Windows NT 4.0 Security Patch: Mar 17

To determine the support lifecycle for your product and version, visit the Microsoft Support Lifecycle Web site. Restart Requirement You must restart your system after you apply this security update.

  • There is no way for an attacker to force a user to open a specially crafted file, except potentially through previewing an email message.
  • During that time, the server cannot respond to requests.
  • The dates and times for these files are listed in coordinated universal time (UTC).
  • On the Version tab, determine the version of the file that is installed on your computer by comparing it to the version that is documented in the appropriate file information table.Note

V2.1 (April 24, 2003): Updated to include download link for NT4 package for Japanese NEC V2.2 (April 24, 2003): Provided additional clarification in FAQ regarding supercedence of Windows 2000 patch by Also, these registry keys may not be created correctly if an administrator or an OEM integrates or slipstreams the 840987 security update into the Windows installation source files.

Restart Requirement You must restart your system after you apply this security update. Also, this registry key may not be created correctly when an administrator or an OEM integrates or slipstreams the 840987 security update into the Windows installation source files. An attacker cannot load and run a program remotely by using this vulnerability.

In certain circumstances, some privileged operating system functions might not validate system structures and could allow an attacker to execute a specially-designed program with system privileges. that's all i ask. You’ll be auto redirected in 1 second.

For more information about the kernel and about other operating system structures, visit the following Web site.

MS04-028 helps protect against the vulnerability that is discussed in that bulletin, but does not address this new vulnerability. If they are, see your product documentation to complete these steps. An attacker could create an HTML e-mail message that has a specially crafted image attached. Can I use Systems Management Server (SMS) to determine if this update is required?

Microsoft had not received any information indicating that this vulnerability had been publicly disclosed when this security bulletin was originally issued. Customers hosting web servers using Microsoft® Windows NT® 4.0, Windows® 2000, or Windows® XP.

Customers wihtout an Alliance, Premier, or Authorized Contract can contact their local Microsoft sales office. When this security bulletin was issued, had Microsoft received any reports that this vulnerability was being exploited?

To unsubscribe from the Microsoft Security Notification Service, please visit the Microsoft Profile Center at http://register.microsoft.com/regsys/pic.asp If you do not wish to use Microsoft Passport, you can unsubscribe from the Microsoft Could the vulnerability be exploited over the Internet?

Registry Key Verification You may also be able to verify the files that this security update has installed by reviewing the following registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB840987\Filelist Note This registry key may No.