Forum Thread: SQL server update+XML Core services 4.x

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
PSI

This thread has been marked as resolved.
macko1944 SQL server update+XML Core services 4.x
Member 30th Mar, 2017 19:15
Ranking: -2
Posts: 26
User Since: 20th Jul, 2009
System Score: N/A
Location: CA
On my Win 7/32 bit I had to switch from Secunia PSI 2.0 to the 3.0 version.It wants me to update manually SQL Server as well as SML Core Services 4.x.
Unfortunately I am too much of a beginner and have NO IDEA what those items stand for or what they do(googling did not help much).So I would like to ask help from the savvy Forum viewers as to what can I do and if possible,HOW TO.
Thanks so much!

Post "RE: SQL server update+XML Core services 4.x" has been selected as an answer.
Maurice Joyce RE: SQL server update+XML Core services 4.x
Handling Contributor 31st Mar, 2017 08:28
Score: 12325
Posts: 9,575
User Since: 4th Jan 2009
System Score: N/A
Location: UK
MSXML 4 is obsolete and has been for years. Is PSI telling you it is EOL and to upgrade to MSXML 6? What is the version number of MSXML 4 currently installed?

What version of SQL Server is PSI telling you to update or is it also telling you to upgrade to another version?



--
Maurice

Microsoft Surface 4 Intel i7 64Bit
Windows 10 Pro version 1809 Build 17763.379
16 GB RAM
IE & Edge Only
Was this reply relevant?
+1
-0
macko1944 RE: SQL server update+XML Core services 4.x
Member 31st Mar, 2017 18:56
Score: -2
Posts: 26
User Since: 20th Jul 2009
System Score: N/A
Location: CA
Thank you very much for your kindness(of reply)!
I am not computer savvy,all I can see is I have SQL Server 2005 edition and XML Core Services 4.x and THESE ARE THE ONES SECUNIA WANTS ME TO MANUALLY UPDATE.And I get this warning every time I open the computer,while Secunia register in RED color.
My computer is an ASUS netbook (12N version),and it has Win 7 Home Premium Edition 32 bit.
I hope this is enough info to answer your question.Unfortunately,I have no idea what the above things do,and what to do(though Secunia does show the links),but I am afraid to go into unnkown things,I have already LOST A COMPUTER for being "brave"in such situation.(It had Vista,but still worked fine,so I shouldn't have tried to fix what "ain't brooke".
Regards,
John
Was this reply relevant?
+0
-0
macko1944 RE: SQL server update+XML Core services 4.x
Member 31st Mar, 2017 18:56
Score: -2
Posts: 26
User Since: 20th Jul 2009
System Score: N/A
Location: CA
sorry,it is broke,not brook!
Was this reply relevant?
+0
-0
Maurice Joyce RE: SQL server update+XML Core services 4.x
Handling Contributor 1st Apr, 2017 17:17
Score: 12325
Posts: 9,575
User Since: 4th Jan 2009
System Score: N/A
Location: UK
John,
Thank you. There is still not enough information to try and help.

At best MSXML 4 is EOL and has been for years. It really should be uninstalled but if you do that it will break the very very old programme it supports. At worse you have got a very old version installed that is vulnerable which can be updated from vulnerable to EOL status.

Please open PSI>click on show programs>look for MSXML 4 - Does it state End of Life(EOL) under the Status Column? Now look at the Installed Version Column - what is the version number?

Can you please supply the same detail for SQL Server 2005

--
Maurice

Microsoft Surface 4 Intel i7 64Bit
Windows 10 Pro version 1809 Build 17763.379
16 GB RAM
IE & Edge Only
Was this reply relevant?
+2
-0
macko1944 RE: SQL server update+XML Core services 4.x
Member 1st Apr, 2017 19:30
Score: -2
Posts: 26
User Since: 20th Jul 2009
System Score: N/A
Location: CA
Hi and THANK YOU!
Unfortunately I may not be much help-showing more ignorance of the issues.In my Update necessary column,I have 3 items,Google Picasa(in spite of I marked IGNORE,and the two others only state
MS SQL Server MSXML Core
2005 Compact Edition and Services (MSXML)4.x
And I couldn't see any other data to come up with.They both have arrows pointing to the right,but I did not click on that.And Update is underlined.And I get daily warning from Secunia which is in red,saying that there are items that need MANUAL updating.All other items are marked up to date.
Sorry,this is all I can see.
And thank you again!!!!!!!!!!!!!!!!
Was this reply relevant?
+0
-0
Maurice Joyce RE: SQL server update+XML Core services 4.x
Handling Contributor 2nd Apr, 2017 17:37
Score: 12325
Posts: 9,575
User Since: 4th Jan 2009
System Score: N/A
Location: UK
John,
Let us see if this helps you better.Open PSI from the Task Tray icon. Once it opens click on SETTINGS at the bottom of the page. Put a tick (check mark)in the box to the left of DETAILED VIEW.

Now click on SHOW PROGRAMS below the green dot. You will see a list of all the programmes you have registered with PSI. I want the details for SQL 2005 and MSXML 4. I have highlighted the information I need on the example here:


https://2xefeg-ch3302.files.1drv.com/y4pWYcBenaVb4...

If necessary click on the image to make it larger.

Hope this helps.

--
Maurice

Microsoft Surface 4 Intel i7 64Bit
Windows 10 Pro version 1809 Build 17763.379
16 GB RAM
IE & Edge Only
Was this reply relevant?
+1
-0
macko1944 RE: SQL server update+XML Core services 4.x
Member 2nd Apr, 2017 18:49
Score: -2
Posts: 26
User Since: 20th Jul 2009
System Score: N/A
Location: CA
Hi Maurice,
Following your instructions resulted in this data:
The SQL Server 2005 Compact Edition
# 2 Installed version: 3.0.5300.0 Secure version: 2800 End of life

The MS XML Core Services(MSXML)4.x :
# 1 Installed version: 4.30.2117.0 Secure version: 6x End of life

Does this help? I sure hope so and many thanks for your kind caring!!!(What would one do without you guys??!!)
Regards,
John
Was this reply relevant?
+0
-0
Maurice Joyce RE: SQL server update+XML Core services 4.x
Handling Contributor 2nd Apr, 2017 21:51
Score: 12325
Posts: 9,575
User Since: 4th Jan 2009
System Score: N/A
Location: UK
Last edited on 2nd Apr, 2017 22:02
John,
Thank you. I am confident that your SQL server 2005 and MSXML 4 were both secure and up to date when Microsoft declared them both End of Life (EOL).

The EOL declaration, some years ago, means that since that date they have not been tracked for vulnerabilities nor will it happen in the future. There current security status is unknown.

The advice given by PSI on MSXML 4 to update to MSXML 6 is very misleading as you already have it installed so there is no action to take to update.

It is decision time on the action to take for the EOL entries. You can either:

1. Uninstall them both - this of course will cripple any programmes dependant on them to work. From a security point of view this is the recommended option.
2. Rename the vulnerable files. This will make your PC safer but will once again cripple any programme reliant on them. It will identify the dependent programme(s)by giving an error message when you try to use it/them so you can make a better judgement on what to do.
3. Take a risk by doing nothing but let PSI continue to show that you are running EOL programmes.
4. Take a risk and create an ignore rule which hides the problem.

If more help is required once you have made a decision please post back. Sorry about the edits.

--
Maurice

Microsoft Surface 4 Intel i7 64Bit
Windows 10 Pro version 1809 Build 17763.379
16 GB RAM
IE & Edge Only
Was this reply relevant?
+2
-0

This thread has been marked as locked.