Welcome to MSDN Blogs Sign in | Join | Help

Important Security Hotfix MS07-059

Please Install New Security Hotfix MS07-059

We will be releasing a security hotfix for Windows SharePoint Services MS07-059 on October 9th.  Be sure to note that as Windows SharePoint Services 3.0 is included with all editions of Office SharePoint Server 2007, Microsoft Office Project Server 2007, and Performance Point Server as well as any others which include WSS 3.0 you need to apply this hotfix on those environments as well. 

 

We recommend applying this hotfix during your next planned downtime, or change management window and scheduling this with priority.  This hotfix contains previously released hotfixes including the DST (Daylight Savings Time) hotfix.

 

First, if you have deployed “host named site collections” previously known as “host header” sites you should contact product support if you have more than 50 host named site collections and ask for the fix related to KB 943594.  This fix includes the same hotfixes as the October 9 public update in addition to the host named site collection update performance related hotfix. <update 10/18/07> This WSS Hotfix KB for customers which meet this condition of "Header Site Collection mode" is now live, http://support.microsoft.com/kb/943594.  </update>

 

The most important thing as the title suggests is this hotfix addresses a security vulnerability in Microsoft Windows SharePoint Services 3.0 that could allow cross-site scripting. This update resolves this vulnerability. Please read the entire contents of the KB article before applying the hotfix as there are a number of known issues which should be well understood.

 

http://support.microsoft.com/kb/942017

 

To view the complete security bulletin, visit the following Microsoft Web site:

 

http://www.microsoft.com/technet/security/bulletin/ms07-059.mspx

 

 

WSS 3.0

http://support.microsoft.com/?id=934525 (http://support.microsoft.com/kb/934525/) Description of the security update for Windows SharePoint Services 3.0: October 9, 2007

 

 

DOWNLOADS

 

Security Update for Windows SharePoint Services 3.0 x64 Edition (KB934525)

http://www.microsoft.com/downloads/info.aspx?na=22&p=1&SrcDisplayLang=en&SrcCategoryId=&SrcFamilyId=&u=%2fdownloads%2fdetails.aspx%3fFamilyID%3d667335dd-df2e-4f14-a130-5758701be055%26DisplayLang%3den

 

Security Update for Windows SharePoint Services 3.0 (KB934525)

http://www.microsoft.com/downloads/info.aspx?na=22&p=2&SrcDisplayLang=en&SrcCategoryId=&SrcFamilyId=&u=%2fdownloads%2fdetails.aspx%3fFamilyID%3d76fc2225-2802-46e5-a294-a842e3841877%26DisplayLang%3den

 

MOSS

http://support.microsoft.com/?id=937832 (http://support.microsoft.com/kb/937832/) Description of the security update for SharePoint Server 2007: October 9, 2007

 

DOWNLOADS

 

Security Update for Microsoft Office SharePoint Server 2007 x64 (KB937832), http://www.microsoft.com/downloads/info.aspx?na=22&p=1&SrcDisplayLang=en&SrcCategoryId=&SrcFamilyId=&u=%2fdownloads%2fdetails.aspx%3fFamilyID%3d1d319164-d133-4493-be27-1aeda62362c4%26DisplayLang%3den

 

Security Update for Microsoft Office SharePoint Server 2007 (KB937832), http://www.microsoft.com/downloads/info.aspx?na=22&p=2&SrcDisplayLang=en&SrcCategoryId=&SrcFamilyId=&u=%2fdownloads%2fdetails.aspx%3fFamilyID%3daaea9695-f541-4c4c-9107-81ead5cfc8c9%26DisplayLang%3den

 

 

 

How to deploy software updates for Windows SharePoint Services 3.0

We recommend that you follow the process and procedures in the Deploy software updates for Windows SharePoint Services 3.0 topic for most deployment scenarios, from stand-alone server deployments to very large server farms.


http://technet2.microsoft.com/windowsserver/WSS/en/library/91649a7e-6b5a-4e5a-9ee5-51951f4b857f1033.mspx

 

If you are running Office SharePoint Server you may find additional guidance in the article Deploy software updates for Office SharePoint Server 2007.

http://technet2.microsoft.com/Office/en-us/library/f484f5f2-35bb-4d70-bf56-dd1c4c287c721033.mspx

 

 

<Updated 11/23>

 

Important Troubleshooting Info on this Hotfix 

 

Product support and MS IT has shared some of their experience with troubleshooting issues related to the patch.

 

 

Other relevant recent posts:

Hotfixes, Service packs, and password resets 

Daylight Savings Time Hotfix post 

FAQ on DST and Hotfix

Published Tuesday, October 09, 2007 8:06 AM by joelo
Filed under: ,

Comment Notification

If you would like to receive an email when updates are made to this post, please register here

Subscribe to this post's comments using RSS

Comments

# Techy News Blog &raquo; Important Security Hotfix MS07-059

Tuesday, October 09, 2007 3:24 AM by Techy News Blog » Important Security Hotfix MS07-059

# re: Important Security Hotfix MS07-059

Note, a couple of these links still aren't live yet as of 12:30am Pacific time on Oct 9.  I wanted to give you a heads up on this as early as I could knowing that these links would be live later.  I hope this doesn't cause confusion.

Joel

Tuesday, October 09, 2007 3:35 AM by joelo

# WSS v3: Important Security Hotfix MS07-059

Be sure to check out this hotfix for WSS v3 as posted on the SharePoint Team Blog: http://blogs.msdn.com/sharepoint/archive/2007/10/09/important-security-hotfix-ms07-059.aspx

Tuesday, October 09, 2007 9:56 AM by Wes Preston

# WSS 2.0 SP3 and SPS 2003 SP3

You may not have heard about these updates, they may not have hit your radar is you're already running

Tuesday, October 09, 2007 2:02 PM by Joel Oleson's SharePoint Land

# no se tarden

Tienes implementado SharePoint en tu empresa? o implementaste sharepoint para tus clientes? Bueno, en

Tuesday, October 09, 2007 7:50 PM by Haaron Gonzalez

# no se tarden

Tienes implementado SharePoint en tu empresa? o implementaste sharepoint para tus clientes? Bueno, en

Tuesday, October 09, 2007 7:50 PM by Haaron Gonzalez

# re: Important Security Hotfix MS07-059

Note the links have been updated and they are now all live.

Tuesday, October 09, 2007 8:38 PM by joelo

# More Harm then Good

I read through the fix, the known issues and what could happen should I install the patch.  From that it sounds like the cure is worse than the illness.  I really like the fact that after the patch is installed in CANNOT be uninstalled and several fix will break when we apply SP1 for WSS3.  So unti MS can make it less dangerous to install patchins for WSS3, I will live with the vulnerbility.

Wednesday, October 10, 2007 11:32 AM by Chris Kuntz

# re: Important Security Hotfix MS07-059

Joel, can you give us any release dates for WSS 3.0 SP1?

Wednesday, October 10, 2007 1:02 PM by Tim

# re: Important Security Hotfix MS07-059

Joel, does this hotfix address the item level permissions issue that results in an permanently broken list - SQL error "Invalid syntax near the keyword 'SET'"?

Support has stated this has been fixed in SP1, but does not know its status in a hotfix. It has broken multiple production lists and really causes the product to be unusable.

Wednesday, October 10, 2007 2:28 PM by Aaron K

# re: Important Security Hotfix MS07-059

I have added the download links to make it easier to get and more accessible.  Still, be sure to read all the information before installing/deploying the hotfix.

Wednesday, October 10, 2007 5:12 PM by joelo

# re: Important Security Hotfix MS07-059

Sorry I can't provide any dates for SP1.  It is still in beta with a select set of customers.

Wednesday, October 10, 2007 5:13 PM by joelo

# WSS HotFix Trashed My SharePoint Server

I was able to install the SharePoint hotfix without any errors, but when I then went to install the WSS hotfix it failed during the SharePoint Wizard.  The upgrade.log file indicates that "CanUpgrade" failed for my databases.

Unfortunately now I can't get my server back to normal.  I made a farm backup of the server before I started and restored it after the failure, but no luck.  The restore completed successfully but my web sites aren't up.

If I try to rerun the patches it says they are already installed.  If I try to run the SharePoint Wizard it says that the database has been upgraded and I need to install the patch.

Where do I go next?  The only thing I can think of is to uninstall SharePoint completely and start over.

If anyone has suggestions you can reach me at daniel.barton@pgnmail.com.

Wednesday, October 10, 2007 5:14 PM by Daniel Barton

# re: Important Security Hotfix MS07-059

After applying this fix we are not able to start WSS Admin service.  Anyone knows how to fix this?

Thanks

Friday, October 12, 2007 4:53 AM by Jan Avramov

# re: Important Security Hotfix MS07-059

I had the same kind of crash, something to do with SQL tables missing, I know that this is not the support forum, but MOSS team should be aware of the "quality" of this patch... not good...

Friday, October 12, 2007 6:26 AM by One more crash

# re: Important Security Hotfix MS07-059

I've forwarded your comments to support.  I'll respond either on the blog or in the comments when I get any answers.

Friday, October 12, 2007 6:47 PM by joelo

# re: Important Security Hotfix MS07-059

If you ran into a problem installing this, you should contact support for the quickest resolution.  Due to the nature of this, I'd like to share a couple of soltuions and will try to track down a couple over the comments if I can get copies of the upgrade logs and explanations of your environment and what you did.  Email me at joelo at microsoft.com  

FYI. The WSS Admin problem is likely fixed by the GroupBoard KB article: http://support.microsoft.com/?id=941678

Also make sure you have already tried the solutions recommended on this post.

http://blogs.msdn.com/joelo/archive/2007/09/26/hotfixes-service-packs-and-password-resets.aspx

specifically try the:

psconfig –cmd upgrade –inplace b2b –wait –force

and then if that doesn't work try:

stsadm -o upgrade -inplace -forceupgrade

Friday, October 12, 2007 9:18 PM by joelo

# re: Important Security Hotfix MS07-059

We also can't start WSS Admin service after applying this hot"fix". This is not good.

The psconfig command doesn't work either - it says something about -cmd being invalid. I haven't tried the stsadm fix as I am looking elsewhere for a solution at the moment.

Monday, October 15, 2007 6:57 AM by Paul Buckle

# re: Important Security Hotfix MS07-059

I’ve applied the hotfix several times with clean installs on two development servers using “complete” installation  and one staging farm of two WFEs and one application server with Central Administration.  I’ve run the installs with and without dropping content databases first.  When I do not drop the content databases I always have to start the indexing manually at Step 9.  I’ve also tried manually forcing software upgrade as you recommended.

Either way when I run the verification steps I get these results:

• Central admin reports version 12.0.0.6039

• SELECT * FROM VERSIONS reports 12.0.0.6039 (not 12.0. 6035 as expected)

• Upgrade.log reports 0 errors and 0 warnings

• Microsoft.SharePoint.dll version is now 12.0.6039.5000

• Microsoft.Office.Server.dll version is 12.0.4518.1014 not 12.0.6036

• HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OSERVER\DisplayVersion reports 12.0.4518.1016 not 12.0.6036

• Windows Update is still reporting WSS and Office Server hotfixes need to be applied

Any advice appreciated.  

Monday, October 15, 2007 8:40 AM by Tronn Carson

# Re: After applying this fix we are not able to start WSS Admin service

I get "Cannot start service SPAdmin on computer '.'.

System.InvalidOperationException: Cannot start service SPAdmin on computer" in PSDiagnostic log file and hotfix doesn't finish installation.

Workaround that help my:

use this command after installing the binary files with SPFarm admin user account:

C:\Program Files\Common Files\Microsoft Shared\web server extensions\12\BIN>psconfig.exe -cmd upgrade inplace b2b wait force

Monday, October 15, 2007 1:21 PM by Pavel Shilov

# SharePoint FAQ on DST and October 9th Public Update

I've gotten some questions asked on the hotfix and public update I wanted to address here. Q. Do I need

Tuesday, October 16, 2007 5:41 PM by Joel Oleson's SharePoint Land

# re: Important Security Hotfix MS07-059

You should look at this post in an FAQ.  I've tried to address a lot of these questions.

http://blogs.msdn.com/joelo/archive/2007/10/16/sharepoint-faq-on-dst-and-october-9th-public-update.aspx

Tuesday, October 16, 2007 5:55 PM by joelo

# re: Important Security Hotfix MS07-059

Anyone know if the other hotfixes such the May 8 hotfix package (KB936867 and KB936877) are also included in this package? When I try to install the May 8 hotfixes after this update it claims the hotfix is already installed, but I am not convinced.

Tuesday, November 06, 2007 4:48 PM by Todd Walker

# Addendum to the SharePoint Deployment Daylight Savings patch issue

There has been much written about the issue (in particular Joel&#39;s Q&amp;A ) with Deploying Solutions

Thursday, November 08, 2007 6:53 PM by Aaron Robertson-Hodders SharePoint Blog

# Addendum to the SharePoint Deployment Daylight Savings patch issue

There has been much written about the issue (in particular Joel&#39;s Q&amp;A ) with Deploying Solutions

Thursday, November 08, 2007 7:35 PM by SHAREPOINTBlogs.com Mirror

# re: Important Security Hotfix MS07-059

Hi Everyone,

My name is Amol and i have been working upon cases where you get issues after you install the update 934525. This is a security update and so, after installing such a hotfix might cause sharepoint to stop working if your server or your configuration has some things missing. So, you need to troubleshoot the issue first and then try to find out why the upgrade of Sharepoint Technologies Wizard is failing.

Now, when you install the hotfix and then try to run the Products and Technologies Wizard, it should get completed if you do not have any things missing. But unfortunately if it fails, then you can try the following steps.

- Run the Products and Technologies Wizard and take a note at what step the wizard if failing. [It should ideally fail at step 2 or 8 or 9.]

- If the wizard fails at Step 8 or 9 then take look at the PSCDiagnostic_<id>.txt file located under C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\12\Logs

- Open that file in notepad and Search for "ERR" and do a match case for it.

- Take a note of the error message.

- Run the following command on the Sharepoint server:

C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\12\Bin > psconfig -cmd upgrade -inplace b2b -force -wait

- If this command failes then open the following file : C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\12\Logs\upgrade.log

- Search for "[ERROR]" (excluding the quotes) and do a match case for that. Look at the error message and take a note of it.

- Now you are ready with the basics that you need to troubleshoot the issue.

- The upgrade.log file should give you clear messages that should help you identify the problem. If you are not able to find out the problem, please paste the error messages in this blog and i will take a look at them.

Thank You,

Amol Ghanwat

Tuesday, November 13, 2007 12:09 PM by Amol Ghanwat

# Cannot start Windows Sharepoint Services Administration

I finished installing the security patches to WSS and MOSS after I ran psconfig –cmd upgrade –inplace b2b –wait –force. But now Windows Sharepoint Services Administration is stopped although it's set to automatic. I tried starting it manually by going to the services console, but it won't start. I get error 1053: The service did not respond to the start or control request in a timely fashion.

How do I fix this?

Tuesday, November 13, 2007 12:32 PM by Peter

# re: Important Security Hotfix MS07-059

We are having no luck installing the updates as we are getting the following error: “The expected version is not found in the system”. The version of SharePoint we have running is 12.0.0.4518.

Do we need install any other fixes before we install the latest one to get the versions up-to-date? Any help will be greatly appreciated.

Sunday, December 09, 2007 7:46 PM by birixiote

# re: Important Security Hotfix MS07-059

I'm also havintg the same problem as birixiote.  I'm getting "The expected version of the product was not found on the system" error when trying to install KB937832.  I have MOSS 12.0.4518.1015 with SQL Server 2005 SP2 back end.

Wednesday, January 09, 2008 4:05 PM by Tom C

# Daylight savings issue with MOSS 2007 deployments pre SP1

Wednesday, April 02, 2008 11:33 AM by Merrick Chaffer's Blog

# Daylight savings times messes up WSP solutions

Last week I encountered something strange here on the servers. Retracting a solution file (*.wsp) took

Monday, April 07, 2008 7:03 AM by Nick's SharePoint Blog

Leave a Comment

(required) 
required 
(required) 

  
Enter Code Here: Required
 
Page view tracker