You may notice an update for your Home Server if it has not been automatically downloaded and installed by Microsoft update. It regards a Windows Kernel TCP/IP vulnerability, which could allow remote code to be executed on supported editions of Windows Small Business Server 2003 and Windows Home Server.
More details are available in Microsoft Security Bulletin MS08-001.
The severity Rating is Critical so if its not installed – install it!




















January 27, 2008 at 3:27 am
Microsoft’s WHS is what cryptologists disparagingly call ‘Security through obscurity’ (look it up).
http://www.support.microsoft.com/kb/946676 still has no resolution regarding WHS data corruption. Is it any wonder why, everyone at Microsoft is quiting?
Open source code is far better… Because,
“With closed source code, only relatively few ‘privileged’ individuals can review the code for problems or actually work on fixing them. Being closed source has not prevented the daily exploitation of security holes that never get fixed in Microsoft products so far, while the Linux holes come a few times a year and get fixed.”
How much longer must everyone wait, hope and wish Microsoft will fix the WHS data corruption serious problem?
January 27, 2008 at 12:39 pm
Should updates like this be installed by using the Remote Desktop into the Windows Home Server?
Should I also be using Windows Update when logged into the server?
Thanks!
January 27, 2008 at 11:40 pm
[...] Churchill hat uns auf MSWHS.COM heute freundlicherweise auf das Update MS08-001 hingewiesen welches den Windows Server 2003 Small [...]
January 30, 2008 at 12:44 pm
[...] KB941644 Installed? January 30, 2008 — Philip Churchill We bought to your attention the other day that the vulnerabilities detailed in the MS08-001 security bulletin also affect Windows Home [...]
January 30, 2008 at 1:01 pm
Is this patch to be applied manually (i.e. download from Microsoft, move to HS and then run on there) or will it come down on regular Microsoft updates?
I tried issuing the download updates from the settings on my HP 475, but it only seemed to download a .Net update and no security patch?
If it’s such a vulnerability, why don’t they do it through regular patch push?
Anybody know?
January 30, 2008 at 11:31 pm
One hand doesn’t know what the other hand is doing…
February 4, 2008 at 11:16 am
Hi Jim Hazlett,
There is no need to Remote Desktop into the Windows Home Server to install this update. Just make sure that within the Console, Settings, General tab that you have “Install Updates Automatically” turned on, if not either do so or click on “Update Now”.
February 4, 2008 at 11:18 am
Hi Steve,
As long as “Install Updates Automatically” is turned on within the console software, then there is no need to install this patch as it would have been done automatically via Windows Update/Microsoft Update.