Skip to content
View in the app

A better way to browse. Learn more.

MSFN

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

released: bug fix for win32k.sys/_SetWindowWord and xxxSetClassData (local variable initialization)

Featured Replies

Hello Windows 2000 fans,

a while ago when WildBill was backporting security updates from Windows XP to Windows 2000 he noticed a flaw in Microsoft's implementation of the security fix in the function "_SetWindowWord". By now Microsoft released an update for Windows 2000 to fix the security problem so WildBill's backported version has been superseded. However, the flaw still exists in the newest versions of win32k.sys from Microsoft both in Windows 2000 and in Windows XP.

The flaw causes problems in some applications which try to deal with their graphical user interface. In an extreme case it can cause the bluescreen "WINLOGON_FATAL_ERROR". The flaw has a pretty small security impact.

There is an update available to fix the flaw:

WINDOWS2000-OTSKB000004-V1-X86-INTL.exe

Since the newest version from Microsoft contains the security fix already, this update fixes the flaw only. It's all that was left to do.

There is more information available about this issue and this update in the article in the knowledge database:

OTSKB.chm

The patch updates the file "win32k.sys"

  • from the version "5.00.2196.0004"
  • to the version "5.00.2196.0005".

Special thanks go to

  • @dencorso for reporting the bluescreen "WINLOGON_FATAL_ERROR" (0xC000021A) in Windows XP and narrowing down the problem to the Windows update "Windows XP (32 bits)/KB981957" and
  • @WildBill for further narrowing down the problem to the function "_SetWindowWord" and to the exact machine instruction within the function.

Edited by Start Me Up

  • Start Me Up changed the title to released: bug fix for win32k.sys/_SetWindowWord and xxxSetClassData (local variable initialization)
  • Author

When WildBill investigated the old version of the file "win32k.sys" from Windows XP, he noticed, that the following functions have the problem with the uninitialized variable:

  • "_SetWindowWord",
  • "xxxSetClassData" and
  • "xxxSetWindowLong"

When I investigated the new version (5.00.2195.7640) of the file "win32k.sys" from Windows 2000, I noticed, that the following functions have the problem with the uninitialized variable:

  • "_SetWindowWord" and
  • "xxxSetClassData"

The function "xxxSetWindowLong" seems to have been fixed somewhen by Microsoft. Now that the update "OTS000004" was released, there was only the following function left to fix:

  • "xxxSetClassData"

To fix the remaining function I released another Windows 2000 update:

There is more information available about this issue and this update in the article in the knowledge database:

The patch updates the file "win32k.sys"

  • from the version "5.00.2196.0005"
  • to the version "5.00.2196.0006".

Before installing OTSKB000005 it is necessary to have OTSKB000004 installed because every update is a patch that needs the previous version to work with. No update contains a full version of the file "win32k.sys" but only the patching instructions.

Edited by Start Me Up

  • 4 weeks later...

Would you please provide WinXP patch too? Or is 2019 updated XP with harkaz' USP4 not problematic?

  • Author

Your assumption, that Windows XP is also affected, is correct in principle. There are multiple versions of win32k.sys for "Windows XP", depending on what you mean by "Windows XP" in connection with an unofficial service pack:

  • The newest version of win32k.sys for vanilla Windows XP (32 bits) is, as far as I know, the version "5.1.2600.7334".
  • The newest version of win32k.sys for Windows Embedded for Point of Service (32 bits) is, as far as I know, also the version "5.1.2600.7334".
  • The newest version of win32k.sys for Windows Embedded POSReady 2009 (32 bits) is, as far as I know, the version "5.1.2600.7684".

Which version would you like to be patched?

Edited by Start Me Up

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.