Lucene search

K
mskbMicrosoftKB2962490
HistoryAug 12, 2014 - 12:00 a.m.

MS14-049: Vulnerability in Windows installer service could allow elevation of privilege: August 12, 2014

2014-08-1200:00:00
Microsoft
support.microsoft.com
23

0.001 Low

EPSS

Percentile

28.6%

<html><body><p>Resolves a vulnerability in Windows that could allow elevation of privilege if an attacker runs a specially crafted application that tries to repair a previously installed application.</p><h2>INTRODUCTION</h2><div>Microsoft has released security bulletin MS14-049. To learn more about this security bulletin:<br /><ul><li>Home users:<br /><div><a href=“https://www.microsoft.com/security/pc-security/updates.aspx” target=“_self”>https://www.microsoft.com/security/pc-security/updates.aspx</a></div><span>Skip the details</span>: Download the updates for your home computer or laptop from the Microsoft Update website now:<br /><div><a href=“https://update.microsoft.com/microsoftupdate/” target=“_self”>https://update.microsoft.com/microsoftupdate/</a></div></li><li>IT professionals:<br /><div><a href=“https://technet.microsoft.com/security/bulletin/ms14-049” target=“_self”>https://technet.microsoft.com/security/bulletin/MS14-049</a></div></li></ul><h3>How to obtain help and support for this security update</h3>Help installing updates:<br /><a href=“https://support.microsoft.com/ph/6527” target=“_self”>Support for Microsoft Update</a><br /><br />Security solutions for IT professionals:<br /><a href=“https://technet.microsoft.com/security/bb980617.aspx” target=“_self”>TechNet Security Troubleshooting and Support</a><br /><br />Help protect your Windows-based computer Windows from viruses and malware:<br /><a href=“https://support.microsoft.com/contactus/cu_sc_virsec_master” target=“_self”>Virus Solution and Security Center</a><br /><br />Local support according to your country:<br /><a href=“https://support.microsoft.com/common/international.aspx” target=“_self”>International Support</a><br /><br /></div><h2>More Information</h2><div><h3>More information about this security update</h3>The following article contains additional information about this security update as it relates to individual product versions. The article may contain known issue information. If this is the case, the known issue is listed under each article link.<br /><ul><li><div><a href=“https://support.microsoft.com/en-us/help/2918614”>2918614 </a> MS14-049: Description of the security update for Windows Installer Service: August 12, 2014</div>Known issues in security update 2918614:<br /><ul><li>After you install this security update and try to install any MSI package that uses a mandatory or temporary user profile, the MSI package installation fails, and you receive an error message that resembles the following:<br /><br /><br /><div>The profile for the user is a temporary profile<br /></div></li><li>After you install this security update, you may receive a User Account Control (UAC) prompt when you try to use remote deployments, centralized deployments, or other local methods to reinstall a program that was already installed before the security update was installed. </li><li>After you apply this security update, a minor upgrade will display a UAC prompt. </li></ul>To resolve these issues in all affected operating systems except for Windows Vista, install update 3008627. For more information, click the following article number to view the article in the Microsoft Knowledge Base: <div><a href=“https://support.microsoft.com/en-us/help/3008627”>3008627 </a> Unexpected UAC prompt after you install update 2918614 in Windows <br /></div></li></ul></div><h2>FILE INFORMATION</h2><div><div><div><div><span><span></span></span><span><span>File hash information</span></span></div><div><span><div><div><table><tr><th>File name</th><th>SHA1 hash</th><th>SHA256 hash</th></tr><tr><td>Windows6.1-KB2918614-x64.msu</td><td>8A78582D33BCD8E6776096B2685D779CC6363B34</td><td>E2CB5D7B896AEC0D2C85A9EBAA571363A0D66717E5A0E7EDD4348B89B43FBC68</td></tr><tr><td>Windows6.1-KB2918614-x86.msu</td><td>1A06DE2EB02190CC04BE92C84BE3F48A588FE6B1</td><td>C6A39B8221D1B029A1F6C7B2DBBD1E539FE9A13A0A2C96C16C155FFA89F3B369</td></tr><tr><td>Windows8-RT-KB2918614-x64.msu</td><td>7349232D7F9816E95777A83C6C62CEC5F2471E78</td><td>AA2F910455621F3422519BF2CCA17688BBF58438C21EF454D3DFD33136C6BE3D</td></tr><tr><td>Windows8-RT-KB2918614-x86.msu</td><td>246CF9A5950FE72735A8BFF9D14A2EDB0D9FD7C6</td><td>3C8A23318BEA604BFC132522F2A1AB8E61536BEB2EE5331E08D3BF66C1694647</td></tr><tr><td>Windows8-RT-KB2918614-x64.msu</td><td>7349232D7F9816E95777A83C6C62CEC5F2471E78</td><td>AA2F910455621F3422519BF2CCA17688BBF58438C21EF454D3DFD33136C6BE3D</td></tr><tr><td>Windows8.1-KB2918614-x64.msu</td><td>E7E76FDF36DE16BF265C6EFFC50BD949C4B148E3</td><td>3404198E0069449AC5BA2ABD955B14ED553F0ADFE238B29EC0BAACC26ADDE1EA</td></tr><tr><td>Windows8.1-KB2918614-x86.msu</td><td>A3BAEA70FA948538A34F6FC75513C68444488693</td><td>DE35FCCB71D4F58C1CCA931670B7F488528B65B1D91CFFAB02DFCD8A34AEF0AE</td></tr><tr><td>Windows8.1-KB2918614-x64.msu</td><td>E7E76FDF36DE16BF265C6EFFC50BD949C4B148E3</td><td>3404198E0069449AC5BA2ABD955B14ED553F0ADFE238B29EC0BAACC26ADDE1EA</td></tr><tr><td>Windows6.1-KB2918614-x64.msu</td><td>8A78582D33BCD8E6776096B2685D779CC6363B34</td><td>E2CB5D7B896AEC0D2C85A9EBAA571363A0D66717E5A0E7EDD4348B89B43FBC68</td></tr><tr><td>Windows6.1-KB2918614-x86.msu</td><td>1A06DE2EB02190CC04BE92C84BE3F48A588FE6B1</td><td>C6A39B8221D1B029A1F6C7B2DBBD1E539FE9A13A0A2C96C16C155FFA89F3B369</td></tr><tr><td>WindowsServer2003-KB2918614-x64-ESN.exe</td><td>8E9BA43C014A9CC4B547E7DC6D4646977362E666</td><td>EF12B4365601C4BB860C62D3FF04E735F6C97EF769A345387EF62A09749E34A5</td></tr><tr><td>WindowsServer2003-KB2918614-ia64-FRA.exe</td><td>560B87DD2CC4B19AFE2CE7C405ADCF5E12D51AA3</td><td>71AF9D25A3F9CC17D52327B3C09FC8AB70029D13A04FB82027079B6C743C27B1</td></tr><tr><td>WindowsServer2003-KB2918614-x86-HUN.exe</td><td>EFF3196665E9BBA6595D40DB589B6D63D84D2C4D</td><td>4A4FCD7EA44D347B6182659464C79D8E0516F8ACF7884AFB6EDD21F3E79D6035</td></tr><tr><td>WindowsServer2003-KB2918614-x86-JPN.exe</td><td>87C17253D9ED641F4C2EB4D8B2D2FE9229DBC08E</td><td>69FD480BD3497C539AD2D13514E0098B477CB148D6E1B4C796503A89880705C1</td></tr><tr><td>WindowsServer2003-KB2918614-x64-KOR.exe</td><td>9B758D9A106918F7BDBE14B1C075DD0FCA4FB0DF</td><td>D0747165B6AB33F2DB3CE45E4AFA0A6FD06635F8684C76E253CF1FD20ADCBE45</td></tr><tr><td>WindowsServer2003-KB2918614-x86-PTG.exe</td><td>785C9CA5A5F004395A1260F1F78F43DD9D7B40C7</td><td>3C2AA236E1C4DC595582FD957FAB21E5322EF7CDA26221ACE5F7FDE5176C02FF</td></tr><tr><td>WindowsServer2003-KB2918614-x64-RUS.exe</td><td>F46D99A434DD321C5D85772D527B3FE837D01542</td><td>62629A9DC6AED1B23CE3AB24CB57C4243BE16720D03681B10DF5F2925CBA8076</td></tr><tr><td>WindowsServer2003-KB2918614-x86-SVE.exe</td><td>F13D3F86D9A48EC275FC94D1F03304BF7471096B</td><td>0DAA3A1AC3FBD22E734D3700F3DD9AC035F0C995724E35280EA75CE607530A7D</td></tr><tr><td>WindowsServer2003-KB2918614-x86-CSY.exe</td><td>BD6AC0F8A338603C68B83122A1398777B320D075</td><td>EF305CA9BD32E6F27B834DDD17E78BA53CD5CDB1B01AE0D550E54819329C70A2</td></tr><tr><td>WindowsServer2003-KB2918614-x64-DEU.exe</td><td>A83870EA3744847BD462FDF7EC10088CE71FE7A1</td><td>610FD528680137C394CF746FDB73ABFF0385DBD882F67F6EB4D2BB2974F6558A</td></tr><tr><td>WindowsServer2003-KB2918614-x86-DEU.exe</td><td>B8465AAD87E3C410284F88837041D6649CF86D91</td><td>761AB9BA1C1184DE99CE444948339867D6628ACC9BE6630F30E53ED0D1A2BFC4</td></tr><tr><td>WindowsServer2003-KB2918614-ia64-ENU.exe</td><td>684A3BBD822A3DDBB343533AB15FADE8726682A3</td><td>D778D2BF90FDAE2A8640E8CF3DC5D5D7AD5A16019044EC1ACAA04EE8DB5E999F</td></tr><tr><td>WindowsServer2003-KB2918614-x86-ENU.exe</td><td>0799ED79FA7D78F768864545650671F981E4FFA0</td><td>E41F1C93016601175E7D602ADD02E248F84DBF389A1C084DFB7875E3BF6433FE</td></tr><tr><td>WindowsServer2003-KB2918614-x64-ITA.exe</td><td>5B4326156B6B524C5EF92AA4AC1040606B0A0826</td><td>D51876B92C201E154555A6B7486C62F915FB20BAF3A36006103501434789528C</td></tr><tr><td>WindowsServer2003-KB2918614-x86-NLD.exe</td><td>446B52445891BD1BA42177C5A617821509CB7938</td><td>B89BAB4BFB948CCA1DC709AED32257FC75C34CA4BD8167B44AEE33F9EC55E311</td></tr><tr><td>WindowsServer2003-KB2918614-x86-PLK.exe</td><td>C14072C4D007D3EF0D4FA6CD779B39B78326EE54</td><td>50C8E37C46E7CE92D5CE4EBD6067C5B2D61746B299052DC476C565A56B0F531B</td></tr><tr><td>WindowsServer2003-KB2918614-x86-RUS.exe</td><td>5F8926E012FF11BFAFD679A4DFF396FE75BDE11D</td><td>93456D1A03F6810FB895EEC81512890F42C6758E0C73F9C9D44071BF5DD0CC15</td></tr><tr><td>WindowsServer2003-KB2918614-x64-CHS.exe</td><td>CBB4BF6C307F2300E4F7D1D465BF611861E6132A</td><td>8D37B599E987949502E8204005893728EDAB48DD39243CAC53B4F1A45EA46002</td></tr><tr><td>WindowsServer2003-KB2918614-x86-CHS.exe</td><td>907028FC790894C2044A02B6C0BA7D39B6A490DD</td><td>8F5D7B438F0AF27BDEAC07EC8B59933D335EAD4E2991424913FCDCEE003859F8</td></tr><tr><td>WindowsServer2003-KB2918614-x64-CHT.exe</td><td>BF5E474B7E5B073BC97AD0964AB5E591AD32100B</td><td>17E06AEA01A3A0FD9ADE5979337A023DF34C61811632F0748F925D20C2C04C2A</td></tr><tr><td>WindowsServer2003-KB2918614-x86-CHT.exe</td><td>60DF5FC80DA85B804E50841C2A0F757724A8780C</td><td>DA29AE687A91A2357739F12078DDB883AD96D22DB92AE18F133C2F15B51A61AB</td></tr><tr><td>WindowsServer2003-KB2918614-ia64-DEU.exe</td><td>9E80B86190E786DA262934E9F2A6E68234D95F38</td><td>B6924C9FA958391703B0390E7A18C8F2088AF29F47B473FC5FBECD1C986288FB</td></tr><tr><td>WindowsServer2003-KB2918614-x86-ESN.exe</td><td>F0FEA5B17E53DA746D680311DFC3BDD2A551E93A</td><td>C2BFE9D8E00AF45CA91797005D59D759274482AE3462481FCFB7BEA878FAFA3C</td></tr><tr><td>WindowsServer2003-KB2918614-x86-FRA.exe</td><td>741D1D4347B74541C8ABE57415752ACEF7B53391</td><td>FA0C9FBCB0D89FF4FF9FC23E569B8651A309E9914BE6979E0709E803C053E076</td></tr><tr><td>WindowsServer2003-KB2918614-x86-ITA.exe</td><td>5D2F775A12C7A9C5BDD684B5A23B6D2B107119C7</td><td>492D1DF1E7AF3EB43CD417DE9FDE381A31C067F54A6F7B354C04DF6E0B4A933C</td></tr><tr><td>WindowsServer2003-KB2918614-ia64-JPN.exe</td><td>A7A516D1DC94FF50DFEA1B73E053842E76A124A0</td><td>D15215706DF6F0D7A3F6F8BABA21A836DA7F0528A5C71B9A97D6CA4DE5D1043B</td></tr><tr><td>WindowsServer2003-KB2918614-x64-JPN.exe</td><td>0F84C2E2DADE5470E10F9522B133C8DA2B73354D</td><td>384B84C3C41BD67D01BB4EE51BFB00A7FD873B3C20E723433A17DB0D0560B61C</td></tr><tr><td>WindowsServer2003-KB2918614-x86-KOR.exe</td><td>DD67BAC6F83E1BD8ADB18FBBE0D7BC8366FC9B01</td><td>E9B3C3C9EE5BF556693ADAA881E7FAB463DFD4C251CCD0CB8D9BFA05E8AE50C6</td></tr><tr><td>WindowsServer2003-KB2918614-x64-PTB.exe</td><td>899BB907B9ADA6A65A1A14D828BAC9A088340F54</td><td>C71618B1FDC9D0CB4D97C1CF858C58D3292EA7769D1491450037C48697AE53AB</td></tr><tr><td>WindowsServer2003-KB2918614-x86-PTB.exe</td><td>B833D2DD5DBAE22C70344A7DCE6A8023A366E85C</td><td>41DF7770A3A62741734A948DAD8287C882F2811775EDD3572F5E8ED995D88B01</td></tr><tr><td>WindowsServer2003-KB2918614-x86-TRK.exe</td><td>EE174AA41835C9B66BE10BD28D9B0D5D5CBA9D5A</td><td>DB6AE2E7E3A1E384609D83685772B57E8F5C1BCCD99A7C8F27003E3255AEAA80</td></tr><tr><td>WindowsServer2003-KB2918614-x64-ENU.exe</td><td>1890CE8FA25034CA0B2A9DD1E2CC36D0D7F8AF4B</td><td>EF51524811DE5FD48D013DD148FAAE281E1F6E6231BED22DA79F29656FEEF9BE</td></tr><tr><td>WindowsServer2003-KB2918614-x64-FRA.exe</td><td>D5DE861749CE3C598EDF3DFA2FEC3F0EAEFF9F20</td><td>22946E5D8D5CBD1775372E358A0EBAE5939E51CFE08CC08C93353AE3E640F3FD</td></tr><tr><td>Windows6.0-KB2918614-ia64.msu</td><td>F8B9F7D4356E6E69E166FAA9F37CD7D099780D83</td><td>529658EF3588F5E511ABE81F0B86690364F82E10ED71638944C1C2C538402DEB</td></tr><tr><td>Windows6.0-KB2918614-x86.msu</td><td>43971C9B28196A6FBA4735F0F847304EAB5D5EFD</td><td>8D93D979C805B4FB920D1C897EEC6D53624766D8F5DC9530E70A4D9A5346A3D5</td></tr><tr><td>Windows6.0-KB2918614-x64.msu</td><td>91AEAA10669C905FC2592AC2B4CDBEDE06DC8BD5</td><td>ACCB4A7B5BA9D24F8ECAA445575F02F938761DD9D448B6CDCE45BCDC84173AFD</td></tr><tr><td>Windows6.1-KB2918614-ia64.msu</td><td>E44863BEBA2B394BF82FA9CBA5BC0E58193AC7FB</td><td>CC01535781EA9B9FFBEA92FAF58E10F7FC8A6C72DC8C32B509182FBC549FF693</td></tr><tr><td>Windows6.1-KB2918614-x64.msu</td><td>8A78582D33BCD8E6776096B2685D779CC6363B34</td><td>E2CB5D7B896AEC0D2C85A9EBAA571363A0D66717E5A0E7EDD4348B89B43FBC68</td></tr><tr><td>Windows6.0-KB2918614-x86.msu</td><td>43971C9B28196A6FBA4735F0F847304EAB5D5EFD</td><td>8D93D979C805B4FB920D1C897EEC6D53624766D8F5DC9530E70A4D9A5346A3D5</td></tr><tr><td>Windows6.0-KB2918614-x64.msu</td><td>91AEAA10669C905FC2592AC2B4CDBEDE06DC8BD5</td><td>ACCB4A7B5BA9D24F8ECAA445575F02F938761DD9D448B6CDCE45BCDC84173AFD</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-CHS.exe</td><td>B02211F1AF1E635C38D6EC72A787A257347AAC6A</td><td>C0235CE26848A77C80ACE223DF627781764CA7BB6909D8161D7BF6FA23D4CFA5</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-DEU.exe</td><td>9F837F44ED79F51206D5BEB2345A4F18EEFFBEEC</td><td>823C00F19170566809E1AB539DCD5D26038AD8B13C7C6D267C56BD84BFB38660</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-ESN.exe</td><td>D7DCA35B8925B724C423ED504F047EBE66508D42</td><td>03E9DABCC324B90DBFB73C40734FCF31E26E38575D4F21BE15D11BE6D3B3AD99</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-HEB.exe</td><td>B0E95A7869E4BC266674CC1634EC701FFDED5E05</td><td>391577C5B67C7BFE1E5F3F74F0CBA66FA9709A976811CAAFBB26766EB8B267D2</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-ITA.exe</td><td>CF9E8DC770A55781256313A809964FC527028ACE</td><td>E45DD6F98EDE9BFA71A0541AF3D6FDF864DC19D3E5BDA394696C13AF852EDE8F</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-RUS.exe</td><td>44BE75ECF114999B27D2BC585ED0C85A9A9A0698</td><td>CB4460D3F3F3310F74FC7B0D9763128078B42A10C64BBB6F676A3A9D48F7B646</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-CHT.exe</td><td>3FEE5F7CF5D778D95A41852E7A9B74819FA994FA</td><td>C8AD2E815B83A754F52D33F3EBDB61239B3D69B75170D7D0E45ACEF347D0F974</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-CSY.exe</td><td>BAAFAF6E0CDEEEDFFEF582441DC03145460AB432</td><td>41DBFD4FA836CC858D67ADBECEB5B350E2251F50C1DF2AEED75D5B66880BB509</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-NLD.exe</td><td>5F7C8B235FFB839099FA709433574F67611F5F12</td><td>D3F34781792B9F22AED9812E2B8626EE31B61ABC7AD71EC4ED9710D7CC2DA93A</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-PLK.exe</td><td>35B25615FD105CC86AA9ADA0D8D7EE07C0F3FB3F</td><td>D85C4F89C5D5B14B0DD1F43AE9B4A23916D7D4B509CD16005CD776589A1445FA</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-PTG.exe</td><td>C8206C9682DB583DCBEBA895DEBDD5F5D31585F1</td><td>B8DDB2409EB717874594935B8DDFC68AF8C1051617AF5A336CF87FCA05314289</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-SVE.exe</td><td>192F5020A34CF00B559CA8F567B67FCCCB6F701F</td><td>AF4CD2DF0893B9444299E88AC676D7E13C7A824A6EB42FE5186B67509389E5C2</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-TRK.exe</td><td>8DC7C2C59D1013319F389DA95258B3CC462B22DB</td><td>D6F27A29F5FC7796C6D2967F92F478540C1DD7790D2DA06F473242894B53B9C8</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-DAN.exe</td><td>F0B0C2FA088D6395327958EB2CC0DFDABA621895</td><td>FA6E6BAED17F830B02D46F728659D0BB8924AF50D143D65999F58565C13BFBA3</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-ELL.exe</td><td>7CADA0A2514B0FAF19C0618E90EFD62C8EA332A6</td><td>C8B85FDD46CF5362E9A799BB6F07D79CCA982A40CBB5D39F5930E679F3D77F3A</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-FIN.exe</td><td>1A56D0A6A192A258F9FD6F75ECE8455ABA94DEC1</td><td>A694643E03D42F78EDF24877D8224BBB9286790AF805552A3AC4FC4E7446212D</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-HUN.exe</td><td>9BAF08A1B4509862D9EAADF9370D2399CB64D133</td><td>48722419CAB6948D55497285C43E67FC3CA91DB081B80C499F12214D7D29667A</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-KOR.exe</td><td>9E87514E4F6EDD51EBF8FFE41D5705222AA0CC06</td><td>3EAEEFF9CEFCA9A7AEE3AF930A011DBFAB73BCE533CB6BC995EC4FB48683526C</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-ARA.exe</td><td>161985B559776EFB0136BBA77D9521489943F4A6</td><td>C8A5E23A355ED3B966F517D8AE1EB78578274CF8932B015FD0CC0C5057FAA345</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-ENU.exe</td><td>F4B42FBACF5497D78C17B11D7249E554C56757E2</td><td>2257FE1CDC3731D0630CFE49BEAF0924D56863E27F745FC2B347DDC30C5B55DA</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-FRA.exe</td><td>87729AC5B1EEB72C6CB9AF2CBE6C5DF9F9064BCD</td><td>CE37F8732C484A94686A15E69250CE93CC2E27A0C7C1EF6BD2B0281E484526B1</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-JPN.exe</td><td>F920F82209D4C7080437FA5071627CF9B34DFBC6</td><td>32B9A0383E8CE51D125522509355C80D17AFBE50A870FCD6889815392383487E</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-NOR.exe</td><td>AFF5078036CBAE1A669DE065C655C9B2CC476AAE</td><td>5316E4FADFED4468BBDDFBF1491D7B4A5004E3D2F0DEBFE4AFCA1911DF2FC3EE</td></tr><tr><td>WindowsXP-KB2918614-x86-Embedded-PTB.exe</td><td>8BDA87CBB4595F565DCEFEEAAC01366768898DA5</td><td>EDBADBD7EBA1754C3EC3EF1A2238BD59E8A56FAC6DB053246A6B52C7DD473F97</td></tr></table></div></div><br /></span></div></div></div></div></body></html>