Secunia PSI false positive warning - MSXML Core Services 4.x

User avatar
HansV
Administrator
Posts: 78237
Joined: 16 Jan 2010, 00:14
Status: Microsoft MVP
Location: Wageningen, The Netherlands

Secunia PSI false positive warning - MSXML Core Services 4.x

Post by HansV »

Recently, Secunia PSI (both version 2 and version 3) has been issuing a warning for some users that Microsoft XML Core Services (MSXML) 4.x is insecure ("End of Life"). If you have the latest version 4.30.2117.0, the warning is incorrect - this version is up-to-date and not a security risk. You can check the version you have by right-clicking the icon in Secunia PSI and selecting Show Details from the context menu. You can also look it up in the Programs and Features control panel - look for the highest 4.x version number (the control panel lists a history of installed versions, not just the current one).

See update MSXML 4? on the Secunia forums for a long discussion on this subject. The conclusion that the warning is a false positive is drawn about halfway down the thread.
Best wishes,
Hans

User avatar
StuartR
Administrator
Posts: 12577
Joined: 16 Jan 2010, 15:49
Location: London, Europe

Re: Secunia PSI false positive warning - MSXML Core Services

Post by StuartR »

Thank you for sharing that. I wasted a lot of time this morning finding and reading that thread. I should have thought to share the findings here.
StuartR


User avatar
aekyall
4StarLounger
Posts: 536
Joined: 05 Feb 2010, 23:23
Location: Whitehaven Cumbria UK

Re: Secunia PSI false positive warning - MSXML Core Services

Post by aekyall »

According to my Secunia PSI scan the most up-to-date version of MSXML is 6x, and offers to update for me. Should I be tempted?
Capture.GIF
You do not have the required permissions to view the files attached to this post.
Regards,
Keith

User avatar
StuartR
Administrator
Posts: 12577
Joined: 16 Jan 2010, 15:49
Location: London, Europe

Re: Secunia PSI false positive warning - MSXML Core Services

Post by StuartR »

aekyall wrote:According to my Secunia PSI scan the most up-to-date version of MSXML is 6x, and offers to update for me. Should I be tempted?
Don't be tempted. It won't help.
StuartR


User avatar
HansV
Administrator
Posts: 78237
Joined: 16 Jan 2010, 00:14
Status: Microsoft MVP
Location: Wageningen, The Netherlands

Re: Secunia PSI false positive warning - MSXML Core Services

Post by HansV »

No, don't do that - it's useless. MSXML 6.x is installed with recent versions of Windows (Vista, 7 and 8), and kept up-to-date through Windows Update.
If you show all programs in Secunia PSI, you'll probably see MSXML 6.x listed.
Trying to install MSXML 6.x through the link provided by Secunia PSI won't install anything new and it won't remove MSXML 4.x - the versions can coexist.
Best wishes,
Hans

User avatar
aekyall
4StarLounger
Posts: 536
Joined: 05 Feb 2010, 23:23
Location: Whitehaven Cumbria UK

Re: Secunia PSI false positive warning - MSXML Core Services

Post by aekyall »

Thanks. Will just ignore
Regards,
Keith