Re: MS04-027 and MS04-028 not detected

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Doug Neal [MSFT] (dugn_at_online.microsoft.com)
Date: 09/15/04


Date: Wed, 15 Sep 2004 14:23:41 -0700

Gerry - Your point is well taken. We're doing our best to provide the best
detection through MBSA as we work on our next major version which is still
quite a way off (no public ETA).

As much as we'd like to avoid it, when MBSA cannot authoritatively and
exhaustively indicate the patch status for a particular patch, we're forced
to create a Note message. For MS04-028, there are 26 various patches
depending on which of 45+ operating systems, IE versions and Microsoft
products are present on a machine. As significant as this GDI+
vulnerability is, there was simply no way MBSA could authoritatively cover
all possible cases and provide the correct patch status for every case.

As a company, we created the GDI+ Detection tool (available for download and
through Windows Update) to help centralize the detection effort across
products MBSA doesn't support (see the full list at KB306460).

It's true that MBSA will not be able to detect the patch status except for
local scans of Microsoft Office products (6 of the 26 potential affected
platforms/products), but we're directing users to the GDI+ Detection tool as
a method to identify all cases and apply the appropriate patch separate from
the limited guidance MBSA can provide in this case. The additional
technical information in the MSRC bulletin (MS04-028) provides enough detail
for the technically minded to create other solutions/use other methods that
may be more appropriate for their environment to identify and patch all
cases of the vulnerable GDI+ instances.

With a good understanding of the security requirements of our customers,
we're working to ensure even better vulnerability assessment in the future.
I hope that helps...

-- 
Doug Neal [MSFT]
dugn@online.microsoft.com
This posting is provided "AS IS" with no warranties, and confers no rights.
If newsgroup discussion with experts and MVPs is unable to solve a problem
to your satisfaction, feel free to contact PSS for the Microsoft Baseline
Security Analyzer (MBSA) at the following link:
http://support.microsoft.com/default.aspx?scid=fh;en-us;Prodoffer20a
This e-mail address does not receive e-mail, but is used for newsgroup
postings only.
"Gerry Hickman" <gerry666uk@yahoo.co.uk> wrote in message 
news:epQeyr1mEHA.3396@tk2msftngp13.phx.gbl...
> Hi Doug,
>
>> MBSA does not support either of these patches for patch detection,
>
> I have to say I find this REALLY disappointing. The whole point of a tool 
> like MBSA is to be able to check file versions against installed products, 
> NOT just say to people "you may need a patch, but we don't really know".
>
> This "note" message is no more use than going to the Microsoft security 
> site. It does not tell you if a machine needs patched or not. What if you 
> have reinstall one of the many vulnerable products - the tool won't tell 
> you you're open to attack again...
>
> It's also disappointing that this newer release 1.2.1 still cannot test 
> missing Microsoft Office patches, unless you install it on 1000+ machines 
> and run it locally? Conversely Shavlik's product does this without any 
> problem.
>
> I realise MBSA is free, but it's supposed to be part of Microsoft's drive 
> towards secure computing, and these limitations relate to thier OWN 
> flagship products (Windows and Office)!
>
> -- 
> Gerry Hickman (London UK) 


Relevant Pages

  • Re: MS04-027 and MS04-028 not detected
    ... default, but since the vulnerable files can be in various locations, MBSA ... cannot authoritatively determine the patch status. ... can provide the best answers for MBSA - the detection tool - not necessarily ... >> vulnerability is, there was simply no way MBSA could authoritatively ...
    (microsoft.public.sms.tools)
  • Re: MS04-027 and MS04-028 not detected
    ... Windows XP and Windows 2003 Server ARE vulnerable by default, ... why exactly can't MBSA detect the requirement for the patch on these ... What is this doing there if MBSA can't ... > vulnerability is, there was simply no way MBSA could authoritatively cover ...
    (microsoft.public.sms.tools)
  • New MSSecure.XML Version 2005.04.12.0 Now Available
    ... release contains 8 new bulletins, 7 of which are fully supported by MBSA. ... Windows Server 2003 Small Business Server Detection: ... provide detection support based on the specifics of each release. ...
    (microsoft.public.security)
  • Re: New MSSecure.XML Version 2005.10.11.0 Now Available
    ... feel free to contact PSS for support on the Microsoft ... Security Analyzer (MBSA). ... >> regarding MBSA 2.0 patch detection for this month's release should by ... This bulletin replaces all previous versions of MS05-039. ...
    (microsoft.public.security)
  • RE: MS defends MBSA
    ... So I am not sure how the patch would apply. ... machines ran the scan and had no change in the results.. ... Subject: MS defends MBSA ... to scan my user's machines and check them for dubious MS Office security ...
    (Focus-Microsoft)