Microsoft Reissues Windows 2000 Server Security Fix

Microsoft this week released an updated critical fix for Windows Media Services on Windows 2000 Server.

The revamped bulletin, MS10-025, addresses a "privately disclosed" bug that could enable remote code execution attacks. The bulletin was reissued less than a week after Microsoft pulled the initial fix from its April monthly security patch rollout.

Microsoft explained at that time that the original fix did not "address the underlying issue effectively." The company added that it was not aware of active attacks seeking to exploit the vulnerability.

Some security experts said they believe that Microsoft recently received private, third-party reports that the patch didn't correctly address the vulnerability and therefore pulled it for a reconfiguration last week.

"For the most part, Microsoft's actions are likely to end up being viewed positively, but, at the same time, we can't help but wonder if they would take the same actions if the affected system were something more critical," said Andrew Storms, director of security at nCircle. "What if the patch involved IE or IIS or a newer OS like Windows7? In that case, it seems likely that Microsoft wouldn't have been so forthcoming, and they probably would have pushed the patch out faster in order to protect customers."

For its part, Microsoft said that the new update remedies the remote code execution exploit, which takes advantage of stack overflow in Windows Media Services. Windows Media Services is an option in Windows Server 2000 that supports streaming media applications.

Microsoft's security bulletin released Tuesday stated that those who installed the earlier fix do not need to remove it before applying this update. In addition, the earlier fix will be updated by those who have turned on the automatic update feature in Windows. If automatic update is not enabled, the fix needs to be installed manually.

About the Author

Jabulani Leffall is a business consultant and an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others. He consulted for Deloitte & Touche LLP and was a business and world affairs commentator on ABC and CNN.

Featured

  • illustration of a human head with a glowing neural network in the brain, connected to tech icons on a cool blue-gray background

    Meta Introduces Stand-Alone AI App

    Meta Platforms has launched a stand-alone artificial intelligence app built on its proprietary Llama 4 model, intensifying the competitive race in generative AI alongside OpenAI, Google, Anthropic, and xAI.

  • laptop screen with a video play icon, surrounded by parts of notebooks, pens, and a water bottle on a student desk

    Studyfetch AI Tool Generates Video Explanations Based on Course Materials

    AI-powered studying and learning platform Studyfetch has introduced Imagine Explainers, a new video creator that utilizes artificial intelligence to generate 10- to 60-minute explainer videos for any topic.

  • interconnected geometric human figures forming a network

    CoSN: School Staffing Is the Top Hurdle to K-12 Innovation

    Hiring and keeping educators and IT staff remains the top challenge for K-12 education in 2025, according to the latest Driving K-12 Innovation Report from the Consortium for School Networking (CoSN).

  • glowing digital brain made of blue circuitry hovers above multiple stylized clouds of interconnected network nodes against a dark, futuristic background

    Report: 85% of Organizations Are Leveraging AI

    Eighty-five percent of organizations today are utilizing some form of AI, according to the latest State of AI in the Cloud 2025 report from Wiz. While AI's role in innovation and disruption continues to expand, security vulnerabilities and governance challenges remain pressing concerns.