S
Steve
From Brian Livingston (InfoWorld columnist) -
I recommend that you install the MS03-040 patch immediately. This
patch, however, is still problematic in two ways that you must deal
with.
1. As was the case with MS03-032 and a few other recent patches,
installing MS03-040 will cause problems with Windows' HTML Help engine
unless you also install a fix to update the help feature. This is
explained in Microsoft Knowledge Base article 811630.
2. After installing MS03-040, you also need to install an update for
Windows Media Player versions 6.4, 7.1, and 9, and Media Player for
XP. Microsoft-style audio and video data files are allowed (stupidly,
in my opinion) to command Media Player to open Web pages. These pages
might be malicious or infected. The update allows administrators to
shut down this feature by making changes to the Registry. I don't
believe this capability should ever have been shipped, but I recommend
that you install the patch and implement the more-secure policies, as
described in KB 828026.
I recommend that you install the MS03-040 patch immediately. This
patch, however, is still problematic in two ways that you must deal
with.
1. As was the case with MS03-032 and a few other recent patches,
installing MS03-040 will cause problems with Windows' HTML Help engine
unless you also install a fix to update the help feature. This is
explained in Microsoft Knowledge Base article 811630.
2. After installing MS03-040, you also need to install an update for
Windows Media Player versions 6.4, 7.1, and 9, and Media Player for
XP. Microsoft-style audio and video data files are allowed (stupidly,
in my opinion) to command Media Player to open Web pages. These pages
might be malicious or infected. The update allows administrators to
shut down this feature by making changes to the Registry. I don't
believe this capability should ever have been shipped, but I recommend
that you install the patch and implement the more-secure policies, as
described in KB 828026.