|
Cisco IP Telephony Operating System, SQL Server, Security Updates |
Last updated 17-January-2012
NOTE: Before you install the file on the server, review the file-specific readme document to verify that the file is compatible with your version of software. Readme documents also provide special notes pertaining to each file. Obtain the readme documents and files by clicking the Cryptographic Software download page.
Use the readme document and this document in conjunction with the document, Installing the Operating System on the Cisco IP Telephony Applications Server, which provides procedures and detailed information for installing/upgrading the operating system and applying support patches. To obtain the installation document, click http://www.cisco.com/en/US/products/hw/voiceapp/ps378/prod_installation_guides_list.html.. You can obtain version-specific operating system release notes by clicking the URL.
Purpose of the Document This document provides information for tracking Cisco-supported operating system, SQL Server, and security files that are available for web download.
Contents This document contains the following sections. Click the hyperlink to go directly to the section.
-
Supported Applications and Servers This section provides a list of Cisco IP telephony applications and servers that use this document.
-
Latest Updates This section provides several lists: Recently released individual Critical hotfixes Latest available OS Service Release Individual updates that are provided prior to inclusion in an OS Service Release.
-
Order for Applying Updates This section provides Cisco recommendations for applying updates on supported servers.
-
Latest Updates for the Operating System and SQL Server This section provides a list of the latest operating system, SQL Server, and security updates that are compatible with supported Cisco IP telephony applications.
-
Cisco Notification Tools This section provides information about how to receive email notifications when new updates post to Cisco.com.
-
End of Sale/End Of Support This section provides information for End of Sale and End of Support Cisco products.
-
File Tracking This section provides a list of operating system and BIOS files that Cisco removed from the web and replaced with an updated version. Review this section if you are looking for a specific file that is mentioned in the Cisco IP telephony application documentation.
Supported Applications and Servers
These updates support all versions of the following applications:
-
Cisco Unified CallManager
-
Cisco Conference Connection
-
Cisco Personal Assistant
-
Cisco IP Interactive Voice Response, and Cisco IP Call Center Express
-
Cisco Emergency Responder
-
Cisco Customer Voice Portal
-
Cisco MeetingPlace
Note: This document does not support Cisco Unity or servers where Cisco Unity is installed.
These updates support all Cisco Media Convergence Servers (MCS), and Cisco-approved, customer-provided Compaq/HPQ and IBM servers. For further information see the Hardware Compatibility Matrixes at the following location:
http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_device_support_tables_list.html
Latest Updates Below is a list of the security bulletins that were released by Microsoft on 10-January-2012. Although rated by Microsoft, Cisco may adjust the rating to reflect the impact to the supported applications and servers (see Supported Applications and Servers).
Bulletin |
Article |
Microsoft Rating |
Cisco Rating |
Bulletin title |
File Name |
Disposition |
MS12-001 |
2644615 | Important | Important | Vulnerability in Windows Kernel Could Allow Security Feature Bypass(2644615) | win-OS-Upgrade-K9.2003-1-5a-sr25.exe |
Available Available |
MS12-002 |
2603381 |
Important |
Important |
Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381) |
win-OS-Upgrade-K9.2003-1-5a-sr25.exe |
Available Available |
MS12-003 | 2646524 | Important | Important |
Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524) |
win-OS-Upgrade-K9.2003-1-5a-sr25.exe | Available |
MS12-004 | 2598479 | Critical | Critical |
Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391) |
win-K9-MS11-087-Windows2003-KB2598479.exe win-OS-Upgrade-K9.2003-1-5a-sr25.exe |
Available Available |
MS12-005 | 2584146 | Important | Important | Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146) | win-OS-Upgrade-K9.2003-1-5a-sr25.exe | Available |
MS12-006 | 2585542 | Important | Important | Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) | win-OS-Upgrade-K9.2003-1-5a-sr25.exe | Available |
MS12-006 | 2638806 | Important | Important | Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) | win-OS-Upgrade-K9.2003-1-5a-sr25.exe | Available |
MS12-007 | 2607664 | Important | N/A | Vulnerabilities in AntiXSS Could Allow Information Disclosure(2607664) | N/A | N/A |
Table 1: Microsoft Hotfix Disposition
Below is a list of the latest available OS upgrade. (The 2000.4.6 upgrade requires users to be at a minimum OS level 2000.2.7, 2000.4.1, 2000.4.1b or higher to apply.)
File Name |
Description |
Status |
win-OS-Upgrade-K9.2000-4-6.exe |
OS Upgrade 2000.4.6 |
Available End of SW Maintenance 19-May-2009 |
win-OS-Upgrade-K9.2003-1-5a.exe |
OS Upgrade 2003.1.5a |
Available |
Table 2: Latest Available OS Upgrade
Below is a list of the Service Releases that contain all the relevant Microsoft Security Bulletins through December 2011 based on the Microsoft Security Bulletin Summary published 13-December-2011
File Name |
Description |
Status |
win-OS-Upgrade-K9.2003-1-5a-sr24.exe |
Service Release 24 for MCS platforms using OS 2003.1.5/2003.1.5a |
Available |
Table 3: Latest Service Release
Internet or Email Vulnerabilities: Critical Microsoft security bulletins for Internet Explorer, Outlook Express, Windows Media Player, and DirectX are generally not considered critical for the Cisco IP Telephony applications supported by this OS Upgrade process. Servers are typically only vulnerable for these Microsoft components when used to surf the Internet to an attacker’s web site or used to receive a specially crafted email. Cisco IP Telephony servers should never be used to surf the web or be configured to receive email. Although not recommended for Cisco IP Telephony servers, using the server to go to Cisco.com and download software updates should be safe from this type of vulnerability.
Order for Applying Updates
Cisco recommends that you apply software updates as they become available on the Cisco voice products software and cryptographic websites.
If you apply all software updates at the same time, Cisco recommends that you apply them in the following order:
-
Operating System upgrades
-
SQL Server Service Pack: For more information, refer to the respective readme document.
-
SQL Server Hotfixes: For more information, refer to the respective readme document(s)
-
Cisco IP telephony application upgrade
-
Cisco IP telephony application Service Release
-
Operating System Service Release
Caution: Always apply the updates to the publisher database server first and verify that the publisher database server behaves as expected. After you apply the updates to the publisher database server, you can apply the updates to the subscriber servers. Always perform the installation updates serially. Applying software updates may cause call-processing interruptions. Install these updates during a maintenance window to minimize call-processing interruptions. If you want to do so, you can apply the operating system upgrade/support patch and the SQL Server support patch/hotfixes during a single maintenance window on the publisher database server first and then every subscriber server in the cluster. During another single maintenance window, you can install the application upgrade and support patch on the publisher database server first and then every subscriber server in the cluster.
Latest Updates for the Operating System and SQL Server
To ensure your servers run the most current operating system and SQL Server versions, verify that all of the following files are installed on every supported server in the cluster.
Operating System Updates 2000.2.7 End of SW Maintenance 19-Oct-2005
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2000.2.7, or |
Yes, 3 times |
About 30 min. |
End of SW Maintenance 19-Oct-2005 |
N/A |
N/A |
win-OS-Upgrade-K9.2000-2-7sr8.exe |
Yes |
About 10 min. |
Requires OS 2000.2.7 |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-6.exe |
Yes, 3 times |
About 30 Min. |
Operating System Updates 2000.4.1 End of SW Maintenance 15-Nov-2005
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2000.4.1 |
Yes, 2 times |
About 30 min. |
End of SW Maintenance 15-Nov-2005 |
N/A |
N/A |
win-OS-Upgrade-K9.2000-4-1sr5.exe |
Yes |
About 10 min. |
Requires OS 2000.4.1 |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-6.exe |
Yes, 3 times |
About 30 Min. |
Operating System Updates 2000.4.2 End of SW Maintenance 20-Mar-2007
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-2.exe |
Yes, 3 times |
About 30 min. |
Requires 2000.2.7 or 2000.4.1 End of SW Maintenance 20-Mar-2007 |
N/A |
N/A |
win-OS-Upgrade-K9.2000-4-2sr16.exe |
Yes |
About 10 min. |
Requires OS 2000.4.2 |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-6.exe |
Yes, 2 times |
About 30 Min. |
Operating System Updates 2000.4.3/2000.4.3a End of SW Maintenance 20-Mar-2007
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2000.4.3 |
Yes, 2 times |
About 30 min. |
End of SW Maintenance 20-Mar-2007 |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-3a.exe |
Yes. Up to 3 times. |
About 30 min. |
Requires 2000.2.7, 2000.4.1, or 2000.4.2 |
N/A |
N/A |
win-OS-Upgrade-K9.2000-4-3a-sr9.exe |
Yes |
About 10 min. |
Requires OS 2000.4.3 or 2000.4.3a |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-6.exe |
Yes, 2 times |
About 30 Min. |
Operating System Updates 2000.4.4/2000.4.4a End of SW Maintenance 20-Nov-2007
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2000.4.4 |
Yes, 2 times |
About 30 min. |
End of SW Maintenance 20-Nov-2007 |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-4a.exe |
Yes. Up to 3 times. |
About 30 min. |
Requires 2000.2.7, 2000.4.1 2000.4.2 or 2000.4.3a |
N/A |
N/A |
win-OS-Upgrade-K9.2000-4-4a-sr12.exe |
Yes |
About 10 min. |
Requires OS 2000.4.4 or 2000.4.4a |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-6.exe |
Yes, 2 times |
About 30 Min. |
Operating System Updates 2000.4.5a End of SW Maintenance 17-Mar-2009
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2000.4.5a |
Yes, 2 times |
About 30 min. |
End of SW Maintenance 17-Mar-2009 |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-5a.exe |
Yes. Up to 3 times. |
About 30 min. |
Requires 2000.2.7, 2000.4.1 2000.4.2, 2000.4.3a, 2000.4.4, or 2000.4.4a |
N/A |
N/A |
win-OS-Upgrade-K9.2000-4-5b-sr21.exe |
Yes |
About 10 min. |
Requires OS 2000.4.5a or 2000.4.5b |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-6.exe |
Yes, 2 times |
About 30 Min. |
Operating System Updates 2000.4.6 End of SW Maintenance 19-May-2009
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2000.4.6 |
Yes, 2 times |
About 30 min. |
End of SW Maintenance 19-May-2009 |
N/A |
N/A |
win-OS-upgrade-K9.2000-4-6.exe |
Yes. Up to 3 times. |
About 30 min. |
Requires 2000.2.7, 2000.4.1, 2000.4.2, 2000.4.3a, 2000.4.4, 2000.4.4a, or 2000.4.5a |
N/A |
N/A |
win-OS-Upgrade-K9.2000-4-6-sr9.exe |
Yes |
About 10 min. |
Requires OS 2000.4.6 |
Operating System Updates 2003.1.1 End of SW Maintenance 20-Nov-2007
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2003.1.1 |
Yes, 2 times |
About 30 min. |
End of SW Maintenance 20-Nov-2007 |
N/A |
N/A |
win-OS-Upgrade-K9.2003-1-1-sr10.exe |
Yes |
About 10 min. |
Requires OS 2003.1.1 |
N/A |
N/A |
OS Upgrade 2003.1.5a |
Yes, up to 3 times |
About 30 min. |
See 2003.1.5 table |
Operating System Updates 2003.1.2/2003.1.2a End of SW Maintenance 17-Mar-2009
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2003.1.2a |
Yes, 2 times |
About 30 min. |
|
N/A |
N/A |
win-OS-Upgrade-K9.2003-1-2a |
Yes. Up to 3 times. |
About 30 min. |
Requires OS 2003.1.1 |
N/A |
N/A |
win-OS-Upgrade-K9.2003-1-2a-sr21.exe |
Yes |
About 10 min. |
Requires OS |
N/A |
N/A |
OS Upgrade 2003.1.5a |
Yes, up to 3 times |
About 30 min. |
See 2003.1.5 table |
Operating System Updates 2003.1.3a/2003.1.3b End of SW Maintenance 19-May-2009
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2003.1.3a |
Yes, 2 times |
About 30 min. |
|
N/A |
N/A |
win-OS-Upgrade-K9.2003-1-3b |
Yes. Up to 3 times. |
About 30 min. |
Requires OS 2003.1.1 or 2003.1.2a |
N/A |
N/A |
win-OS-Upgrade-K9.2003-1-3b-sr9.exe |
Yes |
About 10 min. |
Requires OS |
N/A |
N/A |
OS Upgrade 2003.1.5a |
Yes, up to 2 times |
About 30 min. |
See 2003.1.5 table |
Operating System Updates 2003.1.4/2003.1.4a End of SW Maintenance 13-April-2010
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2003.1.4/2003.1.4a |
Yes, 2 times |
About 30 min. |
|
N/A |
N/A |
win-OS-Upgrade-K9.2003-1-4 |
Yes. Up to 3 times. |
About 30 min. |
Requires OS 2003.1.1, 2003.1.2a, 2003.1.3a or 2003.1.3b |
N/A |
N/A |
win-OS-Upgrade-K9.2003-1-4a-sr16.exe |
Yes |
About 10 min. |
Requires OS 2003.1.4 or 2003.1.4a |
N/A |
N/A |
OS Upgrade 2003.1.5a |
Yes. Up to 2 times. |
About 30 min. |
See 2003.1.5 table |
Operating System Updates 2003.1.5/2003.1.5a End of SW Maintenance 16-Jan-2012
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
OS version 2003.1.5/2003.1.5a |
Yes, 2 times |
About 30 min. |
(2003.1.5a fresh installation is for HP based MCS servers, see defect CSCtd90916) |
N/A |
N/A |
win-OS-Upgrade-K9.2003-1-5a
|
Yes. Up to 3 times. |
About 30 min. |
Requires OS 2003.1.1, 2003.1.2a, 2003.1.3a or 2003.1.3b, 2003.1.4, 2003.1.4a, 2003.1.5 (OS Upgrade 2003.1.5a replaces 2003.1.5, see defect CSCtd09016) |
N/A |
N/A |
win-OS-Upgrade-K9.2003-1-5a-sr24.exe |
Yes |
About 15 min. |
Requires OS 2003.1.5 or 2003.1.5a |
SQL Server 2000 Updates (for Cisco CallManager 4.x)
Bulletin |
Knowledge Base Article |
Description |
Reboot Required? |
Install Time |
Notes |
N/A |
N/A |
SQL 2000 Service Pack 4 |
Yes |
About 20 min. |
It can only be installed on Cisco CallManager 3.3(5), 4.0(2a), and 4.1(x). See SQL2K SP4 readme file for more details. |
MS09-004 |
959420 960083 |
Cumulative SQL 2000 Hotfixes included in OS Upgrades win-OS-Upgrade-K9.2000-4-5b-sr20.exe (or higher) |
Yes |
About 15 min. |
OS Upgrade listed needs applied after CallManager/Communications Manager in order to resolve the listed Security Hotfix(es) |
Cisco Notification Tools Cisco Unified Communications Manager Notification Tool: Cisco has replaced the current Cisco CallManager notification tool with a new, more robust notification tool that is based on your Cisco.com profiles. This new tool delivers email notifications for individual Cisco voice products that you select. Follow the steps below to sign up for the Cisco Voice Technology Group Subscription Tool:
-
Login with your Cisco.com account (at the top of this page) and then go to this link: http://www.cisco.com/pcgi-bin/Software/Newsbuilder/Builder/VOICE.cgi
-
Scroll down under the “IP Telephony†heading to select your CallManager/Communications Manager version to receive notifications when new operating system updates are posted. (for other Cisco applications running on MCS Platform subscribe to CallManager 4.2 for 2000.4.x OS updates and Communications Manager 4.3 for 2003.1.x OS updates)
-
Select any other products updates that you wish to receive.
-
Click update at the bottom of the page.
-
Confirm your selections.
You may see this message at the bottom of the page: "Your Profile Currently Indicates that you do not wish to receive email from Cisco. "
To be able to receive information updates, you must update your email preferences. Click on the link to update your email preferences (located in the Other Information section). Click submit when you are done.
If you have enabled email notification, you may exit now. If you have not enabled email notification, then you will need to repeat the steps above.
This new software notification tool requires a valid Cisco.com login. If you do not currently have a Cisco.com password, please register with Cisco.com at: http://tools.cisco.com/RPF/register/register.do
For information on older Cisco CallManager/Communications Manager releases not listed, see the End-of-Sale and End-of-Life Products page:
http://www.cisco.com/en/US/products/sw/voicesw/ps556/prod_eol_notices_list.html
Cisco PSIRT Advisory Notification Tool: This email service provides automatic notification of all Cisco Security Advisories that are released by the Cisco Product Security Incident Response Team (PSIRT). Security Advisories, which describe security issues that directly impact Cisco products, provide a set of required actions to repair these products. To subscribe, click the following URL and perform the tasks as directed on the web page: http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html - SecurityInfo
File Tracking
The Original File column in the File Tracking table lists files that Cisco has removed from Cisco.com. Cisco has replaced the outdated file in the Original File column with the file that displays in the New File column. Download the file from the New File column.
Note: Files marked with a “*†are deemed critical updates by Cisco. Those files or their replacements should be installed at the earliest opportunity to avoid any unscheduled service outages. While it is always recommended to update to a current release, releases marked critical are viewed as required updates for customer stability. For more information about symptoms and side effects, please go to http://support.microsoft.com/ and search for the affected “MS†security article referenced in the filename of the Cisco packaged hotfix listed below. (ie: “MS10-020†is the MS security article for Cisco package win-K9-MS10-020-Windows2003-KB980032.exe)
Original File |
New File |
7835-BIOS-08-24-00.exe |
win-OS-Upgrade-K9.2000-4-6.exe |
Compaq-NIC-5.29.exe |
win-OS-Upgrade-K9.2000-4-6.exe |
IBMRAID480.exe |
Not required for OS Version 2000.2.3 or later |
IBM-ServeRAID-6.10.exe |
win-OS-Upgrade-K9.2000-4-6.exe |
IBM-Director4.12.exe |
win-OS-Upgrade-K9.2000-4-6.exe |
win-OS-Upgrade-K9.2000-2-4.exe |
win-OS-Upgrade-K9.2000-4-6.exe |
Operating System Updates - 2003.1.x |
|
win-OS-Upgrade-K9.2003-1-2a.exe |
win-OS-Upgrade-K9.2003-1-5a.exe |
win-IIS-SecurityUpdate-2.exe win-OS-Upgrade-K9.2000-4-1sr1.exe win-OS-Upgrade-K9.2000-4-3a-sr1.exe win-OS-Upgrade-K9.2000-4-4-sr1.exe win-OS-Upgrade-K9.2000-4-5a-sr1.exe |
win-OS-Upgrade-K9.2000-4-6.exe |
Operating System Updates - 2000.4.6 - End of SW Maintenance 19-May-2009 |
|
win-K9-MS08-052-Windows2000.exe |
win-OS-Upgrade-K9.2000-4-6-sr9.exe |
Operating System Updates - 2003.1.1 - End of SW Maintenance 20-Nov-2007 |
|
win-OS-Upgrade-K9.2003-1-1-sr1.exe |
win-OS-Upgrade-K9.2003-1-5a.exe |
Operating System Updates - 2003.1.2a - End of SW Maintenance 17-Mar-2009 |
|
win-K9-MS07-033-Windows2003.exe |
|
Operating System Updates - 2003.1.3a / 2003.1.3b - End of SW Maintenance 19-May-2009 |
|
win-K9-MS08-052-Windows2003.exe |
|
Operating System Updates - 2003.1.4 / 2003.1.4a - End of SW Maintenance 13-April-2010 |
|
win-K9-MS08-058-Windows2003.exe |
win-OS-Upgrade-K9.2003-1-5a.exe |
Operating System Updates - 2003.1.5/2003.1.5a - End of SW Maintenance 16-Jan-2012 |
|
win-K9-MS09-028-Windows2003.exe win-OS-Upgrade-K9.2003-1-5a-sr12.exe
win-K9-MS10-090-Windows2003-KB2416400.exe win-OS-Upgrade-K9.2003-1-5a-sr13.exe win-OS-Upgrade-K9.2003-1-5a-sr14.exe win-K9-MS11-006-Windows2003-KB2483185.exe win-OS-Upgrade-K9.2003-1-5a-sr15.exe win-k9-MS11-019-Windows2003-KB2511455.exe win-k9-MS11-020-Windows2003-KB2508429.exe * win-k9-MS11-029-Windows2003-KB2412687.exe win-k9-MS11-031-Windows2003-KB2510587.exe win-OS-Upgrade-K9.2003-1-5a-sr16.exe * win-k9-MS11-035-Windows2003-KB2524426.exe win-OS-Upgrade-K9.2003-1-5a-sr17.exe win-k9-MS11-038-Windows2003-KB2476490.exe win-k9-MS11-042-Windows2003-KB2535512.exe win-k9-MS11-043-Windows2003-KB2536276.exe win-OS-Upgrade-K9.2003-1-5a-sr18.exe win-OS-Upgrade-K9.2003-1-5a-sr19.exe win-K9-MS11-043-Windows2003-KB2536276-v2.exe win-K9-MS11-043-Windows2003-KB2536276-v2.exe win-OS-Upgrade-K9.2003-1-5a-sr20.exe win-OS-Upgrade-K9.2003-1-5a-sr21.exe win-OS-Upgrade-K9.2003-1-5a-sr22.exe win-K9-MS11-078-Windows20003-KB2572069.exe win-OS-Upgrade-K9.2003-1-5a-sr23.exe win-K9-MS11-087-Windows2003-KB2639417.exe win-K9-MS11-090-Windows2003-KB2618451.exe win-K9-MS12-004-Windows2003-KB2598479.exe win-OS-Upgrade-K9.2003-1-5a-sr24.exe |
win-OS-Upgrade-K9.2003-1-5a-sr25.exe |
SQL2K-MS02-061.exe |
SQL2K-ServicePack4.1-0-3.exe See SQL 2000 Updates Table above for further SQL hotfix/security updates |