service Pack 1 Redistributable Package
(KB971117)
Remote Code ExecutionCriticalMS08-052
Microsoft Report Viewer 2008 Redistributable Package
(KB971118)
Remote Code ExecutionCriticalMS08-052
Microsoft Report Viewer 2008 Redistributable Package Service Pack 1
(KB971119)
Remote Code ExecutionCriticalNone
Microsoft Visual FoxPro 8.0 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4
(KB971104)
NoneNone[1]MS08-052
Microsoft Visual FoxPro 9.0 Service Pack 2 when installed on Microsoft Windows 2000 Service Pack 4
(KB971105)
NoneNone[1]MS08-052
Microsoft Platform SDK Redistributable: GDI+
(KB975337)
NoneNone[1]MS08-052

[1]Severity ratings do not apply to this update because Microsoft has not identified any attack vectors relating to the vulnerabilities discussed in this bulletin specific to these software. However, this security update is being offered to developers who use this software so that they may issue their own updated version of their applications. See the entry in the Frequently Asked Questions (FAQ) Related to This Security Update section, below.

Security Software

SoftwareMaximum Security ImpactAggregate Severity RatingBulletins Replaced by this Update
Microsoft Forefront Client Security 1.0 when installed on Microsoft Windows 2000 Service Pack 4
(KB975962)
Remote Code ExecutionImportantMS08-052

Non-Affected Software

SoftwareComponent
Operating Systems and Components
Microsoft Windows 2000 Service Pack 4Not applicable
Windows Vista Service Pack 2Not applicable
Windows Vista x64 Edition Service Pack 2Not applicable
Windows Server 2008 for 32-bit Systems Service Pack 2Not applicable
Windows Server 2008 for x64-based Systems Service Pack 2Not applicable
Windows Server 2008 for Itanium-based Systems Service Pack 2Not applicable
Windows 7 for 32-bit SystemsNot applicable
Windows 7 for x64-based SystemsNot applicable
Windows Server 2008 R2 for x64-based SystemsNot applicable
Windows Server 2008 R2 for Itanium-based SystemsNot applicable
Microsoft Windows 2000 Service Pack 4Microsoft Internet Explorer 5.01 Service Pack 4
Windows Messenger 5.1
Windows XP Service Pack 2 and Windows XP Service Pack 3Microsoft Internet Explorer 6
Windows Internet Explorer 7
Windows Internet Explorer 8
Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Windows Messenger 4.7
Windows Messenger 5.1
Windows XP Professional x64 Edition Service Pack 2Microsoft Internet Explorer 6
Windows Internet Explorer 7
Windows Internet Explorer 8
Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Windows Messenger 4.7
Windows Messenger 5.1
Windows Server 2003 Service Pack 2Microsoft Internet Explorer 6
Windows Internet Explorer 7
Windows Internet Explorer 8
Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Windows Messenger 4.7
Windows Messenger 5.1
Windows Server 2003 x64 Edition Service Pack 2Microsoft Internet Explorer 6
Windows Internet Explorer 7
Windows Internet Explorer 8
Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Windows Messenger 4.7
Windows Messenger 5.1
Windows Server 2003 with SP2 for Itanium-based SystemsMicrosoft Internet Explorer 6
Windows Internet Explorer 7
Windows Internet Explorer 8
Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Windows Messenger 4.7
Windows Vista, Windows Vista Service Pack 1, and Windows Vista Service Pack 2Windows Internet Explorer 7
Windows Internet Explorer 8
Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Windows Messenger 4.7
Windows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2Windows Internet Explorer 7
Windows Internet Explorer 8
Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Windows Messenger 4.7
Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2Windows Internet Explorer 7
Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Windows Messenger 4.7
Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2Windows Internet Explorer 7
Windows Internet Explorer 8
Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Windows Messenger 4.7
Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2Windows Internet Explorer 7
Windows Internet Explorer 8
Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Windows Messenger 4.7
Other Office Software
Microsoft Visio 2003 ViewerNot applicable
Microsoft Office SharePoint Server 2007Not applicable
Microsoft Office SharePoint Server 2007 Service Pack 1Not applicable
Microsoft Works 9.0Not applicable
Microsoft Works Suite 2005Not applicable
Microsoft Works Suite 2006Not applicable
Microsoft Office 2004 for MacNot applicable
Microsoft Office 2008 for MacNot applicable
Microsoft SQL Server
SQL Server 7.0 Service Pack 4Not applicable
SQL Server 2000 Service Pack 4Not applicable
SQL Server 2000 Itanium-based Edition Service Pack 4Not applicable
SQL Server 2008 for 32-bit SystemsNot applicable
SQL Server 2008 for 32-bit Systems Service Pack 1Not applicable
SQL Server 2008 for x64-based SystemsNot applicable
SQL Server 2008 for x64-based Systems Service Pack 1Not applicable
SQL Server 2008 for Itanium-based SystemsNot applicable
SQL Server 2008 for Itanium-based Systems Service Pack 1Not applicable
Microsoft Data Engine (MSDE) 1.0Not applicable
Microsoft SQL Server 2000 Desktop Engine (MSDE 2000)Not applicable
Microsoft SQL Server 2005 Express Edition Service Pack 2 and Microsoft SQL Server 2005 Express Edition Service Pack 3Not applicable

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Information

Severity Ratings and Vulnerability Identifiers

GDI+ WMF Integer Overflow Vulnerability - CVE-2009-2500

GDI+ PNG Heap Overflow Vulnerability - CVE-2009-2501

GDI+ TIFF Buffer Overflow Vulnerability - CVE-2009-2502

GDI+ TIFF Memory Corruption Vulnerability - CVE-2009-2503

GDI+ .NET API Vulnerability - CVE-2009-2504

GDI+ PNG Integer Overflow Vulnerability - CVE-2009-3126

Memory Corruption Vulnerability - CVE-2009-2528

Office BMP Integer Overflow Vulnerability - CVE-2009-2518

Update Information

Detection and Deployment Tools and Guidance

Security Update Deployment

Other Information

Acknowledgments

Microsoft thanks the following for working with us to help protect customers:

  • Yamata Li of Palo Alto Networks for reporting the GDI+ WMF Integer Overflow Vulnerability (CVE-2009-2500)
  • Thomas Garnier of SkyRecon for reporting the GDI+ PNG Heap Overflow Vulnerability (CVE-2009-2501)
  • Wushi of VeriSign iDefense Labs for reporting the GDI+ TIFF Buffer Overflow Vulnerability (CVE-2009-2502)
  • Ivan Fratric of Zero Day Initiative, Tavis Ormandy of Google Inc., and Carlo Di Dato (aka shinnai) for reporting the GDI+ TIFF Memory Corruption Vulnerability (CVE-2009-2503)
  • Tavis Ormandy of Google Inc. for reporting the GDI+ PNG Integer Overflow Vulnerability (CVE-2009-3126)
  • Marsu Pilami of VeriSign iDefense Labs for reporting the Memory Corruption Vulnerability (CVE-2009-2528)
  • Carsten H. Eiram of Secunia for reporting the Office BMP Integer Overflow Vulnerability (CVE-2009-2518)

Microsoft Active Protections Program (MAPP)

To improve security protections for customers, Microsoft provides vulnerability information to major security software providers in advance of each monthly security update release. Security software providers can then use this vulnerability information to provide updated protections to customers via their security software or devices, such as antivirus, network-based intrusion detection systems, or host-based intrusion prevention systems. To determine whether active protections are available from security software providers, please visit the active protections Web sites provided by program partners, listed in Microsoft Active Protections Program (MAPP) Partners.

Support

  • Customers in the U.S. and Canada can receive technical support from Security Support or 1-866-PCSAFETY. There is no charge for support calls that are associated with security updates. For more information about available support options, see Microsoft Help and Support.
  • International customers can receive support from their local Microsoft subsidiaries. There is no charge for support that is associated with security updates. For more information about how to contact Microsoft for support issues, visit the International Support Web site.

Disclaimer

The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions

  • V1.0 (October 13, 2009): Bulletin published.
  • V1.1 (October 14, 2009): Added Microsoft SQL Server 2005 Express Edition Service Pack 3 to the Non-Affected Software table, and updated the Developer Tools entries in the Detection and Deployment Tools and Guidance section.
  • V2.0 (October 28, 2009): Added Microsoft Office Visio Viewer 2007, Microsoft Office Visio Viewer 2007 Service Pack 1, and Microsoft Office Visio Viewer 2007 Service Pack 2 as affected software, and added SQL Server 2008 and SQL Server 2008 Service Pack 1 to the Non-Affected Software table. Also added notes to the Affected Software table for SQL Server 2005 customers with a Reporting Services SharePoint dependency; corrected the MBSA detection entries for Microsoft Report Viewer; and corrected the log file and registry key verification information for Microsoft Internet Explorer 6 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4.
  • V2.1 (November 4, 2009): Removed erroneous references to the original release version of Microsoft Office Visio Viewer 2007 as affected software; corrected the setup switches for Microsoft .NET Framework 1.1 and Microsoft .NET Framework 2.0; clarified the entry, "If I have an installation of SQL Server, how am I affected?" in the FAQ section; and corrected the removal information for Microsoft Windows 2000.
  • V2.2 (January 12, 2010): Corrected references to various Microsoft Office software. See the entry to the Frequently Asked Questions (FAQ) Related to This Security Update section that explains this revision. Customers who have successfully installed this update do not need to reinstall.