News

Microsoft Reissues Windows 2000 Server Security Fix

Microsoft today released an updated critical fix for Windows Media Services on Windows 2000 Server.

The revamped bulletin, MS10-025, addresses a "privately disclosed" bug that could enable remote code execution attacks. The bulletin was reissued less than a week after Microsoft pulled the initial fix from its April monthly security patch rollout.

Microsoft explained at that time that the fix did not "address the underlying issue effectively." The company added that it was not aware of active attacks seeking to exploit the vulnerability.

Some security experts believe that Microsoft recently received private, third-party reports that the patch didn't correctly address the vulnerability and therefore pulled it for a reconfiguration last week.

"For the most part, Microsoft's actions are likely to end up being viewed positively, but, at the same time, we can't help but wonder if they would take the same actions if the affected system were something more critical," said Andrew Storms, director of security at nCircle. "What if the patch involved IE or IIS or a newer OS like Windows7? In that case, it seems likely that Microsoft wouldn't have been so forthcoming, and they probably would have pushed the patch out faster in order to protect customers."

For its part, Microsoft says that the new update remedies the remote code execution exploit, which takes advantage of stack overflow in Windows Media Services. Windows Media Services is an option in Windows Server 2000 that supports streaming media applications.

Microsoft's security bulletin released today states that those who installed the earlier fix do not need to remove it before applying this update. In addition, the earlier fix will be updated by those who have turned on the automatic update feature in Windows. If automatic update is not enabled, the fix needs to be installed manually.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

Featured

  • Microsoft Offers Support Extensions for Exchange 2016 and 2019

    Microsoft has introduced a paid Extended Security Update (ESU) program for on-premises Exchange Server 2016 and 2019, offering a crucial safety cushion as both versions near their Oct. 14, 2025 end-of-support date.

  • An image of planes flying around a globe

    2025 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss.

  • Notebook

    Microsoft Centers AI, Security and Partner Dogfooding at MCAPS

    Microsoft's second annual MCAPS for Partners event took place Tuesday, delivering a volley of updates and directives for its partners for fiscal 2026.

  • Microsoft Layoffs: AI Is the Obvious Elephant in the Room

    As Microsoft doubles down on an $80 billion bet on AI this fiscal year, its workforce reductions are drawing scrutiny over whether AI's ascent is quietly reshaping its human capital strategy, even as official messaging avoids drawing a direct line.