Microsoft Issues Patch With Problems

執筆者
Dennis Fisher
Dennis Fisher
Published: Oct 29, 2001
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

As it struggles to improve its reputation in the security community with sweeping internal and external initiatives, Microsoft Corp. is still trying to get the small things right.

A patch Microsoft issued two weeks ago had to be removed from its security Web site last week after it was discovered that the fix caused systems running Windows 2000 to become unstable. Microsoft posted a new patch Monday afternoon, four days after the original fix was issued.

A similar patch for systems running Windows NT 4.0 is not affected.

Microsoft issued the patch for a problem in the RDP (Remote Data Protocol) used in the terminal service in Windows 2000 and NT 4.0. The service handles a set of RDP packets incorrectly and, as a result, can cause the server to fail.

The vulnerability is relatively minor and was termed a low-to-moderate risk in Microsofts new severity rating system.

Although the problematic patch was on the Microsoft Web site for only a few hours, the users who downloaded and installed it were not happy.

One customer said the patch prevented Terminal Services from working, forcing him to remove the patch and reinstall a .dll and reboot.

“I think it is appalling that Microsoft released [Version] 1.0 of this patch, and it caused both complete system failures and the inability to use the service it was supposed to correct,” said Russ Cooper, surgeon general of Tru-Secure Corp., in Herndon, Va. “Any reasonable testing should have caught the fact that the patch caused these problems. I think Microsoft has totally failed to fulfill the commitment they made in the announcement of the STPP [Strategic Technology Protection Program].”

The situation could have been much worse had the faulty patch been sent out via the automatic distribution system that Microsoft will soon deploy as part of the STPP.

The Redmond, Wash., company issued an apology in the bulletin announcing the error.

“The issue is a result of human error in the patch building process. Microsoft deeply apologizes for any problems this has caused. We assure that a thorough investigation is being conducted into the cause of this problem, and aggressive steps are being taken to prevent it from happening again,” the statement says.

Advertisement

This is not the first time Microsoft has run into such a problem. Earlier this year, the software company released three patches in less than a week for the same flaw in its Exchange Outlook Web Access e-mail client. Each of the first two supposed fixes contained regression errors that not only didnt fix the problem but also caused the Exchange servers to hang.

To remove the error-causing patch, issued with security bulletin MS01-052, Microsoft recommends that users go into the Add/Remove utility in the Control Panel.

Dennis Fisher

Dennis Fisher

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。