Problem Solving:Windows NT/2000
Important NT
Security Patches
Hotfixes appear in between service packs. We explain the simplest way to install large numbers
of fixes, and discuss which fixes exist to help you plug the more important security loopholes.
By Simon Pride
I
n Windows NT Service Pack 4
not to risk, at best, accidentally down
4
Copy or move each hotfix .EXE file
[PCNA 102, File: E1708] we listed
grading a system's hotfix level or, at
into its respective folder.
several elements of Service Pack 4
worst, making the system unstable.
5
Open a command prompt in each
that addressed security issues in NT.
The hotfix application tool HOT
folder in turn and issue the com
This article updates that list, surveying
FIX.EXE is of some help in listing the
mand hotfixfile /X, where hotfix
security issues that have arisen or been
hotfixes already installed on a system,
file is the name of the .EXE archive
discovered since then and detailing
but unfortunately only reports in
you downloaded in step 1 (these are
how to fix them. Many of these patches
stalled hotfixes by the Microsoft
often named after the Q article de
came out first as hotfixes, and were
Knowledge Base Q article number that
scribing them, eg, Q242294.EXE).
subsequently incorporated into the
describes the problem.
This will expand the archive into a
next service pack.
The same information is available
set of installation files and the HOT
Microsoft and other operating sys
by inspection of the registry key
FIX.EXE program.
tem vendors react quickly to new secu
HKLM\SOFTWARE\Microsoft\
rity
threats
to
their
products.
Windows NT\CurrentVersion\Hot
In the root of the hotfixes folder
Microsoft, in particular, responds in
fix, where again the fixes are listed as
create a .BAT or .CMD file which re
two ways:
a series of subkeys named for the Q
sembles Figure 1.
article number.
The z argument means do not re
G
Service Packs are a regular series of
The hotfixes detailed below are all
boot when update completes and is
software releases which address
fully documented in Knowledge Base
vital in order for the batch process to
bugs in the operating system and
articles. To obtain a KB article, go to
continue after each update. The m op
close security loopholes or vulner
support.microsoft.com/support/kb
tion means run in unattended mode
abilities.
/articles/qxxx/x/xx.asp
, where xxxxxx
and requires no action by the user.
G
Hotfixes are patches which address
is the six digit KB article number.
Run the file to apply the hotfixes.
a single bug or security issue and
Remember to construct the batch file
are released as interim fixes until
Batch Processing
so that the fixes are applied in the cor
the same protection can be supplied
rect order.
via the next service pack.
Once you have identified which
Once the last hotfix has completed
hotfixes to apply, there is another ob
you should reboot the computer. As
Managing Hotfixes
stacle to easy management. The hotfix
with service packs, if you add or alter
installation procedure will normally
any system component such that Win
Managing hotfixes can be a difficult
cause a reboot after each hotfix, which
dows NT prompts you for the original
task. The situation following the re
makes upgrading a machine very
distribution CD, you will need to reap
lease of Service Pack 3 was a particu
time consuming. You can apply a se
ply both the current service pack and
larly trying one for the systems
ries of hotfixes in a batch process from
any of its subsequent hotfixes again.
administrator.
a server share or removable drive by
Firstly, there were over 40 different
the following procedure:
Hotfixes For Security
hotfixes released between Service
Packs 3 and 4 and, secondly, many of
1
Download the .EXE files for all the
Let us now look at important secu
the hotfixes were implemented as
hotfixes you wish to apply.
rity related hotfixes in order, starting
changes to the same system component
2
Create a new folder called hot
with those that came after Service Pack
such as TCPIP.SYS, the TCP/IP proto
fixes .
4. Most of these are fixed in Service
col driver. This meant that the order in
3
Within the new hotfixes folder, cre
Pack 6, so if you don't want to install
which hotfixes were installed was ab
ate one new folder for each hotfix to
them separately you can simply up
solutely crucial if the administrator was
be applied.
grade your machines to SP6.
Issue 118 (May 2000) page 3
File: P1718.1
PC Network Advisor
Next page >
New! The best sites for quality inkjet printer cartridges and the best sites for cheap inkjet cartridges