<?xml version="1.0" encoding="UTF-8"?>
<oval xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns:windows="http://oval.mitre.org/XMLSchema/oval#windows" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval oval-schema.xsd http://oval.mitre.org/XMLSchema/oval#windows windows-schema.xsd">
	<generator>
		<schema_version>4</schema_version>
		<timestamp>20050803235300</timestamp>
	</generator>
	<definitions>
		<definition id="OVAL3" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-06-06">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-06-08">DRAFT</status_change>
				<status_change date="2005-06-29">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>'The Exchange 2003 Exadmin virtual directory uses only Integrated Windows Authentication.'</description>
			<reference source="MISC">2.1.6</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<oval:notes>
				<oval:note>Corresponds to item 2.1.6 in the Exchange 2003 Benchmark</oval:note>
			</oval:notes>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1" comment="The exadmin HTTP virtual directory only allows Integrated Windows Authentication" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL12" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
			<reference source="CVE">CVE-2002-0026</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL16" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
			<reference source="CVE">CVE-2002-0079</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL17" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
			<reference source="CVE">CVE-2002-0023</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL18" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2004-09-15">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<modified date="2004-09-16" comment="Completing an initial submission.">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-13">INTERIM</status_change>
				<modified date="2004-10-19" comment="done">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</modified>
				<status_change date="2004-10-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.</description>
			<reference source="CVE">CVE-2002-0070</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-490" comment="the version of shell32.dll is less than 4.0.1381.7116" />
					<criterion test_ref="wrt-288" negate="true" comment="Patch Q313829 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL19" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the &quot;Cross-Site Scripting in Local HTML Resource&quot; vulnerability.</description>
			<reference source="CVE">CAN-2002-0189</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL20" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Distributed Component Object Model (DCOM) interface</product>
			</affected>
			<dates>
				<submitted date="2004-11-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0528.</description>
			<reference source="CVE">CAN-2003-0715</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-568" comment="the version of rpcss.dll is less than 5.0.2195.6810" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL22" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka &quot;Microsoft-discovered variant of Chunked Encoding buffer overrun.&quot;</description>
			<reference source="CVE">CVE-2002-0147</reference>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL23" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
			<reference source="CVE">CVE-2002-0026</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL24" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>FTP</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
			<reference source="CVE">CVE-2002-0073</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-202" comment="FTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL25" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
			<reference source="CVE">CVE-2002-0079</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL26" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Network Connection Manager (NCM)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.</description>
			<reference source="CVE">CVE-2002-0720</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
					<criterion test_ref="wft-207" comment="the version of netman.dll is less than 5.0.2195.5974" />
					<criterion test_ref="wrt-229" negate="true" comment="Patch Q326886 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL27" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the &quot;Content Disposition&quot; vulnerability.</description>
			<reference source="CVE">CVE-2002-0193</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-208" comment="the version of mshtml.dll is less than 5.0.3504.2500" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-215" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL29" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka &quot;Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.&quot;</description>
			<reference source="CVE">CVE-2002-0364</reference>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-209" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" />
					<criterion test_ref="wrt-238" negate="true" comment="Patch Q321599 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL30" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMTP</product>
			</affected>
			<dates>
				<submitted date="2003-05-20">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-30" comment="Changed the registry key in question for the SMTP enabled check to SMTPSVC from SMTP.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
			</dates>
			<description>SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 to cause a denial of service via a command with a malformed data transfer (BDAT) request.</description>
			<reference source="CVE">CVE-2002-0055</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-210" comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" />
					<criterion test_ref="wrt-239" negate="true" comment="Patch Q313450" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-240" comment="SMTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL32" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
			<reference source="CVE">CVE-2002-0026</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL35" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>FTP</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
			<reference source="CVE">CVE-2002-0073</reference>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-202" comment="FTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL37" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and &quot;\&quot; characters twice.</description>
			<reference source="CVE">CVE-2001-0333</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-211" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" />
					<criterion test_ref="wrt-241" negate="true" comment="Patch Q295534 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-243" negate="true" comment="Windows NT 4.0 Security Roll-up Package" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL38" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-05-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.</description>
			<reference source="CVE">CVE-2002-0051</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-220" comment="Windows 2000 (domain controller) is installed" />
					<criterion test_ref="wft-212" comment="the version of srvsvc.dll is less than 5.00.2195.4980" />
					<criterion test_ref="wrt-246" negate="true" comment="Patch Q318593 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL39" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
			<reference source="CVE">CVE-2002-0150</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL40" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
			<reference source="CVE">CVE-2002-0023</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL44" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the &quot;Web Server Folder Traversal&quot; vulnerability.</description>
			<reference source="CVE">CVE-2000-0884</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-213" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" />
					<criterion test_ref="wrt-247" negate="true" comment="Patch Q269862 Installed" />
					<criterion test_ref="wrt-248" negate="true" comment="Patch Q277873 Installed" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL45" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
			<reference source="CVE">CVE-2002-0071</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL46" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.</description>
			<reference source="CVE">CVE-2002-0074</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL49" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka &quot;Improper Cross Domain Security Validation with dialog box.&quot;</description>
			<reference source="CVE">CVE-2003-1326</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-230" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-214" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-252" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL50" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1, or Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
			<reference source="CVE">CVE-2002-0023</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-215" comment="the version of mshtml.dll is less than 5.0.3502.4856" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL57" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka &quot;Improper Cross Domain Security Validation with ShowHelp functionality.&quot;</description>
			<reference source="CVE">CVE-2003-1328</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL58" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-08-20">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (&quot;&quot;302 Object Moved&quot;) message.</description>
			<reference source="CVE">CVE-2002-0075</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL59" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.</description>
			<reference source="CVE">CAN-2002-1561</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-217" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" />
					<criterion test_ref="wrt-253" negate="true" comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" />
					<criterion test_ref="wrt-254" negate="true" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL61" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Access Service (RAS)</product>
			</affected>
			<dates>
				<submitted date="2003-04-04">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
			<reference source="CVE">CVE-2002-0366</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wrt-256" comment="RAS Phonebook" />
					<criterion test_ref="wft-218" comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" />
					<criterion test_ref="wrt-257" negate="true" comment="Patch Q318138 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-258" comment="RAS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL63" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Access Service (RAS)</product>
			</affected>
			<dates>
				<submitted date="2003-04-04">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
			<reference source="CVE">CVE-2002-0366</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-256" comment="RAS Phonebook" />
					<criterion test_ref="wft-219" comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" />
					<criterion test_ref="wrt-257" negate="true" comment="Patch Q318138 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-258" comment="RAS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL64" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-05-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-08-04" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which could allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
			<reference source="CVE">CVE-2002-0018</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-220" comment="File %windir%\system32\netlogon.dll version is less than 5.00.0893.1105" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL66" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</description>
			<reference source="CVE">CAN-2003-0223</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL71" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-06-24">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2005-04-07" comment="modified wft-222 - corrected literal component of file path. It was missing the leading '\'">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<modified date="2005-04-07" comment="modified wft-222 - Corrected comment">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.</description>
			<reference source="CVE">CVE-2001-0344</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-222" comment="the version of sqlservr.exe is less than 2000.80.296.0" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-261" comment="Mixed Mode Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL72" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka &quot;Microsoft-discovered variant of Chunked Encoding buffer overrun.&quot;</description>
			<reference source="CVE">CVE-2002-0147</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL76" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-04-04">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
			<reference source="CVE">CVE-2002-0367</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-223" comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" />
					<criterion test_ref="wrt-262" negate="true" comment="Patch Q320206 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL77" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
			<reference source="CVE">CVE-2002-0023</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL78" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-08-04" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and &quot;\&quot; characters twice.</description>
			<reference source="CVE">CVE-2001-0333</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-224" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL81" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-08-20">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
			<reference source="CVE">CVE-2002-0148</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL82" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-08-27">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2005-04-07" comment="modified wft-225 - correct literal component in file path. Added '\' to the start of the literal string.">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<modified date="2005-04-12" comment="modified wft-89 - wft-89 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.</description>
			<reference source="CVE">CAN-2001-0509</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-225" comment="the version of ssmsrp70.dll is less than 2000.80.213.0" />
					<criterion test_ref="wft-59" comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" />
					<criterion test_ref="wft-89" negate="true" comment="File sqlservr.exe version3 greater than or equal to 384" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL83" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<modified date="2005-04-08" comment="modified wft-227 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CAN-2001-0879.</description>
			<reference source="CVE">CAN-2001-0542</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-227" comment="File sqlservr.exe version3 less than 428" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL87" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.</description>
			<reference source="CVE">CAN-2002-0013</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL89" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Multiple UNC Provider (MUP)</product>
			</affected>
			<dates>
				<submitted date="2003-05-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.</description>
			<reference source="CVE">CVE-2002-0151</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-229" comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" />
					<criterion test_ref="wrt-265" negate="true" comment="Patch Q311967 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL90" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-10-20">INTERIM</status_change>
				<modified date="2004-10-20" comment="corrected configuration criterion">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.</description>
			<reference source="CVE">CVE-2001-0151</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-230" comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" />
					<criterion test_ref="wrt-266" negate="true" comment="Patch Q291845 Installed" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-541" negate="true" comment="WebDav is disabled(for iis 5.0)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL92" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
			<reference source="CVE">CVE-2002-0148</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL95" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
			<reference source="CVE">CVE-2002-0149</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL96" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if cookies are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the &quot;Cookie-based Script Execution&quot; vulnerability.</description>
			<reference source="CVE">CVE-2002-0078</reference>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-231" comment="the version of mshtml.dll is less than 6.0.2715.400" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-250" comment="cookies are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL98" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.</description>
			<reference source="CVE">CAN-2002-0371</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-232" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-271" comment="Gopher Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL99" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the &quot;Content Disposition&quot; vulnerability.</description>
			<reference source="CVE">CVE-2002-0193</reference>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-215" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL103" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Locator service</product>
			</affected>
			<dates>
				<submitted date="2003-08-27">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</description>
			<reference source="CVE">CVE-2003-0003</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-233" comment="the version of locator.exe is less than 4.0.1381.7202" />
					<criterion test_ref="wrt-272" negate="true" comment="Patch Q810833 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-273" comment="Locator Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL109" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</description>
			<reference source="CVE">CAN-2003-0109</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-234" comment="the version of ntdll.dll is less than 5.0.2195.6685" />
					<criterion test_ref="wrt-274" negate="true" comment="the patch q815021 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL117" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>ISA Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for &quot;500 Internal Server error&quot; or (2) 404.htm for &quot;404 Not Found.&quot;</description>
			<reference source="CVE">CAN-2003-0526</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-105" comment="ISA Server 2000 is installed" />
					<criterion test_ref="wrt-276" negate="true" comment="ISA2000-KB816456-x86.exe" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL118" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2003-09-08">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
			<reference source="CVE">CAN-2003-0345</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-235" comment="File %windir%\system32\Drivers\SRV.SYS is less than 5.0.2195.6699" />
					<criterion test_ref="wrt-277" negate="true" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL121" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<modified date="2005-04-08" comment="modified wft-237 - literal string corrected">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-236 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-65 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-66 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-67 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-68 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-69 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.</description>
			<reference source="CVE">CAN-2002-0154</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-236" comment="the version of sqlservr.exe is less than 2000.80.608.0" />
					<criterion test_ref="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL123" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.</description>
			<reference source="CVE">CAN-2003-0809</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" />
					<criterion test_ref="wft-238" comment="the version of mshtml.dll is less than 6.0.2800.1264" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-75" comment="ActiveX controls are enabled" />
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL126" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
			</dates>
			<description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka &quot;Improper Cross Domain Security Validation with dialog box.&quot;</description>
			<reference source="CVE">CVE-2003-1326</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL127" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2003-09-15">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0715.</description>
			<reference source="CVE">CAN-2003-0528</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL130" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
			<reference source="CVE">CVE-2002-0071</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL132" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
			<reference source="CVE">CVE-2002-0149</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL134" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Script Engine for Jscript</product>
			</affected>
			<dates>
				<submitted date="2004-11-02"/>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0010</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1157" comment="jscript.dll version is 5.1, 5.5, or 5.6 " />
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="cmp-1156" negate="true" comment="The patch js56nen.exe is installed for version 5.1, 5.5, or 5.6" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL136" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Virtual Machine (VM)</product>
			</affected>
			<dates>
				<submitted date="2004-04-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka &quot;Flaw in Microsoft VM Could Enable System Compromise.&quot;</description>
			<reference source="CVE">CAN-2003-0111</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wft-301" comment="the version of msjava.dll is less than 5.0.3810.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL137" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
			<reference source="CVE">CVE-2002-0150</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL139" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2004-06-08">
					<contributor organization="The MITRE Corporation">Matt Busby</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the &quot;Registry Permissions&quot; vulnerabilities.</description>
			<reference source="CVE">CAN-2001-0046</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" />
					<criterion test_ref="cmp-1012" comment="For Terminal Server" />
					<criterion test_ref="wrt-454" negate="true" comment="Patch Q265714 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL140" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Transaction Server (MTS)</product>
			</affected>
			<dates>
				<submitted date="2004-06-08">
					<contributor organization="The MITRE Corporation">Matt Busby</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the &quot;Registry Permissions&quot; vulnerabilities.</description>
			<reference source="CVE">CAN-2001-0047</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" />
					<criterion test_ref="cmp-1012" comment="For Terminal Server" />
					<criterion test_ref="wrt-454" negate="true" comment="Patch Q265714 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-455" comment="MTS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL141" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-07-18">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if file downloads are enabled by the current user when local machine settings are not in use.  Changed the status from ACCEPTED to INTERIM">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.</description>
			<reference source="CVE">CVE-2001-0154</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-264" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-240" comment="File %windir%\system32\shdocvw.dll version is less than 5.0.3214.2000" />
					<criterion test_ref="wrt-284" negate="true" comment="the patch q290108 is installed" />
					<criterion test_ref="wrt-285" negate="true" comment="the patch q295106 is installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-265" comment="file downloads are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL142" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-11-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
			<reference source="CVE">CAN-2003-0112</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-536" negate="true" comment="Windows NT Service Pack 6a is installed" />
					<criterion test_ref="wft-436" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" />
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL143" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka &quot;Encoded Characters Information Disclosure.&quot;</description>
			<reference source="CVE">CVE-2002-1186</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL144" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.</description>
			<reference source="CVE">CAN-2002-0012</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL145" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Multiple UNC Provider (MUP)</product>
			</affected>
			<dates>
				<submitted date="2003-05-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.</description>
			<reference source="CVE">CVE-2002-0151</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-243" comment="the version of mup.sys is less than 4.0.1381.7125" />
					<criterion test_ref="wrt-287" negate="true" comment="Patch Q312895 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL146" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2004-11-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
			<reference source="CVE">CAN-2003-0345</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-569" negate="true" comment="Patch Q817606 Installed" />
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-566" comment="The version of srv.sys is less than 4.0.1381.7214" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL147" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.</description>
			<reference source="CVE">CVE-2002-0070</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-244" comment="the version of shell32.dll is less than 5.00.3502.4718" />
					<criterion test_ref="wrt-288" negate="true" comment="Patch Q313829 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL158" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows NT 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-04-04">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
			<reference source="CVE">CVE-2002-0367</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-245" comment="the version of smss.exe is less than 4.0.1381.7152" />
					<criterion test_ref="wrt-262" negate="true" comment="Patch Q320206 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL159" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows NT 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-05-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which could allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
			<reference source="CVE">CVE-2002-0018</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-246" comment="the version of netlogon.dll is less than 4.0.1381.7092" />
					<criterion test_ref="wrt-243" negate="true" comment="Windows NT 4.0 Security Roll-up Package" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL161" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.</description>
			<reference source="CVE">CAN-2002-0012</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL178" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
			</dates>
			<description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka &quot;Improper Cross Domain Security Validation with dialog box.&quot;</description>
			<reference source="CVE">CVE-2003-1326</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-247" comment="the version of mshtml.dll is less than 5.50.4923.2500" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-252" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL182" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka &quot;Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.&quot;</description>
			<reference source="CVE">CVE-2002-0364</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-248" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.776.1" />
					<criterion test_ref="wrt-289" negate="true" comment="Patch Q321599 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL185" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Authenticode</product>
			</affected>
			<dates>
				<submitted date="2003-10-29">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if downloading of signed ActiveX controls are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-05" comment="Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="The compound test that includes SP1 or earlier has been added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-09-13" comment="">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.</description>
			<reference source="CVE">CAN-2003-0660</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-273" comment="a vulnerable version of cryptui.dll exists" />
					<criterion test_ref="wrt-293" negate="true" comment="Patch WindowsXP-KB823182-x86-ENU Installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-275" comment="downloading of signed ActiveX controls is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL188" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word 2000</product>
			</affected>
			<dates>
				<submitted date="2004-08-25">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-08-25" comment="Added word 2000 and winword.exe information">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-08-25" comment="changed to word 2000">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-04-11" comment="modified wft-470 - wft-470 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.</description>
			<reference source="CVE">CAN-2003-0664</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-132" comment="Word 2000 is installed" />
					<criterion test_ref="wft-470" comment="the version of winword.exe is less than 9.0.0.7924" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL189" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka &quot;Unchecked Buffer in Network Share Provider Can Lead to Denial of Service&quot;.</description>
			<reference source="CVE">CAN-2002-0724</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-251" comment="the version of xactsrv.dll is less than 5.0.2195.5971" />
					<criterion test_ref="wrt-295" negate="true" comment="Patch Q326830 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-296" comment="Lanman enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL190" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Certificate Enrollment Control</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.</description>
			<reference source="CVE">CAN-2002-0699</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-252" comment="the version of xenroll.dll is less than 5.131.3659.0" />
					<criterion test_ref="wrt-297" negate="true" comment="Patch Q323172 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-276" comment="ActiveX Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL191" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the &quot;Web Server File Request Parsing&quot; vulnerability.</description>
			<reference source="CVE">CVE-2000-0886</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-253" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2784" />
					<criterion test_ref="wrt-248" negate="true" comment="Patch Q277873 Installed" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL194" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-11-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</description>
			<reference source="CVE">CAN-2003-0352</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-570" negate="true" comment="Patch Q823980 Installed" />
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-567" comment="the version of rpcss.dll is less than 4.0.1381.7203" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL197" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-08-04" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.</description>
			<reference source="CVE">CVE-2001-0500</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-254" comment="File %windir%\system32\idq.dll version is less than 5.0.2195.3645" />
					<criterion test_ref="wrt-299" negate="true" comment="Patch Q300972 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-205" comment="idq.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL198" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-16">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if downloading of signed ActiveX controls are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.</description>
			<reference source="CVE">CAN-2003-0660</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-255" comment="File %windir%\system32\cryptui.dll version is less than 5.131.2195.6758" />
					<criterion test_ref="wrt-293" negate="true" comment="Patch WindowsXP-KB823182-x86-ENU Installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-275" comment="downloading of signed ActiveX controls is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL199" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Data Protocol (RDP)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka &quot;Weak Encryption in RDP Protocol.&quot;</description>
			<reference source="CVE">CAN-2002-0863</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-300" comment="Terminal Server Version" />
					<criterion test_ref="wft-256" comment="File %windir%\system32\drivers\rdpwd.sys version is less than 5.0.2195.5880" />
					<criterion test_ref="wrt-301" negate="true" comment="Patch Q324380 installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-302" comment="RDP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL200" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Script Engine for JScript v5.6</product>
			</affected>
			<dates>
				<submitted date="2003-08-27">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-03" comment="Corrected to reflect the unification of the Windows Schema">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if active scripting is enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-08-24" comment="Added Patch to Definition">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-08-24" comment="negated patch">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0010</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-257" comment="the version of jscript.dll is less than 5.6.0.8513" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
					<criterion test_ref="wrt-499" negate="true" comment="the patch js56nen.exe (5.6.0.8513 version) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-76" comment="active scripting is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL201" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows XP</product>
			</affected>
			<dates>
				<submitted date="2003-10-28">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-05" comment="Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="The compound test that includes a check for SP1 or earlier has been added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-01-27" comment="Added patch KB891711 (from MS05-002) which supercedes the previous patch">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-01-28">INTERIM</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.</description>
			<reference source="CVE">CAN-2003-0659</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-282" comment="a vulnerable version of user32.dll exists" />
					<criterion test_ref="wrt-304" negate="true" comment="the patch kb824141 is installed (Hotfix key)" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-305" comment="the utility manager Service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL202" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word 2000</product>
			</affected>
			<dates>
				<submitted date="2004-08-24">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-04-11" comment="modified wft-478 - wft-478 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka &quot;Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure.&quot;</description>
			<reference source="CVE">CAN-2002-1143</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-132" comment="Word 2000 is installed" />
					<criterion test_ref="wft-478" comment="the version of winword.exe is less than 9.0.0.6926" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL203" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the &amp;lt;frame&amp;gt; or &amp;lt;iframe&amp;gt; element and javascript, aka &quot;Frames Cross Site Scripting,&quot; as demonstrated using the PrivacyPolicy.dlg resource.</description>
			<reference source="CVE">CVE-2002-1187</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL204" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a &quot;data&quot; tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CAN-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe).</description>
			<reference source="CVE">CAN-2003-0838</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" />
					<criterion test_ref="wft-238" comment="the version of mshtml.dll is less than 6.0.2800.1264" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-75" comment="ActiveX controls are enabled" />
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL205" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word 2000</product>
			</affected>
			<dates>
				<submitted date="2004-09-06">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2004-09-07" comment="made into a real definition">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-09-08">DRAFT</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
				<modified date="2005-04-11" comment="modified wft-486 - wft-486 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.</description>
			<reference source="CVE">CVE-2002-1056</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-132" comment="Word 2000 is installed" />
					<criterion test_ref="wft-486" comment="the version of winword.exe is less than 9.0.0.6328" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL206" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
			<reference source="CVE">CAN-2003-1048</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL207" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifiying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a &quot;URL:&quot; prepended to a &quot;ms-its&quot; protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
			<reference source="CVE">CAN-2004-0549</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-266" comment="the version of mshtml.dll is less than 6.00.3790.191" />
					<criterion test_ref="wrt-237" negate="true" comment="the patch kb867801 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL209" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2003-12-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related candidates, especially CAN-2002-0012 and CAN-2002-0013, will be updated when more accurate information is available.</description>
			<reference source="CVE">CAN-2002-0053</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL210" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (&quot;&quot;302 Object Moved&quot;) message.</description>
			<reference source="CVE">CVE-2002-0075</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL212" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
			<reference source="CVE">CAN-2003-1048</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL213" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Messenger Service</product>
			</affected>
			<dates>
				<submitted date="2003-10-16">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2004-03-29" comment="Fixed an error in the configuration section, now correctly testing that messenger service is enabled.  Before it was testing that HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Start=2, now it is testing that it does not equal 4.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0717</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-122" comment="the version of msgsvc.dll is less than 5.0.2195.6861" />
					<criterion test_ref="wft-260" comment="the version of wkssvc.dll is less than 5.0.2195.6861" />
					<criterion test_ref="wrt-83" negate="true" comment="the patch q828035 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-307" comment="the messenger service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL216" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
			<reference source="CVE">CAN-2004-0566</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-279" comment="the version of mshtml.dll is less than 5.00.3819.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL217" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<dates>
				<submitted date="2003-10-16">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2005-01-18" comment="Windows 2000 replaced by check for Windows 2000 SP4 or earlier">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL</description>
			<reference source="CVE">CAN-2003-0711</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" />
					<criterion test_ref="wrt-308" negate="true" comment="Patch KB825119 Installed" />
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-309" negate="true" comment="HCP Protocol" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL218" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>DirectX</product>
			</affected>
			<dates>
				<submitted date="2004-11-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</description>
			<reference source="CVE">CAN-2003-0346</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-569" comment="the version of quartz.dll is less than 6.1.5.132" />
					<criterion test_ref="wrt-571" negate="true" comment="Patch Q19696 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL225" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the &amp;lt;frame&amp;gt; or &amp;lt;iframe&amp;gt; element and javascript, aka &quot;Frames Cross Site Scripting,&quot; as demonstrated using the PrivacyPolicy.dlg resource.</description>
			<reference source="CVE">CVE-2002-1187</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL231" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server</product>
			</affected>
			<dates>
				<submitted date="2003-08-27">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2005-04-08" comment="modified wft-85 - wft-85 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-86 - wft-86 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-87 - wft-87 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-88 - wft-88 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<modified date="2005-04-12" comment="modified wft-89 - wft-89 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the &quot;Extended Stored Procedure Parameter Parsing&quot; vulnerability.</description>
			<reference source="CVE">CAN-2000-1081</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-85" comment="File odsole70.dll Version3 is less than 223" />
					<criterion test_ref="wft-86" comment="File xpqueue.dll Version3 is less than 223" />
					<criterion test_ref="wft-87" comment="File xprepl.dll Version3 is less than 223" />
					<criterion test_ref="wft-88" comment="File xpstar.dll Version3 is less than 223" />
					<criterion test_ref="wft-89" negate="true" comment="File sqlservr.exe version3 greater than or equal to 384" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL235" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<modified date="2005-01-14" comment="modified wft-62 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested.">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wft-72 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-70 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-73 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-78 - wft-78 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-79 - wft-79 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-51 - wft-51 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-52 - wft-52 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-53 - wft-53 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-54 - wft-54 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-60 - wft-60 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-61 - wft-61 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-63 - wft-63 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-64 - wft-64 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft SQL Server 7, 2000, and MSDE allows local users go gain privileges by hijacking a named pipe during the authentication of another user, aka the &quot;Named Pipe Hijacking&quot; vulnerability</description>
			<reference source="CVE">CAN-2003-0230</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-70" comment="File console.exe version3 is less than 818" />
					<criterion test_ref="wft-71" comment="File dbmslpcn.dll version3 is less than 818" />
					<criterion test_ref="wft-72" comment="File sqlmap70.dll version3 is less than 811" />
					<criterion test_ref="wft-73" comment="File sqlrepss.dll version3 is less than 765" />
					<criterion test_ref="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" />
					<criterion test_ref="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" />
					<criterion test_ref="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" />
					<criterion test_ref="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" />
					<criterion test_ref="wft-61" comment="File msgprox.dll version3 is less than 765" />
					<criterion test_ref="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" />
					<criterion test_ref="wft-63" comment="File replrec.dll version3 is less than 765" />
					<criterion test_ref="wft-64" comment="File sqlvdi.dll version3 is less than 765" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL236" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
			<reference source="CVE">CAN-2003-1048</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-267" comment="the version of mshtml.dll is less than 6.00.2800.1458" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL237" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-17">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML formatter e-mail or web page.</description>
			<reference source="CVE">CAN-2003-0662</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-271" comment="the version of tshoot.ocx is less than 1.0.1.2125" />
					<criterion test_ref="wrt-310" negate="true" comment="the patch kb826232 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-75" comment="ActiveX controls are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL241" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifiying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a &quot;URL:&quot; prepended to a &quot;ms-its&quot; protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
			<reference source="CVE">CAN-2004-0549</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL246" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<dates>
				<submitted date="2004-10-26">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an &quot;unchecked buffer,&quot; leading to off-by-one and heap-based buffer overflows.</description>
			<reference source="CVE">CAN-2004-0574</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1153" comment="Exchange Server 2003 is installed on Windows Server 2003" />
					<criterion test_ref="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" />
					<criterion test_ref="wrt-548" comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL253" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
			</dates>
			<description>Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.</description>
			<reference source="CVE">CVE-2001-0879</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-312" negate="true" comment="Patch Q305601 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL258" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<modified date="2005-06-24" comment="added description">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
			<reference source="CVE">CAN-2005-1211</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-115" comment="the version of mshtml.dll is less than 5.0.3541.2700" />
					<criterion test_ref="wrt-62" negate="true" comment="the patch kb883939 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-59" comment="PNG image rendering enabled in Internet Explorer" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL259" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the &quot;Server Message Block Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-1206</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-231" comment="a vulnerable version of srv.sys exists" />
					<criterion test_ref="wrt-63" negate="true" comment="the patch KB896422 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL262" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-11-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
			<reference source="CVE">CAN-2003-0112</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-570" comment="the version of kernel32.dll is less than 5.0.2195.6011" />
					<criterion test_ref="wrt-478" comment="the patch Q811493 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL264" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-12-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0528.</description>
			<reference source="CVE">CAN-2003-0715</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL266" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Client Server Runtime System (CSRSS)</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
			<reference source="CVE">CAN-2005-0551</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-581" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL268" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows XP</product>
			</affected>
			<dates>
				<submitted date="2003-10-28">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-05" comment="Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="CMP-66 has been added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0717</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-30" comment="a vulnerable version of wkssvc.dll exists" />
					<criterion test_ref="cmp-295" comment="a vulnerable version of msgsvc.dll exists" />
					<criterion test_ref="wrt-83" negate="true" comment="the patch q828035 is installed (Hotfix key)" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-307" comment="the messenger service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL271" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<modified date="2005-04-08" comment="modified wft-274 - wft-274 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-275 - wft-275 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.</description>
			<reference source="CVE">CAN-2002-0056</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-274" comment="File sqlservr.exe version3 is less than 578" />
					<criterion test_ref="wft-275" comment="File xpstar.dll version3 is less than 561" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL272" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses &amp;lt;frame&amp;gt; and &amp;lt;iframe&amp;gt; domain restrictions.</description>
			<reference source="CVE">CAN-2002-1217</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL277" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMB Signing (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2003-09-16">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.</description>
			<reference source="CVE">CVE-2002-1256</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-276" comment="the version of srvsvc.dll is less than 5.0.2195.6110" />
					<criterion test_ref="wrt-314" negate="true" comment="Patch Q329170 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-315" comment="SMB Signing enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL281" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Media Player for Windows XP</product>
			</affected>
			<dates>
				<submitted date="2003-11-26">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored in the IE cache, aka the &quot;Cache Path Disclosure via Windows Media Player&quot;.</description>
			<reference source="CVE">CVE-2002-0372</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-316" comment="Windows Media Player for Windows XP is installed" />
					<criterion test_ref="wft-277" comment="the version of dxmasf.dll is less than 6.4.9.1121" />
					<criterion test_ref="wft-140" comment="the version of msdxm.ocx is less than 6.4.9.1124" />
					<criterion test_ref="wft-141" comment="the version of wmpcore.dll is less than 8.0.0.4482" />
					<criterion test_ref="wft-142" comment="the version of wmplayer.exe is less than 8.0.0.4482" />
					<criterion test_ref="wrt-317" negate="true" comment="Patch wm320920_8.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL287" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Media Player for Windows XP</product>
			</affected>
			<dates>
				<submitted date="2003-11-26">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.</description>
			<reference source="CVE">CVE-2001-0719</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-316" comment="Windows Media Player for Windows XP is installed" />
					<criterion test_ref="wft-143" comment="the version of msdxm.ocx is less than 6.4.9.1121" />
					<criterion test_ref="wft-277" comment="the version of dxmasf.dll is less than 6.4.9.1121" />
					<criterion test_ref="wrt-318" negate="true" comment="Patch wm308567 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL291" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<modified date="2005-04-08" comment="modified wft-237 - literal string corrected">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-65 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-66 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-67 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-68 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-69 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-278 - wft-278 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka &quot;Unchecked Buffer in Password Encryption Procedure.&quot;</description>
			<reference source="CVE">CAN-2002-0624</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-278" comment="the version of sqlservr.exe is less than 2000.80.650.0" />
					<criterion test_ref="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-261" comment="Mixed Mode Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL294" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>MDAC 2.6</product>
			</affected>
			<dates>
				<submitted date="2004-08-24">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-02-28" comment="removed the test for windows NT and added a test for MDAC 2.6 since this definition is dependent on the MDAC version and not the platform">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
			<reference source="CVE">CVE-2002-1142</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-101" comment="MDAC 2.6 is installed" />
					<criterion test_ref="wft-481" comment="the version of msadco.dll is less than 2.62.9119.1" />
					<criterion test_ref="wrt-503" negate="true" comment="Patch Q329414 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL296" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2003-12-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</description>
			<reference source="CVE">CAN-2003-0352</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-280" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6753" />
					<criterion test_ref="wrt-254" negate="true" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL298" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<modified date="2004-09-20" comment="Changed CAN-2002-0012 to CAN-2002-0013.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.</description>
			<reference source="CVE">CAN-2002-0013</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
					<criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL299" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<modified date="2005-01-14" comment="modified wft-55 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested. ">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wft-72 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-70 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-73 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-78 - wft-78 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-79 - wft-79 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-51 - wft-51 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-52 - wft-52 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-53 - wft-53 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-54 - wft-54 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-60 - wft-60 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe</description>
			<reference source="CVE">CAN-2003-0231</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-70" comment="File console.exe version3 is less than 818" />
					<criterion test_ref="wft-50" comment="the version of dbmslpcn.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-72" comment="File sqlmap70.dll version3 is less than 811" />
					<criterion test_ref="wft-73" comment="File sqlrepss.dll version3 is less than 765" />
					<criterion test_ref="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" />
					<criterion test_ref="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" />
					<criterion test_ref="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" />
					<criterion test_ref="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" />
					<criterion test_ref="wft-55" comment="the version of msgprox.dll is less than 2000.80.765.0" />
					<criterion test_ref="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" />
					<criterion test_ref="wft-56" comment="the version of replrec.dll is less than 2000.80.765.0" />
					<criterion test_ref="wft-57" comment="the version of sqlvdi.dll is less than 2000.80.765.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL303" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<modified date="2005-01-14" comment="modified wft-55 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested. ">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wft-72 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-70 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-73 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-78 - wft-78 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-79 - wft-79 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-51 - wft-51 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-52 - wft-52 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-53 - wft-53 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-54 - wft-54 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-60 - wft-60 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow</description>
			<reference source="CVE">CAN-2003-0232</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-70" comment="File console.exe version3 is less than 818" />
					<criterion test_ref="wft-50" comment="the version of dbmslpcn.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-72" comment="File sqlmap70.dll version3 is less than 811" />
					<criterion test_ref="wft-73" comment="File sqlrepss.dll version3 is less than 765" />
					<criterion test_ref="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" />
					<criterion test_ref="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" />
					<criterion test_ref="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" />
					<criterion test_ref="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" />
					<criterion test_ref="wft-55" comment="the version of msgprox.dll is less than 2000.80.765.0" />
					<criterion test_ref="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" />
					<criterion test_ref="wft-56" comment="the version of replrec.dll is less than 2000.80.765.0" />
					<criterion test_ref="wft-57" comment="the version of sqlvdi.dll is less than 2000.80.765.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL306" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
			<reference source="CVE">CAN-2004-0566</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL308" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<dates>
				<submitted date="2003-12-09">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-01-14" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
			<reference source="CVE">CAN-2003-0824</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-12" comment="the version of shtml.dll is less than 4.0.2.7523" />
					<criterion test_ref="wrt-88" negate="true" comment="the patch q810217 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" />
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL316" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<modified date="2005-04-08" comment="modified wft-237 - literal string corrected">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-65 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-66 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-67 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-68 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-69 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-278 - wft-278 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-58 - wft-58 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.</description>
			<reference source="CVE">CAN-2002-0641</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-278" comment="the version of sqlservr.exe is less than 2000.80.650.0" />
					<criterion test_ref="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" />
					<criterion test_ref="wft-58" comment="the version of impprov.dll is less than 2000.80.650.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL319" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows NT 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.</description>
			<reference source="CVE">CAN-2003-0525</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-40" negate="true" comment="this is an NT Workstation" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-282" comment="the version of kernel32.dll is less than 4.0.1381.7224" />
					<criterion test_ref="wrt-323" negate="true" comment="Patch Q823803 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL321" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Media Player for Windows XP</product>
			</affected>
			<dates>
				<submitted date="2003-11-26">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.</description>
			<reference source="CVE">CAN-2003-0228</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-316" comment="Windows Media Player for Windows XP is installed" />
					<criterion test_ref="wft-144" comment="the version of wmplayer.exe is less than 8.0.0.4490" />
					<criterion test_ref="wrt-324" negate="true" comment="Patch WindowsMedia8-KB817787-x86-ENU.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL322" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
			<reference source="CVE">CAN-2004-0566</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL330" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Color Management Module </product>
			</affected>
			<dates>
				<submitted date="2005-08-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-08-03">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1219</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-409" comment="the version of mscms.dll is less than 5.1.2600.2709" />
					<criterion test_ref="wrt-128" negate="true" comment="the patch KB901214 is installed " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL331" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Windows Workstation Service</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-08" comment="Added 64-bit edition support to this definition allowing us to deprecated OVAL332">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file (&quot;NetSetup.LOG&quot;), as demonstrated using the NetAddAlternateComputerName API.</description>
			<reference source="CVE">CAN-2003-0812</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-30" comment="a vulnerable version of wkssvc.dll exists" />
					<criterion test_ref="wrt-83" negate="true" comment="the patch q828035 is installed (Hotfix key)" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-71" comment="the workstation service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL333" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses &amp;lt;frame&amp;gt; and &amp;lt;iframe&amp;gt; domain restrictions.</description>
			<reference source="CVE">CAN-2002-1217</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL334" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<dates>
				<submitted date="2003-09-16">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts.</description>
			<reference source="CVE">CVE-2001-0543</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
					<criterion test_ref="wft-283" comment="the version of nntpsvc.dll is less than 5.0.2195.3881" />
					<criterion test_ref="wrt-325" negate="true" comment="Patch Q303984 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL335" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's &quot;href&quot; to the malicious Javascript, then calling execCommand(&quot;Refresh&quot;) to refresh the page, aka BodyRefreshLoadsJPU or the &quot;ExecCommand Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0814</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL336" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word 2000</product>
			</affected>
			<dates>
				<submitted date="2003-11-19">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2005-04-11" comment="modified wft-19 - wft-19 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the &quot;Macro names&quot; data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0820</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-132" comment="Word 2000 is installed" />
					<criterion test_ref="wft-19" comment="the version of winword.exe is less than 9.0.0.8216" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL340" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-16">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2005-01-27" comment="Added the patch KB891711 (from MS05-002) which supercedes the previous patch">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-01-28">INTERIM</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.</description>
			<reference source="CVE">CAN-2003-0659</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-285" comment="File %windir%\system32\user32.dll version is less than 5.00.2195.6799" />
					<criterion test_ref="wrt-304" negate="true" comment="the patch kb824141 is installed (Hotfix key)" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-305" comment="the utility manager Service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL341" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's &quot;href&quot; to the malicious Javascript, then calling execCommand(&quot;Refresh&quot;) to refresh the page, aka BodyRefreshLoadsJPU or the &quot;ExecCommand Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0814</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL342" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's &quot;href&quot; to the malicious Javascript, then calling execCommand(&quot;Refresh&quot;) to refresh the page, aka BodyRefreshLoadsJPU or the &quot;ExecCommand Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0814</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL343" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's &quot;href&quot; to the malicious Javascript, then calling execCommand(&quot;Refresh&quot;) to refresh the page, aka BodyRefreshLoadsJPU or the &quot;ExecCommand Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0814</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL344" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-01-29" comment="Added Windows XP 64-bit to the list of affected platforms">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's &quot;href&quot; to the malicious Javascript, then calling execCommand(&quot;Refresh&quot;) to refresh the page, aka BodyRefreshLoadsJPU or the &quot;ExecCommand Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0814</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL349" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-01-29" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's &quot;href&quot; to the malicious Javascript, then calling execCommand(&quot;Refresh&quot;) to refresh the page, aka BodyRefreshLoadsJPU or the &quot;ExecCommand Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0814</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" />
					<criterion test_ref="wrt-60" negate="true" comment="the patch q824145 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL351" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp2 installed.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the &quot;Function Pointer Override Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0815</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL352" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp3 installed.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the &quot;Function Pointer Override Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0815</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL353" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp4 installed.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the &quot;Function Pointer Override Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0815</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL356" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the &quot;Function Pointer Override Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0815</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL357" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-01-29" comment="Added Windows XP 64-bit to the list of affected platforms">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the &quot;Function Pointer Override Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0815</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL359" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-01-29" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the &quot;Function Pointer Override Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0815</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" />
					<criterion test_ref="wrt-60" negate="true" comment="the patch q824145 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL361" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the &quot;Script URLs Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0816</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL362" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the &quot;Script URLs Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0816</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL363" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the &quot;Script URLs Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0816</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL364" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<dates>
				<submitted date="2003-12-09">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-05" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions 2000 and 2002 allows remote attackers to execute arbitrary code via a certain chunked encoded request.</description>
			<reference source="CVE">CAN-2003-0822</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
					<criterion test_ref="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists" />
					<criterion test_ref="wrt-88" negate="true" comment="the patch q810217 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL366" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2002</product>
			</affected>
			<dates>
				<submitted date="2003-12-09">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-05" comment="Changed the definition to test for fp30reg.dll and fp5areg.dll instead of fp5awel.dll.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-09-14" comment="XP SP2 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions 2000 and 2002 allows remote attackers to execute arbitrary code via a certain chunked encoded request.</description>
			<reference source="CVE">CAN-2003-0822</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-77" comment="Windows NT, 2000, or XP is installed" />
					<criterion test_ref="cmp-113" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL367" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft SharePoint Team Services</product>
			</affected>
			<dates>
				<submitted date="2003-12-09">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-05" comment="Changed the definition to test for fp30reg.dll and fp5areg.dll instead of fp5awel.dll.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-09-14" comment="XP SP2 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions 2000 and 2002 allows remote attackers to execute arbitrary code via a certain chunked encoded request.</description>
			<reference source="CVE">CAN-2003-0822</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-78" comment="Windows 2000, XP, or 2003 is installed" />
					<criterion test_ref="cmp-113" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL368" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-12-18">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027.</description>
			<reference source="CVE">CAN-2003-0823</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL369" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2003-12-18">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027.</description>
			<reference source="CVE">CAN-2003-0823</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL370" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2003-12-18">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027.</description>
			<reference source="CVE">CAN-2003-0823</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL371" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-12-18">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027.</description>
			<reference source="CVE">CAN-2003-0823</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL372" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-12-18">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-01-29" comment="Added Windows XP 64-bit to the list of affected platforms">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027.</description>
			<reference source="CVE">CAN-2003-0823</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL373" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.</description>
			<reference source="CVE">CAN-2003-0225</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL374" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HTML Help ActiveX Control</product>
			</affected>
			<dates>
				<submitted date="2003-09-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if active scripting is enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.</description>
			<reference source="CVE">CAN-2002-0693</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-286" comment="the version of hhctrl.ocx is less than 5.2.3669.0" />
					<criterion test_ref="wft-287" comment="the version of hhsetup.dll is less than 5.2.3644.0" />
					<criterion test_ref="wft-102" comment="the version of itircl.dll is less than 5.2.3644.0" />
					<criterion test_ref="wft-103" comment="the version of itss.dll is less than 5.2.3644.0" />
					<criterion test_ref="wrt-328" negate="true" comment="the patch q323255 is installed (Hotfix key)" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-76" comment="active scripting is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL381" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2005-06-20">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a &quot;ms-its:&quot; URL in Internet Explorer.</description>
			<reference source="CVE">CAN-2005-1208</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-84" comment="a vulnerable version of hh.exe exists" />
					<criterion test_ref="wrt-57" negate="true" comment="the patch kb896358 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL388" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka &quot;Cross Domain Verification via Cached Methods.&quot;</description>
			<reference source="CVE">CAN-2002-1254</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL392" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's &quot;href&quot; to the malicious Javascript, then calling execCommand(&quot;Refresh&quot;) to refresh the page, aka BodyRefreshLoadsJPU or the &quot;ExecCommand Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0814</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL393" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka &quot;Malformed PNG Image File Failure.&quot;</description>
			<reference source="CVE">CVE-2002-1185</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL402" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2004-09-15">
					<contributor organization="The MITRE Corporation">Matt Busby</contributor>
				</submitted>
				<modified date="2004-09-15" comment="Filled out initial submission.  Now a complete definition.">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</modified>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related candidates, especially CAN-2002-0012 and CAN-2002-0013, will be updated when more accurate information is available.</description>
			<reference source="CVE">CAN-2002-0053</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL403" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2003-09-30">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka &quot;Code Execution via Compiled HTML Help File.&quot;</description>
			<reference source="CVE">CVE-2002-0694</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-287" comment="the version of hhsetup.dll is less than 5.2.3644.0" />
					<criterion test_ref="wft-102" comment="the version of itircl.dll is less than 5.2.3644.0" />
					<criterion test_ref="wft-103" comment="the version of itss.dll is less than 5.2.3644.0" />
					<criterion test_ref="wrt-328" negate="true" comment="the patch q323255 is installed (Hotfix key)" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL406" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>ISA Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-12-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</description>
			<reference source="CVE">CAN-2003-0110</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-105" comment="ISA Server 2000 is installed" />
					<criterion test_ref="wft-100" comment="the version of w3proxy.exe is less than 3.0.1200.257" />
					<criterion test_ref="wft-101" comment="the version of wpsrv.exe is less than 3.0.1200.257" />
					<criterion test_ref="wrt-331" negate="true" comment="Patch isahf257 installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-332" comment="Microsoft Firewall Service Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL407" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2005-05-04">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
			<reference source="CVE">CAN-2005-0063</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-182" comment="Microsoft Windows Server 2003 32-Bit Edition" />
					<criterion test_ref="wft-588" comment="the version of shell32.dll is less than 6.0.3790.280" />
					<criterion test_ref="wrt-434" negate="true" comment="the patch  KB893086 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL408" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka &quot;Cross Domain Verification via Cached Methods.&quot;</description>
			<reference source="CVE">CAN-2002-1254</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL409" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the &quot;Script URLs Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0816</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL416" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-01-29" comment="Added Windows XP 64-bit to the list of affected platforms">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the &quot;Script URLs Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0816</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL424" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Telnet protocol</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-07-20" comment="Changed patch registry key value to IsInstalled">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-11">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in telnet server in Windows 2000 and Interix 2.2 allows remote attackers to execute arbitrary code via malformed protocol options.</description>
			<reference source="CVE">CVE-2002-0020</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-290" comment="the version of tlntsvr.exe is less than 5.0.33668.1" />
					<criterion test_ref="wrt-333" negate="true" comment="Patch Q307298 Installed" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-334" comment="the telnet service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL429" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word 2002</product>
			</affected>
			<dates>
				<submitted date="2004-08-24">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-01-13" comment="modified wft-484 - Corrected registry key in path component">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to</description>
			<reference source="CVE">CVE-2002-1056</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-133" comment="Word 2002 is installed" />
					<criterion test_ref="wft-484" comment="the version of msohev.dll less than 10.0.2609.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL440" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Color Management Module </product>
			</affected>
			<dates>
				<submitted date="2005-08-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-08-03">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1219</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-57" comment="Windows XP 32-bit SP1 is installed" />
					<criterion test_ref="wft-411" comment="the version of mscms.dll is less than 5.1.2600.1710" />
					<criterion test_ref="wrt-128" negate="true" comment="the patch KB901214 is installed " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL444" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka &quot;Temporary Internet Files folders Name Reading.&quot;</description>
			<reference source="CVE">CVE-2002-1188</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL450" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-12-21">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka &quot;Windows Kernel Vulnerability.</description>
			<reference source="CVE">CAN-2004-0893</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-327" comment="the version of lsasrv.dll is less than 5.1.2600.2525" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL451" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Utilities Manager/Windows Messaging</product>
			</affected>
			<dates>
				<submitted date="2003-09-09">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a &quot;Shatter&quot; style message to the Utility Manager that references a user-controlled callback function.</description>
			<reference source="CVE">CAN-2003-0350</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-291" comment="the version of sp3res.dll is less than 5.0.2195.6713" />
					<criterion test_ref="wft-292" comment="the version of umandlg.dll is less than 1.0.0.3" />
					<criterion test_ref="wrt-335" negate="true" comment="Patch KB822679 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL459" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-01-29" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the &quot;Script URLs Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0816</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" />
					<criterion test_ref="wrt-60" negate="true" comment="the patch q824145 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL463" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2005-06-20">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1208</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-4" comment="the version of hh.exe is less than 5.2.3790.309" />
					<criterion test_ref="wrt-57" negate="true" comment="the patch kb896358 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL467" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Small Business Server 2000</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1206</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-63" negate="true" comment="the patch KB896422 is installed" />
					<criterion test_ref="wft-145" comment="the version of srv.sys is less than 5.0.2195.7044" />
					<criterion test_ref="wrt-539" negate="true" comment="Win2K/XP/2003 service pack 5 (or later) is installed" />
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL468" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>ISA Server 2000</product>
			</affected>
			<dates>
				<submitted date="2005-06-23">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-06-29">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.</description>
			<reference source="CVE">CAN-2005-1216</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-11" comment="ISA Server 2000 SP2 (or earlier) is installed" />
					<criterion test_ref="wft-81" comment="the version of w3proxy.exe is less than 3.0.1200.430" />
					<criterion test_ref="wrt-52" negate="true" comment="the patch KB899753 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL471" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01</product>
			</affected>
			<dates>
				<submitted date="2003-08-29">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka &quot;Encoded Characters Information Disclosure.&quot;</description>
			<reference source="CVE">CVE-2002-1186</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-293" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3510.1100" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL472" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the &quot;Function Pointer Override Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0815</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL477" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-01-20">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.</description>
			<reference source="CVE">CAN-2003-0904</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
					<criterion test_ref="wft-34" comment="the version of exprox.dll is less than 6.5.6980.57" />
					<criterion test_ref="wrt-109" negate="true" comment="the patch KB832759 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-21" comment="this is a front-end server providing Outlook Web Access" />
					<criterion test_ref="ukn-22" comment="the back-end server is Exchange Server 2003 running on Windows 2003" />
					<criterion test_ref="wrt-106" negate="true" comment="HTTP connection reuse is disabled" />
					<criterion test_ref="ukn-20" comment="Kerberos is disabled on the virtual server that hosts OWA on the Exchange Server 2003 back-end server" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL478" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Security and Acceleration Server 2000</product>
			</affected>
			<dates>
				<submitted date="2004-01-13">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
			<reference source="CVE">CAN-2003-0819</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-105" comment="ISA Server 2000 is installed" />
					<criterion test_ref="wft-33" comment="the version of h32fltr.dll is less than 3.0.1200.291" />
					<criterion test_ref="wrt-112" negate="true" comment="the patch q816458 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-108" comment="H.323 filter is enabled" />
					<criterion test_ref="wrt-107" comment="Microsoft Firewall Service is not disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL479" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the &quot;Script URLs Cross Domain&quot; vulnerability.</description>
			<reference source="CVE">CAN-2003-0816</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL483" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka &quot;Server Side Include Web Pages Buffer Overrun.&quot;</description>
			<reference source="CVE">CAN-2003-0224</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-296" comment="File %windir%\system32\inetsrv\ssinc.dll version is less than 5.0.2195.6624" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL484" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2004-09-15">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<modified date="2004-09-16" comment="filling out initial submission.">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</modified>
				<modified date="2004-09-16" comment="Added service pack 3 test">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</modified>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wft-492 - wft-492 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka &quot;Unchecked Buffer in SQLXML ISAPI Extension.</description>
			<reference source="CVE">CVE-2002-0186</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wrt-101" comment="MDAC 2.6 is installed" />
					<criterion test_ref="wft-491" comment="the version of sqlisapi.dll is less than 2000.80.309.0" />
					<criterion test_ref="wft-492" comment="the version of sqlservr.exe is less than 2000.80.760.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL489" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2004-09-15">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<modified date="2004-09-16" comment="Input of initial submission.">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</modified>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wft-492 - wft-492 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka &quot;Unchecked Buffer in SQLXML ISAPI Extension.&quot;</description>
			<reference source="CVE">CVE-2002-0186</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-460" comment="SQL Server 2000 installed" />
					<criterion test_ref="wrt-102" comment="MDAC 2.7 (RTM) is installed" />
					<criterion test_ref="wft-491" comment="the version of sqlisapi.dll is less than 2000.80.309.0" />
					<criterion test_ref="wft-492" comment="the version of sqlservr.exe is less than 2000.80.760.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL490" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a &quot;%01&quot; character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the &quot;Improper URL Canonicalization Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1025</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL491" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a &quot;%01&quot; character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the &quot;Improper URL Canonicalization Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1025</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL494" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2003-12-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.</description>
			<reference source="CVE">CAN-2003-0605</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL495" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka &quot;Encoded Characters Information Disclosure.&quot;</description>
			<reference source="CVE">CVE-2002-1186</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL500" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Access Service (RAS)</product>
			</affected>
			<dates>
				<submitted date="2003-06-08">
					<contributor organization="The MITRE Corporation">Matt Busby</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the &quot;Registry Permissions&quot; vulnerabilities.</description>
			<reference source="CVE">CAN-2001-0045</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" />
					<criterion test_ref="cmp-1012" comment="For Terminal Server" />
					<criterion test_ref="wrt-454" negate="true" comment="Patch Q265714 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-258" comment="RAS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL507" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
			<reference source="CVE">CAN-2004-0566</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-268" comment="the version of mshtml.dll is less than 6.00.2743.600" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL508" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
			<reference source="CVE">CAN-2003-0817</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL509" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
			<reference source="CVE">CAN-2003-1048</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-279" comment="the version of mshtml.dll is less than 5.00.3819.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL510" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a &quot;%01&quot; character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the &quot;Improper URL Canonicalization Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1025</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-91" comment="the version of mshtml.dll is less than 5.00.3813.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL511" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a &quot;%01&quot; character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the &quot;Improper URL Canonicalization Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1025</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL512" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a &quot;%01&quot; character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the &quot;Improper URL Canonicalization Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1025</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-93" comment="the version of mshtml.dll is less than 6.00.2737.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL513" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a &quot;%01&quot; character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the &quot;Improper URL Canonicalization Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1025</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-94" comment="the version of mshtml.dll is less than 6.00.2800.1400" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL515" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
			<reference source="CVE">CAN-2004-0566</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL517" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
			<reference source="CVE">CAN-2003-1048</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-266" comment="the version of mshtml.dll is less than 6.00.3790.191" />
					<criterion test_ref="wrt-237" negate="true" comment="the patch kb867801 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL519" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifiying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a &quot;URL:&quot; prepended to a &quot;ms-its&quot; protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
			<reference source="CVE">CAN-2004-0549</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-268" comment="the version of mshtml.dll is less than 6.00.2743.600" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL520" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
			<reference source="CVE">CAN-2003-0817</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL525" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Data Access Compnents 2.5</product>
			</affected>
			<dates>
				<submitted date="2004-01-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
			<reference source="CVE">CVE-2003-0903</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-100" comment="MDAC 2.5 is installed" />
					<criterion test_ref="wft-40" comment="the version of odbcbcp.dll is less than 3.70.11.46" />
					<criterion test_ref="wft-35" comment="the version of sqlsrv32.dll is less than 3.70.11.46" />
					<criterion test_ref="wrt-110" negate="true" comment="the patch q832483 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL526" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a &quot;%01&quot; character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the &quot;Improper URL Canonicalization Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1025</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-95" comment="the version of mshtml.dll is less than 6.00.3790.118" />
					<criterion test_ref="wrt-140" negate="true" comment="the patch q832894 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL527" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the &quot;Function Pointer Drag and Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1027</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL529" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the &quot;Function Pointer Drag and Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1027</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL530" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the &quot;Function Pointer Drag and Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1027</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-91" comment="the version of mshtml.dll is less than 5.00.3813.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL531" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the &quot;Function Pointer Drag and Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1027</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL532" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the &quot;Function Pointer Drag and Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1027</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-93" comment="the version of mshtml.dll is less than 6.00.2737.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL534" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the &quot;Function Pointer Drag and Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1027</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-94" comment="the version of mshtml.dll is less than 6.00.2800.1400" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL539" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-06">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Font Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0571.</description>
			<reference source="CVE">CAN-2004-0901</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-33" comment="The version of mswrd664.wpc OR wmswrd632.wpc is less than 2004.10.25.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL542" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka &quot;Malformed PNG Image File Failure.&quot;</description>
			<reference source="CVE">CVE-2002-1185</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL543" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
			<reference source="CVE">CAN-2003-0817</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL548" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
			<reference source="CVE">CAN-2003-0817</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL549" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
			<reference source="CVE">CAN-2003-0817</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL553" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Data Access Compnents 2.6</product>
			</affected>
			<dates>
				<submitted date="2004-01-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
			<reference source="CVE">CVE-2003-0903</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-101" comment="MDAC 2.6 is installed" />
					<criterion test_ref="wft-41" comment="the version of odbcbcp.dll is less than 2000.80.747.0" />
					<criterion test_ref="wft-36" comment="the version of sqlsrv32.dll is less than 2000.80.747.0" />
					<criterion test_ref="wrt-110" negate="true" comment="the patch q832483 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL556" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-01-29" comment="Added Windows XP 64-bit to the list of affected platforms">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
			<reference source="CVE">CAN-2003-0817</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL566" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-01-29" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
			<reference source="CVE">CAN-2003-0817</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" />
					<criterion test_ref="wrt-60" negate="true" comment="the patch q824145 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL573" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2005-05-04">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
			<reference source="CVE">CAN-2005-0063</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-591" comment="the version of shell32.dll is less than 6.0.2900.2620" />
					<criterion test_ref="wrt-435" negate="true" comment="the patch  KB893086 is installed " />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL575" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Windows Workstation Service</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file (&quot;NetSetup.LOG&quot;), as demonstrated using the NetAddAlternateComputerName API.</description>
			<reference source="CVE">CAN-2003-0812</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-8" comment="the version of wkssvc.dll is less than 5.00.2195.6862" />
					<criterion test_ref="wrt-86" negate="true" comment="the patch q828748 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-71" comment="the workstation service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL582" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Virtual Machine (VM)</product>
			</affected>
			<dates>
				<submitted date="2004-04-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.</description>
			<reference source="CVE">CAN-2002-1258</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wft-302" comment="the version of msjava.dll is less than 5.0.3809.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL585" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word 97</product>
			</affected>
			<dates>
				<submitted date="2003-11-19">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-04-11" comment="modified wft-17 - wft-17 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<modified date="2005-04-20" comment="Corrected unknown test">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
			</dates>
			<description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the &quot;Macro names&quot; data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0820</reference>
			<status>INTERIM</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="ukn-10" comment="Word 97 is installed" />
					<criterion test_ref="wft-17" comment="the version of winword.exe is less than 8.0.0.9315" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL586" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word 98</product>
			</affected>
			<dates>
				<submitted date="2003-11-19">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the &quot;Macro names&quot; data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0820</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="ukn-11" comment="Word 98 is installed" />
					<criterion test_ref="wft-18" comment="the version of winword.exe is less than 8.0.0.9716" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL587" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2005-05-04">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
			<reference source="CVE">CAN-2005-0063</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-183" comment="Windows Server 2003 64-Bit Edition or Windows XP 64-Bit Edition Version 2003 " />
					<criterion test_ref="wft-589" comment="the version of shell32.dll is less than 6.0.3790.274" />
					<criterion test_ref="wrt-434" negate="true" comment="the patch  KB893086 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL588" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2003-12-18">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-01-29" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027.</description>
			<reference source="CVE">CAN-2003-0823</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" />
					<criterion test_ref="wrt-60" negate="true" comment="the patch q824145 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL591" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<dates>
				<submitted date="2003-12-09">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-14" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
			<reference source="CVE">CAN-2003-0824</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-12" comment="the version of shtml.dll is less than 4.0.2.7523" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-33" comment="FrontPage Server Extensions 2000 are enabled (WinNT)" />
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL594" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>MSN Messenger</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
			<reference source="CVE">CAN-2004-0597</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-195" negate="true" comment="MSN Messenger 6.2.0205 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL605" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Services for UNIX</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
			<reference source="CVE">CAN-2005-1205</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-167" comment="a vulnerable version of telnet.exe exists" />
					<criterion test_ref="wrt-27" negate="true" comment="the patch KB896428 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL606" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<dates>
				<submitted date="2003-12-09">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-14" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
			<reference source="CVE">CAN-2003-0824</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
					<criterion test_ref="wft-12" comment="the version of shtml.dll is less than 4.0.2.7523" />
					<criterion test_ref="wrt-88" negate="true" comment="the patch q810217 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" />
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL608" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6.0 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>The legacy &lt;script&gt; data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose &quot;src&quot; attribute redirects to a local file.</description>
			<reference source="CVE">CVE-2002-0648</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="cmp-179" comment="a vulnerable version of mshtml.dll exisits" />
					<criterion test_ref="wrt-62" negate="true" comment="the patch kb883939 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL625" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2002</product>
			</affected>
			<dates>
				<submitted date="2003-12-09">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-14" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-09-14" comment="XP SP2 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
			</dates>
			<description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
			<reference source="CVE">CAN-2003-0824</reference>
			<status>INTERIM</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-77" comment="Windows NT, 2000, or XP is installed" />
					<criterion test_ref="ukn-13" comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" />
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL629" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the &quot;Function Pointer Drag and Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1027</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-95" comment="the version of mshtml.dll is less than 6.00.3790.118" />
					<criterion test_ref="wrt-140" negate="true" comment="the patch q832894 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL630" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the &quot;Travel Log Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1026</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL636" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Excel 2000</product>
			</affected>
			<dates>
				<submitted date="2003-11-19">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2005-04-11" comment="modified wft-15 - wft-15 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
			<reference source="CVE">CAN-2003-0821</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-137" comment="Excel 2000 is installed" />
					<criterion test_ref="wft-15" comment="the version of excel.exe is less than 9.0.0.8216" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL643" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the &quot;Travel Log Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1026</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL644" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>MDAC 2.8</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an &quot;unchecked buffer&quot; and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the &quot;License Logging Service Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0050</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wrt-96" negate="true" comment="the patch kb885834 is installed (Hotfix key)" />
					<criterion test_ref="wft-393" comment="the version of Llssrv.exe is less than 4.0.1381.33632" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-344" comment="license logging service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL653" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<dates>
				<submitted date="2004-02-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
			<reference source="CVE">CAN-2003-0818</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-49" comment="the version of msasn1.dll is less than 5.0.2195.6823" />
					<criterion test_ref="wrt-99" negate="true" comment="the patch kb828028 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL668" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word 2002</product>
			</affected>
			<dates>
				<submitted date="2003-11-19">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-04-11" comment="modified wft-22 - wft-22 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the &quot;Macro names&quot; data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0820</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-133" comment="Word 2002 is installed" />
					<criterion test_ref="wft-22" comment="the version of winword.exe is less than 10.0.5815.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL675" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Excel 97</product>
			</affected>
			<dates>
				<submitted date="2003-11-19">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-04-11" comment="modified wft-14 - wft-14 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
			</dates>
			<description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
			<reference source="CVE">CAN-2003-0821</reference>
			<status>INTERIM</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="ukn-12" comment="Excel 97 is installed" />
					<criterion test_ref="wft-14" comment="the version of excel.exe is less than 8.00.01.9904" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL681" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>NetDDE Agent</product>
			</affected>
			<dates>
				<submitted date="2004-08-24">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via &quot;shatter&quot; style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka &quot;Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation.&quot;</description>
			<reference source="CVE">CVE-2002-1230</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-474" comment="the version of user32.dll is less than 4.0.1381.7177" />
					<criterion test_ref="wft-475" comment="the version of gdi32.dll is less than 4.0.1381.7177" />
					<criterion test_ref="wft-476" comment="the version of winsrv.dll is less than 4.0.1381.7202" />
					<criterion test_ref="wft-477" comment="the version of win32k.sys is less than 4.0.1381.7207" />
					<criterion test_ref="wrt-502" negate="true" comment="Patch Q328310 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL682" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Agent</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<modified date="2005-06-24" comment="added cve description">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</description>
			<reference source="CVE">CAN-2005-1214</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-117" comment="the version of agentdpv.dll is less than 2.0.0.3423" />
					<criterion test_ref="wrt-64" negate="true" comment="the patch kb890046 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL684" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-06-07">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-06-08">DRAFT</status_change>
				<status_change date="2005-06-29">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Review blocked recipient list</description>
			<reference source="MISC">1.2.7</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<oval:notes>
				<oval:note>Corresponds to item 1.2.7 in the Exchange 2003 Benchmark</oval:note>
			</oval:notes>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-6" comment="Review list of blocked recipients" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL685" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<modified date="2005-02-09" comment="modified cmp-35 - Corrected test comment">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wrt-35 - wrt-35 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Table Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0901</description>
			<reference source="CVE">CAN-2004-0571</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-300" comment="the version of mswrd6.wpc is less than 10.0.803.2" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-35" comment="Word for Windows 6.0 Converter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL687" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the &quot;Travel Log Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1026</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-91" comment="the version of mshtml.dll is less than 5.00.3813.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL688" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-06-07">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-06-08">DRAFT</status_change>
				<status_change date="2005-06-29">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Review the global accept and deny lists.</description>
			<reference source="MISC">1.2.1</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<oval:notes>
				<oval:note>Corresponds to item 1.2.1 in the Exchange 2003 Benchmark</oval:note>
			</oval:notes>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-2" comment="Review global accept list" />
					<criterion test_ref="wat-3" comment="Review global deny list" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL689" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the &quot;Travel Log Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1026</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL690" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka &quot;Temporary Internet Files folders Name Reading.&quot;</description>
			<reference source="CVE">CVE-2002-1188</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL695" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Excel 2002</product>
			</affected>
			<dates>
				<submitted date="2003-11-19">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-04-11" comment="modified wft-16 - wft-16 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
			<reference source="CVE">CAN-2003-0821</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-138" comment="Excel 2002 is installed" />
					<criterion test_ref="wft-16" comment="the version of excel.exe is less than 10.0.5815.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL699" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<dates>
				<submitted date="2003-03-04">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2003-03-05" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions 2000 and 2002 allows remote attackers to execute arbitrary code via a certain chunked encoded request.</description>
			<reference source="CVE">CAN-2003-0822</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists" />
				</software>
				<configuration>
					<criterion test_ref="wrt-33" comment="FrontPage Server Extensions 2000 are enabled (WinNT)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL704" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<dates>
				<submitted date="2004-02-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
			<reference source="CVE">CVE-2003-0825</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" />
					<criterion test_ref="wft-98" comment="the version of wins.exe is less than 5.0.2195.6870" />
					<criterion test_ref="wrt-97" negate="true" comment="the patch kb830352 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL710" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<modified date="2005-04-21" comment="modified wrt-159 - unchecked value">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the &quot;DHTML Method Heap Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0055</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" />
					<criterion test_ref="wft-500" comment="the version of mshtml.dll is less than 6.0.2900.2604" />
					<criterion test_ref="wrt-159" negate="true" comment="the patch kb867282 is installed (XP SP2 Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL712" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Animated Cursor</product>
			</affected>
			<dates>
				<submitted date="2005-01-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>The Windows Animated Cursor (ANI) in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to cause a denial of service (kernel crash or resource consumption) via the (1) frame number or (2) rate number set to zero</description>
			<reference source="CVE">CAN-2004-1305</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-351" comment="the version of user32.dll is less than 4.0.1381.7342" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL713" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Hyperlink Object Library</product>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0057</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-369" comment="the version of hlink.dll is less than 5.2.3790.227" />
					<criterion test_ref="wrt-78" negate="true" comment="the patch kb888113 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL721" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Web Client Service</product>
			</affected>
			<dates>
				<submitted date="2005-07-15">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-07-27">DRAFT</status_change>
			</dates>
			<description>Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.</description>
			<reference source="CVE">CAN-2005-1207</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" />
					<criterion test_ref="wrt-3" negate="true" comment="a Win2K/XP/2003 service pack is installed" />
					<criterion test_ref="wft-161" comment="the version of webclnt.dll is less than 5.2.3790.316" />
					<criterion test_ref="wrt-124" negate="true" comment="the patch kb896426 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL733" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-12-18">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-01-21" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-04" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027.</description>
			<reference source="CVE">CAN-2003-0823</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL743" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<dates>
				<submitted date="2003-03-04">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2003-03-05" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions 2000 and 2002 allows remote attackers to execute arbitrary code via a certain chunked encoded request.</description>
			<reference source="CVE">CAN-2003-0822</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists" />
					<criterion test_ref="wrt-88" negate="true" comment="the patch q810217 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL745" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the &quot;Travel Log Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1026</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-93" comment="the version of mshtml.dll is less than 6.00.2737.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL751" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Data Access Compnents 2.7</product>
			</affected>
			<dates>
				<submitted date="2004-01-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
			<reference source="CVE">CVE-2003-0903</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-100" comment="MDAC 2.7 is installed and a vulnerable version of sqlsrv32.dll and odbcbcp.dll exists" />
					<criterion test_ref="wrt-110" negate="true" comment="the patch q832483 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL762" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft SharePoint Team Services</product>
			</affected>
			<dates>
				<submitted date="2003-12-09">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-01-14" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-09-14" comment="XP SP2 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
			</dates>
			<description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
			<reference source="CVE">CAN-2003-0824</reference>
			<status>INTERIM</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-78" comment="Windows 2000, XP, or 2003 is installed" />
					<criterion test_ref="ukn-13" comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-34" comment="SharePoint Team Services are enabled (2K, XP, 2003)" />
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL768" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-06-08">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-06-08">DRAFT</status_change>
				<status_change date="2005-06-29">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Review whether anonymous HTTP access is allowed</description>
			<reference source="MISC">2.1.2</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<oval:notes>
				<oval:note>Corresponds to item 2.1.2 in the Exchange 2003 Benchmark</oval:note>
			</oval:notes>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wwt-2" comment="Review whether anonymous HTTP access is allowed through IIS" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL769" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Color Management Module </product>
			</affected>
			<dates>
				<submitted date="2005-08-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-08-03">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1219</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-330" comment="Windows Server 2003 with Service Pack 1" />
					<criterion test_ref="wft-573" comment="the version of mscms.dll is less than 5.2.3790.2476" />
					<criterion test_ref="wrt-128" negate="true" comment="the patch KB901214 is installed " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL770" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<modified date="2005-06-24" comment="added description">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file. </description>
			<reference source="CVE">CAN-2005-1211</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="cmp-158" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506" />
					<criterion test_ref="wrt-62" negate="true" comment="the patch kb883939 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-59" comment="PNG image rendering enabled in Internet Explorer" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL774" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the &quot;Travel Log Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1026</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-94" comment="the version of mshtml.dll is less than 6.00.2800.1400" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL775" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Data Access Compnents 2.8</product>
			</affected>
			<dates>
				<submitted date="2004-01-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
			<reference source="CVE">CVE-2003-0903</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-104" comment="MDAC 2.8 (RTM) is installed" />
					<criterion test_ref="wft-44" comment="the version of odbcbcp.dll is less than 2000.85.1025.0" />
					<criterion test_ref="wft-39" comment="the version of sqlsrv32.dll is less than 2000.85.1025.0" />
					<criterion test_ref="cmp-103" comment="the patch q832483 is not installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL776" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>The legacy &lt;script&gt; data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose &quot;src&quot; attribute redirects to a local file.</description>
			<reference source="CVE">CVE-2002-0648</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-116" comment="the version of mshtml.dll is less than 5.0.3828.2700" />
					<criterion test_ref="wrt-62" negate="true" comment="the patch kb883939 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL777" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Client Server Runtime System (CSRSS)</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>The Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
			<reference source="CVE">CAN-2005-0551</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-579" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL778" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<dates>
				<submitted date="2004-12-28">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program</description>
			<reference source="CVE">CAN-2004-0894</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-328" comment="the version of lsasrv.dll is less than 5.0.2195.6987" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL779" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-11-30">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger</description>
			<reference source="CVE">CAN-2003-0112</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-76" comment="The version of Ntoskrnl.exe is less than 5.1.2600.160" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL782" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<modified date="2005-06-24" comment="updated description ">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file. </description>
			<reference source="CVE">CAN-2005-1211</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="cmp-179" comment="a vulnerable version of mshtml.dll exisits" />
					<criterion test_ref="wrt-62" negate="true" comment="the patch kb883939 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-59" comment="PNG image rendering enabled in Internet Explorer" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL784" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Services for UNIX</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1205</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-49" negate="true" comment="the patch KB896428 for Services for UNIX is installed" />
					<criterion test_ref="cmp-47" comment="Services for UNIX is instaled and a vulnerable version of telnet.exe exists" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL789" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka &quot;URL Parsing Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0554</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="cmp-292" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" />
					<criterion test_ref="wrt-440" negate="true" comment="the patch kb890923  is installed (XP Win2K Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL794" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Script Engine for JScript v5.1</product>
			</affected>
			<dates>
				<submitted date="2004-03-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-08-24" comment="Added patch information to definition">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0010</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-120" comment="the version of jscript.dll is less than 5.1.0.8513" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
					<criterion test_ref="wrt-500" negate="true" comment="the patch js56nen.exe (5.1.0.8513 version) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-76" comment="active scripting is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL795" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Script Engine for JScript v5.5</product>
			</affected>
			<dates>
				<submitted date="2004-03-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-08-24" comment="Added patch information to definition">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0010</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-121" comment="the version of jscript.dll is less than 5.5.0.8513" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
					<criterion test_ref="wrt-501" negate="true" comment="the patch js56nen.exe (5.5.0.8513 version) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-76" comment="active scripting is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL796" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<dates>
				<submitted date="2004-02-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
			<reference source="CVE">CAN-2003-0818</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-108" comment="the version of msasn1.dll is less than 5.0.2195.6824" />
					<criterion test_ref="wrt-99" negate="true" comment="the patch kb828028 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL797" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<dates>
				<submitted date="2004-02-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
			<reference source="CVE">CAN-2003-0818</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-53" comment="a vulnerable version of msasn1.dll exists" />
					<criterion test_ref="wrt-99" negate="true" comment="the patch kb828028 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL799" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<dates>
				<submitted date="2004-02-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
			<reference source="CVE">CAN-2003-0818</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-106" comment="the version of msasn1.dll is less than 5.2.3790.88" />
					<criterion test_ref="wrt-99" negate="true" comment="the patch kb828028 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL800" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<dates>
				<submitted date="2004-02-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
			<reference source="CVE">CVE-2003-0825</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-110" comment="the version of wins.exe is less than 4.0.1381.7255" />
					<criterion test_ref="wrt-97" negate="true" comment="the patch kb830352 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL801" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<dates>
				<submitted date="2004-02-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
			<reference source="CVE">CVE-2003-0825</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-111" comment="the version of wins.exe is less than 4.0.1381.33554" />
					<criterion test_ref="wrt-97" negate="true" comment="the patch kb830352 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL802" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<dates>
				<submitted date="2004-02-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
			<reference source="CVE">CVE-2003-0825</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-112" comment="the version of wins.exe is less than 5.2.3790.99" />
					<criterion test_ref="wrt-97" negate="true" comment="the patch kb830352 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL805" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-02-03">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the &quot;Travel Log Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-1026</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-95" comment="the version of mshtml.dll is less than 6.00.3790.118" />
					<criterion test_ref="wrt-140" negate="true" comment="the patch q832894 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL842" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Media Services</product>
			</affected>
			<dates>
				<submitted date="2004-03-09">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-25">INTERIM</status_change>
			</dates>
			<description>Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.</description>
			<reference source="CVE">CVE-2003-0905</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-59" comment="Windows Media Services 4.1 is installed on Microsoft Windows 2000 Server" />
					<criterion test_ref="wft-46" comment="the version of nscm.exe is less than 4.1.0.3934" />
					<criterion test_ref="wft-47" comment="the version of nspmon.exe is less than 4.1.0.3934" />
					<criterion test_ref="wrt-149" negate="true" comment="the patch kb832359 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-3" negate="true" comment="configured to only offer streaming media over unicast" />
					<criterion test_ref="wrt-160" negate="true" comment="the Windows Media Station service is disabled" />
					<criterion test_ref="wrt-161" negate="true" comment="the Windows Media Monitor service is disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL843" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Outlook</product>
			</affected>
			<dates>
				<submitted date="2004-03-09">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
				<modified date="2005-01-13" comment="modified wft-130 - Added path to the end of the registry key specified in the first component of the file path">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs</description>
			<reference source="CVE">CVE-2004-0121</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-197" comment="Outlook 2002 is installed" />
					<criterion test_ref="wft-130" comment="the version of outlook.exe is less than 10.00.5709.0000" />
					<criterion test_ref="wrt-198" negate="true" comment="the patch kb828040 is installed" />
					<criterion test_ref="wrt-199" negate="true" comment="Microsoft Office XP Service Pack 3 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL844" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>MSN Messenger</product>
			</affected>
			<dates>
				<submitted date="2004-03-09">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-03-25">INTERIM</status_change>
				<modified date="2004-03-30" comment="Fixed the path for both versions of the file to look at the correct registry key to determine the location of the 'Program Files' folder..  ">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.</description>
			<reference source="CVE">CVE-2004-0122</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-68" comment="Microsoft MSN Messenger 6.0 or 6.1 (but less than 6.1.0211) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL882" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the &quot;MHTML URL Processing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0380</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-170" comment="Outlook Express 5.5 SP2 is installed" />
					<criterion test_ref="wft-182" comment="the version of inetcomm.dll is less than 5.50.4939.300" />
					<criterion test_ref="wrt-188" negate="true" comment="the patch kb837009 is installed (installed components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL883" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
			<reference source="CVE">CAN-2003-0533</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-192" comment="the version of lsasrv.dll is less than 5.0.2195.6902" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL885" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Secure Sockets Layer (SSL)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
			<reference source="CVE">CAN-2004-0120</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-172" comment="the version of schannel.dll is less than 5.2.3790.132" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL886" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Secure Sockets Layer (SSL)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
			<reference source="CVE">CAN-2004-0120</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-130" comment="a vulnerable version of schannel.dll exists" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL889" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Private Communications Transport (PCT)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="added cmp-66">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
			<reference source="CVE">CAN-2003-0719</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-130" comment="a vulnerable version of schannel.dll exists" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
					<criterion test_ref="wrt-165" negate="true" comment="PCT support is disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL890" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Local Descriptor Table (LDT)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</description>
			<reference source="CVE">CAN-2003-0910</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-191" comment="the version of wintrust.dll is less than 5.131.2195.6824" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL892" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Secure Sockets Layer (SSL)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
			<reference source="CVE">CAN-2004-0120</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-171" comment="the version of schannel.dll is less than 5.1.2195.6899" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL893" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-20">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CAN-2003-0352 (Blaster/Nachi), CAN-2003-0715, and CAN-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
			<reference source="CVE">CAN-2003-0813</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-186" comment="the version of rpcrt4.dll is less than 5.0.2195.6904" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL894" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-20">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
			</dates>
			<description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CAN-2003-0352 (Blaster/Nachi), CAN-2003-0715, and CAN-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
			<reference source="CVE">CAN-2003-0813</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-17" comment="a vulnerable version of rpcrt4.dll exists on Server 2003" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL895" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows logon process (winlogon)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
			<reference source="CVE">CAN-2003-0806</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-136" comment="a vulnerable version of msgina.dll exists on NT" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-196" comment="machine is a member of a domain" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL896" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows logon process (winlogon)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
			<reference source="CVE">CAN-2003-0806</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-133" comment="the version of msgina.dll is less than 5.1.2600.136" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-196" comment="machine is a member of a domain" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL897" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
				<product>Windows Metafile (WMF)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1allows remote attackers to execute arbitrary code via a malformed WNF or EMF image.</description>
			<reference source="CVE">CAN-2003-0906</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-89" comment="a vulnerable version of mf3216.dll exists on NT" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL898" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
			<reference source="CVE">CAN-2003-0533</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-143" comment="a vulnerable version of lsasrv.dll exists on XP" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL900" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-20">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CAN-2003-0352 (Blaster/Nachi), CAN-2003-0715, and CAN-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
			<reference source="CVE">CAN-2003-0813</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-1" comment="a vulnerable version of rpcrt4.dll exists on XP" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL901" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>COM Internet Services</product>
			</affected>
			<dates>
				<submitted date="2005-02-15">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2005-02-16" comment="Added compound statement to include three platforms">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-02-23">DRAFT</status_change>
				<status_change date="2005-03-23">INTERIM</status_change>
				<status_change date="2005-04-13">ACCEPTED</status_change>
			</dates>
			<description>Windows 2000, XP, and Server 2003 does not properly &quot;validate the use of memory regions&quot; for COM structured storage files, which allows attackers to execute arbitrary code, aka the &quot;COM Structured Storage Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0047</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-389" comment="the version of ole32.dll is less than 5.2.3790.250" />
					<criterion test_ref="wrt-91" negate="true" comment="the patch KB873333 is installed" />
					<criterion test_ref="cmp-187" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL903" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Private Communications Transport (PCT)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
			<reference source="CVE">CAN-2003-0719</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-170" comment="the version of schannel.dll is less than 4.87.1964.1880" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
					<criterion test_ref="wrt-165" negate="true" comment="PCT support is disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL904" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-14">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<modified date="2004-05-12" comment="Added a criterion to the configuration section to see if the HCP protocol is registered.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.</description>
			<reference source="CVE">CAN-2003-0907</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-303" comment="the version of helpctr.exe is less than 5.2.3790.125" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-12" negate="true" comment="the HCP Protocol is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL906" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Agent</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<modified date="2005-06-24" comment="added description">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page. </description>
			<reference source="CVE">CAN-2005-1214</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-200" comment=" a vulnerable version of agentdpv exists" />
					<criterion test_ref="wrt-64" negate="true" comment="the patch kb890046 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL907" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>H.323</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
			<reference source="CVE">CAN-2004-0117</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-150" comment="the version of h323.tsp is less than 5.0.2195.6901" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL909" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the &quot;System file listing privilege elevation&quot; vulnerability.</description>
			<reference source="CVE">CVE-2001-0507</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-304" comment="File %windir%\System32\w3svc.dll is less than 4.2.769.1" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL911" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Local Descriptor Table (LDT)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</description>
			<reference source="CVE">CAN-2003-0910</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-190" comment="the version of wintrust.dll is less than 5.131.1880.14" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL912" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<modified date="2005-01-11" comment="modified wft-305 - changed the version of msw3prt.dll to test against from 5.5.2195.3649 to 5.0.2195.3649">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the &quot;System file listing privilege elevation&quot; vulnerability</description>
			<reference source="CVE">CVE-2001-0507</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-305" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.3649" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL913" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>In IIS, remote attackers can obtain source code for ASP files by appending &quot;::$DATA&quot; to the URL.</description>
			<reference source="CVE">CVE-1999-0278</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-306" comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" />
					<criterion test_ref="wrt-347" negate="true" comment="Service Pack 6 Installed (or later)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL915" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.</description>
			<reference source="CVE">CVE-1999-0874</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-306" comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" />
					<criterion test_ref="wrt-347" negate="true" comment="Service Pack 6 Installed (or later)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL916" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-06-06">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-06-08">DRAFT</status_change>
				<status_change date="2005-06-29">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>IIS HTTP service uses Integrated Windows authentication.</description>
			<reference source="MISC">2.1.4</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<oval:notes>
				<oval:note>Corresponds to item 2.1.4 in the Exchange 2003 Benchmark</oval:note>
			</oval:notes>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wwt-1" comment="Integrated Windows Authentication is used for all directories" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL919" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
			<reference source="CVE">CAN-2003-0533</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-157" comment="the version of lsasrv.dll is less than 5.2.3790.134" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL920" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5, Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2004-04-29">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.</description>
			<reference source="CVE">CVE-2001-0002</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-901" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-307" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4613.1700" />
					<criterion test_ref="wrt-351" negate="true" comment="Patch Q286045 Installed" />
					<criterion test_ref="wrt-352" negate="true" comment="Patch Q295106 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL921" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-04-29">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<modified date="2004-09-22" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the &quot;File Execution Vulnerability.&quot;</description>
			<reference source="CVE">CVE-2001-0727</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-353" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-308" comment="the version of mshtml.dll is less than 6.0.2712.0300" />
					<criterion test_ref="wrt-354" negate="true" comment="Patch Q313675 Installed" />
					<criterion test_ref="wrt-355" negate="true" comment="Patch Q316059.exe Installed" />
					<criterion test_ref="wrt-356" negate="true" comment="Patch Q319282 Installed" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-902" comment="File Downloads Not Disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL922" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-04-29">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<modified date="2004-09-22" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.</description>
			<reference source="CVE">CAN-2003-0344</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL923" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-04-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<modified date="2004-09-22" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka &quot;Zone Spoofing through Malformed Web Page&quot; vulnerability.</description>
			<reference source="CVE">CVE-2002-0190</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-353" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-310" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2716.2200" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL924" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
			<reference source="CVE">CAN-2004-0123</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-194" comment="the version of msasn1.dll is less than 5.2.3790.139" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL925" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-04-29">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<modified date="2004-09-22" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated.</description>
			<reference source="CVE">CVE-2002-0022</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-353" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-311" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-355" negate="true" comment="Patch Q316059.exe Installed" />
					<criterion test_ref="wrt-356" negate="true" comment="Patch Q319282 Installed" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-903" comment="Run ActiveX Controls and Plugins Not Disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL926" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-04-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<modified date="2004-09-22" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</description>
			<reference source="CVE">CAN-2003-0113</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" />
					<criterion test_ref="wft-312" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4927.2100" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL927" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a &quot;Translate: f&quot; header, aka the &quot;Specialized Header&quot; vulnerability.</description>
			<reference source="CVE">CVE-2000-0778</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL929" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka &quot;Out of Process Privilege Elevation.&quot;</description>
			<reference source="CVE">CAN-2002-0869</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-329" comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL930" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
				<modified date="2005-01-11" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka &quot;Out of Process Privilege Elevation.&quot;</description>
			<reference source="CVE">CAN-2002-0869</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL931" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
				<modified date="2005-01-11" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka &quot;Script Source Access Vulnerability.&quot;</description>
			<reference source="CVE">CVE-2002-1180</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL932" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-17">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</description>
			<reference source="CVE">CAN-1999-0736</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-331" comment="File %windir%\System32\code.asp is less than 4.0.1381.279" />
					<criterion test_ref="wrt-386" negate="true" comment="Patch Q232449 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL933" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-17">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.</description>
			<reference source="CVE">CAN-2003-0226</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-332" comment="File %windir%\System32\w3svc.dll is less than 5.0.2195.6672" />
					<criterion test_ref="wrt-387" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL934" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-06-07">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-06-08">DRAFT</status_change>
				<status_change date="2005-06-29">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Review block-list Exception list entries</description>
			<reference source="MISC">1.2.3</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-4" comment="Review block-list exception values" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL936" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</description>
			<reference source="CVE">CAN-2003-0227</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-333" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3931" />
					<criterion test_ref="wrt-388" negate="true" comment="Patch KB817772 Installed" />
					<criterion test_ref="wrt-389" negate="true" comment="Patch KB822343 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL938" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.</description>
			<reference source="CVE">CAN-2003-0349</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-334" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3932" />
					<criterion test_ref="wrt-389" negate="true" comment="Patch KB822343 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL942" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
				<modified date="2005-01-11" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors</description>
			<reference source="CVE">CAN-2002-1181</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL944" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.</description>
			<reference source="CVE">CAN-2002-1181</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-329" comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL946" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>H.323</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
			<reference source="CVE">CAN-2004-0117</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-151" comment="the version of h323.tsp is less than 5.2.3790.132" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL948" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-04-29">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<modified date="2004-09-22" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the &quot;File Download Dialog Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-0309</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL951" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Private Communications Transport (PCT)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
			<reference source="CVE">CAN-2003-0719</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-171" comment="the version of schannel.dll is less than 5.1.2195.6899" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
					<criterion test_ref="wrt-165" negate="true" comment="PCT support is disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL952" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>SNMP</product>
			</affected>
			<dates>
				<submitted date="2004-05-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<modified date="2005-03-14" comment="Switched the service pack test from wrt-373 to wrt-539.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.</description>
			<reference source="CVE">CVE-1999-0815</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-313" comment="File %windir%\system32\snmp.exe is less than 4.0.1381.133" />
					<criterion test_ref="wrt-539" negate="true" comment="Win2K/XP/2003 service pack 5 (or later) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL955" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-20">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
			<reference source="CVE">CAN-2004-0116</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-189" comment="the version of rpcss.dll is less than 5.0.2195.6906" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL956" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing &quot;..&quot; (dot dot) sequences and a filename that ends in &quot;::&quot; which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CAN-2004-0475.</description>
			<reference source="CVE">CAN-2003-1041</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1071" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL957" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-20">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
			</dates>
			<description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
			<reference source="CVE">CAN-2004-0116</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-16" comment="a vulnerable version of rpcss.dll exists on Server 2003" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL958" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-20">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
			<reference source="CVE">CAN-2004-0116</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-10" comment="a vulnerable version of rpcss.dll exists on XP" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL959" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
				<product>Windows Metafile (WMF)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1allows remote attackers to execute arbitrary code via a malformed WNF or EMF image.</description>
			<reference source="CVE">CAN-2003-0906</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-138" comment="the version of mf3216.dll is less than 5.0.2195.6898" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL961" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>MDAC 2.5</product>
			</affected>
			<dates>
				<submitted date="2004-05-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<modified date="2005-02-28" comment="split out the MDAC and file version tests from the compound test">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
			<reference source="CVE">CAN-2003-0353</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-100" comment="MDAC 2.5 is installed" />
					<criterion test_ref="wft-314" comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" />
					<criterion test_ref="wrt-376" negate="true" comment="Patch Q823718 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL962" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Data Access Components 2.6</product>
			</affected>
			<dates>
				<submitted date="2004-05-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
			<reference source="CVE">CAN-2003-0353</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-377" comment="DataAccess Installed" />
					<criterion test_ref="wft-315" comment="File %windir%\System32\odbcbcp.dll is less than 2000.80.746.0" />
					<criterion test_ref="wrt-376" negate="true" comment="Patch Q823718 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL963" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-04-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<modified date="2004-09-22" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</description>
			<reference source="CVE">CAN-2003-0114</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL964" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>H.323</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
			<reference source="CVE">CAN-2004-0117</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-160" comment="a vulnerable version of h323.tsp exists" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL966" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</description>
			<reference source="CVE">CAN-2003-0227</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-335" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3861" />
					<criterion test_ref="wrt-388" negate="true" comment="Patch KB817772 Installed" />
					<criterion test_ref="wrt-389" negate="true" comment="Patch KB822343 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL968" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Jet Database Engine</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.</description>
			<reference source="CVE">CAN-2004-0197</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-140" comment="a vulnerable version of Microsoft Jet 4.0 is installed" />
					<criterion test_ref="wrt-185" negate="true" comment="the patch kb837001 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL969" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>COM Internet Services</product>
			</affected>
			<dates>
				<submitted date="2004-05-25">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-18">INTERIM</status_change>
				<status_change date="2004-07-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a specially crafted request.</description>
			<reference source="CVE">CAN-2003-0807</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-8" comment="Windows NT 4.0 Server or Terminal Server is installed" />
					<criterion test_ref="cmp-21" comment="a vulnerable version of rpcproxy.dll exists on NT" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-385" comment="COM Internet Services are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL974" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-04-29">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<modified date="2004-09-22" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the &quot;Frame Domain Verification&quot; vulnerability described in MS:MS01-058/CAN-2001-0874.</description>
			<reference source="CVE">CVE-2002-0027</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-353" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-311" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-355" negate="true" comment="Patch Q316059.exe Installed" />
					<criterion test_ref="wrt-356" negate="true" comment="Patch Q319282 Installed" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL983" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>IIS 5.1</product>
			</affected>
			<dates>
				<submitted date="2004-05-19">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka &quot;Out of Process Privilege Elevation.&quot;</description>
			<reference source="CVE">CAN-2002-0869</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-390" comment="IIS 5.1 Minor Version" />
					<criterion test_ref="wft-336" comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL990" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the &quot;MHTML URL Processing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0380</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-171" comment="Outlook Express 6 is installed" />
					<criterion test_ref="wft-183" comment="the version of inetcomm.dll is less than 6.00.2739.300" />
					<criterion test_ref="wrt-188" negate="true" comment="the patch kb837009 is installed (installed components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL995" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>COM Internet Services</product>
			</affected>
			<dates>
				<submitted date="2004-05-25">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-18">INTERIM</status_change>
				<status_change date="2004-07-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a specially crafted request.</description>
			<reference source="CVE">CAN-2003-0807</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-289" comment="the version of rpcproxy.dll is less than 5.0.2195.6904" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-385" comment="COM Internet Services are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL996" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>File and Print Sharing</product>
			</affected>
			<dates>
				<submitted date="2004-05-18">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the &quot;Share Level Password&quot; vulnerability.</description>
			<reference source="CVE">CVE-2000-0979</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-391" comment="Windows 98 Installed" />
					<criterion test_ref="wft-337" comment="File %windir%\system\vserver.vxd version is less than 4.10.2001" />
					<criterion test_ref="wrt-392" negate="true" comment="Patch 273991USA8.EXE Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL999" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-06-07">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-06-08">DRAFT</status_change>
				<status_change date="2005-06-29">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Review blocked sender list</description>
			<reference source="MISC">1.2.8</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<oval:notes>
				<oval:note>Corresponds to item 1.2.8 in the Exchange 2003 Benchmark</oval:note>
			</oval:notes>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-5" comment="Review blocked senders" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1000" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-14">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<modified date="2004-05-12" comment="Added a criterion to the configuration section to see if the HCP protocol is registered.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.</description>
			<reference source="CVE">CAN-2003-0907</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-905" comment="a vulnerable version of helpctr.exe exists on XP" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-12" negate="true" comment="the HCP Protocol is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1004" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows XP</product>
			</affected>
			<dates>
				<submitted date="2004-04-14">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka &quot;Windows Management Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2003-0909</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-908" comment="A vulnerable version of evtgprov.dll exists on XP" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1005" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the &quot;DHTML Method Heap Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0055</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="cmp-257" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" />
					<criterion test_ref="wrt-163" negate="true" comment="the patch kb867282 is installed (XP Win2K Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1007" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
			<reference source="CVE">CAN-2004-0123</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-150" comment="a vulnerable version of msasn1.dll exists" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1008" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</description>
			<reference source="CVE">CAN-2004-0199</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-114" comment="a vulnerable version of helpctr.exe exists on XP" />
					<criterion test_ref="wrt-10" negate="true" comment="the patch kb840374 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-12" negate="true" comment="the HCP Protocol is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1009" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>IIS 5.1</product>
			</affected>
			<dates>
				<submitted date="2004-05-19">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.</description>
			<reference source="CVE">CVE-2002-1182</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-390" comment="IIS 5.1 Minor Version" />
					<criterion test_ref="wft-336" comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1010" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the &quot;MHTML URL Processing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0380</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-173" comment="Outlook Express 6 SP1 is installed" />
					<criterion test_ref="wft-185" comment="the version of inetcomm.dll is less than 6.00.2800.1409" />
					<criterion test_ref="wrt-188" negate="true" comment="the patch kb837009 is installed (installed components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1011" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
				<modified date="2005-01-11" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned</description>
			<reference source="CVE">CVE-2002-1182</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1014" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-04-29">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<modified date="2004-09-22" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.</description>
			<reference source="CVE">CVE-2001-0875</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-353" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-308" comment="the version of mshtml.dll is less than 6.0.2712.0300" />
					<criterion test_ref="wrt-354" negate="true" comment="Patch Q313675 Installed" />
					<criterion test_ref="wrt-355" negate="true" comment="Patch Q316059.exe Installed" />
					<criterion test_ref="wrt-356" negate="true" comment="Patch Q319282 Installed" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-902" comment="File Downloads Not Disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1016" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Lightweight Directory Access Protocol (LDAP)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.</description>
			<reference source="CVE">CAN-2003-0663</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-220" comment="Windows 2000 (domain controller) is installed" />
					<criterion test_ref="wft-192" comment="the version of lsasrv.dll is less than 5.0.2195.6902" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1018" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and &quot;\&quot; characters twice.</description>
			<reference source="CVE">CVE-2001-0333</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-338" comment="File %windir%\System32\w3svc.dll is less than 4.2.764.1" />
					<criterion test_ref="wrt-241" negate="true" comment="Patch Q295534 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1021" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<dates>
				<submitted date="2004-06-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the &quot;Remote Registry Access Authentication&quot; vulnerability.</description>
			<reference source="CVE">CVE-2000-0377</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1043" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" />
					<criterion test_ref="cmp-1044" comment="For Terminal Server" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1022" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange 2000</product>
			</affected>
			<dates>
				<submitted date="2004-06-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2000 System Attendant gives &quot;Everyone&quot; group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.</description>
			<reference source="CVE">CVE-2002-0049</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-457" comment="Microsoft Exchange 2000 Installed" />
					<criterion test_ref="wft-417" comment="File %ExchangeInstallDir%\bin\mad.exe is less than 6.0.5770.21" />
					<criterion test_ref="wrt-458" negate="true" comment="Patch Q316056 installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-459" comment="Everyone group given remote access permissions" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1023" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<dates>
				<submitted date="2004-06-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The registry in Windows NT can be accessed remotely by users who are not administrators.</description>
			<reference source="CVE">CAN-1999-0562</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-399" comment="Remote access to registry not controlled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1024" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>NetBIOS</product>
			</affected>
			<dates>
				<submitted date="2004-05-18">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>A component service related to NETBIOS is running.</description>
			<reference source="CVE">CAN-1999-0621</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="cmp-933" comment="Windows NT or 2000 Installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-934" comment="NetBIOS enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1025" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2004-06-15">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
				<modified date="2005-01-13" comment="modified wft-418 - Added space to registry key. used to say &quot;AppPath&quot; I changed it to &quot;App Path&quot;">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wft-418 - wft-418 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-419 - wft-419 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-420 - wft-420 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-428 - wft-428 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-429 - wft-429 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-430 - wft-430 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-431 - wft-431 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka &quot;Incorrect Permission on SQL Server Service Account Registry Key.&quot;</description>
			<reference source="CVE">CVE-2002-0642</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-460" comment="SQL Server 2000 installed" />
					<criterion test_ref="wft-418" comment="the version of sqlservr.exe is less than 2000.80.650.0" />
					<criterion test_ref="wft-419" comment="the version of odsole70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-428" comment="the version of xpqueue.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-429" comment="the version of xprepl.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-430" comment="the version of xplog70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-431" comment="the version of xpweb70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-420" comment="the version of xpstar.dll is less than 2000.80.628.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1026" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>The legacy &lt;script&gt; data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose &quot;src&quot; attribute redirects to a local file.</description>
			<reference source="CVE">CVE-2002-0648</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-115" comment="the version of mshtml.dll is less than 5.0.3541.2700" />
					<criterion test_ref="wrt-62" negate="true" comment="the patch kb883939 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1027" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft DirectPlay</product>
			</affected>
			<dates>
				<submitted date="2004-06-11">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
			<reference source="CVE">CAN-2004-0202</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="cmp-1045" comment="Vulnerable versions of DirectX" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1028" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the &quot;MHTML URL Processing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0380</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-172" comment="Outlook Express 6 for Windows 2003 is installed" />
					<criterion test_ref="wft-184" comment="the version of inetcomm.dll is less than 6.00.3790.137" />
					<criterion test_ref="wrt-186" negate="true" comment="the patch kb837009 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1030" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>COM Internet Services</product>
			</affected>
			<dates>
				<submitted date="2004-05-25">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-18">INTERIM</status_change>
				<status_change date="2004-07-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a specially crafted request.</description>
			<reference source="CVE">CAN-2003-0807</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-193" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed" />
					<criterion test_ref="cmp-190" comment="a vulnerable version of rpcproxy.dll exists on Server 2003" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-385" comment="COM Internet Services are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1032" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</description>
			<reference source="CVE">CAN-2004-0199</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-294" comment="the version of helpctr.exe is less than 5.2.3790.161" />
					<criterion test_ref="wrt-10" negate="true" comment="the patch kb840374 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-12" negate="true" comment="the HCP Protocol is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1036" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Veritas Backup Exec 8.5</product>
			</affected>
			<dates>
				<submitted date="2004-06-15">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<modified date="2005-04-08" comment="modified wrt-472 - wrt-472 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
			</dates>
			<description>Veritas Backup Exec 8.5 and earlier requires that the &quot;RestrictAnonymous&quot; registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.</description>
			<reference source="CVE">CVE-2002-1117</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="ukn-25" comment="Affected bkupexec.exe versions 3.60.1.298" />
					<criterion test_ref="wrt-472" comment="Veritas Backup Exec 8.5 Installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-471" comment="RestrictAnonymous registry value allows anonymous connections" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1039" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Data Access Components 2.7</product>
			</affected>
			<dates>
				<submitted date="2004-05-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-07-20" comment="Changed patch registry key value to IsInstalled">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
			<reference source="CVE">CAN-2003-0353</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-912" comment="Affected MDAC versions" />
					<criterion test_ref="wrt-376" negate="true" comment="Patch Q823718 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1041" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-19">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-04-20">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an &quot;alter context&quot; call that contains additional data, aka the &quot;Object Identity Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0124</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-195" comment="a vulnerable version of ole32.dll exists on NT" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1046" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Utility Manager</product>
			</affected>
			<dates>
				<submitted date="2004-04-14">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a &quot;Shatter&quot; style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CAN-2004-0213.</description>
			<reference source="CVE">CAN-2003-0908</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-322" comment="the version of umandlg.dll is less than 1.0.0.4" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1051" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and &quot;\&quot; characters twice.</description>
			<reference source="CVE">CVE-2001-0333</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-339" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.3649" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1053" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Compressed Folders</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<modified date="2005-01-13" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
				<modified date="2005-05-05" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
					<contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an &quot;unchecked buffer&quot; and improper length validation</description>
			<reference source="CVE">CAN-2004-0575</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1141" comment="vulnerable 32-bit version of zipfldr.dll" />
					<criterion test_ref="wrt-553" negate="true" comment="the patch q873376 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-554" comment="Compressed Folders with zipfldr.dll are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1054" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows logon process (winlogon)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
			<reference source="CVE">CAN-2003-0806</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-120" comment="a vulnerable version of msgina.dll exists" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-196" comment="machine is a member of a domain" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1056" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>CertGetCertificateChain, CertVerifyCertificateChainPolicy, and WinVerifyTrust APIs</product>
			</affected>
			<dates>
				<submitted date="2004-07-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-07-13" comment="Added superceding patch info.">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
			<reference source="CVE">CAN-2002-0862</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-432" comment="the version of crypt32.dll is less than 5.131.2600.1123" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1057" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2005-06-20">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1208</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-49" comment="a vulnerable version of hh.exe exists" />
					<criterion test_ref="wrt-57" negate="true" comment="the patch kb896358 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1059" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Certificate Validation</product>
			</affected>
			<dates>
				<submitted date="2004-07-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-07-13" comment="Added superceding patch info.">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-07-14" comment="Changed to DRAFT">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka &quot;New Variant of Certificate Validation Flaw Could Enable Identity Spoofing&quot; (CAN-2002-0862).</description>
			<reference source="CVE">CVE-2002-1183</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1062" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-20">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an &quot;alter context&quot; call that contains additional data, aka the &quot;Object Identity Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0124</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-177" comment="the version of comsvcs.dll is less than 2000.2.3511.0" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1064" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
				<product>Windows Metafile (WMF)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1allows remote attackers to execute arbitrary code via a malformed WNF or EMF image.</description>
			<reference source="CVE">CAN-2003-0906</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-170" comment="a vulnerable version of mf3216.dll exists on XP" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1066" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an &quot;alter context&quot; call that contains additional data, aka the &quot;Object Identity Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0124</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-179" comment="the version of comsvcs.dll is less than 2001.12.4720.130" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1068" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-05-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
				<modified date="2005-01-14" comment="modified wft-340 - added .dll to end of literal string as needed">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0</description>
			<reference source="CVE">CVE-2001-0241</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-340" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.2956" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1072" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-04-20">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an &quot;alter context&quot; call that contains additional data, aka the &quot;Object Identity Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0124</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-178" comment="the version of comsvcs.dll is less than 2001.12.4414.53" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1076" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
			<reference source="CVE">CAN-2004-0123</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-139" comment="Windows NT or 2000 is installed" />
					<criterion test_ref="wft-193" comment="the version of msasn1.dll is less than 5.0.2195.6905" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1077" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2004-06-15">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
				<modified date="2005-01-13" comment="modified wft-426 - Added space to registry key. used to say &quot;AppPaths&quot; I changed it to &quot;App Paths&quot;">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wft-426 - wft-426 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-427 - wft-427 correct literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in SQL Server 2000 Resolution Service allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption</description>
			<reference source="CVE">CAN-2002-0649</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-460" comment="SQL Server 2000 installed" />
					<criterion test_ref="wft-426" comment="the version of sqlservr.exe is less than 2000.80.636.0" />
					<criterion test_ref="wft-427" comment="the version of ssnetlib.dll is less than 2000.80.636.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1079" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>NetBIOS</product>
			</affected>
			<dates>
				<submitted date="2004-05-18">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
				<modified date="2005-01-13" comment="modified wrt-398 - corrected regular expression on key. needed to escape all back slashes">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram</description>
			<reference source="CVE">CAN-2000-1079</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-943" comment="Windows 95, 98, NT or 2000 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-397" comment="TCP/IP NetBIOS not disabled" />
					<criterion test_ref="wrt-398" comment="WINS Client binding not disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1093" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Private Communications Transport (PCT)</product>
			</affected>
			<dates>
				<submitted date="2004-04-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
			<reference source="CVE">CAN-2003-0719</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-172" comment="the version of schannel.dll is less than 5.2.3790.132" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
					<criterion test_ref="wrt-165" negate="true" comment="PCT support is disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1094" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-04-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<modified date="2004-09-22" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CAN-2003-0115.</description>
			<reference source="CVE">CAN-2003-0233</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1096" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5, Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2004-04-29">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the &quot;Web page spoofing vulnerability.&quot;</description>
			<reference source="CVE">CVE-2001-0339</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-901" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-323" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4616.200" />
					<criterion test_ref="wft-324" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4701.2400" />
					<criterion test_ref="wrt-352" negate="true" comment="Patch Q295106 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1105" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>GDI+</product>
			</affected>
			<dates>
				<submitted date="2004-09-20">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-413" comment="Windows XP or Windows Server 2003 is installed" />
					<criterion test_ref="wft-493" comment="the version of sxs.dll is less than 5.2.3790.121" />
					<criterion test_ref="wrt-512" negate="true" comment="the patch KB833987 is installed (for Windows Server 2003)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1114" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by &quot;AbusiveParent&quot; in Internet Explorer 6.0.2900.2180.</description>
			<reference source="CVE">CAN-2004-1319</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-182" comment="Microsoft Windows Server 2003 32-Bit Edition" />
					<criterion test_ref="wft-376" comment="the version of dhtmled.ocx is less than 6.1.0.9231" />
					<criterion test_ref="wrt-87" negate="true" comment="the patch kb891781 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1115" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<modified date="2005-06-24" comment="added description ">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file. </description>
			<reference source="CVE">CAN-2005-1211</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" />
					<criterion test_ref="wft-99" comment="the version of mshtml.dll is less than 6.0.2900.2668" />
					<criterion test_ref="wrt-62" negate="true" comment="the patch kb883939 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-59" comment="PNG image rendering enabled in Internet Explorer" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1118" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function</description>
			<reference source="CVE">CAN-2003-0605</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1125" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Color Management Module </product>
			</affected>
			<dates>
				<submitted date="2005-08-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-08-03">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1219</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-572" comment="the version of mscms.dll is less than 5.2.3790.359" />
					<criterion test_ref="wrt-128" negate="true" comment="the patch KB901214 is installed " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1132" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Services for UNIX</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1205</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-181" comment="a vulnerable version of telnet.exe exists" />
					<criterion test_ref="wrt-27" negate="true" comment="the patch KB896428 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1133" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifiying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a &quot;URL:&quot; prepended to a &quot;ms-its&quot; protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
			<reference source="CVE">CAN-2004-0549</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-267" comment="the version of mshtml.dll is less than 6.00.2800.1458" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1142" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1206</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-254" comment=" a vulnerable version of srv.sys exists" />
					<criterion test_ref="wrt-63" negate="true" comment="the patch KB896422 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1145" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>ISA Server 2000</product>
			</affected>
			<dates>
				<submitted date="2005-06-23">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-06-29">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.</description>
			<reference source="CVE">CAN-2005-1215</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-11" comment="ISA Server 2000 SP2 (or earlier) is installed" />
					<criterion test_ref="wft-81" comment="the version of w3proxy.exe is less than 3.0.1200.430" />
					<criterion test_ref="wrt-52" negate="true" comment="the patch KB899753 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1148" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>The legacy &lt;script&gt; data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose &quot;src&quot; attribute redirects to a local file.</description>
			<reference source="CVE">CVE-2002-0648</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" />
					<criterion test_ref="wft-99" comment="the version of mshtml.dll is less than 6.0.2900.2668" />
					<criterion test_ref="wrt-62" negate="true" comment="the patch kb883939 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1157" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Crystal Enterprise</product>
				<product>Crystal Reports</product>
			</affected>
			<dates>
				<submitted date="2004-06-09">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2005-01-18" comment="modified wrt-400 - Changed datatype to int was incorrectly set to binary">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
			</dates>
			<description>Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via &quot;..&quot; sequences in the dynamicimag argument to crystalimagehandler.aspx</description>
			<reference source="CVE">CAN-2004-0204</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-341" comment="the version of CrystalDecisions.Web.dll is less than 9.1.9800.9" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-400" comment="the w3svc service is enabled" />
					<criterion test_ref="ukn-24" comment="a website linked to the Crystal Reports Viewer is active" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1159" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>COM Internet Services</product>
			</affected>
			<dates>
				<submitted date="2005-02-15">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-18">DRAFT</status_change>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Windows 2000, XP, and Server 2003 does not properly &quot;validate the use of memory regions&quot; for COM structured storage files, which allows attackers to execute arbitrary code, aka the &quot;COM Structured Storage Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0047</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-386" comment="the version of ole32.dll is less than 5.0.2195.7021" />
					<criterion test_ref="wrt-91" negate="true" comment="the patch KB873333 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1168" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wrt-35 - wrt-35 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>'Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka \&quot;Table Conversion Vulnerability,\&quot; a different vulnerability than CAN-2004-0901'</description>
			<reference source="CVE">CAN-2004-0571</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-35" comment="Word for Windows 6.0 Converter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1180" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Media Player 9</product>
			</affected>
			<dates>
				<submitted date="2005-02-15">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-18">DRAFT</status_change>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the &quot;Input Validation Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0044</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-388" comment="the version of ole32.dll is less than 5.1.2600.2595" />
					<criterion test_ref="wrt-91" negate="true" comment="the patch KB873333 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1186" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2004-07-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-07-14" comment="added the unregistered HTML Help criterion to the configuration section of the criteria">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing &quot;..&quot; (dot dot) sequences and a filename that ends in &quot;::&quot; which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CAN-2004-0475.</description>
			<reference source="CVE">CAN-2003-1041</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1190" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Office XP SP3</product>
			</affected>
			<dates>
				<submitted date="2005-07-21">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-07-27">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0564</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-199" comment="Microsoft Office XP Service Pack 3 is installed" />
					<criterion test_ref="wft-368" comment="the version of winword.exe is less than 10.00.6764.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1194" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Agent</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<modified date="2005-06-24" comment="added description">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page. </description>
			<reference source="CVE">CAN-2005-1214</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-225" comment=" a vulnerable version of agentdpv exists" />
					<criterion test_ref="wrt-64" negate="true" comment="the patch kb890046 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1196" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka &quot;URL Parsing Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0554</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-598" comment="the version of mshtml.dll is less than 5.0.3539.2400" />
					<criterion test_ref="wrt-441" negate="true" comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1202" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Distributed Component Object Model (DCOM) interface</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0528</description>
			<reference source="CVE">CAN-2003-0715</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" />
					<criterion test_ref="wft-358" comment="the version of rpcrt4.dll is less than 5.2.3790.76" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1207" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>The legacy &lt;script&gt; data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose &quot;src&quot; attribute redirects to a local file.</description>
			<reference source="CVE">CVE-2002-0648</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="cmp-158" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506" />
					<criterion test_ref="wrt-62" negate="true" comment="the patch kb883939 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1239" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-06-22">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-06-22">DRAFT</status_change>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1211</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-116" comment="the version of mshtml.dll is less than 5.0.3828.2700" />
					<criterion test_ref="wrt-62" negate="true" comment="the patch kb883939 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-59" comment="PNG image rendering enabled in Internet Explorer" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1241" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-06">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Font Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0571.</description>
			<reference source="CVE">CAN-2004-0901</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-326" comment="the version of mswrd632.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1255" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Web Client Service</product>
			</affected>
			<dates>
				<submitted date="2005-07-15">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-07-27">DRAFT</status_change>
			</dates>
			<description>Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.</description>
			<reference source="CVE">CAN-2005-1207</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="wft-167" comment="the version of webclnt.dll is less than 5.2.3790.1673" />
					<criterion test_ref="wrt-124" negate="true" comment="the patch kb896426 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1264" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-01-31">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
			<reference source="CVE">CAN-2003-0112</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" />
					<criterion test_ref="wft-480" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1151" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1271" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka &quot;Object Management Vulnerability&quot;.</description>
			<reference source="CVE">CAN-2005-0550</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-583" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1279" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
			<reference source="CVE">CAN-2004-0572</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wrt-391" comment="Windows 98 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1280" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Color Management Module </product>
			</affected>
			<dates>
				<submitted date="2005-08-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-08-03">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-1219</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-396" comment="the version of mscms.dll is less than 5.0.2195.7054" />
					<criterion test_ref="wrt-128" negate="true" comment="the patch KB901214 is installed " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1288" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2005-04-22">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-27">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the &quot;Land&quot; vulnerability (CVE-1999-0016).</description>
			<reference source="CVE">CAN-2005-0688</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" />
					<criterion test_ref="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" />
					<criterion test_ref="wrt-443" negate="true" comment="the patch KB893066 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1294" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 6</product>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="modified wrt-24 - corrected hotfix key">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>'Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utilit'</description>
			<reference source="CVE">CAN-2004-1050</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" />
					<criterion test_ref="cmp-25" negate="true" comment="patch kb889293 is installed (hotfix or ID)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1304" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Animated Cursor</product>
			</affected>
			<dates>
				<submitted date="2005-01-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>The Windows Animated Cursor (ANI) in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to cause a denial of service (kernel crash or resource consumption) via the (1) frame number or (2) rate number set to zero</description>
			<reference source="CVE">CAN-2004-1305</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" />
					<criterion test_ref="wft-354" comment="the version of user32.dll is less than 5.1.2600.1617" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1306" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Media Player 9</product>
			</affected>
			<dates>
				<submitted date="2005-02-16">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-18">DRAFT</status_change>
				<modified date="2005-02-22" comment="Added vulnerable configuration">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-169 - fixed version">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-169 - fixed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-174 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-175 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-176 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-177 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-178 - modified name ">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the &quot;PNG Processing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-1244</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-82" comment="Windows Media Player 9.0 installed" />
					<criterion test_ref="wft-374" comment="the version of wmp.dll is les than 9.0.0.3250" />
					<criterion test_ref="wrt-84" negate="true" comment="The patch KB885492 is installed on Windows XP" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-188" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1308" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the &quot;URL Decoding Zone Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0054</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-407" comment="the version of mshtml.dll is less than 5.0.3825.700" />
					<criterion test_ref="wrt-166" negate="true" comment="the patch kb867282 is installed (Win2K SP4  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1321" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-12-16">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka &quot;Windows Kernel Vulnerability.</description>
			<reference source="CVE">CAN-2004-0893</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-146" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7268" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1330" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</description>
			<reference source="CVE">CAN-2003-0718</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1107" comment="Windows 2000 (sp5 or earlier) is installed" />
					<criterion test_ref="wft-501" comment="the version of httpext.dll is less than 5.0.2195.6958" />
					<criterion test_ref="wrt-549" negate="true" comment="the patch KB824151 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-541" negate="true" comment="WebDav is disabled(for iis 5.0)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1331" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Office 2000 SP3</product>
			</affected>
			<dates>
				<submitted date="2005-07-21">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-07-27">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0564</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1103" comment="Microsoft Office 2000 (Premium or Professional) Service Pack 3 is installed" />
					<criterion test_ref="wft-571" comment="the version of winword.exe is less than 9.0.0.8930" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1332" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Certificate Validation</product>
			</affected>
			<dates>
				<submitted date="2004-07-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-07-13" comment="Added superceding patch info.">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-07-14" comment="Changed to DRAFT">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
			<reference source="CVE">CAN-2002-0862</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-215" comment="Windows 2000 Service Pack 4 (or later) is installed" />
					<criterion test_ref="wft-433" comment="the version of cryptdlg.dll is less than 5.0.1558.6608" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1334" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6.0 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<modified date="2005-04-21" comment="modified wrt-158 - removed value to check against">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<modified date="2005-04-21" comment="modified wrt-158 - removed note">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the &quot;Drag-and-Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0053</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-405" comment="the version of mshtml.dll is less than 6.0.3790.259" />
					<criterion test_ref="wrt-158" negate="true" comment="the patch kb867282 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-258" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing" />
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1344" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
			<reference source="CVE">CAN-2004-0212</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-347" comment="Service Pack 6 Installed (or later)" />
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-457" comment="the version of mstask.dll is less than 4.71.1979.1" />
					<criterion test_ref="wrt-492" negate="true" comment="Patch IE-KB841873-WindowsNT4sp6-x86-ENU.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1349" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>HTML Help ActiveX Control</product>
			</affected>
			<dates>
				<submitted date="2005-03-30">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-12">DRAFT</status_change>
				<status_change date="2005-04-27">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the &quot;Related Topics&quot; command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using &quot;writehta.txt&quot; and the ADODB recordset, which saves a .HTA file to the local system, aka the &quot;HTML Help ActiveX control Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-1043</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-93" negate="true" comment="the patch kb890175 is installed" />
					<criterion test_ref="wft-390" comment="the version of hhctrl.ocx is less than 5.2.3790.233" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1351" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should disallow execute permissions to the Exchange HTTP virtual directory</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-140" negate="true" comment="allow script execute permissions to Exchange HTTP virtual directories" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1352" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should only allow digest or integrated windows authentication (NTLM) to connect to the Exchange HTTP virtual directories</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-850" comment="only allow integrated windows authentication (NTLM) to connect to the Exchange HTTP virtual directories" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1353" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should disallow all access to Exchange HTTP virtual directories</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-860" negate="true" comment="allow read access to the Exchange HTTP virtual directories" />
					<criterion test_ref="wat-861" negate="true" comment="allow write access to the Exchange HTTP virtual directories" />
					<criterion test_ref="wat-862" negate="true" comment="allow script source access to the Exchange HTTP virtual directories" />
					<criterion test_ref="wat-863" negate="true" comment="allow directory browsing in the Exchange HTTP virtual directories" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1354" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should Display the routing groups in the Exchange System Manager</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1030" comment="Display the routing groups in the Exchange System Manager" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1355" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should Display the administrative groups in the Exchange System Manager</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1040" comment="Display the administrative groups in the Exchange System Manager" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1356" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should enable forms based authentication</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1140" comment="enable forms based authentication" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1357" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should only allow digest or integrated windows authentication (NTLM) to connect to the Public HTTP virtual directories</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1150" comment="only allow integrated windows authentication (NTLM) to connect to the Public HTTP virtual directories" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1358" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should disallow execute permissions to the Public HTTP virtual directory</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1160" negate="true" comment="allow script execute permissions to the Public HTTP virtual directory" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1359" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should disallow all access to Public HTTP virtual directories</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1170" negate="true" comment="allow read access to the Public HTTP virtual directories" />
					<criterion test_ref="wat-1171" negate="true" comment="allow write access to the Public HTTP virtual directories" />
					<criterion test_ref="wat-1172" negate="true" comment="allow script source access to the Public HTTP virtual directories" />
					<criterion test_ref="wat-1173" negate="true" comment="allow directory browsing in the Public HTTP virtual directories" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1360" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should zero out deleted database pages</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1185" comment="zero out deleted database pages" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1361" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should disable all automated message generation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1190" comment="disable all automated message generation on the default domain" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1362" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should only allow basic authentication with TSL encryption to connect to the IMAP4 service</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1200" comment="allow basic authentication to connect to the IMAP4 service" />
					<criterion test_ref="wat-1201" comment="require TSL encryption to connect to the IMAP4 service" />
					<criterion test_ref="wat-1202" negate="true" comment="allow simple authentication and security layer (SASL) to connect to the IMAP4 service" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1363" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should use SSL when downloading meeting requests</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1240" comment="use SSL when downloading meeting requests using IMAP4" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1364" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should use the default TCP ports for the the IMAP4 services</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1250" comment="use TCP 143 for the IMAP4 service" />
					<criterion test_ref="wat-1251" comment="use TCP 993 for the secure IMAP4 service" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1365" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should archive all messages received by mailboxes on this store</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1280" comment="archive all messages received by mailboxes on this store" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1366" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should have clients support S/MIME</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1290" comment="have clients support S/MIME" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1367" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should not delete mailboxes without waiting for the store to be backed up</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1300" comment="delete mailboxes without waiting for the store to be backed up" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1368" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should subscribe to a block list to block spam</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1350" comment="subscribe to a block list to block spam" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1369" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should limit the size of messages to and from the server to 30MB</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1370" comment="limit the size of messages to the server to 30MB" />
					<criterion test_ref="wat-1371" comment="limit the size of messages from the server to 30MB" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1370" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should limit the number of recipients in outbound messages to 5000</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1380" comment="limit the number of recipients in outbound messages to 5000" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1371" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should disable the filtering of recipients who are not in Active Directory</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1390" comment="disable the filtering of recipients who are not in Active Directory" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1372" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
				<modified date="2005-06-08" comment="Previously, definition would return true if &quot;filter messages with blank sender&quot; was true. This is unrelated and hence was deleted.">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should archive filtered messages</description>
			<reference source="MISC">1.2.9</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<oval:notes>
				<oval:note>Corresponds to item 1.2.9 in the Exchange 2003 Benchmark</oval:note>
			</oval:notes>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1420" comment="archive filtered messages" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1373" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should filter messages with a blank sender</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1430" comment="filter messages with a blank sender" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1374" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should drop connections if the address matches filters</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1440" negate="true" comment="do not drop connections if the address matches filters" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1375" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should accept messages without notifying the sender of filtering</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wat-1450" comment="accept messages without notifying the sender of filtering" />
					<criterion test_ref="wat-1440" negate="true" comment="do not drop connections if the address matches filters" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1376" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should disable Outlook Mobile Access</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1470" comment="disable Outlook Mobile Access" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1377" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should disable ActiveSync</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1480" comment="disable ActiveSync" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1378" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should only allow basic authentication with TSL encryption to connect to the POP3 service</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1530" comment="allow basic authentication to connect to the POP3 service" />
					<criterion test_ref="wat-1531" comment="require TSL encryption to connect to the POP3 service" />
					<criterion test_ref="wat-1532" negate="true" comment="allow simple authentication and security layer (SASL) to connect to the POP3 service" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1379" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should use SSL when downloading meeting requests</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1570" comment="use SSL when downloading meeting requests using POP3" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1380" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should use TCP ports 143 and 995 for the POP3 service</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1580" comment="use TCP port 110 for the POP3 service" />
					<criterion test_ref="wat-1581" comment="use TCP port 995 for the secure POP3 service" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1381" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should have mailbox store clients support S/MIME signatures</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1590" negate="true" comment="don't have mailbox store clients support S/MIME signatures" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1382" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should enable subject logging and display</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1670" comment="enable subject logging and display" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1383" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should enable message tracking</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1680" comment="enable message tracking" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1384" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should disable automatic log removal</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1690" comment="disable automatic log removal" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1385" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should not disable all monitoring on this server</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1720" negate="true" comment="disable all monitoring on this server" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1386" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should change state to critical when any service stops</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1737" comment="change state to critical when any basic Exchange service stops" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1387" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should limit any connector scope to the routing group</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wat-1770" comment="limit SMTP connector scope to the routing group" />
					<criterion test_ref="wat-1771" negate="true" comment="SMTP connector object exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1388" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should disallow unauthenticated entities to relay through this SMTP connector</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wat-1780" negate="true" comment="allow unauthenticated entities to relay through this SMTP connector" />
					<criterion test_ref="wat-1771" negate="true" comment="SMTP connector object exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1389" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should force outbound connections to use basic authentication with TLS encryption</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wat-1790" comment="force outbound connections to use only basic authentication with TLS encryption" />
					<criterion test_ref="wat-1771" negate="true" comment="SMTP connector object exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1390" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should have any SMTP connectors use a smart host</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wat-1810" comment="have any SMTP connectors use a smart host" />
					<criterion test_ref="wat-1771" negate="true" comment="SMTP connector object exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1391" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should only allow basic authentication with TSL encryption to connect to the SMTP server</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1820" comment="only allow basic authentication to connect to the SMTP server" />
					<criterion test_ref="wat-1821" comment="require TSL encryption to connect to the SMTP server" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1392" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should not resolve anonymous email</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1830" negate="true" comment="resolve anonymous email" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1393" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should only allow explicitly listed hosts to relay messages through this sever</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1875" comment="only allow explicitly listed hosts to relay messages through this sever" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1394" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should use a smart host to relay SMTP messages</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1880" comment="use a smart host to relay SMTP messages" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1395" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should not perform reverse DNS lookups on incoming messages</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1890" negate="true" comment="perform reverse DNS lookups on incoming messages" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1396" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should use port 25 for outbound SMTP connections</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1900" comment="use port 25 for outbound SMTP connections" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1397" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should use only basic authentication with TLS encryption for outbound SMTP connections</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1910" comment="use only basic authentication with TLS encryption for outbound SMTP connections" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1398" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should enable logging of connections between SMTP hosts</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1920" comment="enable logging of connections between SMTP hosts" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1399" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should use port 25 for inbound SMTP connections</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1930" comment="use port 25 for inbound SMTP connections" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1400" class="compliance">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-12-29">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-01-26">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2003 should apply sender, recipient, and connection filters</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1940" comment="apply recipient and connection filters" />
					<criterion test_ref="wat-1941" comment="apply sender filters" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1417" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Table Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0901</description>
			<reference source="CVE">CAN-2004-0571</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-325" comment="the version of mswd6_32.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1427" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>IIS 5.1</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</description>
			<reference source="CVE">CAN-2003-0718</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-1110" comment="a vulnerable version of httpext.dll exists" />
					<criterion test_ref="wrt-549" negate="true" comment="the patch KB824151 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1455" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Certificate Validation</product>
			</affected>
			<dates>
				<submitted date="2004-07-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-07-13" comment="Added superceding patch info.">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-07-14" comment="Changed to DRAFT">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka &quot;New Variant of Certificate Validation Flaw Could Enable Identity Spoofing&quot; (CAN-2002-0862).</description>
			<reference source="CVE">CVE-2002-1183</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1503" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CAN-2003-1041.</description>
			<reference source="CVE">CAN-2004-0201</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1512" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>VDM</product>
			</affected>
			<dates>
				<submitted date="2004-06-11">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2004-07-19" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</description>
			<reference source="CVE">CAN-2004-0118</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-342" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6902" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-933" comment="Windows NT or 2000 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1530" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2004-07-13">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-07-14" comment="added the unregistered HTML Help criterion to the configuration section of the criteria">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CAN-2003-1041.</description>
			<reference source="CVE">CAN-2004-0201</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1549" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<dates>
				<submitted date="2005-01-03">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>'The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42'</description>
			<reference source="CVE">CAN-2004-1080</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
					<criterion test_ref="wft-350" comment="the version of wins.exe is less than 5.2.3790.239" />
					<criterion test_ref="wrt-38" negate="true" comment="the patch KB870763 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1561" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-12-16">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka &quot;Windows Kernel Vulnerability.</description>
			<reference source="CVE">CAN-2004-0893</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-148" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6992" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1563" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by &quot;wottapoop.html&quot;.</description>
			<reference source="CVE">CAN-2004-0839</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1568" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Media Player 9</product>
			</affected>
			<dates>
				<submitted date="2005-02-22">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2005-02-22" comment="changed product affected">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-169 - fixed version">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-169 - fixed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-174 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-175 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-176 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-177 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-178 - modified name ">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-02-23">DRAFT</status_change>
				<status_change date="2005-03-23">INTERIM</status_change>
				<status_change date="2005-04-13">ACCEPTED</status_change>
			</dates>
			<description>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the &quot;PNG Processing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-1244</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-82" comment="Windows Media Player 9.0 installed" />
					<criterion test_ref="wft-374" comment="the version of wmp.dll is les than 9.0.0.3250" />
					<criterion test_ref="wrt-167" negate="true" comment="The patch KB885492 is installed on Windows Server 2003" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-188" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1581" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-06">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka &quot;Windows Kernel Vulnerability.</description>
			<reference source="CVE">CAN-2004-0893</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1601" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
			<reference source="CVE">CAN-2004-0214</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wrt-550" comment="Windows ME Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1603" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>HyperTerminal</product>
			</affected>
			<dates>
				<submitted date="2004-12-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-18">DRAFT</status_change>
				<modified date="2005-01-27" comment="Change OS test to include XP gold in addition to XP SP1">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<modified date="2005-03-02" comment="modified wft-175 - Access DLL via HKLM">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-03-23">INTERIM</status_change>
				<modified date="2005-03-29" comment="modified wrt-45 - deleted an extra space after Filelist">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-04-22" comment="modified wrt-45 - Removed extra space between 'Windows XP' in the key field">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</modified>
				<status_change date="2005-05-11">ACCEPTED</status_change>
			</dates>
			<description>'HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.'</description>
			<reference source="CVE">CVE-2004-0568</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-175" comment="the version of hypertrm.dll is less than 5.1.2600.1609" />
					<criterion test_ref="wrt-45" comment="the patch WindowsXP-KB87339-x86-ENU.exe is installed " />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" />
					<criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1606" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2005-02-15">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-18">DRAFT</status_change>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>The Server Message Block (SMB) implementation for Windows 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code using certain broadcast packets, aka the &quot;Server Message Block Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0045</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-380" comment="the version of mrxsmb.sys is less than 5.1.2600.2598" />
					<criterion test_ref="wrt-90" negate="true" comment="the patch KB885250 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1655" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-06">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Font Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0571.</description>
			<reference source="CVE">CAN-2004-0901</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
					<criterion test_ref="cmp-33" comment="The version of mswrd664.wpc OR wmswrd632.wpc is less than 2004.10.25.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1656" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
			<reference source="CVE">CAN-2005-0061</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-581" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1695" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka &quot;DHTML Object Memory Corruption Vulnerability&quot;.</description>
			<reference source="CVE">CAN-2005-0553</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" />
					<criterion test_ref="wft-595" comment="the version of mshtml.dll is less than 6.0.2900.2627" />
					<criterion test_ref="wrt-439" negate="true" comment="the patch kb890923  is installed (XP SP2 Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1701" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The DHTML Edit Control (dhtmled.ocx) in Internet Explorer 6.0.2900.2180 allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by &quot;AbusiveParent.&quot;</description>
			<reference source="CVE">CAN-2004-1319</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" />
					<criterion test_ref="wft-383" comment="the version of wdhtmled.ocx is less than 6.1.0.9232" />
					<criterion test_ref="wrt-87" negate="true" comment="the patch kb891781 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1718" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>VDM</product>
			</affected>
			<dates>
				<submitted date="2004-06-11">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</description>
			<reference source="CVE">CAN-2004-0118</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-1085" comment="Version check of Ntoskrnl for NT Terminal Server or NT Workstation" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1721" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Visual Studio .NET 2003</product>
			</affected>
			<dates>
				<submitted date="2004-09-24">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-09-29">DRAFT</status_change>
				<modified date="2004-09-30" comment="changed affected platforms">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-519" comment="Microsoft Visual Studio .NET 2003 Installed" />
					<criterion test_ref="wrt-518" negate="true" comment="The patch KB830348 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1736" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the &quot;URL Decoding Zone Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0054</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-406" comment="the version of mshtml.dll is less than 5.0.3528.700" />
					<criterion test_ref="wrt-164" negate="true" comment="the patch kb867282 is installed (Win2K SP3  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1749" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
			<reference source="CVE">CAN-2004-0214</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1124" comment="a vulnerable version of shell32.dll exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1751" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>VDM</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2004-10-13" comment="fixed OS ">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
			<reference source="CVE">CAN-2004-0208</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" />
					<criterion test_ref="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1761" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
			<reference source="CVE">CAN-2005-0061</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-583" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1781" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Task Scheduler</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2004-09-14" comment="">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
			<reference source="CVE">CAN-2004-0212</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-455" comment="the version of mstask.dll is less than 5.1.2600.1555" />
					<criterion test_ref="wrt-483" negate="true" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" />
					<criterion test_ref="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1793" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
			<reference source="CVE">CAN-2003-1048</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-268" comment="the version of mshtml.dll is less than 6.00.2743.600" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1808" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Negotiate SSP interface</product>
			</affected>
			<dates>
				<submitted date="2004-06-14">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
				<modified date="2005-01-13" comment="modified wft-345 - Addded a space in the registry key component of the file path">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection</description>
			<reference source="CVE">CAN-2004-0119</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="wft-345" comment="The version of Ipnathlp.dll is less than 5.0.2195.6902" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-206" comment="Negotiate is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1813" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Distributed Component Object Model (DCOM) interface</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0528</description>
			<reference source="CVE">CAN-2003-0715</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-57" comment="Windows XP 32-bit SP1 is installed" />
					<criterion test_ref="wft-366" comment="the version of rpcrt4.dll is less than 5.1.2600.1254" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1822" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Client Server Runtime System (CSRSS)</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
			<reference source="CVE">CAN-2005-0551</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-583" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1837" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
			<reference source="CVE">CAN-2004-0572</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1133" comment="a vulnerable version of grpconv.exe exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1843" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
			<reference source="CVE">CAN-2004-0572</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1136" comment="a vulnerable version of grpconv.exe exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1847" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2005-02-15">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-18">DRAFT</status_change>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>The Server Message Block (SMB) implementation for Windows 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code using certain broadcast packets, aka the &quot;Server Message Block Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0045</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-381" comment="the version of mrxsmb.sys is less than 5.2.3790.252" />
					<criterion test_ref="wrt-90" negate="true" comment="the patch KB885250 is installed" />
					<criterion test_ref="cmp-187" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1852" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>NetDDE</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an &quot;unchecked buffer,&quot; possibly a buffer overflow.</description>
			<reference source="CVE">CAN-2004-0206</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-520" comment="the version of nddenb32.dll is less than 4.0.1381.33565" />
					<criterion test_ref="wft-521" comment="the version of netdde.exe is less than 4.0.1381.33574" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1872" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve &quot;an unchecked buffer.&quot;</description>
			<reference source="CVE">CAN-2004-0209</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-535" comment="the version of vdmdbg.dll is less than 5.1.2600.1560" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1886" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-06">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wft-154 - wft-154 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka &quot;Windows Kernel Vulnerability.</description>
			<reference source="CVE">CAN-2004-0893</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-154" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1888" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<dates>
				<submitted date="2005-01-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program</description>
			<reference source="CVE">CAN-2004-0894</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
					<criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1889" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>The Server Message Block (SMB) implementation for Windows 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code using certain broadcast packets, aka the &quot;Server Message Block Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0045</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" />
					<criterion test_ref="wft-382" comment="the version of mrxsmb.sys is less than 5.1.2600.1620" />
					<criterion test_ref="wrt-90" negate="true" comment="the patch KB885250 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1943" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing &quot;..&quot; (dot dot) sequences and a filename that ends in &quot;::&quot; which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CAN-2004-0475.</description>
			<reference source="CVE">CAN-2003-1041</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1950" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<dates>
				<submitted date="2004-08-26">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-08-26">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
			<reference source="CVE">CAN-2004-0215</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-173" comment="Outlook Express 6 SP1 is installed" />
					<criterion test_ref="wft-467" comment="the version of inetcomm.dll is less than 6.0.2800.1441" />
					<criterion test_ref="wrt-494" negate="true" comment="the patch kb823353 is installed " />
				</software>
				<configuration>
					<criterion test_ref="wrt-495" negate="true" comment="all users have the preview pane disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1959" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<modified date="2005-03-01" comment="modified wft-123 - Changed/Corrected literal path">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-23">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wft-123 - wft-123 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Table Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0901</description>
			<reference source="CVE">CAN-2004-0571</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-123" comment="the version of wordpad.exe is less than 5.1.2600.1606" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1962" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Negotiate Security Software Provider</product>
			</affected>
			<dates>
				<submitted date="2004-06-15">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</description>
			<reference source="CVE">CAN-2004-0119</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-952" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and 64-bit or 32-bit version of Windows is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-206" comment="Negotiate is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1963" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows XP</product>
			</affected>
			<dates>
				<submitted date="2005-03-30">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-12">DRAFT</status_change>
				<status_change date="2005-04-27">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the &quot;Related Topics&quot; command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using &quot;writehta.txt&quot; and the ADODB recordset, which saves a .HTA file to the local system, aka the &quot;HTML Help ActiveX control Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-1043</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-93" negate="true" comment="the patch kb890175 is installed" />
					<criterion test_ref="cmp-242" comment="A vulnerable version of hhctrl.ocx exists on Windows XP" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1964" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Task Scheduler</product>
			</affected>
			<dates>
				<submitted date="2004-07-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-07-14" comment="added compound tests">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
			<reference source="CVE">CAN-2004-0212</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="cmp-1070" comment="Affected mstask.dll file versions based on service pack levels" />
					<criterion test_ref="wrt-483" negate="true" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1976" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Table Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0901</description>
			<reference source="CVE">CAN-2004-0571</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-33" comment="The version of mswrd664.wpc OR wmswrd632.wpc is less than 2004.10.25.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1997" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Negotiate SSP interface</product>
			</affected>
			<dates>
				<submitted date="2004-06-15">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2004-07-19" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2004-07-20" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-08-11">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</description>
			<reference source="CVE">CAN-2004-0119</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-1095" comment="Version checks on XP for Ipnathlp.dll" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-206" comment="Negotiate is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2008" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-06">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wft-154 - wft-154 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka &quot;Windows Kernel Vulnerability.</description>
			<reference source="CVE">CAN-2004-0893</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-154" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
					<criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" />
					<criterion test_ref="cmp-1112" comment="Windows XP 64-bit" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2016" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Outlook Web Access</product>
			</affected>
			<dates>
				<submitted date="2004-08-25">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.</description>
			<reference source="CVE">CAN-2004-0203</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-504" comment="Exchange 5.5 with SP4 Installed" />
					<criterion test_ref="wft-485" comment="the version of cdo.dll is less than 5.5.2558.10" />
					<criterion test_ref="wrt-505" negate="true" comment="the  patch kb842436 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-506" comment="Outlook Web Access exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2022" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-07-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
			<reference source="CVE">CAN-2003-0112</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-436" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" />
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2043" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka &quot;Object Management Vulnerability&quot;.</description>
			<reference source="CVE">CAN-2005-0550</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-581" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2046" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2005-03-31">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-12">DRAFT</status_change>
				<status_change date="2005-04-27">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the &quot;Drag-and-Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0053</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" />
					<criterion test_ref="wft-400" comment="the version of shell32.dll is less than 5.0.3900.7009" />
					<criterion test_ref="wrt-155" comment="the patch kb890047 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-157" negate="true" comment="Drag-and-Drop disabled when set to 3" />
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2062" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<dates>
				<submitted date="2005-01-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program</description>
			<reference source="CVE">CAN-2004-0894</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" />
					<criterion test_ref="wft-349" comment="the version of lsasrv.dll is less than 5.1.2600.1597" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2073" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by &quot;wottapoop.html&quot;.</description>
			<reference source="CVE">CAN-2004-0839</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" />
					<criterion test_ref="wrt-559" negate="true" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2077" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka &quot;Content Advisor Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0555</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-598" comment="the version of mshtml.dll is less than 5.0.3539.2400" />
					<criterion test_ref="wrt-441" negate="true" comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2100" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-07-30">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
			<reference source="CVE">CAN-2003-1048</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2108" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Certificate Validation</product>
			</affected>
			<dates>
				<submitted date="2004-07-12">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-07-13" comment="Added superceding patch info.">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-07-14" comment="Changed to DRAFT">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka &quot;New Variant of Certificate Validation Flaw Could Enable Identity Spoofing&quot; (CAN-2002-0862).</description>
			<reference source="CVE">CVE-2002-1183</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2114" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve &quot;an unchecked buffer.&quot;</description>
			<reference source="CVE">CAN-2004-0209</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-507" comment="the version of gdi32.dll is less than 5.0.2195.6945" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2128" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Indexing Service</product>
			</affected>
			<dates>
				<submitted date="2005-03-23">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
			<reference source="CVE">CAN-2004-0897</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" />
					<criterion test_ref="wft-356" comment="Indexing Service ciodm.dll is less than 5.2.3790.220" />
					<criterion test_ref="wrt-69" negate="true" comment="the patch Windows 2003 KB871250 is installed " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2137" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<dates>
				<submitted date="2004-08-26">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-08-26">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
			<reference source="CVE">CAN-2004-0215</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-170" comment="Outlook Express 5.5 SP2 is installed" />
					<criterion test_ref="wft-469" comment="the version of inetcomm.dll is less than 5.50.4942.400" />
					<criterion test_ref="wrt-494" negate="true" comment="the patch kb823353 is installed " />
				</software>
				<configuration>
					<criterion test_ref="wrt-495" comment="all users have the preview pane disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2155" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CAN-2003-1041.</description>
			<reference source="CVE">CAN-2004-0201</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2166" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>POSIX</product>
			</affected>
			<dates>
				<submitted date="2004-07-13">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2004-07-14" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</description>
			<reference source="CVE">CAN-2004-0210</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-480" negate="true" comment="the patch kb841872 is installed" />
					<criterion test_ref="cmp-1064" comment="Version check for psxss.exe on NT Workstation, Server 4.0 and NT Terminal Server" />
				</software>
				<configuration>
					<criterion test_ref="wrt-479" comment="POSIX is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2184" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2005-05-04">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
			<reference source="CVE">CAN-2005-0063</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" />
					<criterion test_ref="wft-590" comment="the version of shell32.dll is less than 6.0.2800.1643" />
					<criterion test_ref="wrt-435" negate="true" comment="the patch  KB893086 is installed " />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2188" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2005-04-22">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-27">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP (&quot;Fragmentation Needed and Don't Fragment was Set&quot;) packets with a low next-hop MTU value, aka the &quot;Path MTU discovery attack.&quot;  NOTE: CAN-2004-0790, CAN-2004-0791, and CAN-2004-1060 have been SPLIT based on different attacks; CAN-2005-0065, CAN-2005-0066, CAN-2005-0067, and CAN-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
			<reference source="CVE">CAN-2004-1060</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" />
					<criterion test_ref="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" />
					<criterion test_ref="wrt-443" negate="true" comment="the patch KB893066 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-380" negate="true" comment="Enable Path MTU Discovery is Disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2190" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>DirectX</product>
			</affected>
			<dates>
				<submitted date="2004-06-15">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-06-16" comment="Added cmp-966 to test for vulnerable versions of DirectX">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<modified date="2004-06-17" comment="Re-added cmp-966">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<modified date="2004-07-06" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-07-12">INTERIM</status_change>
				<status_change date="2004-07-21">ACCEPTED</status_change>
			</dates>
			<description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
			<reference source="CVE">CAN-2004-0202</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="cmp-966" comment="DirectX without KB839643 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2204" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-07-13">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.</description>
			<reference source="CVE">CAN-2004-0205</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-484" negate="true" comment="the patch q841373 is installed (Hotfix key)" />
					<criterion test_ref="wft-446" comment="the version of w3svc.dll is less than 4.2.788.1" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-207" comment="Permanent redirects enabled" />
					<criterion test_ref="wrt-485" negate="true" comment="MaxClientRequestBufferData less than or equal to 16384" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2219" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-10-26">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
			<reference source="CVE">CAN-2004-0845</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2245" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2004-09-14" comment="">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
			<reference source="CVE">CAN-2004-0420</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-450" comment="the version of shell32.dll is less than 6.0.2800.1556" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
					<criterion test_ref="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2253" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka &quot;URL Parsing Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0554</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-599" comment="the version of mshtml.dll is less than 5.0.3826.2400" />
					<criterion test_ref="wrt-442" negate="true" comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2265" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-07-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
			<reference source="CVE">CAN-2003-0112</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-437" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33545" />
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2274" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>MDAC 2.8</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
			<reference source="CVE">CAN-2004-0597</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-179" negate="true" comment="Windows Messenger 5.1 is installed" />
					<criterion test_ref="wft-410" comment="the version of msmsgs.exe is less than 5.1.0.639" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2280" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>DHCP</product>
			</affected>
			<dates>
				<submitted date="2004-12-16">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<modified date="2005-01-27" comment="Corrected the patch number being checked">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-02-07" comment="negated the patch check">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-23">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka &quot;Logging Vulnerability.</description>
			<reference source="CVE">CAN-2004-0899</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-156" comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" />
					<criterion test_ref="wrt-37" negate="true" comment="the patch KB885249 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2292" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
				<modified date="2005-05-02" comment="Added negate to the patch check. Accidentally left off.">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-05-04">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0051</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-373" comment="the version of srvsvc.dll is less than 5.1.2600.2577" />
					<criterion test_ref="wrt-81" negate="true" comment="the patch kb888302 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2300" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>SMTP</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<modified date="2004-10-26" comment="">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</description>
			<reference source="CVE">CAN-2004-0840</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" />
					<criterion test_ref="wrt-542" comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" />
					<criterion test_ref="cmp-1153" comment="Exchange Server 2003 is installed on Windows Server 2003" />
				</software>
				<configuration>
					<criterion test_ref="wrt-240" comment="SMTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2343" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Distributed Component Object Model (DCOM) interface</product>
			</affected>
			<dates>
				<submitted date="2005-04-28">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</description>
			<reference source="CVE">CAN-2003-0352</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<oval:notes>
				<oval:note>This bulletin has been superceded by MS03-039.  Definition reflects updated information. </oval:note>
			</oval:notes>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-310" comment="Windows XP 32-bit OR Windows XP 64-bit is installed" />
					<criterion test_ref="cmp-312" comment="A vulnerable version of rpcrt4.dll exists depending on service pack level" />
					<criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2348" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Project Professional 2002</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) &quot;%00 (null byte) in .doc filenames or (2) &quot;%0a&quot; (carriage return) in .rtf filenames.</description>
			<reference source="CVE">CAN-2004-0848</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-523" comment="Windows Project Professional 2002 Service Pack 1 is installed" />
					<criterion test_ref="wft-377" comment="the version of mso.dll is less than 10.0.6735.0" />
					<criterion test_ref="wrt-94" negate="true" comment="Patch KB873355 installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2351" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>COM Internet Services</product>
			</affected>
			<dates>
				<submitted date="2005-02-15">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-18">DRAFT</status_change>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Windows 2000, XP, and Server 2003 does not properly &quot;validate the use of memory regions&quot; for COM structured storage files, which allows attackers to execute arbitrary code, aka the &quot;COM Structured Storage Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0047</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-388" comment="the version of ole32.dll is less than 5.1.2600.2595" />
					<criterion test_ref="wrt-91" negate="true" comment="the patch KB873333 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2379" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Media Player 9</product>
			</affected>
			<dates>
				<submitted date="2005-02-22">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2005-02-22" comment="modified wrt-169 - fixed version">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-169 - fixed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-174 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-175 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-176 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-177 - modified name">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-02-22" comment="modified wrt-178 - modified name ">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-02-23">DRAFT</status_change>
				<status_change date="2005-03-23">INTERIM</status_change>
				<status_change date="2005-04-13">ACCEPTED</status_change>
			</dates>
			<description>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the &quot;PNG Processing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-1244</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-82" comment="Windows Media Player 9.0 installed" />
					<criterion test_ref="wft-374" comment="the version of wmp.dll is les than 9.0.0.3250" />
					<criterion test_ref="wrt-85" negate="true" comment="The patch KB885492 is installed on Windows 2000" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-188" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2381" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
			<reference source="CVE">CAN-2004-0420</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-451" comment="the version of shell32.dll is less than 6.0.3790.163" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2385" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the &quot;Channel Definition Format (CDF) Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0056</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-406" comment="the version of mshtml.dll is less than 5.0.3528.700" />
					<criterion test_ref="wrt-164" comment="the patch kb867282 is installed (Win2K SP3  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2394" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>NetDDE</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an &quot;unchecked buffer,&quot; possibly a buffer overflow.</description>
			<reference source="CVE">CAN-2004-0206</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-518" comment="the version of nddenb32.dll is less than 4.0.1381.7268" />
					<criterion test_ref="wft-522" comment="the version of netdde.exe is less than 4.0.1381.7280" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2413" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>DirectX</product>
			</affected>
			<dates>
				<submitted date="2004-06-15">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-06-16" comment="Changed Status to Draft; Added cmp-967">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<modified date="2004-07-06" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-07-12">INTERIM</status_change>
				<status_change date="2004-07-21">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-09-14" comment="">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-09-14" comment="">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
			<reference source="CVE">CAN-2004-0202</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-967" comment="DirectX 8.1 without kb839643 installed" />
					<criterion test_ref="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2428" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2004-10-13" comment="changed OS">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve &quot;an unchecked buffer.&quot;</description>
			<reference source="CVE">CAN-2004-0209</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2447" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Indexing Service</product>
			</affected>
			<dates>
				<submitted date="2005-03-23">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
			<reference source="CVE">CAN-2004-0897</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
					<criterion test_ref="wft-357" comment="Indexing Service ciodm.dll is less than 5.1.2600.1596" />
					<criterion test_ref="wrt-74" negate="true" comment="the patch Windows XP KB871250 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2448" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the &quot;Address Bar Spoofing on Double Byte Character Set Systems Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0844</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2487" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the &quot;Plug-in Navigation Address Bar Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0843</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2495" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Utility Manager</product>
			</affected>
			<dates>
				<submitted date="2004-07-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a &quot;Shatter&quot; style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CAN-2003-0908.</description>
			<reference source="CVE">CAN-2004-0213</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-439" comment="the version of Sp3res.dll is less than 5.0.2195.6928" />
					<criterion test_ref="wft-442" comment="the version of Umandlg.dll is less than 1.0.0.5" />
					<criterion test_ref="wrt-481" negate="true" comment="the patch kb842526 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2505" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-10-18">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.</description>
			<reference source="CVE">CAN-2004-0569</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-552" comment="the version of rpcrt4.dll is less than 4.0.1381.7299" />
					<criterion test_ref="wrt-558" comment="Patch KB873350 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2516" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>DirectX</product>
			</affected>
			<dates>
				<submitted date="2004-06-15">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-06-16" comment="Changed Status to Draft; Added cmp-969">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<modified date="2004-07-06" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-07-12">INTERIM</status_change>
				<status_change date="2004-07-21">ACCEPTED</status_change>
			</dates>
			<description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
			<reference source="CVE">CAN-2004-0202</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="cmp-969" comment="DirectX without KB839643 Installed on Windows Server 2003" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2537" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the &quot;Plug-in Navigation Address Bar Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0843</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2541" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2005-01-03">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42</description>
			<reference source="CVE">CAN-2004-1080</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" />
					<criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" />
					<criterion test_ref="wft-163" comment="the version of wins.exe is less than 5.0.2195.7005" />
					<criterion test_ref="wrt-38" negate="true" comment="the patch KB870763 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2545" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>HyperTerminal</product>
			</affected>
			<dates>
				<submitted date="2004-12-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-18">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<modified date="2005-03-02" comment="modified wft-176 - access DLL via HKLM">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-03-23">ACCEPTED</status_change>
				<modified date="2005-03-29" comment="modified wrt-45 - deleted an extra space after Filelist">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-04-22" comment="modified wrt-45 - Removed extra space between 'Windows XP' in the key field">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</modified>
				<status_change date="2005-04-27">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
			<reference source="CVE">CVE-2004-0568</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" />
					<criterion test_ref="wft-176" comment="the version of hypertrm.dll is less than 5.1.2600.2563" />
					<criterion test_ref="wrt-45" negate="true" comment="the patch WindowsXP-KB87339-x86-ENU.exe is installed " />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" />
					<criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2559" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka &quot;URL Parsing Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0554</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-594" comment="the version of mshtml.dll is less than 6.00.3790.279" />
					<criterion test_ref="wrt-438" negate="true" comment="the patch kb890923 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2562" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
			<reference source="CVE">CAN-2005-0060</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-579" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2568" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>MDAC 2.8</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an &quot;unchecked buffer&quot; and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the &quot;License Logging Service Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0050</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" />
					<criterion test_ref="wrt-96" negate="true" comment="the patch kb885834 is installed (Hotfix key)" />
					<criterion test_ref="wft-394" comment="the version of Llssrv.exe is less than 5.0.2195.7021" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-344" comment="license logging service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2570" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Hyperlink Object Library</product>
			</affected>
			<dates>
				<submitted date="2005-02-24">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2005-03-02">DRAFT</status_change>
				<status_change date="2005-03-23">INTERIM</status_change>
				<status_change date="2005-04-13">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0057</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wft-369" comment="the version of hlink.dll is less than 5.2.3790.227" />
					<criterion test_ref="wrt-78" negate="true" comment="the patch kb888113 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2580" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Animated Cursor</product>
			</affected>
			<dates>
				<submitted date="2005-01-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>The Windows Animated Cursor (ANI) in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to cause a denial of service (kernel crash or resource consumption) via the (1) frame number or (2) rate number set to zero</description>
			<reference source="CVE">CAN-2004-1305</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-62" comment="Windows Server 2003 or Windows Server 2003 64-bit Edition is installed" />
					<criterion test_ref="wft-355" comment="the version of user32.dll is less than 5.2.3790.245" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2611" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka &quot;HijackClick 3&quot; and the &quot;Script in Image Tag File Download Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0841</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2638" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
			<reference source="CVE">CAN-2004-0214</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wrt-391" comment="Windows 98 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2657" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<dates>
				<submitted date="2004-08-26">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-08-26">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
			<reference source="CVE">CAN-2004-0215</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-172" comment="Outlook Express 6 for Windows 2003 is installed" />
					<criterion test_ref="wrt-494" negate="true" comment="the patch kb823353 is installed " />
					<criterion test_ref="cmp-1098" comment="a vulnerable version of inetcomm.dll exisits" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-495" comment="all users have the preview pane disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2670" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Office 2000 SP3</product>
			</affected>
			<dates>
				<submitted date="2004-09-28">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
				<modified date="2005-02-10" comment="modified wft-489 - corrected registry path check for .dll file">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-11">INTERIM</status_change>
				<status_change date="2005-03-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
			<reference source="CVE">CAN-2004-0573</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " />
					<criterion test_ref="wrt-530" negate="true" comment="the patch kb873380 for Office 2000 SP3 is installed " />
					<criterion test_ref="cmp-1103" comment="Microsoft Office 2000 (Premium or Professional) Service Pack 3 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2671" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Certificate Validation</product>
			</affected>
			<dates>
				<submitted date="2004-07-11">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-07-12" comment="negated patch info.">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-07-13" comment="Added superceding patch info.">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-07-14" comment="Changed to DRAFT">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
			<reference source="CVE">CAN-2002-0862</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2673" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Excel 2000</product>
			</affected>
			<dates>
				<submitted date="2004-10-18">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.</description>
			<reference source="CVE">CAN-2004-0846</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-535" comment="Microsoft Office 2000 Professional Service Pack 3 is installed" />
					<criterion test_ref="wrt-137" comment="Excel 2000 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2692" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the &quot;DHTML Method Heap Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0055</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-406" comment="the version of mshtml.dll is less than 5.0.3528.700" />
					<criterion test_ref="wrt-164" negate="true" comment="the patch kb867282 is installed (Win2K SP3  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2705" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>DirectX</product>
			</affected>
			<dates>
				<submitted date="2004-06-15">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-06-16" comment="Changed Status to Draft; Added cmp-970">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<modified date="2004-07-06" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-07-12">INTERIM</status_change>
				<status_change date="2004-07-21">ACCEPTED</status_change>
			</dates>
			<description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
			<reference source="CVE">CAN-2004-0202</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-413" comment="Windows XP or Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="cmp-967" comment="DirectX 8.1 without kb839643 installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2706" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Office 2003</product>
			</affected>
			<dates>
				<submitted date="2004-09-24">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2004-09-27" comment="changed affected product from GDI+ and office2003 to just office 2003">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-13">INTERIM</status_change>
				<status_change date="2004-10-27">ACCEPTED</status_change>
				<modified date="2005-02-10" comment="modified wft-495 - corrected registry path check for .dll file">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-11">INTERIM</status_change>
				<status_change date="2005-03-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-515" comment="Microsoft Office 2003 is installed" />
					<criterion test_ref="wrt-517" negate="true" comment="Patch KB838905 is installed" />
					<criterion test_ref="wft-495" comment="the version of gdiplus.dll is less than 6.0.3264.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2730" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>MDAC 2.5</product>
			</affected>
			<dates>
				<submitted date="2004-08-24">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-02-28" comment="removed the test for windows NT and added a test for MDAC 2.5 since this definition is dependent on the MDAC version and not the platform">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
			<reference source="CVE">CVE-2002-1142</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-100" comment="MDAC 2.5 is installed" />
					<criterion test_ref="wft-482" comment="the version of msadco.dll is less than 2.53.6202.0" />
					<criterion test_ref="wrt-503" negate="true" comment="Patch Q329414 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2731" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
			<reference source="CVE">CAN-2005-0060</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-583" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2734" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<dates>
				<submitted date="2004-12-17">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42</description>
			<reference source="CVE">CAN-2004-1080</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-43" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-165" comment="the version of wins.exe is less than 4.0.1381.33618" />
					<criterion test_ref="wrt-38" negate="true" comment="the patch KB870763 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2738" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Visio Professional 2002</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a long URL file location.</description>
			<reference source="CVE">CAN-2004-0848</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-525" comment="Visio Professional 2002 with service pack 2" />
					<criterion test_ref="wrt-89" negate="true" comment="Patch KB873354 installed" />
					<criterion test_ref="wft-377" comment="the version of mso.dll is less than 10.0.6735.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2753" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
			<reference source="CVE">CAN-2004-0572</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-519" comment="the version of grpconv.exe (system32) is less than 5.0.2195.6966" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2786" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0555</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-599" comment="the version of mshtml.dll is less than 5.0.3826.2400" />
					<criterion test_ref="wrt-442" negate="true" comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2817" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6.0 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<modified date="2005-04-21" comment="modified wrt-158 - removed value to check against">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<modified date="2005-04-21" comment="modified wrt-158 - removed note">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the &quot;Channel Definition Format (CDF) Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0056</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-405" comment="the version of mshtml.dll is less than 6.0.3790.259" />
					<criterion test_ref="wrt-158" negate="true" comment="the patch kb867282 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2830" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<modified date="2005-03-01" comment="Removed software test to check for Windows service Packs">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</modified>
				<modified date="2005-03-24" comment="Added a configuration test to see if ActiveX controls are enabled.">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</modified>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the &quot;Related Topics&quot; command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using &quot;writehta.txt&quot; and the ADODB recordset, which saves a .HTA file to the local system, aka the &quot;HTML Help ActiveX control Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-1043</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-390" comment="the version of hhctrl.ocx is less than 5.2.3790.233" />
					<criterion test_ref="wrt-93" negate="true" comment="the patch kb890175 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2847" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>POSIX</product>
			</affected>
			<dates>
				<submitted date="2004-07-13">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</description>
			<reference source="CVE">CAN-2004-0210</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-480" negate="true" comment="the patch kb841872 is installed" />
					<criterion test_ref="wft-441" comment="the version of psxss.exe is less than 5.0.2195.6929" />
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-479" comment="POSIX is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2884" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Distributed Component Object Model (DCOM) interface</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0715</description>
			<reference source="CVE">CAN-2003-0528</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-57" comment="Windows XP 32-bit SP1 is installed" />
					<criterion test_ref="wft-366" comment="the version of rpcrt4.dll is less than 5.1.2600.1254" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2892" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>COM Internet Services</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Windows 2000, XP, and Server 2003 does not properly &quot;validate the use of memory regions&quot; for COM structured storage files, which allows attackers to execute arbitrary code, aka the &quot;COM Structured Storage Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0047</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" />
					<criterion test_ref="wft-387" comment="the version of ole32.dll is less than 5.1.2600.1619" />
					<criterion test_ref="wrt-91" negate="true" comment="the patch KB873333 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2894" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
			<reference source="CVE">CAN-2004-0420</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-413" comment="Windows XP or Windows Server 2003 is installed" />
					<criterion test_ref="wft-448" comment="the version of shell32.dll is less than 6.0.3790.168" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2906" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from &quot;memory corruption&quot;) via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the &quot;&lt;STYLE&gt;@;/*&quot; string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the &quot;CSS Heap Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0842</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2917" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Media Player 9</product>
			</affected>
			<dates>
				<submitted date="2005-02-15">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-18">DRAFT</status_change>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the &quot;Input Validation Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0044</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-386" comment="the version of ole32.dll is less than 5.0.2195.7021" />
					<criterion test_ref="wrt-91" negate="true" comment="the patch KB873333 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2919" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Adobe Acrobat Reader</product>
			</affected>
			<dates>
				<submitted date="2005-04-26">
					<contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
				</submitted>
				<status_change date="2005-04-27">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.</description>
			<reference source="CVE">CAN-2004-1153</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<oval:notes>
				<oval:note>iDEFENSE reports that deleting eBook.api from the plug_ins directory is a workaround.  See http://www.idefense.com/application/poi/display?id=163&amp;type=vulnerabilities</oval:note>
			</oval:notes>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-301" comment="the software Adobe Acrobat Reader major version 6, minor version less than 3 is installed" />
					<criterion test_ref="wft-603" comment="Adobe Acrobat Reader eBook.api plug-in software installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2953" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<modified date="2005-04-21" comment="modified wrt-159 - unchecked value">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the &quot;Drag-and-Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0053</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" />
					<criterion test_ref="wft-500" comment="the version of mshtml.dll is less than 6.0.2900.2604" />
					<criterion test_ref="wrt-159" negate="true" comment="the patch kb867282 is installed (XP SP2 Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-258" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing" />
					<criterion test_ref="cmp-99" comment="local machine settings are being used and ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2956" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Cursor and Icon Formatting</product>
			</affected>
			<dates>
				<submitted date="2005-01-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<reference source="CVE">CAN-2004-1049</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" />
					<criterion test_ref="wft-354" comment="the version of user32.dll is less than 5.1.2600.1617" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2968" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Distributed Component Object Model (DCOM) interface</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0715</description>
			<reference source="CVE">CAN-2003-0528</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wft-359" comment="the version of rpcrt4.dll is less than 5.1.2600.109" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3006" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the &quot;Drag-and-Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0053</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-406" comment="the version of mshtml.dll is less than 5.0.3528.700" />
					<criterion test_ref="wrt-164" negate="true" comment="the patch kb867282 is installed (Win2K SP3  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-258" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing" />
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3038" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Project Professional 2002</product>
			</affected>
			<dates>
				<submitted date="2004-09-27">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-09-29">DRAFT</status_change>
				<modified date="2004-09-30" comment="Changed affected platforms">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
				<modified date="2005-02-10" comment="modified wft-496 - corrected registry path check">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-11">INTERIM</status_change>
				<status_change date="2005-03-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-523" comment="Windows Project Professional 2002 Service Pack 1 is installed" />
					<criterion test_ref="wrt-524" negate="true" comment="Patch KB831931 installed" />
					<criterion test_ref="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3055" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0051</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" />
					<criterion test_ref="wft-372" comment="the version of srvsvc.dll is less than 5.1.2600.1613" />
					<criterion test_ref="wrt-81" negate="true" comment="the patch kb888302 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3060" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<modified date="2005-04-21" comment="modified wrt-158 - removed value to check against">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<modified date="2005-04-21" comment="modified wrt-158 - removed note">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the &quot;URL Decoding Zone Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0054</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-405" comment="the version of mshtml.dll is less than 6.0.3790.259" />
					<criterion test_ref="wrt-158" negate="true" comment="the patch kb867282 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3071" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
			<reference source="CVE">CAN-2004-0572</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1128" comment="a vulnerable version of grpconv.exe exists on NT" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3082" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Visio Professional 2002</product>
			</affected>
			<dates>
				<submitted date="2004-09-27">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-09-29">DRAFT</status_change>
				<modified date="2004-09-30" comment="Changed affected platforms">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
				<modified date="2005-02-10" comment="modified wft-496 - corrected registry path check">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-11">INTERIM</status_change>
				<status_change date="2005-03-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-525" comment="Visio Professional 2002 with service pack 2" />
					<criterion test_ref="wrt-526" negate="true" comment="Patch KB831932 installed" />
					<criterion test_ref="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3095" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Explorer.exe</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2004-07-19" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.</description>
			<reference source="CVE">CAN-2003-0306</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-493" negate="true" comment="Patch KB821557 Installed" />
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-1074" comment="Version check for XP SP1 and XP no service pack for shell32.dll" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3097" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Cursor and Icon Formatting</product>
			</affected>
			<dates>
				<submitted date="2005-01-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<reference source="CVE">CAN-2004-1049</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-352" comment="the version of user32.dll is less than 4.0.1381.33630" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3100" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka &quot;DHTML Object Memory Corruption Vulnerability&quot;.</description>
			<reference source="CVE">CAN-2005-0553</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-594" comment="the version of mshtml.dll is less than 6.00.3790.279" />
					<criterion test_ref="wrt-438" negate="true" comment="the patch kb890923 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3120" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>NetDDE</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an &quot;unchecked buffer,&quot; possibly a buffer overflow.</description>
			<reference source="CVE">CAN-2004-0206</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1107" comment="Windows 2000 (sp5 or earlier) is installed" />
					<criterion test_ref="wft-527" comment="the version of netdde.exe is less than 5.0.2195.6952" />
					<criterion test_ref="wft-528" comment="the version of nddenb32.dll is less than 5.0.2195.6922" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3137" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6.0 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<modified date="2005-04-21" comment="modified wrt-158 - removed value to check against">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<modified date="2005-04-21" comment="modified wrt-158 - removed note">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the &quot;DHTML Method Heap Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0055</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-405" comment="the version of mshtml.dll is less than 6.0.3790.259" />
					<criterion test_ref="wrt-158" negate="true" comment="the patch kb867282 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3138" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>HyperTerminal</product>
			</affected>
			<dates>
				<submitted date="2005-01-07">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-24">DRAFT</status_change>
				<modified date="2005-01-27" comment="modified wrt-44 -  ">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<modified date="2005-03-02" comment="modified wft-169 - Change to access dll via HKLM">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-03-23">INTERIM</status_change>
				<status_change date="2005-04-13">ACCEPTED</status_change>
			</dates>
			<description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow. </description>
			<reference source="CVE">CVE-2004-0568</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-44" negate="true" comment="the patch Windows 2003 kb873339 is installed " />
					<criterion test_ref="wft-169" comment="the version of hypertrm.dll is less than 5.2.3790.233" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" />
					<criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3145" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-07-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-07-14" comment="Changed to DRAFT">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
			<reference source="CVE">CAN-2003-0112</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-435" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6159" />
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3157" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0555</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" />
					<criterion test_ref="wft-595" comment="the version of mshtml.dll is less than 6.0.2900.2627" />
					<criterion test_ref="wrt-439" negate="true" comment="the patch kb890923  is installed (XP SP2 Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3161" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>VDM</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
			<reference source="CVE">CAN-2004-0208</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-535" comment="the version of vdmdbg.dll is less than 5.1.2600.1560" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3179" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CAN-2003-1041.</description>
			<reference source="CVE">CAN-2004-0201</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1071" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3196" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<modified date="2005-04-21" comment="modified wrt-159 - unchecked value">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the &quot;URL Decoding Zone Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0054</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" />
					<criterion test_ref="wft-500" comment="the version of mshtml.dll is less than 6.0.2900.2604" />
					<criterion test_ref="wrt-159" comment="the patch kb867282 is installed (XP SP2 Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3203" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Hyperlink Object Library</product>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0057</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-177" comment="a vulnerable version of hlink.dll exists on Server 2003" />
					<criterion test_ref="wrt-78" negate="true" comment="the patch kb888113 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3216" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Animated Cursor</product>
			</affected>
			<dates>
				<submitted date="2005-01-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>The Windows Animated Cursor (ANI) in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to cause a denial of service (kernel crash or resource consumption) via the (1) frame number or (2) rate number set to zero</description>
			<reference source="CVE">CAN-2004-1305</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-353" comment="the version of user32.dll is less than 5.0.2195.7017" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3220" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Cursor and Icon Formatting</product>
			</affected>
			<dates>
				<submitted date="2005-01-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<reference source="CVE">CAN-2004-1049</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-355" comment="the version of user32.dll is less than 5.2.3790.245" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
					<criterion test_ref="cmp-62" comment="Windows Server 2003 or Windows Server 2003 64-bit Edition is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3242" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>NetDDE</product>
			</affected>
			<dates>
				<submitted date="2004-10-15">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an &quot;unchecked buffer,&quot; possibly a buffer overflow.</description>
			<reference source="CVE">CAN-2004-0206</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1152" comment="a vulnerable version of netdde.exe exists" />
					<criterion test_ref="cmp-1151" comment="a vulnerable version of nddenb32.dll exists" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3310" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-06">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<reference source="CVE">CAN-2004-0901</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-325" comment="the version of mswd6_32.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3311" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Office 2003</product>
			</affected>
			<dates>
				<submitted date="2004-09-23">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-13">INTERIM</status_change>
				<status_change date="2004-10-27">ACCEPTED</status_change>
				<modified date="2005-02-10" comment="modified wft-489 - corrected registry path check for .dll file">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-11">INTERIM</status_change>
				<status_change date="2005-03-02">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wrt-516 - wrt-516 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
			<reference source="CVE">CAN-2004-0573</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-515" comment="Microsoft Office 2003 is installed" />
					<criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " />
					<criterion test_ref="wrt-516" comment="Patch KB873378 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3312" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program</description>
			<reference source="CVE">CAN-2004-0894</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" />
					<criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3318" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the &quot;Channel Definition Format (CDF) Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0056</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="cmp-257" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" />
					<criterion test_ref="wrt-163" negate="true" comment="the patch kb867282 is installed (XP Win2K Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3320" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Visio Professional 2003</product>
			</affected>
			<dates>
				<submitted date="2004-09-27">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-09-29">DRAFT</status_change>
				<modified date="2004-09-30" comment="Changed affected platforms">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
				<modified date="2005-02-10" comment="modified wft-495 - corrected registry path check for .dll file">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-11">INTERIM</status_change>
				<status_change date="2005-03-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-527" comment="Visio Professional 2003 is Installed" />
					<criterion test_ref="wrt-528" negate="true" comment="Patch KB838345 installed" />
					<criterion test_ref="wft-495" comment="the version of gdiplus.dll is less than 6.0.3264.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3325" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<dates>
				<submitted date="2004-12-28">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program</description>
			<reference source="CVE">CAN-2004-0894</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" />
					<criterion test_ref="wft-349" comment="the version of lsasrv.dll is less than 5.1.2600.1597" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3333" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Office XP SP3</product>
			</affected>
			<dates>
				<submitted date="2004-09-22">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-09-23">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
				<modified date="2005-02-10" comment="modified wft-489 - corrected registry path check for .dll file">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-11">INTERIM</status_change>
				<status_change date="2005-03-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
			<reference source="CVE">CAN-2004-0573</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-199" comment="Microsoft Office XP Service Pack 3 is installed" />
					<criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3355" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Cursor and Icon Formatting</product>
			</affected>
			<dates>
				<submitted date="2005-01-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<reference source="CVE">CAN-2004-1049</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-351" comment="the version of user32.dll is less than 4.0.1381.7342" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3372" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.1 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from &quot;memory corruption&quot;) via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the &quot;&lt;STYLE&gt;@;/*&quot; string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the &quot;CSS Heap Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0842</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3376" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<dates>
				<submitted date="2004-08-26">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-08-26">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<modified date="2004-09-13" comment="cmp-66 added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
			<reference source="CVE">CAN-2004-0215</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-171" comment="Outlook Express 6 is installed" />
					<criterion test_ref="wft-461" comment="the version of inetcomm.dll is less than 6.0.2742.200" />
					<criterion test_ref="wrt-494" negate="true" comment="the patch kb823353 is installed " />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-495" comment="all users have the preview pane disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3386" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-10-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-10-06">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
			<reference source="CVE">CAN-2004-0420</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-447" comment="the version of shell32.dll is less than 5.0.3900.6922" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
					<criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3391" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2004-07-19">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
			<reference source="CVE">CAN-2003-0345</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-277" negate="true" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" />
					<criterion test_ref="cmp-1094" comment="XP SP1 or pre SP1 with version check on Srv.sys" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3416" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka </description>
			<reference source="CVE">CAN-2004-0571</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-326" comment="the version of mswrd632.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3428" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Task Scheduler</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
			<reference source="CVE">CAN-2004-0212</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-445" comment="the version of mstask.dll is less than 4.71.2195.6920" />
					<criterion test_ref="wrt-483" negate="true" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3456" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2005-05-04">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
			<reference source="CVE">CAN-2005-0063</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-57" comment="Windows XP 32-bit SP1 is installed" />
					<criterion test_ref="wft-590" comment="the version of shell32.dll is less than 6.0.2800.1643" />
					<criterion test_ref="wrt-434" negate="true" comment="the patch  KB893086 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3458" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2005-04-22">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-27">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the &quot;blind connection-reset attack.&quot;  NOTE: CAN-2004-0790, CAN-2004-0791, and CAN-2004-1060 have been SPLIT based on different attacks; CAN-2005-0065, CAN-2005-0066, CAN-2005-0067, and CAN-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
			<reference source="CVE">CAN-2004-0790</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" />
					<criterion test_ref="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" />
					<criterion test_ref="wrt-443" negate="true" comment="the patch KB893066 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3460" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>SMTP</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</description>
			<reference source="CVE">CAN-2004-0840</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" />
					<criterion test_ref="wrt-544" negate="true" comment="the patch WindowsServer2003-KB885881-ia64-enu.exe is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-240" comment="SMTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3464" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The DHTML Edit Control (dhtmled.ocx) in Internet Explorer 6.0.2900.2180 allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by &quot;AbusiveParent.&quot;</description>
			<reference source="CVE">CAN-2004-1319</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-180" comment="Windows XP 32-bit edition is installed  with service pack 2 (or earlier)" />
					<criterion test_ref="wft-375" comment="the version of dhtmled.ocx is less than 6.1.0.9232" />
					<criterion test_ref="wrt-87" negate="true" comment="the patch kb891781 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3483" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>NetBT Name Service</product>
			</affected>
			<dates>
				<submitted date="2004-07-01">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2004-07-19" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2004-07-20" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.</description>
			<reference source="CVE">CAN-2003-0661</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-1051" negate="true" comment="Patch WindowsXP-KB824105-x86-ENU.exe installed on XP or XP SP1" />
					<criterion test_ref="cmp-1097" comment="XP SP1 or Pre SP1 with correct netbt.sys version" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3496" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>HTML Help ActiveX Control</product>
			</affected>
			<dates>
				<submitted date="2005-03-30">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-12">DRAFT</status_change>
				<status_change date="2005-04-27">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the &quot;Related Topics&quot; command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using &quot;writehta.txt&quot; and the ADODB recordset, which saves a .HTA file to the local system, aka the &quot;HTML Help ActiveX control Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-1043</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-390" comment="the version of hhctrl.ocx is less than 5.2.3790.233" />
					<criterion test_ref="wrt-184" negate="true" comment="the patch Q890175 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3514" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing &quot;..&quot; (dot dot) sequences and a filename that ends in &quot;::&quot; which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CAN-2004-0475.</description>
			<reference source="CVE">CAN-2003-1041</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3533" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-07-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
			<reference source="CVE">CAN-2004-0420</reference>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
					<criterion test_ref="wft-449" comment="the version of shell32.dll is less than 6.0.2800.1517" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3544" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Client Server Runtime System (CSRSS)</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
			<reference source="CVE">CAN-2005-0551</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
					<criterion test_ref="cmp-328" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3556" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>MDAC 2.7</product>
			</affected>
			<dates>
				<submitted date="2005-03-31">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-12">DRAFT</status_change>
				<status_change date="2005-04-27">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) &quot;\&quot; (backslash) or (2) &quot;%5C&quot; (encoded backslash), aka &quot;Path Validation Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0847</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-117" comment="Is the .NET Framework 1.1 installed" />
					<criterion test_ref="cmp-253" comment="A vulnerable version of .NET Framework v1.1 is installed." />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3568" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>OLE</product>
			</affected>
			<dates>
				<submitted date="2005-02-15">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2005-02-16" comment="Added registry check to include three platforms">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-02-18">DRAFT</status_change>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the &quot;Input Validation Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0044</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-389" comment="the version of ole32.dll is less than 5.2.3790.250" />
					<criterion test_ref="wrt-91" negate="true" comment="the patch KB873333 is installed" />
					<criterion test_ref="cmp-187" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3573" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>MDAC 2.1</product>
			</affected>
			<dates>
				<submitted date="2004-08-24">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-02-28" comment="removed the test for windows NT and added a test for MDAC 2.1 since this definition is dependent on the MDAC version and not the platform">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
			<reference source="CVE">CVE-2002-1142</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-183" comment="MDAC 2.1 is installed" />
					<criterion test_ref="wft-483" comment="the version of msadco.dll is less than 2.12.5118.0" />
					<criterion test_ref="wrt-503" negate="true" comment="Patch Q329414 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3577" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>DHCP</product>
			</affected>
			<dates>
				<submitted date="2005-01-27">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-01-28">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the &quot;DHCP Request Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0900</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-156" comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" />
					<criterion test_ref="wrt-37" negate="true" comment="the patch KB885249 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3582" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>MDAC 2.8</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Corrected Windows Server 2003 test logic">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an &quot;unchecked buffer&quot; and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the &quot;License Logging Service Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0050</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-96" negate="true" comment="the patch kb885834 is installed (Hotfix key)" />
					<criterion test_ref="wft-395" comment="the version of Llssrv.exe is less than 5.2.3790.242" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-344" comment="license logging service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3585" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Explorer</product>
			</affected>
			<dates>
				<submitted date="2005-05-13">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-06-01">DRAFT</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-07-27">INTERIM</status_change>
			</dates>
			<description>The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe (&quot;'&quot;) in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.</description>
			<reference source="CVE">CAN-2005-1191</reference>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-613" comment="the version of webvw.dll is less than 5.0.3900.7036" />
					<criterion test_ref="wrt-608" negate="true" comment="the patch KB894320 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-609" comment="Webview is  Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3586" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the &quot;URL Decoding Zone Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0054</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="cmp-257" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" />
					<criterion test_ref="wrt-163" comment="the patch kb867282 is installed (XP Win2K Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3604" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-10-04">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-10-06">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
			<reference source="CVE">CAN-2004-0420</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1067" comment="Windows NT 4.0 with Active Desktop Installed" />
					<criterion test_ref="wft-452" comment="the version of shell32.dll is less than 4.72.3841.1100" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3677" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<dates>
				<submitted date="2005-01-03">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42</description>
			<reference source="CVE">CAN-2004-1080</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-193" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed" />
					<criterion test_ref="wft-350" comment="the version of wins.exe is less than 5.2.3790.239" />
					<criterion test_ref="wrt-38" negate="true" comment="the patch KB870763 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3685" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL</description>
			<reference source="CVE">CAN-2003-0711</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1112" comment="Windows XP 64-bit" />
					<criterion test_ref="wrt-308" negate="true" comment="Patch KB825119 Installed" />
					<criterion test_ref="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-309" negate="true" comment="HCP Protocol" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3743" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Table Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0901</description>
			<reference source="CVE">CAN-2004-0571</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
					<criterion test_ref="cmp-33" comment="The version of mswrd664.wpc OR wmswrd632.wpc is less than 2004.10.25.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3752" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka &quot;DHTML Object Memory Corruption Vulnerability&quot;.</description>
			<reference source="CVE">CAN-2005-0553</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="cmp-292" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" />
					<criterion test_ref="wrt-440" negate="true" comment="the patch kb890923  is installed (XP Win2K Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3768" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
			<reference source="CVE">CAN-2004-0572</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wrt-550" comment="Windows ME Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3773" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by &quot;wottapoop.html&quot;</description>
			<reference source="CVE">CAN-2004-0839</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3810" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Project Professional 2003</product>
			</affected>
			<dates>
				<submitted date="2004-09-24">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-09-29">DRAFT</status_change>
				<modified date="2004-09-30" comment="Changed affected platforms">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
				<modified date="2005-02-10" comment="modified wft-495 - corrected registry path check for .dll file">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-11">INTERIM</status_change>
				<status_change date="2005-03-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-521" comment="Project Professional 2003 Installed" />
					<criterion test_ref="wrt-522" negate="true" comment="Patch KB838344 Installed" />
					<criterion test_ref="wft-495" comment="the version of gdiplus.dll is less than 6.0.3264.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3817" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka &quot;URL Parsing Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0554</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" />
					<criterion test_ref="wft-595" comment="the version of mshtml.dll is less than 6.0.2900.2627" />
					<criterion test_ref="wrt-439" negate="true" comment="the patch kb890923  is installed (XP SP2 Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3822" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
			<reference source="CVE">CAN-2004-0572</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1115" comment="a vulnerable version of shell32.dll exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3824" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2005-04-22">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-27">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the &quot;IP Validation Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0048</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" />
					<criterion test_ref="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" />
					<criterion test_ref="wrt-443" negate="true" comment="the patch KB893066 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3851" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>The DHTML Edit Control (dhtmled.ocx) in Internet Explorer 6.0.2900.2180 allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by &quot;AbusiveParent.&quot;</description>
			<reference source="CVE">CAN-2004-1319</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-375" comment="the version of dhtmled.ocx is less than 6.1.0.9232" />
					<criterion test_ref="wrt-87" negate="true" comment="the patch kb891781 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3872" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-10-26">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
			<reference source="CVE">CAN-2004-0845</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3881" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Office XP SP2</product>
			</affected>
			<dates>
				<submitted date="2004-10-04">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-10-06">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
				<modified date="2005-02-10" comment="modified wft-496 - corrected registry path check">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-11">INTERIM</status_change>
				<status_change date="2005-03-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-514" comment="Microsoft Office XP Service Pack 2 is installed" />
					<criterion test_ref="wrt-533" negate="true" comment="Patch KB832332 installed" />
					<criterion test_ref="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3882" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-06">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Font Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0571.</description>
			<reference source="CVE">CAN-2004-0901</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" />
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3889" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Help and Support Center</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL</description>
			<reference source="CVE">CAN-2003-0711</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" />
					<criterion test_ref="wrt-308" negate="true" comment="Patch KB825119 Installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-309" comment="HCP Protocol" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3910" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the &quot;DHTML Method Heap Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0055</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-407" comment="the version of mshtml.dll is less than 5.0.3825.700" />
					<criterion test_ref="wrt-166" negate="true" comment="the patch kb867282 is installed (Win2K SP4  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3913" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Compressed Folders</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<modified date="2005-01-13" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
				<modified date="2005-05-05" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
					<contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an &quot;unchecked buffer&quot; and improper length validation</description>
			<reference source="CVE">CAN-2004-0575</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wft-537" comment="the 32-bit version of zipfldr.dll is less than 6.0.3790.198" />
					<criterion test_ref="wrt-553" negate="true" comment="the patch q873376 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-554" comment="Compressed Folders with zipfldr.dll are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3926" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0555</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="cmp-292" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" />
					<criterion test_ref="wrt-440" negate="true" comment="the patch kb890923  is installed (XP Win2K Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3941" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
			<reference source="CVE">CAN-2005-0060</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-581" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3949" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the &quot;Plug-in Navigation Address Bar Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0843</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" />
					<criterion test_ref="wrt-559" negate="true" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3953" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>VDM</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
			<reference source="CVE">CAN-2004-0208</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-41" comment="this is an NT Server (stand-alone)" />
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-512" comment="the version of gdi32.dll is less than 4.0.1381.7270" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3957" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Animated Cursor</product>
			</affected>
			<dates>
				<submitted date="2005-01-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>The Windows Animated Cursor (ANI) in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to cause a denial of service (kernel crash or resource consumption) via the (1) frame number or (2) rate number set to zero</description>
			<reference source="CVE">CAN-2004-1305</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-352" comment="the version of user32.dll is less than 4.0.1381.33630" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3966" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Distributed Component Object Model (DCOM) interface</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0715</description>
			<reference source="CVE">CAN-2003-0528</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" />
					<criterion test_ref="wft-358" comment="the version of rpcrt4.dll is less than 5.2.3790.76" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3973" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>HyperTerminal</product>
			</affected>
			<dates>
				<submitted date="2004-12-21">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-18">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<modified date="2005-03-02" comment="modified wft-226 - access DLL via HKLM">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
			<reference source="CVE">CVE-2004-0568</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-226" comment="the version of hypertrm.dll is less than 4.0.1381.7323" />
					<criterion test_ref="wrt-47" negate="true" comment="the patch NT Server kb873339 is installed " />
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" />
					<criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3994" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
			<reference source="CVE">CAN-2005-0061</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
					<criterion test_ref="cmp-328" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4003" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>GDI+</product>
			</affected>
			<dates>
				<submitted date="2004-09-20">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-513" negate="true" comment="the patch KB833987 is installed (for Windows XP)" />
					<criterion test_ref="wft-494" comment="the version of sxs.dll is less than 5.1.2600.1363" />
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4005" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Office XP SP2</product>
			</affected>
			<dates>
				<submitted date="2004-09-22">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-09-23">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
				<modified date="2005-02-10" comment="modified wft-489 - corrected registry path check for .dll file">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-02-11">INTERIM</status_change>
				<status_change date="2005-03-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
			<reference source="CVE">CAN-2004-0573</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-514" comment="Microsoft Office XP Service Pack 2 is installed" />
					<criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4021" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-12-16">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka &quot;Windows Kernel Vulnerability.</description>
			<reference source="CVE">CAN-2004-0893</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-147" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33591" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4022" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Office XP SP3</product>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2005-02-11" comment="Added patch check">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-03-29" comment="corrected patch negation">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) &quot;%00 (null byte) in .doc filenames or (2) &quot;%0a&quot; (carriage return) in .rtf filenames.</description>
			<reference source="CVE">CAN-2004-0848</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-199" comment="Microsoft Office XP Service Pack 3 is installed" />
					<criterion test_ref="wft-377" comment="the version of mso.dll is less than 10.0.6735.0" />
					<criterion test_ref="wrt-95" negate="true" comment="Patch KB873352 installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4032" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-04-21">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-04-27">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted extended verb request to the SMTP port.</description>
			<reference source="CVE">CAN-2005-0560</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-566" comment="Exchange Server 2003 is installed" />
					<criterion test_ref="wft-575" comment="the version of xlsasink.dll is less than 6.5.6981.3" />
					<criterion test_ref="wrt-423" negate="true" comment="the patch KB894549 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4043" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2005-02-15">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-02-18">DRAFT</status_change>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>The Server Message Block (SMB) implementation for Windows 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code using certain broadcast packets, aka the &quot;Server Message Block Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0045</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-385" comment="the version of mrxsmb.sys is less than 5.0.2195.7023" />
					<criterion test_ref="wrt-90" negate="true" comment="the patch KB885250 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4076" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
				<modified date="2005-04-08" comment="modified wrt-35 - wrt-35 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Font Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0571.</description>
			<reference source="CVE">CAN-2004-0901</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-35" comment="Word for Windows 6.0 Converter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4085" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<modified date="2005-04-21" comment="modified wrt-159 - unchecked value">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the &quot;Channel Definition Format (CDF) Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0056</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" />
					<criterion test_ref="wft-500" comment="the version of mshtml.dll is less than 6.0.2900.2604" />
					<criterion test_ref="wrt-159" negate="true" comment="the patch kb867282 is installed (XP SP2 Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4152" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by &quot;wottapoop.html&quot;.</description>
			<reference source="CVE">CAN-2004-0839</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4169" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.1 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from &quot;memory corruption&quot;) via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the &quot;&amp;lt;STYLE&amp;gt;@;/*&quot; string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the &quot;CSS Heap Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0842</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4216" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2004-10-04">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-10-06">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wrt-534" negate="true" comment="the patch q833989 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4224" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Distributed Component Object Model (DCOM) interface</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0528</description>
			<reference source="CVE">CAN-2003-0715</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wft-359" comment="the version of rpcrt4.dll is less than 5.1.2600.109" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4226" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Excel 2002</product>
			</affected>
			<dates>
				<submitted date="2004-10-18">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
			</dates>
			<description>Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.</description>
			<reference source="CVE">CAN-2004-0846</reference>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-138" comment="Excel 2002 is installed" />
					<criterion test_ref="ukn-38" comment="Service Pack 2 or less for Windows Office XP" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4244" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
			<reference source="CVE">CAN-2004-0572</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wft-525" comment="the version of grpconv.exe (system32) is less than 5.2.3790.205" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4264" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>ISA Server 2000</product>
			</affected>
			<dates>
				<submitted date="2004-11-17">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup resul</description>
			<reference source="CVE">CAN-2004-0892</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-6" comment="the version of msphlpr.dll is less than 3.0.1200.408" />
					<criterion test_ref="wrt-11" comment="ISA Server 2000 SP2 (or earlier) is installed" />
					<criterion test_ref="wrt-13" comment="the patch KB888258 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4276" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Compressed Folders</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<modified date="2005-01-13" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
				<modified date="2005-05-05" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
					<contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an &quot;unchecked buffer&quot; and improper length validation</description>
			<reference source="CVE">CAN-2004-0575</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wft-538" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.3790.198" />
					<criterion test_ref="wrt-553" negate="true" comment="the patch q873376 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-554" comment="Compressed Folders with zipfldr.dll are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4282" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>DHCP</product>
			</affected>
			<dates>
				<submitted date="2005-01-27">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-01-28">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka &quot;Logging Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0899</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-162" comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" />
					<criterion test_ref="wrt-37" negate="true" comment="the patch KB885249 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4307" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Visual Studio .NET 2002</product>
			</affected>
			<dates>
				<submitted date="2004-09-30">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-10-06">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
			<reference source="CVE">CAN-2004-0200</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-531" comment="Microsoft Visual Studio .NET 2002 Installed" />
					<criterion test_ref="wrt-532" negate="true" comment="Patch KB830348 installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4316" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>VDM</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
			<reference source="CVE">CAN-2004-0208</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-505" comment="the version of vdmdbg.dll is less than 5.0.2195.6946" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4328" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Table Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0901</description>
			<reference source="CVE">CAN-2004-0571</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-325" comment="the version of mswd6_32.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4345" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
			<reference source="CVE">CAN-2004-0214</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-499" comment="the version of shell32.dll is less than 5.0.3900.6970" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4363" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka &quot;HijackClick 3&quot; and the &quot;Script in Image Tag File Download Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0841</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" />
					<criterion test_ref="wrt-559" negate="true" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4368" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<dates>
				<submitted date="2004-12-28">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program</description>
			<reference source="CVE">CAN-2004-0894</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" />
					<criterion test_ref="wft-327" comment="the version of lsasrv.dll is less than 5.1.2600.2525" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4372" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<dates>
				<submitted date="2004-12-16">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42.</description>
			<reference source="CVE">CAN-2004-1080</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-165" comment="the version of wins.exe is less than 4.0.1381.33618" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4384" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Message Queuing</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</description>
			<reference source="CVE">CAN-2005-0059</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-313" comment="Windows XP Service Pack 1" />
					<criterion test_ref="wft-577" comment="the version of mqrt.dll is less than 5.1.0.1044" />
					<criterion test_ref="wrt-426" negate="true" comment="the patch KB892944 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-425" comment="Message Queuing Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4392" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an &quot;unchecked buffer,&quot; leading to off-by-one and heap-based buffer overflows.</description>
			<reference source="CVE">CAN-2004-0574</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" />
					<criterion test_ref="wrt-552" negate="true" comment="the patch WindowsServer2003-KB883935-x86-enu.exe is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4397" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka &quot;Object Management Vulnerability&quot;.</description>
			<reference source="CVE">CAN-2005-0550</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
					<criterion test_ref="cmp-328" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4458" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-06">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka &quot;Windows Kernel Vulnerability.</description>
			<reference source="CVE">CAN-2004-0893</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4492" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Adobe Acrobat Reader</product>
			</affected>
			<dates>
				<submitted date="2005-04-26">
					<contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
				</submitted>
				<status_change date="2005-04-27">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
			<reference source="CVE">CAN-2004-0597</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-301" comment="the software Adobe Acrobat Reader major version 6, minor version less than 3 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4493" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
			<reference source="CVE">CAN-2004-0572</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="cmp-1137" comment="a vulnerable version of grpconv.exe exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4499" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>unknown</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the &quot;Input Validation Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0044</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" />
					<criterion test_ref="wft-387" comment="the version of ole32.dll is less than 5.1.2600.1619" />
					<criterion test_ref="wrt-91" negate="true" comment="the patch KB873333 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4508" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>HyperTerminal</product>
			</affected>
			<dates>
				<submitted date="2004-12-21">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-18">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<modified date="2005-03-02" comment="modified wft-263 - access DLL via HKLM">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
			<reference source="CVE">CVE-2004-0568</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-263" comment="the version of hypertrm.dll is less than 4.0.1381.842" />
					<criterion test_ref="wrt-47" negate="true" comment="the patch NT Server kb873339 is installed " />
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" />
					<criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4576" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-06">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Font Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0571.</description>
			<reference source="CVE">CAN-2004-0901</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-325" comment="the version of mswd6_32.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4592" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>NetDDE</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an &quot;unchecked buffer,&quot; possibly a buffer overflow.</description>
			<reference source="CVE">CAN-2004-0206</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wft-540" comment="the version of nddenb32.dll is less than 5.2.3790.173" />
					<criterion test_ref="wft-541" comment="the version of netdde.exe is less than 5.2.3790.184" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4593" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
			<reference source="CVE">CAN-2005-0061</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-579" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4671" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Cursor and Icon Formatting</product>
			</affected>
			<dates>
				<submitted date="2005-01-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-06-22">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<reference source="CVE">CAN-2004-1049</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-353" comment="the version of user32.dll is less than 5.0.2195.7017" />
					<criterion test_ref="wrt-68" negate="true" comment="the patch kb891711 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4674" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2005-0555</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-594" comment="the version of mshtml.dll is less than 6.00.3790.279" />
					<criterion test_ref="wrt-438" negate="true" comment="the patch kb890923 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4702" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the &quot;Similar Method Name Redirection Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0727</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4706" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL</description>
			<reference source="CVE">CAN-2003-0711</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1111" comment="Windows Server 2003 or Windows 64-bit Edition is installed" />
					<criterion test_ref="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" />
					<criterion test_ref="wrt-308" negate="true" comment="Patch KB825119 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4710" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2005-05-04">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
			<reference source="CVE">CAN-2005-0063</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-592" comment="the version of shell32.dll is less than 5.0.3900.7032" />
					<criterion test_ref="wrt-436" negate="true" comment="the patch  KB893086 is installed " />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4726" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Messenger</product>
			</affected>
			<dates>
				<submitted date="2005-03-31">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-12">DRAFT</status_change>
				<status_change date="2005-04-27">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the &quot;Drag-and-Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0053</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" />
					<criterion test_ref="wft-401" comment="the version of shell32.dll is less than 6.0.3790.241" />
					<criterion test_ref="wrt-155" comment="the patch kb890047 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-157" negate="true" comment="Drag-and-Drop disabled when set to 3" />
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4741" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HyperTerminal</product>
			</affected>
			<dates>
				<submitted date="2004-12-21">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-18">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<modified date="2005-03-02" comment="modified wft-200 - access DLL via HKLM">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-03-23">ACCEPTED</status_change>
			</dates>
			<description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
			<reference source="CVE">CVE-2004-0568</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" />
					<criterion test_ref="wft-200" comment="the version of hypertrm.dll is less than 5.0.2195.7000" />
					<criterion test_ref="wrt-46" negate="true" comment="the patch Windows2000-KB873339-x86-ENU.EXE is installed " />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" />
					<criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4749" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<dates>
				<submitted date="2005-01-05">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Font Conversion Vulnerability,&quot; a different vulnerability than CAN-2004-0571</description>
			<reference source="CVE">CAN-2004-0901</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" />
					<criterion test_ref="wft-300" comment="the version of mswrd6.wpc is less than 10.0.803.2" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4758" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2005-02-10">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2005-02-11">DRAFT</status_change>
				<status_change date="2005-03-02">INTERIM</status_change>
				<status_change date="2005-03-23">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>The DHTML Edit Control (dhtmled.ocx) in Internet Explorer 6.0.2900.2180 allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by &quot;AbusiveParent.&quot;</description>
			<reference source="CVE">CAN-2004-1319</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-183" comment="Windows Server 2003 64-Bit Edition or Windows XP 64-Bit Edition Version 2003 " />
					<criterion test_ref="wft-378" comment="the version of wdhtmled.ocx is less than 6.1.0.9231" />
					<criterion test_ref="wrt-87" negate="true" comment="the patch kb891781 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4762" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>VDM</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
			<reference source="CVE">CAN-2004-0208</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-43" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-511" comment="the version of gdi32.dll is less than 4.0.1381.33566" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4767" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>IIS 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</description>
			<reference source="CVE">CAN-2003-0718</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-3" negate="true" comment="a Win2K/XP/2003 service pack is installed" />
					<criterion test_ref="wft-515" comment="the version of httpext.dll is less than 6.0.3790.212" />
					<criterion test_ref="wrt-549" comment="the patch KB824151 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4786" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>MDAC 2.8</product>
			</affected>
			<dates>
				<submitted date="2005-03-29">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-03-29">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an &quot;unchecked buffer&quot; and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the &quot;License Logging Service Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0050</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wrt-96" negate="true" comment="the patch kb885834 is installed (Hotfix key)" />
					<criterion test_ref="wft-392" comment="the version of Llssrv.exe is less than 4.0.1381.7345" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-344" comment="license logging service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4791" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2005-04-22">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-27">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</description>
			<reference source="CVE">CAN-2004-0230</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" />
					<criterion test_ref="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" />
					<criterion test_ref="wrt-443" negate="true" comment="the patch KB893066 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4797" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
			<reference source="CVE">CAN-2005-0060</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
					<criterion test_ref="cmp-328" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4831" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows NT 4.0</product>
			</affected>
			<dates>
				<submitted date="2005-01-03">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42</description>
			<reference source="CVE">CAN-2004-1080</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-164" comment="the version of wins.exe is less than 4.0.1381.7329" />
					<criterion test_ref="wrt-38" negate="true" comment="the patch KB870763 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4832" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka &quot;Object Management Vulnerability&quot;.</description>
			<reference source="CVE">CAN-2005-0550</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-579" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" />
					<criterion test_ref="wrt-427" negate="true" comment="the patch KB890859 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4846" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>DHCP</product>
			</affected>
			<dates>
				<submitted date="2004-12-16">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the &quot;DHCP Request Vulnerability.</description>
			<reference source="CVE">CAN-2004-0900</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" comment="this is an NT Terminal Server" />
					<criterion test_ref="wrt-37" negate="true" comment="the patch KB885249 is installed (Hotfix key)" />
					<criterion test_ref="wft-162" comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4859" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Proxy Server 2.0 SP1</product>
			</affected>
			<dates>
				<submitted date="2004-11-17">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<modified date="2005-03-01" comment="modified wft-7 - Corrected path">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-06-02" comment="modified wft-7 - corrected object path">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.</description>
			<reference source="CVE">CAN-2004-0892</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-9" comment="Microsoft Proxy Server 2.0 SP1 is installed" />
					<criterion test_ref="wft-7" comment="the version of w3proxy.dll is less than 2.0.390.16" />
					<criterion test_ref="wrt-14" comment="the patch KB888258 for Proxy Server 2.0 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4864" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the &quot;Drag-and-Drop Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0053</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-407" comment="the version of mshtml.dll is less than 5.0.3825.700" />
					<criterion test_ref="wrt-166" negate="true" comment="the patch kb867282 is installed (Win2K SP4  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-258" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing" />
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4874" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka &quot;DHTML Object Memory Corruption Vulnerability&quot;.</description>
			<reference source="CVE">CAN-2005-0553</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-598" comment="the version of mshtml.dll is less than 5.0.3539.2400" />
					<criterion test_ref="wrt-441" negate="true" comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4893" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<modified date="2004-10-13" comment="changed OS ">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.</description>
			<reference source="CVE">CAN-2004-0211</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4927" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>MSN Messenger</product>
			</affected>
			<dates>
				<submitted date="2005-04-19">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2005-04-20">DRAFT</status_change>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.</description>
			<reference source="CVE">CAN-2005-0562</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-431" negate="true" comment="MSN Messenger 6.2.0208 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4947" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-03-17">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-03-23">DRAFT</status_change>
				<status_change date="2005-04-13">INTERIM</status_change>
				<status_change date="2005-05-04">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the &quot;Channel Definition Format (CDF) Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2005-0056</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-407" comment="the version of mshtml.dll is less than 5.0.3825.700" />
					<criterion test_ref="wrt-166" negate="true" comment="the patch kb867282 is installed (Win2K SP4  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4985" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-05-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-05-11">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<status_change date="2005-06-22">ACCEPTED</status_change>
			</dates>
			<description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka &quot;DHTML Object Memory Corruption Vulnerability&quot;.</description>
			<reference source="CVE">CAN-2005-0553</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-599" comment="the version of mshtml.dll is less than 5.0.3826.2400" />
					<criterion test_ref="wrt-442" negate="true" comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4987" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>MDAC 2.7</product>
			</affected>
			<dates>
				<submitted date="2005-03-31">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2005-04-12">DRAFT</status_change>
				<status_change date="2005-04-27">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) &quot;\&quot; (backslash) or (2) &quot;%5C&quot; (encoded backslash), aka &quot;Path Validation Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0847</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-116" comment="Is the .NET Framework 1.0 installed" />
					<criterion test_ref="cmp-252" comment="A vulnerable version of .NET Framework v1.0 is installed. " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4988" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Message Queuing</product>
			</affected>
			<dates>
				<submitted date="2005-05-02">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</submitted>
				<status_change date="2005-05-04">DRAFT</status_change>
				<status_change date="2005-06-01">INTERIM</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2005-06-17" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</description>
			<reference source="CVE">CAN-2005-0059</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-576" comment="the version of mqrt.dll is less than 5.0.0.799" />
					<criterion test_ref="wrt-426" negate="true" comment="the patch KB892944 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL5021" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
			<reference source="CVE">CAN-2004-0573</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" />
					<criterion test_ref="wrt-548" negate="true" comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5070" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an &quot;unchecked buffer,&quot; leading to off-by-one and heap-based buffer overflows.</description>
			<reference source="CVE">CAN-2004-0574</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-539" comment="the version of nntpsvc.dll is less than 5.5.1877.79" />
					<criterion test_ref="wrt-556" negate="true" comment="Patch WindowsNT4OptionPack-KB883935-x86-enu.EXE" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5074" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>NetDDE</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an &quot;unchecked buffer,&quot; possibly a buffer overflow.</description>
			<reference source="CVE">CAN-2004-0206</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1147" comment="a vulnerable version of nddenb32.dll exists" />
					<criterion test_ref="cmp-1150" comment="a vulnerable version of netdde.exe exists" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL5150" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site</description>
			<reference source="CVE">CAN-2004-0845</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5277" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2004-10-18">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.</description>
			<reference source="CVE">CAN-2003-0569</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-43" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-559" comment="the version of rpcrt4.dll is less than 4.0.1381.33578" />
					<criterion test_ref="wrt-558" comment="Patch KB873350 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL5307" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
			<reference source="CVE">CAN-2004-0214</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1118" comment="a vulnerable version of shell32.dll exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL5316" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email.</description>
			<reference source="CVE">CAN-2004-0216</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5329" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email.</description>
			<reference source="CVE">CAN-2004-0216</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5509" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>SMTP</product>
			</affected>
			<dates>
				<submitted date="2004-10-13">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</description>
			<reference source="CVE">CAN-2004-0840</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" />
					<criterion test_ref="wrt-542" negate="true" comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-240" comment="SMTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5520" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site</description>
			<reference source="CVE">CAN-2004-0845</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5592" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.1 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from &quot;memory corruption&quot;) via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the &quot;&amp;lt;STYLE&amp;gt;@;/*&quot; string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the &quot;CSS Heap Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0842</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5620" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka &quot;HijackClick 3&quot; and the &quot;Script in Image Tag File Download Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0841</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5740" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2004-10-26">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
			<reference source="CVE">CAN-2004-0845</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5926" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an &quot;unchecked buffer,&quot; leading to off-by-one and heap-based buffer overflows.</description>
			<reference source="CVE">CAN-2004-0574</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" />
					<criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
					<criterion test_ref="wft-533" comment="the version of nntpsvc.dll is less than 5.0.2195.6972" />
					<criterion test_ref="wrt-555" negate="true" comment="Patch Windows2000-KB883935-x86-ENU.exe Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6031" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka &quot;HijackClick 3&quot; and the &quot;Script in Image Tag File Download Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0841</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6048" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka &quot;HijackClick 3&quot; and the &quot;Script in Image Tag File Download Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0841</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6100" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email</description>
			<reference source="CVE">CAN-2004-0216</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6272" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by &quot;wottapoop.html&quot;.</description>
			<reference source="CVE">CAN-2004-0839</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6313" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<modified date="2005-05-10" comment="modified wrt-51 - Comment updated to indicate IE 6.">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the &quot;Plug-in Navigation Address Bar Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0843</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6397" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Compressed Folders</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<modified date="2005-01-13" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-01-20">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
				<modified date="2005-05-05" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
					<contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
				</modified>
				<status_change date="2005-05-11">INTERIM</status_change>
				<status_change date="2005-06-01">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an &quot;unchecked buffer&quot; and improper length validation</description>
			<reference source="CVE">CAN-2004-0575</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="wft-536" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.2800.1584" />
					<criterion test_ref="wrt-553" negate="true" comment="the patch q873376 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-554" comment="Compressed Folders with zipfldr.dll are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6579" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.1 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from &quot;memory corruption&quot;) via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the &quot;&amp;lt;STYLE&amp;gt;@;/*&quot; string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the &quot;CSS Heap Memory Corruption Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0842</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6600" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email.</description>
			<reference source="CVE">CAN-2004-0216</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6788" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>NetDDE</product>
			</affected>
			<dates>
				<submitted date="2004-10-14">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an &quot;unchecked buffer,&quot; possibly a buffer overflow.</description>
			<reference source="CVE">CAN-2004-0206</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="cmp-1143" comment="a vulnerable version of netdde.exe exists" />
					<criterion test_ref="cmp-1144" comment="a vulnerable version of nddenb32.dll exists" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL6829" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the &quot;Similar Method Name Redirection Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0727</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7084" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the &quot;Similar Method Name Redirection Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0727</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" />
					<criterion test_ref="wrt-559" negate="true" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7095" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the &quot;Plug-in Navigation Address Bar Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0843</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL7194" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the &quot;Plug-in Navigation Address Bar Spoofing Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0843</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7448" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.</description>
			<reference source="CVE">CAN-2003-0727</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7496" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the &quot;Similar Method Name Redirection Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0727</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-565" comment="Internet Explorer 6 Service Pack 2 for XP is installed" />
					<criterion test_ref="cmp-1154" comment="a vulnerable version of mshtml.dll exisits" />
					<criterion test_ref="wrt-564" negate="true" comment="the patch kb834707  is installed (Installed Components key) " />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7611" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2004-10-26">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
			<reference source="CVE">CAN-2004-0845</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" />
					<criterion test_ref="wrt-559" negate="true" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7717" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email.</description>
			<reference source="CVE">CAN-2004-0216</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7721" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by &quot;wottapoop.html&quot;.</description>
			<reference source="CVE">CAN-2004-0839</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7865" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email.</description>
			<reference source="CVE">CAN-2004-0216</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" />
					<criterion test_ref="wrt-559" negate="true" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7906" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<dates>
				<submitted date="2004-10-19">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the &quot;Similar Method Name Redirection Cross Domain Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0727</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL8077" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2005-01-18">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2005-01-20">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka &quot;HijackClick 3&quot; and the &quot;Script in Image Tag File Download Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0841</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL8127" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<dates>
				<submitted date="2004-10-25">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the &quot;Address Bar Spoofing on Double Byte Character Set Systems Vulnerability.&quot;</description>
			<reference source="CVE">CAN-2004-0844</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wft-561" negate="true" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
	</definitions>
	<tests>
		<compound_test id="cmp-1" operation="OR" comment="a vulnerable version of rpcrt4.dll exists on XP">
			<subtest negate="false" test_ref="cmp-2"/>
			<subtest negate="false" test_ref="cmp-6"/>
		</compound_test>
		<compound_test id="cmp-10" operation="OR" comment="a vulnerable version of rpcss.dll exists on XP">
			<subtest negate="false" test_ref="cmp-11"/>
			<subtest negate="false" test_ref="cmp-15"/>
		</compound_test>
		<compound_test id="cmp-100" operation="OR" comment="MDAC 2.7 is installed and a vulnerable version of sqlsrv32.dll and odbcbcp.dll exists">
			<subtest negate="false" test_ref="cmp-101"/>
			<subtest negate="false" test_ref="cmp-102"/>
		</compound_test>
		<compound_test id="cmp-101" operation="AND" comment="MDAC 2.7 (RTM) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9002.0">
			<subtest negate="false" test_ref="wrt-102"/>
			<subtest negate="false" test_ref="wft-37"/>
			<subtest negate="false" test_ref="wft-42"/>
		</compound_test>
		<compound_test id="cmp-1011" operation="AND" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition">
			<subtest negate="false" test_ref="wft-414"/>
			<subtest negate="true" test_ref="wrt-243"/>
		</compound_test>
		<compound_test id="cmp-1012" operation="AND" comment="For Terminal Server">
			<subtest negate="false" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-415"/>
		</compound_test>
		<compound_test id="cmp-102" operation="AND" comment="MDAC 2.7 (SP1) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9042.0">
			<subtest negate="false" test_ref="wrt-103"/>
			<subtest negate="false" test_ref="wft-38"/>
			<subtest negate="false" test_ref="wft-43"/>
		</compound_test>
		<compound_test id="cmp-103" operation="OR" comment="the patch q832483 is not installed">
			<subtest negate="false" test_ref="cmp-104"/>
			<subtest negate="false" test_ref="cmp-105"/>
		</compound_test>
		<compound_test id="cmp-104" operation="AND" comment="32-bit edition of windows and patch q832483 is not installed">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="true" test_ref="wrt-110"/>
		</compound_test>
		<compound_test id="cmp-1043" operation="AND" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition">
			<subtest negate="false" test_ref="wft-416"/>
			<subtest negate="true" test_ref="wrt-243"/>
		</compound_test>
		<compound_test id="cmp-1044" operation="AND" comment="For Terminal Server">
			<subtest negate="false" test_ref="wrt-43"/>
			<subtest negate="true" test_ref="wrt-456"/>
		</compound_test>
		<compound_test id="cmp-1045" operation="OR" comment="Vulnerable versions of DirectX">
			<subtest negate="false" test_ref="cmp-1046"/>
			<subtest negate="false" test_ref="cmp-1047"/>
			<subtest negate="false" test_ref="cmp-1048"/>
			<subtest negate="false" test_ref="cmp-1049"/>
			<subtest negate="false" test_ref="cmp-1050"/>
		</compound_test>
		<compound_test id="cmp-1046" operation="AND" comment="Unpatched DirectX 7.0">
			<subtest negate="false" test_ref="wrt-461"/>
			<subtest negate="false" test_ref="wft-421"/>
			<subtest negate="true" test_ref="wrt-462"/>
		</compound_test>
		<compound_test id="cmp-1047" operation="AND" comment="Unpatched DirectX 8.0x">
			<subtest negate="false" test_ref="wrt-463"/>
			<subtest negate="false" test_ref="wft-422"/>
			<subtest negate="true" test_ref="wrt-464"/>
		</compound_test>
		<compound_test id="cmp-1048" operation="AND" comment="Unpatched DirectX 8.1x">
			<subtest negate="false" test_ref="wrt-465"/>
			<subtest negate="false" test_ref="wft-423"/>
			<subtest negate="true" test_ref="wrt-466"/>
		</compound_test>
		<compound_test id="cmp-1049" operation="AND" comment="Unpatched DirectX 8.2x">
			<subtest negate="false" test_ref="wrt-467"/>
			<subtest negate="false" test_ref="wft-424"/>
			<subtest negate="true" test_ref="wrt-468"/>
		</compound_test>
		<compound_test id="cmp-105" operation="AND" comment="64-bit edition of windows and patch q832483 is not installed">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="true" test_ref="wrt-111"/>
		</compound_test>
		<compound_test id="cmp-1050" operation="AND" comment="Unpatched DirectX 9.0x">
			<subtest negate="false" test_ref="wrt-469"/>
			<subtest negate="false" test_ref="wft-425"/>
			<subtest negate="true" test_ref="wrt-470"/>
		</compound_test>
		<compound_test id="cmp-1051" operation="OR" comment="Patch WindowsXP-KB824105-x86-ENU.exe installed on XP or XP SP1">
			<subtest negate="false" test_ref="wrt-475"/>
			<subtest negate="false" test_ref="wrt-476"/>
		</compound_test>
		<compound_test id="cmp-1058" operation="AND" comment="Windows XP 32-bit edition is installed">
			<subtest negate="false" test_ref="wrt-2"/>
			<subtest negate="false" test_ref="wrt-72"/>
		</compound_test>
		<compound_test id="cmp-106" operation="AND" comment="current user settings are being used and the downloading of signed ActiveX controls is enabled">
			<subtest negate="true" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-294"/>
		</compound_test>
		<compound_test id="cmp-1060" operation="AND" comment="This is an NT Terminal Server and the version of psxss.exe is less than 4.0.1381.33567">
			<subtest negate="false" test_ref="wft-440"/>
			<subtest negate="false" test_ref="wrt-43"/>
		</compound_test>
		<compound_test id="cmp-1062" operation="OR" comment="This is an NT Workstation or Windows NT Server 4.0 is installed">
			<subtest negate="false" test_ref="cmp-44"/>
			<subtest negate="false" test_ref="wrt-40"/>
		</compound_test>
		<compound_test id="cmp-1063" operation="AND" comment="The version of psxss.exe is less than 4.0.1381.7269 on either NT Workstation or NT Server 4.0">
			<subtest negate="false" test_ref="cmp-1062"/>
			<subtest negate="false" test_ref="wft-443"/>
		</compound_test>
		<compound_test id="cmp-1064" operation="OR" comment="Version check for psxss.exe on NT Workstation, Server 4.0 and NT Terminal Server">
			<subtest negate="false" test_ref="cmp-1060"/>
			<subtest negate="false" test_ref="cmp-1063"/>
		</compound_test>
		<compound_test id="cmp-1066" operation="AND" comment="Windows XP 64-bit with Service Pack 1">
			<subtest negate="false" test_ref="wrt-2"/>
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-1067" operation="AND" comment="Windows NT 4.0 with Active Desktop Installed">
			<subtest negate="false" test_ref="wrt-490"/>
			<subtest negate="false" test_ref="wrt-77"/>
		</compound_test>
		<compound_test id="cmp-1068" operation="AND" comment="no service pack is installed and mstask.dll is less than 5.1.2600.155">
			<subtest negate="false" test_ref="wft-453"/>
			<subtest negate="false" test_ref="wrt-3"/>
		</compound_test>
		<compound_test id="cmp-1069" operation="AND" comment="service pack 1 is installed and mstask.dll is less than 5.1.2600.1564">
			<subtest negate="false" test_ref="wft-454"/>
			<subtest negate="false" test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-107" operation="AND" comment="local machine settings are being used and the downloading of signed ActiveX controls is enabled">
			<subtest negate="false" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-190"/>
		</compound_test>
		<compound_test id="cmp-1070" operation="OR" comment="Affected mstask.dll file versions based on service pack levels">
			<subtest negate="false" test_ref="cmp-1068"/>
			<subtest negate="false" test_ref="cmp-1069"/>
		</compound_test>
		<compound_test id="cmp-1071" operation="OR" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed">
			<subtest negate="false" test_ref="wrt-50"/>
			<subtest negate="false" test_ref="wrt-51"/>
			<subtest negate="false" test_ref="wrt-53"/>
		</compound_test>
		<compound_test id="cmp-1072" operation="AND" comment="XP Service Pack 1 and version of Shell32.dll is less than 6.0.2800.1233 ">
			<subtest negate="false" test_ref="wft-458"/>
			<subtest negate="false" test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-1073" operation="AND" comment="XP no Service Pack installed and version of Shell32.dll is less than 6.0.2600.115">
			<subtest negate="false" test_ref="wft-459"/>
			<subtest negate="false" test_ref="wrt-410"/>
		</compound_test>
		<compound_test id="cmp-1074" operation="OR" comment="Version check for XP SP1 and XP no service pack for shell32.dll">
			<subtest negate="false" test_ref="cmp-1072"/>
			<subtest negate="false" test_ref="cmp-1073"/>
		</compound_test>
		<compound_test id="cmp-108" operation="AND" comment="current user settings are being used and file downloads are enabled">
			<subtest negate="true" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-286"/>
		</compound_test>
		<compound_test id="cmp-1084" operation="AND" comment="Version Ntoskrnl.exe is less than 4.0.1381.7265 and this is an NT Workstation">
			<subtest negate="false" test_ref="wft-343"/>
			<subtest negate="false" test_ref="wrt-40"/>
		</compound_test>
		<compound_test id="cmp-1085" operation="OR" comment="Version check of Ntoskrnl for NT Terminal Server or NT Workstation">
			<subtest negate="false" test_ref="cmp-1084"/>
			<subtest negate="false" test_ref="cmp-944"/>
		</compound_test>
		<compound_test id="cmp-1086" operation="AND" comment="Pre Service Pack XP and netbt.sys is less than 5.1.2600.117">
			<subtest negate="false" test_ref="wft-463"/>
			<subtest negate="false" test_ref="wrt-410"/>
		</compound_test>
		<compound_test id="cmp-109" operation="AND" comment="local machine settings are being used and file downloads are enabled">
			<subtest negate="false" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-191"/>
		</compound_test>
		<compound_test id="cmp-1092" operation="AND" comment="XP Pre- SP1 with Srv.sys is less than 5.1.2600.112">
			<subtest negate="false" test_ref="wft-465"/>
			<subtest negate="false" test_ref="wrt-410"/>
		</compound_test>
		<compound_test id="cmp-1093" operation="AND" comment="XP SP1 and srv.sys is less than 5.1.2600.1193">
			<subtest negate="false" test_ref="wft-466"/>
			<subtest negate="false" test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-1094" operation="OR" comment="XP SP1 or pre SP1 with version check on Srv.sys">
			<subtest negate="false" test_ref="cmp-1092"/>
			<subtest negate="false" test_ref="cmp-1093"/>
		</compound_test>
		<compound_test id="cmp-1095" operation="OR" comment="Version checks on XP for Ipnathlp.dll">
			<subtest negate="false" test_ref="cmp-946"/>
			<subtest negate="false" test_ref="cmp-947"/>
			<subtest negate="false" test_ref="cmp-948"/>
		</compound_test>
		<compound_test id="cmp-1096" operation="AND" comment="XP SP1 and netbt.sys is less than 5.1.2600.1243">
			<subtest negate="false" test_ref="wft-464"/>
			<subtest negate="false" test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-1097" operation="OR" comment="XP SP1 or Pre SP1 with correct netbt.sys version">
			<subtest negate="false" test_ref="cmp-1086"/>
			<subtest negate="false" test_ref="cmp-1096"/>
		</compound_test>
		<compound_test id="cmp-1098" operation="OR" comment="a vulnerable version of inetcomm.dll exisits">
			<subtest negate="false" test_ref="wft-462"/>
			<subtest negate="false" test_ref="wft-468"/>
		</compound_test>
		<compound_test id="cmp-11" operation="AND" comment="32-bit version of Windows and a vulnerable version of rpcss.dll exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="cmp-12"/>
		</compound_test>
		<compound_test id="cmp-110" operation="AND" comment="current user settings are being used and cookies are enabled">
			<subtest negate="true" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-270"/>
			<subtest negate="false" test_ref="wrt-192"/>
		</compound_test>
		<compound_test id="cmp-1102" operation="AND" comment="Windows XP 64-bit with SP1 (or earlier) installed">
			<subtest negate="false" test_ref="cmp-66"/>
		</compound_test>
		<compound_test id="cmp-1103" operation="OR" comment="Microsoft Office 2000 (Premium or Professional) Service Pack 3 is installed">
			<subtest negate="false" test_ref="wrt-529"/>
			<subtest negate="false" test_ref="wrt-535"/>
		</compound_test>
		<compound_test id="cmp-1106" operation="AND" comment="Windows 2000 (sp4 or earlier) is installed">
			<subtest negate="false" test_ref="wrt-1"/>
			<subtest negate="true" test_ref="wrt-539"/>
		</compound_test>
		<compound_test id="cmp-1107" operation="AND" comment="Windows 2000 (sp5 or earlier) is installed">
			<subtest negate="false" test_ref="wrt-1"/>
			<subtest negate="true" test_ref="wrt-539"/>
		</compound_test>
		<compound_test id="cmp-1108" operation="AND" comment="Service pack 1 and the version of httpext.dll is less than 6.0.2600.1579">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-504"/>
		</compound_test>
		<compound_test id="cmp-1109" operation="AND" comment="no service pack and the version of httpext.dll is less than 6.0.2600.165">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-503"/>
		</compound_test>
		<compound_test id="cmp-111" operation="AND" comment="local machine settings are being used and cookies are enabled">
			<subtest negate="false" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-193"/>
			<subtest negate="false" test_ref="wrt-194"/>
		</compound_test>
		<compound_test id="cmp-1110" operation="OR" comment="a vulnerable version of httpext.dll exists">
			<subtest negate="false" test_ref="cmp-1108"/>
			<subtest negate="false" test_ref="cmp-1109"/>
		</compound_test>
		<compound_test id="cmp-1111" operation="OR" comment="Windows Server 2003 or Windows 64-bit Edition is installed">
			<subtest negate="false" test_ref="wrt-61"/>
			<subtest negate="false" test_ref="cmp-1066"/>
		</compound_test>
		<compound_test id="cmp-1112" operation="AND" comment="Windows XP 64-bit">
			<subtest negate="false" test_ref="wrt-2"/>
			<subtest negate="false" test_ref="wrt-70"/>
		</compound_test>
		<compound_test id="cmp-1113" operation="OR" comment="Windows 2003 Server or Windows XP 64-bit">
			<subtest negate="false" test_ref="cmp-1112"/>
			<subtest negate="false" test_ref="wrt-61"/>
		</compound_test>
		<compound_test id="cmp-1115" operation="OR" comment="a vulnerable version of shell32.dll exists">
			<subtest negate="false" test_ref="wft-510"/>
			<subtest negate="false" test_ref="wft-509"/>
		</compound_test>
		<compound_test id="cmp-1116" operation="AND" comment="service pack 1 is installed and a vulnerable version of shell32.dll exists">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-510"/>
		</compound_test>
		<compound_test id="cmp-1117" operation="AND" comment="no service pack is installed and a vulnerable version of shell32.dll exists">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-514"/>
		</compound_test>
		<compound_test id="cmp-1118" operation="OR" comment="a vulnerable version of shell32.dll exists">
			<subtest negate="false" test_ref="cmp-1117"/>
			<subtest negate="false" test_ref="cmp-1116"/>
		</compound_test>
		<compound_test id="cmp-1119" operation="AND" comment="Active Desktop is not installed and shell32.dll is less than 4.0.1381.7267">
			<subtest negate="true" test_ref="wrt-490"/>
			<subtest negate="false" test_ref="wft-471"/>
		</compound_test>
		<compound_test id="cmp-112" operation="OR" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists">
			<subtest negate="false" test_ref="wft-31"/>
			<subtest negate="false" test_ref="wft-114"/>
		</compound_test>
		<compound_test id="cmp-1120" operation="AND" comment="Active Desktop is installed and shell32.dll is less than 4.72.3843.3100">
			<subtest negate="false" test_ref="wrt-490"/>
			<subtest negate="false" test_ref="wft-516"/>
		</compound_test>
		<compound_test id="cmp-1121" operation="AND" comment="a vulnerable version of shell32.dll exists on NT Server">
			<subtest negate="false" test_ref="cmp-50"/>
			<subtest negate="false" test_ref="cmp-1122"/>
		</compound_test>
		<compound_test id="cmp-1122" operation="OR" comment="a vulnerable version of shell32.dll exists">
			<subtest negate="false" test_ref="cmp-1120"/>
			<subtest negate="false" test_ref="cmp-1119"/>
		</compound_test>
		<compound_test id="cmp-1123" operation="AND" comment="a vulnerable version of shell32.dll exists on NT Terminal Server">
			<subtest negate="false" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-517"/>
		</compound_test>
		<compound_test id="cmp-1124" operation="OR" comment="a vulnerable version of shell32.dll exists">
			<subtest negate="false" test_ref="cmp-1121"/>
			<subtest negate="false" test_ref="cmp-1123"/>
		</compound_test>
		<compound_test id="cmp-1126" operation="AND" comment="NT Server and grpconv.exe less than 4.0.1381.7286">
			<subtest negate="false" test_ref="cmp-50"/>
			<subtest negate="false" test_ref="wft-523"/>
		</compound_test>
		<compound_test id="cmp-1127" operation="AND" comment="NT Terminal Server and grpconv.exe less than 4.0.1381.33577">
			<subtest negate="false" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-524"/>
		</compound_test>
		<compound_test id="cmp-1128" operation="OR" comment="a vulnerable version of grpconv.exe exists on NT">
			<subtest negate="false" test_ref="cmp-1126"/>
			<subtest negate="false" test_ref="cmp-1127"/>
		</compound_test>
		<compound_test id="cmp-113" operation="OR" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists">
			<subtest negate="false" test_ref="wft-32"/>
			<subtest negate="false" test_ref="wft-113"/>
		</compound_test>
		<compound_test id="cmp-1133" operation="OR" comment="a vulnerable version of grpconv.exe exists">
			<subtest negate="false" test_ref="wft-530"/>
			<subtest negate="false" test_ref="wft-531"/>
		</compound_test>
		<compound_test id="cmp-1134" operation="AND" comment="no service pack is installed and a vulnerable version of grpconv.exe exists">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-529"/>
		</compound_test>
		<compound_test id="cmp-1135" operation="AND" comment="service pack 1 is installed and a vulnerable version of grpconv.exe exists">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-530"/>
		</compound_test>
		<compound_test id="cmp-1136" operation="OR" comment="a vulnerable version of grpconv.exe exists">
			<subtest negate="false" test_ref="cmp-1134"/>
			<subtest negate="false" test_ref="cmp-1135"/>
		</compound_test>
		<compound_test id="cmp-1137" operation="OR" comment="a vulnerable version of grpconv.exe exists">
			<subtest negate="false" test_ref="wft-525"/>
			<subtest negate="false" test_ref="wft-526"/>
		</compound_test>
		<compound_test id="cmp-1139" operation="AND" comment="no service pack and vulnerable 32-bit version of zipfldr.dll">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-532"/>
		</compound_test>
		<compound_test id="cmp-114" operation="OR" comment="a vulnerable version of helpctr.exe exists on XP">
			<subtest negate="false" test_ref="cmp-126"/>
			<subtest negate="false" test_ref="cmp-149"/>
		</compound_test>
		<compound_test id="cmp-1140" operation="AND" comment="service pack 1 and vulnerable 32-bit version of zipfldr.dll">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-534"/>
		</compound_test>
		<compound_test id="cmp-1141" operation="OR" comment="vulnerable 32-bit version of zipfldr.dll">
			<subtest negate="false" test_ref="cmp-1139"/>
			<subtest negate="false" test_ref="cmp-1140"/>
		</compound_test>
		<compound_test id="cmp-1143" operation="OR" comment="a vulnerable version of netdde.exe exists">
			<subtest negate="false" test_ref="wft-541"/>
			<subtest negate="false" test_ref="wft-543"/>
		</compound_test>
		<compound_test id="cmp-1144" operation="OR" comment="a vulnerable version of nddenb32.dll exists">
			<subtest negate="false" test_ref="wft-540"/>
			<subtest negate="false" test_ref="wft-542"/>
		</compound_test>
		<compound_test id="cmp-1145" operation="AND" comment="no service pack is installed and a vulnerable version of nddenb32.dll exists">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-546"/>
		</compound_test>
		<compound_test id="cmp-1146" operation="AND" comment="Service Pack 1 is installed and a vulnerable version of nddenb32.dll exists">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-545"/>
		</compound_test>
		<compound_test id="cmp-1147" operation="OR" comment="a vulnerable version of nddenb32.dll exists">
			<subtest negate="false" test_ref="cmp-1145"/>
			<subtest negate="false" test_ref="cmp-1146"/>
		</compound_test>
		<compound_test id="cmp-1148" operation="AND" comment="no service pack is installed and a vulnerable version of netdde.exe exists">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-547"/>
		</compound_test>
		<compound_test id="cmp-1149" operation="AND" comment="Service Pack 1 is installed and a vulnerable version of netdde.exe exists">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-544"/>
		</compound_test>
		<compound_test id="cmp-115" operation="AND" comment="no service pack is installed and cryptui.dll is less than 5.131.2600.117">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-249"/>
		</compound_test>
		<compound_test id="cmp-1150" operation="OR" comment="a vulnerable version of netdde.exe exists">
			<subtest negate="false" test_ref="cmp-1148"/>
			<subtest negate="false" test_ref="cmp-1149"/>
		</compound_test>
		<compound_test id="cmp-1151" operation="OR" comment="a vulnerable version of nddenb32.dll exists">
			<subtest negate="false" test_ref="wft-545"/>
			<subtest negate="false" test_ref="wft-549"/>
		</compound_test>
		<compound_test id="cmp-1152" operation="OR" comment="a vulnerable version of netdde.exe exists">
			<subtest negate="false" test_ref="wft-544"/>
			<subtest negate="false" test_ref="wft-548"/>
		</compound_test>
		<compound_test id="cmp-1153" operation="AND" comment="Exchange Server 2003 is installed on Windows Server 2003">
			<subtest negate="false" test_ref="wrt-61"/>
			<subtest negate="false" test_ref="wrt-113"/>
		</compound_test>
		<compound_test id="cmp-1154" operation="OR" comment="a vulnerable version of mshtml.dll exisits">
			<subtest negate="false" test_ref="wft-550"/>
			<subtest negate="false" test_ref="wft-551"/>
		</compound_test>
		<compound_test id="cmp-1156" operation="AND" comment="The patch js56nen.exe is installed for version 5.1, 5.5, or 5.6">
			<subtest negate="false" test_ref="wrt-499"/>
			<subtest negate="false" test_ref="wrt-500"/>
			<subtest negate="false" test_ref="wrt-501"/>
		</compound_test>
		<compound_test id="cmp-1157" operation="AND" comment="jscript.dll version is 5.1, 5.5, or 5.6 ">
			<subtest negate="false" test_ref="wft-120"/>
			<subtest negate="false" test_ref="wft-121"/>
			<subtest negate="false" test_ref="wft-257"/>
		</compound_test>
		<compound_test id="cmp-116" operation="AND" comment="32-bit version of windows with SP2 is installed and vulnerable version of telnet.exe exists">
			<subtest negate="false" test_ref="wft-77"/>
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="wrt-250"/>
		</compound_test>
		<compound_test id="cmp-117" operation="AND" comment="no service pack is installed and user32.dll is less than 5.1.2600.118">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-258"/>
		</compound_test>
		<compound_test id="cmp-119" operation="AND" comment="no service pack is installed and msgsvc.dll is less than 5.1.2600.120">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-272"/>
		</compound_test>
		<compound_test id="cmp-12" operation="OR" comment="a vulnerable version of rpcss.dll exists depending on service pack level">
			<subtest negate="false" test_ref="cmp-13"/>
			<subtest negate="false" test_ref="cmp-14"/>
		</compound_test>
		<compound_test id="cmp-120" operation="OR" comment="a vulnerable version of msgina.dll exists">
			<subtest negate="false" test_ref="cmp-121"/>
			<subtest negate="false" test_ref="cmp-125"/>
		</compound_test>
		<compound_test id="cmp-121" operation="AND" comment="32-bit version of Windows and a vulnerable version of msgina.dll exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="cmp-122"/>
		</compound_test>
		<compound_test id="cmp-122" operation="OR" comment="a vulnerable version of msgina.dll exists depending on service pack level">
			<subtest negate="false" test_ref="cmp-123"/>
			<subtest negate="false" test_ref="cmp-124"/>
		</compound_test>
		<compound_test id="cmp-123" operation="AND" comment="no service pack is installed and msgina.dll is less than 5.1.2600.128">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-134"/>
		</compound_test>
		<compound_test id="cmp-124" operation="AND" comment="service pack 1 is installed and msgina.dll is less than 5.1.2600.1343">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-135"/>
		</compound_test>
		<compound_test id="cmp-125" operation="AND" comment="64-bit version of Windows and msgina.dll is less than 5.1.2600.1343">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-135"/>
		</compound_test>
		<compound_test id="cmp-126" operation="AND" comment="32-bit version of Windows and a vulnerable version of helpctr.exe exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="cmp-127"/>
		</compound_test>
		<compound_test id="cmp-127" operation="OR" comment="a vulnerable version of helpctr.exe exists exists depending on service pack level">
			<subtest negate="false" test_ref="cmp-128"/>
			<subtest negate="false" test_ref="cmp-129"/>
		</compound_test>
		<compound_test id="cmp-128" operation="AND" comment="service pack 1 or earlier is installed and helpctr.exe is less than 5.1.2600.137">
			<subtest negate="true" test_ref="wrt-29"/>
			<subtest negate="false" test_ref="wft-2"/>
		</compound_test>
		<compound_test id="cmp-129" operation="AND" comment="service pack 2 is installed and helpctr.exe is less than 5.1.2600.1515">
			<subtest negate="false" test_ref="wrt-250"/>
			<subtest negate="false" test_ref="wft-3"/>
		</compound_test>
		<compound_test id="cmp-13" operation="AND" comment="no service pack is installed and rpcss.dll is less than 5.1.2600.135">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-197"/>
		</compound_test>
		<compound_test id="cmp-130" operation="OR" comment="a vulnerable version of schannel.dll exists">
			<subtest negate="false" test_ref="cmp-131"/>
			<subtest negate="false" test_ref="cmp-135"/>
		</compound_test>
		<compound_test id="cmp-131" operation="AND" comment="32-bit version of Windows and a vulnerable version of schannel.dll exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="cmp-132"/>
		</compound_test>
		<compound_test id="cmp-132" operation="OR" comment="a vulnerable version of schannel.dll exists depending on service pack level">
			<subtest negate="false" test_ref="cmp-133"/>
			<subtest negate="false" test_ref="cmp-134"/>
		</compound_test>
		<compound_test id="cmp-133" operation="AND" comment="no service pack is installed and schannel.dll is less than 5.1.2600.136">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-173"/>
		</compound_test>
		<compound_test id="cmp-134" operation="AND" comment="service pack 1 is installed and schannel.dll is less than 5.1.2600.1347">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-174"/>
		</compound_test>
		<compound_test id="cmp-135" operation="AND" comment="64-bit version of Windows and schannel.dll is less than 5.1.2600.1347">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-174"/>
		</compound_test>
		<compound_test id="cmp-136" operation="OR" comment="a vulnerable version of msgina.dll exists on NT">
			<subtest negate="false" test_ref="cmp-137"/>
			<subtest negate="false" test_ref="cmp-138"/>
		</compound_test>
		<compound_test id="cmp-137" operation="AND" comment="non Terminal Server and msgina.dll is less than 4.0.1381.7255">
			<subtest negate="true" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-131"/>
		</compound_test>
		<compound_test id="cmp-138" operation="AND" comment="Terminal Server and msgina.dll is less than 4.0.1381.33559">
			<subtest negate="false" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-132"/>
		</compound_test>
		<compound_test id="cmp-139" operation="OR" comment="Windows NT or 2000 is installed">
			<subtest negate="false" test_ref="wrt-77"/>
			<subtest negate="false" test_ref="wrt-1"/>
		</compound_test>
		<compound_test id="cmp-14" operation="AND" comment="service pack 1 is installed and rpcss.dll is less than 5.1.2600.1361">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-198"/>
		</compound_test>
		<compound_test id="cmp-140" operation="OR" comment="a vulnerable version of Microsoft Jet 4.0 is installed">
			<subtest negate="false" test_ref="cmp-141"/>
			<subtest negate="false" test_ref="cmp-142"/>
		</compound_test>
		<compound_test id="cmp-141" operation="AND" comment="32-bit version of Windows and msjet40.dll is less than 4.0.8618.0">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="wft-180"/>
		</compound_test>
		<compound_test id="cmp-142" operation="AND" comment="64-bit version of Windows and wmsjet40.dll is less than 4.0.8618.0">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-181"/>
		</compound_test>
		<compound_test id="cmp-143" operation="OR" comment="a vulnerable version of lsasrv.dll exists on XP">
			<subtest negate="false" test_ref="cmp-144"/>
			<subtest negate="false" test_ref="cmp-148"/>
		</compound_test>
		<compound_test id="cmp-144" operation="AND" comment="32-bit version of Windows and a vulnerable version of lsasrv.dll exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="cmp-145"/>
		</compound_test>
		<compound_test id="cmp-145" operation="OR" comment="a vulnerable version of lsasrv.dll exists depending on service pack level">
			<subtest negate="false" test_ref="cmp-146"/>
			<subtest negate="false" test_ref="cmp-147"/>
		</compound_test>
		<compound_test id="cmp-146" operation="AND" comment="no service pack is installed and lsasrv.dll is less than 5.1.2600.134">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-158"/>
		</compound_test>
		<compound_test id="cmp-147" operation="AND" comment="service pack 1 is installed and lsasrv.dll is less than 5.1.2600.1361">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-159"/>
		</compound_test>
		<compound_test id="cmp-148" operation="AND" comment="64-bit version of Windows and lsasrv.dll is less than 5.1.2600.1361">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-159"/>
		</compound_test>
		<compound_test id="cmp-149" operation="AND" comment="64-bit version of Windows and helpctr.exe is less than 5.1.2600.1515">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-3"/>
		</compound_test>
		<compound_test id="cmp-15" operation="AND" comment="64-bit version of Windows and rpcss.dll is less than 5.1.2600.1361">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-198"/>
		</compound_test>
		<compound_test id="cmp-150" operation="OR" comment="a vulnerable version of msasn1.dll exists">
			<subtest negate="false" test_ref="cmp-151"/>
			<subtest negate="false" test_ref="cmp-155"/>
		</compound_test>
		<compound_test id="cmp-151" operation="AND" comment="32-bit version of Windows and a vulnerable version of msasn1.dll exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="cmp-152"/>
		</compound_test>
		<compound_test id="cmp-152" operation="OR" comment="a vulnerable version of msasn1.dll exists depending on service pack level">
			<subtest negate="false" test_ref="cmp-153"/>
			<subtest negate="false" test_ref="cmp-154"/>
		</compound_test>
		<compound_test id="cmp-153" operation="AND" comment="no service pack is installed and msasn1.dll is less than 5.1.2600.137">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-195"/>
		</compound_test>
		<compound_test id="cmp-154" operation="AND" comment="service pack 1 is installed and msasn1.dll is less than 5.1.2600.1362">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-196"/>
		</compound_test>
		<compound_test id="cmp-155" operation="AND" comment="64-bit version of Windows and msasn1.dll is less than 5.1.2600.1362">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-196"/>
		</compound_test>
		<compound_test id="cmp-158" operation="OR" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506">
			<subtest negate="false" test_ref="wft-104"/>
			<subtest negate="false" test_ref="wft-105"/>
		</compound_test>
		<compound_test id="cmp-159" operation="AND" comment=" for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of telnet.exe exists">
			<subtest negate="false" test_ref="wrt-22"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-74"/>
		</compound_test>
		<compound_test id="cmp-16" operation="OR" comment="a vulnerable version of rpcss.dll exists on Server 2003">
			<subtest negate="false" test_ref="cmp-18"/>
			<subtest negate="false" test_ref="cmp-20"/>
		</compound_test>
		<compound_test id="cmp-160" operation="OR" comment="a vulnerable version of h323.tsp exists">
			<subtest negate="false" test_ref="cmp-161"/>
			<subtest negate="false" test_ref="cmp-165"/>
		</compound_test>
		<compound_test id="cmp-161" operation="AND" comment="32-bit version of Windows and a vulnerable version of h323.tsp exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="cmp-162"/>
		</compound_test>
		<compound_test id="cmp-162" operation="OR" comment="a vulnerable version of h323.tsp exists depending on service pack level">
			<subtest negate="false" test_ref="cmp-163"/>
			<subtest negate="false" test_ref="cmp-164"/>
		</compound_test>
		<compound_test id="cmp-163" operation="AND" comment="no service pack is installed and h323.tsp is less than 5.1.2600.134">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-153"/>
		</compound_test>
		<compound_test id="cmp-164" operation="AND" comment="service pack 1 is installed and h323.tsp is less than 5.1.2600.1348">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-152"/>
		</compound_test>
		<compound_test id="cmp-165" operation="AND" comment="64-bit version of Windows and h323.tsp is less than 5.1.2600.1348">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-152"/>
		</compound_test>
		<compound_test id="cmp-166" operation="OR" comment="for specific Windows configurations a vulnerable version of telnet.exe exists">
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-77"/>
		</compound_test>
		<compound_test id="cmp-167" operation="OR" comment="a vulnerable version of telnet.exe exists">
			<subtest negate="false" test_ref="cmp-184"/>
			<subtest negate="false" test_ref="cmp-186"/>
			<subtest negate="false" test_ref="cmp-189"/>
		</compound_test>
		<compound_test id="cmp-168" operation="AND" comment="a vulnerable version of mshtml.dll exists">
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-96"/>
		</compound_test>
		<compound_test id="cmp-169" operation="AND" comment=" a vulnerable version of mshtml.dll exists">
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-97"/>
		</compound_test>
		<compound_test id="cmp-17" operation="OR" comment="a vulnerable version of rpcrt4.dll exists on Server 2003">
			<subtest negate="false" test_ref="ukn-16"/>
			<subtest negate="false" test_ref="ukn-17"/>
		</compound_test>
		<compound_test id="cmp-170" operation="OR" comment="a vulnerable version of mf3216.dll exists on XP">
			<subtest negate="false" test_ref="cmp-171"/>
			<subtest negate="false" test_ref="cmp-175"/>
		</compound_test>
		<compound_test id="cmp-171" operation="AND" comment="32-bit version of Windows and a vulnerable version of mf3216.dll exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="cmp-172"/>
		</compound_test>
		<compound_test id="cmp-172" operation="OR" comment="a vulnerable version of mf3216.dll exists depending on service pack level">
			<subtest negate="false" test_ref="cmp-173"/>
			<subtest negate="false" test_ref="cmp-174"/>
		</compound_test>
		<compound_test id="cmp-173" operation="AND" comment="no service pack is installed and mf3216.dll is less than 5.1.2600.132">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-139"/>
		</compound_test>
		<compound_test id="cmp-174" operation="AND" comment="service pack 1 is installed and mf3216.dll is less than 5.1.2600.1331">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-149"/>
		</compound_test>
		<compound_test id="cmp-175" operation="AND" comment="64-bit version of Windows and mf3216.dll is less than 5.1.2600.1331">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-149"/>
		</compound_test>
		<compound_test id="cmp-176" operation="AND" comment="    a vulnerable version of mshtml.dll exists ">
			<subtest negate="false" test_ref="wrt-22"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-97"/>
		</compound_test>
		<compound_test id="cmp-177" operation="OR" comment="a vulnerable version of hlink.dll exists on Server 2003">
			<subtest negate="false" test_ref="wft-371"/>
			<subtest negate="false" test_ref="wft-370"/>
		</compound_test>
		<compound_test id="cmp-179" operation="OR" comment="a vulnerable version of mshtml.dll exisits">
			<subtest negate="false" test_ref="cmp-168"/>
			<subtest negate="false" test_ref="cmp-169"/>
			<subtest negate="false" test_ref="cmp-176"/>
		</compound_test>
		<compound_test id="cmp-18" operation="AND" comment="32-bit machine a vulnerable version of rpcss.dll exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="cmp-19"/>
		</compound_test>
		<compound_test id="cmp-180" operation="AND" comment="Windows XP 32-bit edition is installed  with service pack 2 (or earlier)">
			<subtest negate="false" test_ref="wrt-2"/>
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="wrt-79"/>
		</compound_test>
		<compound_test id="cmp-181" operation="OR" comment="a vulnerable version of telnet.exe exists">
			<subtest negate="false" test_ref="cmp-166"/>
			<subtest negate="false" test_ref="cmp-116"/>
			<subtest negate="false" test_ref="cmp-159"/>
		</compound_test>
		<compound_test id="cmp-182" operation="AND" comment="Microsoft Windows Server 2003 32-Bit Edition">
			<subtest negate="false" test_ref="wrt-61"/>
			<subtest negate="false" test_ref="wrt-72"/>
		</compound_test>
		<compound_test id="cmp-183" operation="OR" comment="Windows Server 2003 64-Bit Edition or Windows XP 64-Bit Edition Version 2003 ">
			<subtest negate="false" test_ref="cmp-34"/>
			<subtest negate="false" test_ref="cmp-1112"/>
		</compound_test>
		<compound_test id="cmp-184" operation="AND" comment="for specific Windows configurations a vulnerable version of telnet.exe exists">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="false" test_ref="wft-75"/>
		</compound_test>
		<compound_test id="cmp-186" operation="AND" comment="  for specific Windows configurations a vulnerable version of telnet.exe exists ">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="false" test_ref="wft-74"/>
		</compound_test>
		<compound_test id="cmp-187" operation="OR" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed">
			<subtest negate="false" test_ref="cmp-38"/>
			<subtest negate="false" test_ref="cmp-34"/>
		</compound_test>
		<compound_test id="cmp-188" operation="AND" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST">
			<subtest negate="false" test_ref="wrt-168"/>
			<subtest negate="false" test_ref="wrt-169"/>
			<subtest negate="false" test_ref="wrt-174"/>
			<subtest negate="false" test_ref="wrt-175"/>
			<subtest negate="false" test_ref="wrt-176"/>
			<subtest negate="false" test_ref="wrt-177"/>
			<subtest negate="false" test_ref="wrt-178"/>
		</compound_test>
		<compound_test id="cmp-189" operation="AND" comment="  for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of telnet.exe exists">
			<subtest negate="false" test_ref="wrt-22"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-74"/>
		</compound_test>
		<compound_test id="cmp-19" operation="OR" comment="a vulnerable version of rpcss.dll exists on non 64-bit Server 2003">
			<subtest negate="false" test_ref="ukn-18"/>
			<subtest negate="false" test_ref="ukn-19"/>
		</compound_test>
		<compound_test id="cmp-190" operation="OR" comment="a vulnerable version of rpcproxy.dll exists on Server 2003">
			<subtest negate="false" test_ref="wft-284"/>
			<subtest negate="false" test_ref="wft-288"/>
		</compound_test>
		<compound_test id="cmp-191" operation="AND" comment="a vulnerable version of agentdpv exists">
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-117"/>
		</compound_test>
		<compound_test id="cmp-192" operation="AND" comment=" a vulnerable version of agentdpv exists">
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-118"/>
		</compound_test>
		<compound_test id="cmp-193" operation="AND" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed">
			<subtest negate="false" test_ref="wrt-61"/>
			<subtest negate="true" test_ref="wrt-40"/>
		</compound_test>
		<compound_test id="cmp-194" operation="AND" comment=" a vulnerable version of agentdpv exists for Windows Gold 64-bit (x64)">
			<subtest negate="false" test_ref="wrt-22"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-118"/>
		</compound_test>
		<compound_test id="cmp-195" operation="OR" comment="a vulnerable version of ole32.dll exists on NT">
			<subtest negate="false" test_ref="cmp-196"/>
			<subtest negate="false" test_ref="cmp-197"/>
		</compound_test>
		<compound_test id="cmp-196" operation="AND" comment="non Terminal Server and ole32.dll is less than 4.0.1381.7263">
			<subtest negate="true" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-295"/>
		</compound_test>
		<compound_test id="cmp-197" operation="AND" comment="Terminal Server and ole32.dll is less than 4.0.1381.33562">
			<subtest negate="false" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-297"/>
		</compound_test>
		<compound_test id="cmp-198" operation="AND" comment="non Terminal Server and rpcproxy.dll is less than 4.0.1381.7255">
			<subtest negate="true" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-298"/>
		</compound_test>
		<compound_test id="cmp-199" operation="AND" comment="Terminal Server and rpcproxy.dll is less than 4.0.1381.33559">
			<subtest negate="false" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-299"/>
		</compound_test>
		<compound_test id="cmp-2" operation="AND" comment="32-bit version of Windows and a vulnerable version of rpcrt4.dll exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="cmp-3"/>
		</compound_test>
		<compound_test id="cmp-20" operation="AND" comment="64-bit machine and rpcss.dll is less than 5.2.3790.146">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-199"/>
		</compound_test>
		<compound_test id="cmp-200" operation="OR" comment=" a vulnerable version of agentdpv exists">
			<subtest negate="false" test_ref="cmp-191"/>
			<subtest negate="false" test_ref="cmp-192"/>
			<subtest negate="false" test_ref="cmp-194"/>
		</compound_test>
		<compound_test id="cmp-21" operation="OR" comment="a vulnerable version of rpcproxy.dll exists on NT">
			<subtest negate="false" test_ref="cmp-198"/>
			<subtest negate="false" test_ref="cmp-199"/>
		</compound_test>
		<compound_test id="cmp-212" operation="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
			<subtest negate="false" test_ref="wrt-1"/>
			<subtest negate="false" test_ref="wrt-28"/>
		</compound_test>
		<compound_test id="cmp-213" operation="OR" comment="Internet Explorer 5.5 Installed">
			<subtest negate="false" test_ref="wrt-225"/>
			<subtest negate="false" test_ref="wrt-226"/>
			<subtest negate="false" test_ref="wrt-227"/>
		</compound_test>
		<compound_test id="cmp-214" operation="OR" comment="Internet Explorer 5.01 Installed">
			<subtest negate="false" test_ref="wrt-230"/>
			<subtest negate="false" test_ref="wrt-231"/>
			<subtest negate="false" test_ref="wrt-232"/>
			<subtest negate="false" test_ref="wrt-233"/>
			<subtest negate="false" test_ref="wrt-234"/>
			<subtest negate="false" test_ref="wrt-235"/>
			<subtest negate="false" test_ref="wrt-236"/>
			<subtest negate="false" test_ref="wrt-56"/>
		</compound_test>
		<compound_test id="cmp-215" operation="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
			<subtest negate="false" test_ref="wrt-1"/>
			<subtest negate="false" test_ref="wrt-222"/>
		</compound_test>
		<compound_test id="cmp-218" operation="AND" comment=" a vulnerable version of agentdpv exists">
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="true" test_ref="wrt-29"/>
			<subtest negate="false" test_ref="wft-117"/>
		</compound_test>
		<compound_test id="cmp-220" operation="AND" comment="Windows 2000 (domain controller) is installed">
			<subtest negate="false" test_ref="wrt-1"/>
			<subtest negate="false" test_ref="wrt-42"/>
		</compound_test>
		<compound_test id="cmp-222" operation="AND" comment=" a vulnerable version of agentdpv exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="wrt-250"/>
			<subtest negate="false" test_ref="wft-118"/>
		</compound_test>
		<compound_test id="cmp-224" operation="AND" comment=" a vulnerable version of agentdpv exists for Windows Gold 64-bit (x64) ">
			<subtest negate="false" test_ref="wrt-22"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-118"/>
		</compound_test>
		<compound_test id="cmp-225" operation="OR" comment=" a vulnerable version of agentdpv exists">
			<subtest negate="false" test_ref="cmp-218"/>
			<subtest negate="false" test_ref="cmp-222"/>
			<subtest negate="false" test_ref="cmp-224"/>
		</compound_test>
		<compound_test id="cmp-226" operation="AND" comment="for specific Windows configurations a vulnerable version of srv.sys exists">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="false" test_ref="wft-125"/>
		</compound_test>
		<compound_test id="cmp-227" operation="AND" comment="for specific Windows configurations a vulnerable version of srv.sys exists ">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="false" test_ref="wft-126"/>
		</compound_test>
		<compound_test id="cmp-228" operation="AND" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of srv.sys exists">
			<subtest negate="false" test_ref="wrt-22"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-126"/>
		</compound_test>
		<compound_test id="cmp-23" operation="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
			<oval:notes>
				<oval:note>This test should fail if the 64-bit (x64 architecture) version of Windows is installed.</oval:note>
			</oval:notes>
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="wrt-70"/>
		</compound_test>
		<compound_test id="cmp-230" operation="OR" comment="Internet Explorer 5.01 Installed">
			<subtest negate="false" test_ref="wrt-230"/>
			<subtest negate="false" test_ref="wrt-231"/>
			<subtest negate="false" test_ref="wrt-232"/>
			<subtest negate="false" test_ref="wrt-233"/>
			<subtest negate="false" test_ref="wrt-234"/>
			<subtest negate="false" test_ref="wrt-235"/>
			<subtest negate="false" test_ref="wrt-236"/>
			<subtest negate="false" test_ref="wrt-56"/>
			<subtest negate="false" test_ref="wrt-55"/>
		</compound_test>
		<compound_test id="cmp-231" operation="OR" comment="a vulnerable version of srv.sys exists">
			<subtest negate="false" test_ref="cmp-226"/>
			<subtest negate="false" test_ref="cmp-227"/>
			<subtest negate="false" test_ref="cmp-228"/>
		</compound_test>
		<compound_test id="cmp-234" operation="AND" comment="for specific Windows configurations a vulnerable version of srv.sys exists">
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-119"/>
		</compound_test>
		<compound_test id="cmp-236" operation="AND" comment="32-bit version of windows with SP2 is installed and vulnerable version of srv.sys exists">
			<subtest negate="false" test_ref="wrt-250"/>
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="wft-124"/>
		</compound_test>
		<compound_test id="cmp-237" operation="AND" comment="Windows XP SP1 or earlier and version of hhctrl.ocx is less than 5.2.3790.233">
			<subtest negate="true" test_ref="wrt-29"/>
			<subtest negate="false" test_ref="wft-390"/>
		</compound_test>
		<compound_test id="cmp-241" operation="AND" comment="Windows XP SP2 or later and version of hhctrl.ocx is less than 5.2.3790.1280">
			<subtest negate="false" test_ref="wrt-29"/>
			<subtest negate="false" test_ref="wft-391"/>
		</compound_test>
		<compound_test id="cmp-242" operation="OR" comment="A vulnerable version of hhctrl.ocx exists on Windows XP">
			<subtest negate="false" test_ref="cmp-237"/>
			<subtest negate="false" test_ref="cmp-241"/>
		</compound_test>
		<compound_test id="cmp-243" operation="AND" comment="A vulnerable version of .NET Framework v1.0 (SP 2) is installed. ">
			<subtest negate="true" test_ref="wrt-145"/>
			<subtest negate="false" test_ref="wft-438"/>
			<subtest negate="false" test_ref="wrt-122"/>
		</compound_test>
		<compound_test id="cmp-244" operation="AND" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of srv.sys exists">
			<subtest negate="false" test_ref="wrt-22"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-126"/>
		</compound_test>
		<compound_test id="cmp-248" operation="AND" comment="A vulnerable version of .NET Framework v1.0 (SP 3) is installed.">
			<subtest negate="false" test_ref="wrt-123"/>
			<subtest negate="false" test_ref="wft-397"/>
			<subtest negate="true" test_ref="wrt-146"/>
		</compound_test>
		<compound_test id="cmp-249" operation="AND" comment="A vulnerable version of .NET Framework v1.1 (SP 1) is installed.">
			<subtest negate="false" test_ref="wrt-118"/>
			<subtest negate="false" test_ref="wft-460"/>
			<subtest negate="true" test_ref="wrt-143"/>
		</compound_test>
		<compound_test id="cmp-25" operation="OR" comment="patch kb889293 is installed (hotfix or ID)">
			<subtest negate="false" test_ref="wrt-23"/>
			<subtest negate="false" test_ref="wrt-24"/>
		</compound_test>
		<compound_test id="cmp-250" operation="AND" comment="cookies are enabled">
			<subtest negate="false" test_ref="cmp-110"/>
			<subtest negate="false" test_ref="cmp-111"/>
		</compound_test>
		<compound_test id="cmp-251" operation="AND" comment="A vulnerable version of .NET Framework v1.1 (Gold) is installed.">
			<subtest negate="true" test_ref="wrt-118"/>
			<subtest negate="false" test_ref="wft-456"/>
			<subtest negate="true" test_ref="wrt-144"/>
		</compound_test>
		<compound_test id="cmp-252" operation="OR" comment="A vulnerable version of .NET Framework v1.0 is installed. ">
			<subtest negate="false" test_ref="cmp-243"/>
			<subtest negate="false" test_ref="cmp-248"/>
		</compound_test>
		<compound_test id="cmp-253" operation="OR" comment="A vulnerable version of .NET Framework v1.1 is installed.">
			<subtest negate="false" test_ref="cmp-249"/>
			<subtest negate="false" test_ref="cmp-251"/>
		</compound_test>
		<compound_test id="cmp-254" operation="OR" comment=" a vulnerable version of srv.sys exists">
			<subtest negate="false" test_ref="cmp-234"/>
			<subtest negate="false" test_ref="cmp-236"/>
			<subtest negate="false" test_ref="cmp-244"/>
		</compound_test>
		<compound_test id="cmp-256" operation="OR" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed">
			<subtest negate="false" test_ref="wrt-18"/>
			<subtest negate="false" test_ref="wrt-50"/>
		</compound_test>
		<compound_test id="cmp-257" operation="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
			<subtest negate="false" test_ref="wft-403"/>
			<subtest negate="false" test_ref="wft-404"/>
		</compound_test>
		<compound_test id="cmp-258" operation="AND" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing">
			<subtest negate="true" test_ref="wrt-157"/>
			<subtest negate="true" test_ref="wrt-156"/>
		</compound_test>
		<compound_test id="cmp-264" operation="OR" comment="Internet Explorer 5.01 Installed">
			<subtest negate="false" test_ref="wrt-230"/>
			<subtest negate="false" test_ref="wrt-231"/>
			<subtest negate="false" test_ref="wrt-232"/>
			<subtest negate="false" test_ref="wrt-233"/>
			<subtest negate="false" test_ref="wrt-234"/>
			<subtest negate="false" test_ref="wrt-235"/>
		</compound_test>
		<compound_test id="cmp-265" operation="AND" comment="file downloads are enabled">
			<subtest negate="false" test_ref="cmp-108"/>
			<subtest negate="false" test_ref="cmp-109"/>
		</compound_test>
		<compound_test id="cmp-271" operation="OR" comment="Internet Explorer 5.5 Installed">
			<subtest negate="false" test_ref="wrt-225"/>
			<subtest negate="false" test_ref="wrt-226"/>
			<subtest negate="false" test_ref="wrt-227"/>
			<subtest negate="false" test_ref="wrt-53"/>
		</compound_test>
		<compound_test id="cmp-273" operation="OR" comment="a vulnerable version of cryptui.dll exists">
			<subtest negate="false" test_ref="cmp-115"/>
			<subtest negate="false" test_ref="cmp-274"/>
		</compound_test>
		<compound_test id="cmp-274" operation="AND" comment="service pack 1 is installed and cryptui.dll is less than 5.131.2600.1243">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-250"/>
		</compound_test>
		<compound_test id="cmp-275" operation="AND" comment="downloading of signed ActiveX controls is enabled">
			<subtest negate="false" test_ref="cmp-106"/>
			<subtest negate="false" test_ref="cmp-107"/>
		</compound_test>
		<compound_test id="cmp-276" operation="AND" comment="ActiveX Enabled">
			<subtest negate="false" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-298"/>
		</compound_test>
		<compound_test id="cmp-28" operation="AND" comment="for specific Windows configurations a vulnerable version of hh.exe exists">
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="true" test_ref="wrt-29"/>
			<subtest negate="false" test_ref="wft-9"/>
		</compound_test>
		<compound_test id="cmp-282" operation="OR" comment="a vulnerable version of user32.dll exists">
			<subtest negate="false" test_ref="cmp-117"/>
			<subtest negate="false" test_ref="cmp-283"/>
		</compound_test>
		<compound_test id="cmp-283" operation="AND" comment="service pack 1 is installed and user32.dll is less than 5.1.2600.1255">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-259"/>
		</compound_test>
		<compound_test id="cmp-29" operation="AND" comment="for 32-bit Windows with sp2 a vulnerable version of hh.exe exists">
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="wrt-250"/>
			<subtest negate="false" test_ref="wft-10"/>
		</compound_test>
		<compound_test id="cmp-292" operation="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
			<subtest negate="false" test_ref="wft-596"/>
			<subtest negate="false" test_ref="wft-597"/>
		</compound_test>
		<compound_test id="cmp-295" operation="OR" comment="a vulnerable version of msgsvc.dll exists">
			<subtest negate="false" test_ref="cmp-119"/>
			<subtest negate="false" test_ref="cmp-296"/>
		</compound_test>
		<compound_test id="cmp-296" operation="AND" comment="service pack 1 is installed and msgsvc.dll is less than 5.1.2600.1301">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-273"/>
		</compound_test>
		<compound_test id="cmp-3" operation="OR" comment="a vulnerable version of rpcrt4.dll exists depending on service pack level">
			<subtest negate="false" test_ref="cmp-4"/>
			<subtest negate="false" test_ref="cmp-5"/>
		</compound_test>
		<compound_test id="cmp-30" operation="OR" comment="a vulnerable version of wkssvc.dll exists">
			<subtest negate="false" test_ref="cmp-31"/>
			<subtest negate="false" test_ref="cmp-32"/>
		</compound_test>
		<compound_test id="cmp-301" operation="AND" comment="the software Adobe Acrobat Reader major version 6, minor version less than 3 is installed">
			<subtest negate="false" test_ref="wrt-578"/>
			<subtest negate="false" test_ref="wrt-579"/>
		</compound_test>
		<compound_test id="cmp-306" operation="AND" comment="no service pack is installed and rpcrt4.dll is less than 5.1.2600.109">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-359"/>
		</compound_test>
		<compound_test id="cmp-31" operation="AND" comment="no service pack is installed and wkssvc.dll is less than 5.1.2600.120">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-20"/>
		</compound_test>
		<compound_test id="cmp-310" operation="OR" comment="Windows XP 32-bit OR Windows XP 64-bit is installed">
			<subtest negate="false" test_ref="cmp-1058"/>
			<subtest negate="false" test_ref="cmp-1112"/>
		</compound_test>
		<compound_test id="cmp-311" operation="AND" comment="SP1 is installed and the version of rpcrt4.dll is less than 5.1.2600.1254">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-366"/>
		</compound_test>
		<compound_test id="cmp-312" operation="AND" comment="A vulnerable version of rpcrt4.dll exists depending on service pack level">
			<subtest negate="false" test_ref="cmp-306"/>
			<subtest negate="false" test_ref="cmp-311"/>
		</compound_test>
		<compound_test id="cmp-313" operation="AND" comment="Windows XP Service Pack 1">
			<subtest negate="false" test_ref="wrt-2"/>
			<subtest negate="false" test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-32" operation="AND" comment="service pack 1 is installed and wkssvc.dll is less than 5.1.2600.1301">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-21"/>
		</compound_test>
		<compound_test id="cmp-327" operation="OR" comment="Windows No Service Pack or Service Pack 1">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="true" test_ref="wrt-410"/>
		</compound_test>
		<compound_test id="cmp-328" operation="AND" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634">
			<subtest negate="false" test_ref="cmp-327"/>
			<subtest negate="false" test_ref="wft-580"/>
		</compound_test>
		<compound_test id="cmp-33" operation="OR" comment="The version of mswrd664.wpc OR wmswrd632.wpc is less than 2004.10.25.0">
			<subtest negate="false" test_ref="wft-264"/>
			<subtest negate="false" test_ref="wft-265"/>
		</compound_test>
		<compound_test id="cmp-330" operation="AND" comment="Windows Server 2003 with Service Pack 1">
			<subtest negate="false" test_ref="wrt-61"/>
			<subtest negate="false" test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-34" operation="AND" comment="Microsoft Windows Server 2003 64-Bit Edition ">
			<subtest negate="false" test_ref="wrt-61"/>
			<subtest negate="false" test_ref="wrt-70"/>
		</compound_test>
		<compound_test id="cmp-35" operation="AND" comment="Windows XP 32 bit Service Pack 2">
			<subtest negate="false" test_ref="wrt-250"/>
			<subtest negate="false" test_ref="cmp-1058"/>
		</compound_test>
		<compound_test id="cmp-36" operation="AND" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of hh.exe exists">
			<subtest negate="false" test_ref="wrt-22"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-11"/>
		</compound_test>
		<compound_test id="cmp-37" operation="AND" comment="Services for UNIX version 2.2 and telnet.exe version less than 5.3000.2073.13">
			<subtest negate="false" test_ref="wft-5"/>
			<subtest negate="false" test_ref="wrt-17"/>
		</compound_test>
		<compound_test id="cmp-38" operation="OR" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
			<subtest negate="false" test_ref="wrt-61"/>
			<subtest negate="false" test_ref="cmp-1112"/>
		</compound_test>
		<compound_test id="cmp-39" operation="AND" comment="Services for UNIX version 3.0 and telnet.exe version less than 7.0.1701.44">
			<subtest negate="false" test_ref="wrt-20"/>
			<subtest negate="false" test_ref="wft-29"/>
		</compound_test>
		<compound_test id="cmp-4" operation="AND" comment="no service pack is installed and rpcrt4.dll is less than 5.1.2600.135">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-187"/>
		</compound_test>
		<compound_test id="cmp-44" operation="AND" comment="Windows NT Server 4.0 is installed">
			<subtest negate="false" test_ref="wrt-77"/>
			<subtest negate="false" test_ref="cmp-50"/>
		</compound_test>
		<compound_test id="cmp-45" operation="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
			<subtest negate="false" test_ref="wrt-77"/>
			<subtest negate="false" test_ref="wrt-43"/>
		</compound_test>
		<compound_test id="cmp-46" operation="AND" comment="Services for UNIX version 3.5 and telnet.exe version less than 8.0.1969.33">
			<subtest negate="false" test_ref="wrt-21"/>
			<subtest negate="false" test_ref="wft-48"/>
		</compound_test>
		<compound_test id="cmp-47" operation="OR" comment="Services for UNIX is instaled and a vulnerable version of telnet.exe exists">
			<subtest negate="false" test_ref="cmp-37"/>
			<subtest negate="false" test_ref="cmp-39"/>
			<subtest negate="false" test_ref="cmp-46"/>
		</compound_test>
		<compound_test id="cmp-49" operation="OR" comment="a vulnerable version of hh.exe exists">
			<subtest negate="false" test_ref="cmp-28"/>
			<subtest negate="false" test_ref="cmp-29"/>
			<subtest negate="false" test_ref="cmp-36"/>
		</compound_test>
		<compound_test id="cmp-5" operation="AND" comment="service pack 1 is installed and rpcrt4.dll is less than 5.1.2600.1361">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-188"/>
		</compound_test>
		<compound_test id="cmp-50" operation="OR" comment="Windows NT server product option">
			<subtest negate="false" test_ref="wrt-41"/>
			<subtest negate="false" test_ref="wrt-42"/>
		</compound_test>
		<compound_test id="cmp-51" operation="AND" comment="no service pack is installed and msasn1.dll is less than 5.1.2600.119">
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-107"/>
		</compound_test>
		<compound_test id="cmp-52" operation="AND" comment="service pack 1 is installed and msasn1.dll is less than 5.1.2600.1274">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-109"/>
		</compound_test>
		<compound_test id="cmp-53" operation="OR" comment="a vulnerable version of msasn1.dll exists">
			<subtest negate="false" test_ref="cmp-51"/>
			<subtest negate="false" test_ref="cmp-52"/>
		</compound_test>
		<compound_test id="cmp-55" operation="AND" comment="for specific Windows configurations a vulnerable version of hh.exe exists ">
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-9"/>
		</compound_test>
		<compound_test id="cmp-57" operation="AND" comment="Windows XP 32-bit SP1 is installed">
			<subtest negate="false" test_ref="cmp-1058"/>
			<subtest negate="false" test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-58" operation="AND" comment="   for specific Windows configurations a vulnerable version of hh.exe exists ">
			<subtest negate="false" test_ref="cmp-23"/>
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-13"/>
		</compound_test>
		<compound_test id="cmp-59" operation="AND" comment="Windows Media Services 4.1 is installed on Microsoft Windows 2000 Server">
			<subtest negate="false" test_ref="wrt-162"/>
			<subtest negate="false" test_ref="cmp-60"/>
		</compound_test>
		<compound_test id="cmp-6" operation="AND" comment="64-bit version of Windows and rpcrt4.dll is less than 5.1.2600.1361">
			<subtest negate="false" test_ref="wrt-70"/>
			<subtest negate="false" test_ref="wft-188"/>
		</compound_test>
		<compound_test id="cmp-60" operation="AND" comment="Windows 2000 Server is installed">
			<subtest negate="false" test_ref="wrt-1"/>
			<subtest negate="false" test_ref="cmp-50"/>
		</compound_test>
		<compound_test id="cmp-61" operation="OR" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed">
			<subtest negate="false" test_ref="cmp-57"/>
			<subtest negate="false" test_ref="cmp-1066"/>
		</compound_test>
		<compound_test id="cmp-62" operation="OR" comment="Windows Server 2003 or Windows Server 2003 64-bit Edition is installed">
			<subtest negate="false" test_ref="wrt-61"/>
			<subtest negate="false" test_ref="cmp-34"/>
		</compound_test>
		<compound_test id="cmp-65" operation="AND" comment="Windows 2000 (sp3 or earlier) is installed">
			<subtest negate="false" test_ref="wrt-1"/>
			<subtest negate="true" test_ref="wrt-28"/>
		</compound_test>
		<compound_test id="cmp-66" operation="AND" comment="Windows XP (sp1 or earlier) is installed">
			<subtest negate="false" test_ref="wrt-2"/>
			<subtest negate="true" test_ref="wrt-29"/>
		</compound_test>
		<compound_test id="cmp-67" operation="AND" comment=" for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of hh.exe exists">
			<subtest negate="false" test_ref="wrt-22"/>
			<subtest negate="true" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wft-11"/>
		</compound_test>
		<compound_test id="cmp-68" operation="AND" comment="Microsoft MSN Messenger 6.0 or 6.1 (but less than 6.1.0211) is installed">
			<subtest negate="false" test_ref="wft-45"/>
			<subtest negate="false" test_ref="wft-30"/>
		</compound_test>
		<compound_test id="cmp-7" operation="AND" comment="DCOM is enabled on systems with SP3 or later">
			<subtest negate="false" test_ref="wrt-224"/>
			<subtest negate="false" test_ref="wrt-283"/>
		</compound_test>
		<compound_test id="cmp-75" operation="OR" comment="ActiveX controls are enabled">
			<subtest negate="false" test_ref="cmp-92"/>
			<subtest negate="false" test_ref="cmp-93"/>
		</compound_test>
		<compound_test id="cmp-76" operation="OR" comment="active scripting is enabled">
			<subtest negate="false" test_ref="cmp-94"/>
			<subtest negate="false" test_ref="cmp-95"/>
		</compound_test>
		<compound_test id="cmp-77" operation="OR" comment="Windows NT, 2000, or XP is installed">
			<subtest negate="false" test_ref="wrt-77"/>
			<subtest negate="false" test_ref="wrt-1"/>
			<subtest negate="false" test_ref="wrt-2"/>
		</compound_test>
		<compound_test id="cmp-78" operation="OR" comment="Windows 2000, XP, or 2003 is installed">
			<subtest negate="false" test_ref="wrt-1"/>
			<subtest negate="false" test_ref="wrt-2"/>
			<subtest negate="false" test_ref="wrt-61"/>
		</compound_test>
		<compound_test id="cmp-8" operation="OR" comment="Windows NT 4.0 Server or Terminal Server is installed">
			<subtest negate="false" test_ref="wrt-77"/>
			<subtest negate="false" test_ref="cmp-9"/>
		</compound_test>
		<compound_test id="cmp-84" operation="OR" comment="a vulnerable version of hh.exe exists">
			<subtest negate="false" test_ref="cmp-55"/>
			<subtest negate="false" test_ref="cmp-58"/>
			<subtest negate="false" test_ref="cmp-67"/>
		</compound_test>
		<compound_test id="cmp-89" operation="OR" comment="a vulnerable version of mf3216.dll exists on NT">
			<subtest negate="false" test_ref="cmp-90"/>
			<subtest negate="false" test_ref="cmp-91"/>
		</compound_test>
		<compound_test id="cmp-9" operation="OR" comment="Server or Terminal Server product option">
			<subtest negate="false" test_ref="cmp-50"/>
			<subtest negate="false" test_ref="wrt-43"/>
		</compound_test>
		<compound_test id="cmp-90" operation="AND" comment="non Terminal Server and mf3216.dll is less than 4.0.1381.7263">
			<subtest negate="true" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-136"/>
		</compound_test>
		<compound_test id="cmp-901" operation="OR" comment="Internet Explorer 5.5 Installed">
			<subtest negate="false" test_ref="wrt-348"/>
			<subtest negate="false" test_ref="wrt-349"/>
			<subtest negate="false" test_ref="wrt-350"/>
		</compound_test>
		<compound_test id="cmp-902" operation="AND" comment="File Downloads Not Disabled">
			<subtest negate="false" test_ref="wrt-368"/>
			<subtest negate="false" test_ref="wrt-369"/>
		</compound_test>
		<compound_test id="cmp-903" operation="AND" comment="Run ActiveX Controls and Plugins Not Disabled">
			<subtest negate="false" test_ref="wrt-368"/>
			<subtest negate="false" test_ref="wrt-371"/>
		</compound_test>
		<compound_test id="cmp-905" operation="OR" comment="a vulnerable version of helpctr.exe exists on XP">
			<subtest negate="false" test_ref="cmp-906"/>
			<subtest negate="false" test_ref="cmp-907"/>
		</compound_test>
		<compound_test id="cmp-906" operation="AND" comment="No service pack is installed, 32 bit Edition, and helpctr.exe is less than 5.1.2600.128">
			<subtest negate="false" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="wft-316"/>
		</compound_test>
		<compound_test id="cmp-907" operation="AND" comment="Affected helpctr.exe versions on Windows XP SP1">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-317"/>
		</compound_test>
		<compound_test id="cmp-908" operation="OR" comment="A vulnerable version of evtgprov.dll exists on XP">
			<subtest negate="false" test_ref="cmp-909"/>
			<subtest negate="false" test_ref="cmp-910"/>
		</compound_test>
		<compound_test id="cmp-909" operation="AND" comment="No service pack is installed, 32 bit Edition, and evtgprov.dll is less than 5.1.2600.136">
			<subtest negate="false" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wrt-72"/>
			<subtest negate="false" test_ref="wft-318"/>
		</compound_test>
		<compound_test id="cmp-91" operation="AND" comment="NT Terminal Server and mf3216.dll is less than 4.0.1381.33562">
			<subtest negate="false" test_ref="wrt-43"/>
			<subtest negate="false" test_ref="wft-137"/>
		</compound_test>
		<compound_test id="cmp-910" operation="AND" comment="Affected evtgprov.dll versions on Windows XP SP1">
			<subtest negate="false" test_ref="wrt-4"/>
			<subtest negate="false" test_ref="wft-319"/>
		</compound_test>
		<compound_test id="cmp-912" operation="OR" comment="Affected MDAC versions">
			<subtest negate="false" test_ref="wft-320"/>
			<subtest negate="false" test_ref="wft-321"/>
			<subtest negate="false" test_ref="wrt-382"/>
		</compound_test>
		<compound_test id="cmp-92" operation="AND" comment="current user settings are being used and ActiveX controls are enabled">
			<subtest negate="true" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-121"/>
		</compound_test>
		<compound_test id="cmp-93" operation="AND" comment="local machine settings are being used and ActiveX controls are enabled">
			<subtest negate="false" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-120"/>
		</compound_test>
		<compound_test id="cmp-933" operation="OR" comment="Windows NT or 2000 Installed">
			<subtest negate="false" test_ref="wrt-77"/>
			<subtest negate="false" test_ref="wrt-1"/>
		</compound_test>
		<compound_test id="cmp-934" operation="AND" comment="NetBIOS enabled">
			<subtest negate="false" test_ref="wrt-393"/>
			<subtest negate="false" test_ref="wrt-394"/>
			<subtest negate="false" test_ref="wrt-395"/>
		</compound_test>
		<compound_test id="cmp-94" operation="AND" comment="current user settings are being used and active scripting is enabled">
			<subtest negate="true" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-126"/>
		</compound_test>
		<compound_test id="cmp-943" operation="OR" comment="Windows 95, 98, NT or 2000 is installed">
			<subtest negate="false" test_ref="wrt-396"/>
			<subtest negate="false" test_ref="cmp-933"/>
		</compound_test>
		<compound_test id="cmp-944" operation="AND" comment="This is an NT Terminal Server and the version of Ntoskrnl.exe is less than 4.0.1381.33563">
			<subtest negate="false" test_ref="wft-344"/>
			<subtest negate="false" test_ref="wrt-43"/>
		</compound_test>
		<compound_test id="cmp-946" operation="AND" comment="No service pack is installed and the version of Ipnathlp.dll is less than 5.1.2600.137">
			<subtest negate="false" test_ref="wft-346"/>
			<subtest negate="false" test_ref="wrt-3"/>
		</compound_test>
		<compound_test id="cmp-947" operation="AND" comment="The version of Ipnathlp.dll is less than 5.1.2600.1364 and windows service pack 1 is installed">
			<subtest negate="false" test_ref="wft-347"/>
			<subtest negate="false" test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-948" operation="AND" comment="64 bit version of windows with service pack 1 installed and the version of Ipnathlp.dll is less than 5.1.2600.1364">
			<subtest negate="false" test_ref="cmp-947"/>
			<subtest negate="false" test_ref="wrt-70"/>
		</compound_test>
		<compound_test id="cmp-949" operation="AND" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and a 64 bit version of Windows is installed">
			<subtest negate="false" test_ref="wft-348"/>
			<subtest negate="false" test_ref="wrt-70"/>
		</compound_test>
		<compound_test id="cmp-95" operation="AND" comment="local machine settings are being used and active scripting is enabled">
			<subtest negate="false" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-125"/>
		</compound_test>
		<compound_test id="cmp-951" operation="AND" comment="The version of Ipnathlp.dll is less than 5.2.3790.142 and a 32-bit version of Windows is installed">
			<subtest negate="false" test_ref="wft-348"/>
			<subtest negate="false" test_ref="wrt-72"/>
		</compound_test>
		<compound_test id="cmp-952" operation="OR" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and 64-bit or 32-bit version of Windows is installed">
			<subtest negate="false" test_ref="cmp-949"/>
			<subtest negate="false" test_ref="cmp-951"/>
		</compound_test>
		<compound_test id="cmp-961" operation="AND" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed on XP Gold">
			<subtest negate="false" test_ref="wft-360"/>
			<subtest negate="false" test_ref="wrt-3"/>
			<subtest negate="false" test_ref="wrt-404"/>
			<subtest negate="true" test_ref="wrt-407"/>
		</compound_test>
		<compound_test id="cmp-962" operation="AND" comment="DirectX 8.2 without DirectX82-KB839643-x86-ENU.EXE Installed">
			<subtest negate="false" test_ref="wft-362"/>
			<subtest negate="false" test_ref="wrt-405"/>
			<subtest negate="true" test_ref="wrt-408"/>
		</compound_test>
		<compound_test id="cmp-963" operation="AND" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed on XP SP1">
			<subtest negate="false" test_ref="wft-361"/>
			<subtest negate="false" test_ref="wrt-404"/>
			<subtest negate="false" test_ref="wrt-407"/>
			<subtest negate="true" test_ref="wrt-410"/>
		</compound_test>
		<compound_test id="cmp-964" operation="AND" comment="DirectX 9.0 without DirectX9-KB839643-x86-ENU.EXE Installed">
			<subtest negate="false" test_ref="wft-363"/>
			<subtest negate="false" test_ref="wrt-406"/>
			<subtest negate="true" test_ref="wrt-409"/>
		</compound_test>
		<compound_test id="cmp-965" operation="OR" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed">
			<subtest negate="false" test_ref="cmp-961"/>
			<subtest negate="false" test_ref="cmp-963"/>
		</compound_test>
		<compound_test id="cmp-966" operation="OR" comment="DirectX without KB839643 Installed">
			<subtest negate="false" test_ref="cmp-962"/>
			<subtest negate="false" test_ref="cmp-964"/>
			<subtest negate="false" test_ref="cmp-965"/>
		</compound_test>
		<compound_test id="cmp-967" operation="AND" comment="DirectX 8.1 without kb839643 installed">
			<subtest negate="false" test_ref="wft-364"/>
			<subtest negate="false" test_ref="wrt-404"/>
			<subtest negate="true" test_ref="wrt-407"/>
		</compound_test>
		<compound_test id="cmp-968" operation="AND" comment="DirectX 8.1 without WindowsServer2003-KB839643-x86-ENU.EXE Installed">
			<subtest negate="false" test_ref="wft-365"/>
			<subtest negate="false" test_ref="wrt-404"/>
			<subtest negate="true" test_ref="wrt-407"/>
		</compound_test>
		<compound_test id="cmp-969" operation="OR" comment="DirectX without KB839643 Installed on Windows Server 2003">
			<subtest negate="false" test_ref="cmp-962"/>
			<subtest negate="false" test_ref="cmp-964"/>
			<subtest negate="false" test_ref="cmp-968"/>
		</compound_test>
		<compound_test id="cmp-97" operation="OR" comment="ActiveX controls and active scripting are enabled">
			<subtest negate="false" test_ref="cmp-98"/>
			<subtest negate="false" test_ref="cmp-99"/>
		</compound_test>
		<compound_test id="cmp-98" operation="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
			<subtest negate="true" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-121"/>
			<subtest negate="false" test_ref="wrt-126"/>
		</compound_test>
		<compound_test id="cmp-99" operation="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
			<subtest negate="false" test_ref="wrt-30"/>
			<subtest negate="false" test_ref="wrt-120"/>
			<subtest negate="false" test_ref="wrt-125"/>
		</compound_test>
		<unknown_test id="ukn-10" comment="Word 97 is installed">
			<oval:notes>
				<oval:note>We think, but are not sure that the affected version of bkupexec.exe is 3.60.1.298 The file should be found in C:Program Files\VERITAS\Backup Exec\NT\bkupexec.exe</oval:note>
			</oval:notes>
		</unknown_test>
		<unknown_test id="ukn-11" comment="Word 98 is installed"/>
		<unknown_test id="ukn-12" comment="Excel 97 is installed"/>
		<unknown_test id="ukn-13" comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)"/>
		<unknown_test id="ukn-16" comment="machine has followed the GDR update path and rpcrt4.dll is less than 5.2.3790.137"/>
		<unknown_test id="ukn-17" comment="machine has followed the QFE update path and rpcrt4.dll is less than 5.2.3790.141"/>
		<unknown_test id="ukn-18" comment="machine has followed the GDR update path and rpcss.dll is less than 5.2.3790.132"/>
		<unknown_test id="ukn-19" comment="machine has followed the QFE update path and rpcss.dll is less than 5.2.3790.142"/>
		<unknown_test id="ukn-20" comment="Kerberos is disabled on the virtual server that hosts OWA on the Exchange Server 2003 back-end server"/>
		<unknown_test id="ukn-21" comment="this is a front-end server providing Outlook Web Access"/>
		<unknown_test id="ukn-22" comment="the back-end server is Exchange Server 2003 running on Windows 2003"/>
		<unknown_test id="ukn-24" comment="a website linked to the Crystal Reports Viewer is active"/>
		<unknown_test id="ukn-25" comment="Affected bkupexec.exe versions 3.60.1.298">
			<oval:notes>
				<oval:note>We think, but are not sure that the affected version of bkupexec.exe is 3.60.1.298 The file should be found in C:\Program Files\VERITAS\Backup Exec\NT\bkupexec.exe</oval:note>
			</oval:notes>
		</unknown_test>
		<unknown_test id="ukn-3" comment="configured to only offer streaming media over unicast"/>
		<unknown_test id="ukn-38" comment="Service Pack 2 or less for Windows Office XP">
			<oval:notes>
				<oval:note>Service Pack 2 or less for Windows Office XP needs regex involving strings and less than</oval:note>
			</oval:notes>
		</unknown_test>
		<activedirectory_test id="wat-1" check="none exist" comment="The exadmin HTTP virtual directory only allows Integrated Windows Authentication" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context operator="equals">configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Exadmin,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
				<attribute operator="equals">msExchAuthenticationFlags</attribute>
			</object>
			<data operation="AND">
				<value operator="not equal">4</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1030" check="all" comment="Display the routing groups in the Exchange System Manager" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchRoutingEnabled</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1040" check="all" comment="Display the administrative groups in the Exchange System Manager" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAdminGroupsEnabled</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1140" check="all" comment="enable forms based authentication" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchDS2MBOptions</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">64</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1150" check="all" comment="only allow integrated windows authentication (NTLM) to connect to the Public HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAuthenticationFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">4</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1160" check="all" comment="allow script execute permissions to the Public HTTP virtual directory" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAccessFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">512</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1170" check="all" comment="allow read access to the Public HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAccessFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1171" check="all" comment="allow write access to the Public HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAccessFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">2</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1172" check="all" comment="allow script source access to the Public HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAccessFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">16</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1173" check="all" comment="allow directory browsing in the Public HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchDirBrowseFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">2147483648</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1185" check="all" comment="zero out deleted database pages" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=InformationStore,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchESEParamZeroDatabaseDuringBackup</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1190" check="all" comment="disable all automated message generation on the default domain" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Default,CN=Internet Message Formats,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchRoutingAcceptMessageType</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">0</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1200" check="all" comment="allow basic authentication to connect to the IMAP4 service" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAuthenticationFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">2</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1201" check="all" comment="require TSL encryption to connect to the IMAP4 service" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>attribute>msExchOtherAuthenticationFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1202" check="all" comment="allow simple authentication and security layer (SASL) to connect to the IMAP4 service" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAuthenticationFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">4</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1240" check="all" comment="use SSL when downloading meeting requests using IMAP4" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>oWAServer</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_PRINTABLE_STRING</adstype>
				<value operator="pattern match">^https\:\/\/</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1250" check="all" comment="use TCP 143 for the IMAP4 service" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchServerBindings</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">143</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1251" check="all" comment="use TCP 993 for the secure IMAP4 service" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSecureBindings</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">993</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1280" check="all" comment="archive all messages received by mailboxes on this store" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Mailbox Store \([^\)]*\),CN=[^,]*,CN=InformationStore,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchMessageJournalRecipient</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_DN_STRING</adstype>
				<value operator="pattern match">.+</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1290" check="all" comment="have clients support S/MIME" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Mailbox Store \([^\)]*\),CN=[^,]*,CN=InformationStore,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchDownGradeMultipartSigned</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">0</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1300" check="all" comment="delete mailboxes without waiting for the store to be backed up" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Mailbox Store \([^\)]*\),CN=[^,]*,CN=InformationStore,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>deletedItemFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">2</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1350" check="all" comment="subscribe to a block list to block spam" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=[^,]+,CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute operator="pattern match">.*</attribute>
			</object>
		</activedirectory_test>
		<activedirectory_test id="wat-1370" check="all" comment="limit the size of messages to the server to 30MB" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>delivContLength</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="less than or equal">30720</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1371" check="all" comment="limit the size of messages from the server to 30MB" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>submissionContLength</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="less than or equal">30720</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1380" check="all" comment="limit the number of recipients in outbound messages to 5000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchRecipLimit</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="less than or equal">5000</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1390" check="all" comment="disable the filtering of recipients who are not in Active Directory" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute operator="not equal">msExchRecipTurfListOptions</attribute>
			</object>
		</activedirectory_test>
		<activedirectory_test id="wat-140" check="all" comment="allow script execute permissions to Exchange HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAccessFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">512</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1420" check="all" comment="archive filtered messages" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchTurfListAction</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_PRINTABLE_STRING</adstype>
				<value operator="pattern match">Filter</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1430" check="all" comment="filter messages with a blank sender" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchTurfListOptions</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">2</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1440" check="all" comment="do not drop connections if the address matches filters" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchTurfListOptions</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">8</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1450" check="all" comment="accept messages without notifying the sender of filtering" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchTurfListOptions</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1470" check="all" comment="disable Outlook Mobile Access" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Outlook Mobile Access,CN=Global Settings,CN=Labtop Organization,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchMoaAdminWirelessEnable</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">2</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1480" check="all" comment="disable ActiveSync" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Outlook Mobile Access,CN=Global Settings,CN=Labtop Organization,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchMoaAdminWirelessEnable</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">4</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1530" check="all" comment="allow basic authentication to connect to the POP3 service" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAuthenticationFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">2</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1531" check="all" comment="require TSL encryption to connect to the POP3 service" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>attribute>msExchAuthenticationFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1532" check="all" comment="allow simple authentication and security layer (SASL) to connect to the POP3 service" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAuthenticationFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">4</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1570" check="all" comment="use SSL when downloading meeting requests using POP3" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>oWAServer</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_PRINTABLE_STRING</adstype>
				<value operator="pattern match">^https\:\/\/</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1580" check="all" comment="use TCP port 110 for the POP3 service" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchServerBindings</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">110</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1581" check="all" comment="use TCP port 995 for the secure POP3 service" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSecureBindings</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">995</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1590" check="all" comment="don't have mailbox store clients support S/MIME signatures" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=Public Folder Store \([^\)]+\),CN=[^,]*,CN=InformationStore,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchDownGradeMultipartSigned</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1670" check="all" comment="enable subject logging and display" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>messageTrackingEnabled</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">262144</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1680" check="all" comment="enable message tracking" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchMessageTrackLogFilter</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1690" check="all" comment="disable automatic log removal" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchTrkLogCleaningInterval</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">0</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1720" check="all" comment="disable all monitoring on this server" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchMonitoringMode</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="not equal">0</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1737" check="all" comment="change state to critical when any basic Exchange service stops" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchMonitoringResources</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_PRINTABLE_STRING</adstype>
				<value operator="pattern match">^\d+\:1\:</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1770" check="all" comment="limit SMTP connector scope to the routing group" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Connections,CN=[^,]*,CN=Routing Groups,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>routingList</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_PRINTABLE_STRING</adstype>
				<value operator="pattern match">^local\:</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1771" check="all" comment="SMTP connector object exists" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Connections,CN=[^,]*,CN=Routing Groups,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute operator="pattern match">.*</attribute>
			</object>
		</activedirectory_test>
		<activedirectory_test id="wat-1780" check="all" comment="allow unauthenticated entities to relay through this SMTP connector" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Connections,CN=[^,]*,CN=Routing Groups,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSmtpOutboundSecurityFlag</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">4096</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1790" check="all" comment="force outbound connections to use only basic authentication with TLS encryption" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Connections,CN=[^,]*,CN=Routing Groups,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSmtpOutboundSecurityFlag</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">270</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1810" check="all" comment="have any SMTP connectors use a smart host" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]*,CN=Connections,CN=[^,]*,CN=Routing Groups,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSmtpSmartHost</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_PRINTABLE_STRING</adstype>
				<value operator="pattern match">.+</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1820" check="all" comment="only allow basic authentication to connect to the SMTP server" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAuthenticationFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">2</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1821" check="all" comment="require TSL encryption to connect to the SMTP server" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSmtpInboundCommandSupportOptions</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">131072</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1830" check="all" comment="resolve anonymous email" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAuthMailDisposition</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1875" check="all" comment="only allow explicitly listed hosts to relay messages through this sever" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSmtpRelayForAuth</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">0</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1880" check="all" comment="use a smart host to relay SMTP messages" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSmtpSmartHost</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_PRINTABLE_STRING</adstype>
				<value operator="pattern match">.+</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1890" check="all" comment="perform reverse DNS lookups on incoming messages" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSmtpPerformReverseDnsLookup</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1900" check="all" comment="use port 25 for outbound SMTP connections" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSmtpOutgoingPort</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">25</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1910" check="all" comment="use only basic authentication with TLS encryption for outbound SMTP connections" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchSmtpOutboundSecurityFlag</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">268</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1920" check="all" comment="enable logging of connections between SMTP hosts" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchLogType</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1930" check="all" comment="use port 25 for inbound SMTP connections" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchServerBindings</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">25</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1940" check="all" comment="apply recipient and connection filters" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchServerBindingsFiltering</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_PRINTABLE_STRING</adstype>
				<value operator="pattern match">\:3$</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-1941" check="all" comment="apply sender filters" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchServerBindingsTurflist</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_PRINTABLE_STRING</adstype>
				<value operator="pattern match">.+</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-2" check="all" comment="Review global accept list" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<oval:notes>
				<oval:note>Non-perjorative test</oval:note>
			</oval:notes>
			<object>
				<naming_context operator="equals">configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=Default Message Filter,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
				<attribute operator="equals">msExchSMTPGlobalIPAcceptList</attribute>
			</object>
			<data operation="AND">
				<value operator="pattern match">.*</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-3" check="all" comment="Review global deny list" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<oval:notes>
				<oval:note>Non-perjorative test</oval:note>
			</oval:notes>
			<object>
				<naming_context operator="equals">configuration</naming_context>
				<relative_dn operator="pattern match">^CN=[^,]+,CN=Default Message Filter,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
				<attribute operator="equals">msExchSMTPGlobalIPDenyList</attribute>
			</object>
			<data operation="AND">
				<value operator="pattern match">.*</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-4" check="all" comment="Review block-list exception values" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<oval:notes>
				<oval:note>Non-perjoritive test</oval:note>
			</oval:notes>
			<object>
				<naming_context operator="equals">configuration</naming_context>
				<relative_dn operator="equals">CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
				<attribute operator="equals">msExchRecipTurfListNames</attribute>
			</object>
			<data operation="AND">
				<value operator="pattern match">.*</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-5" check="all" comment="Review blocked senders" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<oval:notes>
				<oval:note>Non-perjoritive check</oval:note>
			</oval:notes>
			<object>
				<naming_context operator="equals">configuration</naming_context>
				<relative_dn operator="pattern match">CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
				<attribute operator="equals">msExchTurfListNames</attribute>
			</object>
			<data operation="AND">
				<value operator="equals">.*</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-6" check="all" comment="Review list of blocked recipients" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<oval:notes>
				<oval:note>Non-pejorative test</oval:note>
			</oval:notes>
			<object>
				<naming_context operator="equals">configuration</naming_context>
				<relative_dn operator="pattern match">CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
				<attribute operator="equals">msExchRecipTurfListNames</attribute>
			</object>
			<data operation="AND">
				<value operator="equals">.*</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-850" check="all" comment="only allow integrated windows authentication (NTLM) to connect to the Exchange HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAuthenticationFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="equals">4</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-860" check="all" comment="allow read access to the Exchange HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAccessFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">1</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-861" check="all" comment="allow write access to the Exchange HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAccessFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">2</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-862" check="all" comment="allow script source access to the Exchange HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchAccessFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">16</value>
			</data>
		</activedirectory_test>
		<activedirectory_test id="wat-863" check="all" comment="allow directory browsing in the Exchange HTTP virtual directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<naming_context>configuration</naming_context>
				<relative_dn operator="pattern match">^Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
				<attribute>msExchDirBrowseFlags</attribute>
			</object>
			<data>
				<adstype>ADSTYPE_INTEGER</adstype>
				<value datatype="int" operator="bitwise and">2147483648</value>
			</data>
		</activedirectory_test>
		<file_test id="wft-10" check="at least one" comment="the version of hh.exe is less than 5.2.3790.2453" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\hh.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>2453</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-100" check="at least one" comment="the version of w3proxy.exe is less than 3.0.1200.257" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server\InstallationLocation</component>
					<component type="literal">\w3proxy.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>0</minor>
					<build>1200</build>
					<private>257</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-101" check="at least one" comment="the version of wpsrv.exe is less than 3.0.1200.257" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server\InstallationLocation</component>
					<component type="literal">\wspsrv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>0</minor>
					<build>1200</build>
					<private>257</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-102" check="at least one" comment="the version of itircl.dll is less than 5.2.3644.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\itircl.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3644</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-103" check="at least one" comment="the version of itss.dll is less than 5.2.3644.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\itss.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3644</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-104" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1505 (RTMGDR)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1505</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-105" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1506 (RTMQFE)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1506</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-106" check="at least one" comment="the version of msasn1.dll is less than 5.2.3790.88" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>88</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-107" check="at least one" comment="the version of msasn1.dll is less than 5.1.2600.119" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>119</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-108" check="at least one" comment="the version of msasn1.dll is less than 5.0.2195.6824" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6824</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-109" check="at least one" comment="the version of msasn1.dll is less than 5.1.2600.1274" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1274</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-11" check="at least one" comment="the version of hh.exe is less than 5.2.3790.2435" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\hh.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>2435</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-110" check="at least one" comment="the version of wins.exe is less than 4.0.1381.7255" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7255</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-111" check="at least one" comment="the version of wins.exe is less than 4.0.1381.33554" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33554</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-112" check="at least one" comment="the version of wins.exe is less than 5.2.3790.99" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>99</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-113" check="at least one" comment="the version of fp30reg.dll is less than 10.00.4205.0000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\web server extensions\50\bin\fp30reg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>00</minor>
					<build>4205</build>
					<private>0000</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-114" check="at least one" comment="the version of fp30reg.dll is less than 4.0.02.7523" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\web server extensions\40\bin\fp30reg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>00</minor>
					<build>02</build>
					<private>7523</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-115" check="at least one" comment="the version of mshtml.dll is less than 5.0.3541.2700" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3541</build>
					<private>2700</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-116" check="at least one" comment="the version of mshtml.dll is less than 5.0.3828.2700" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3828</build>
					<private>2700</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-117" check="at least one" comment="the version of agentdpv.dll is less than 2.0.0.3423" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\agentdpv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2</major>
					<minor>0</minor>
					<build>0</build>
					<private>3423</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-118" check="at least one" comment="the version of agentdpv.dll is less than 5.2.3790.1241" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\agentdpv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>1241</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-119" check="all" comment="the version of srv.sys is less than 5.1.2600.1683" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SYSTEM32\DRIVERS\srv.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1683</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-12" check="at least one" comment="the version of shtml.dll is less than 4.0.2.7523" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\web server extensions\40\isapi\shtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>00</minor>
					<build>02</build>
					<private>7523</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-120" check="at least one" comment="the version of jscript.dll is less than 5.1.0.8513" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\jscript.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>0</build>
					<private>8513</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-121" check="at least one" comment="the version of jscript.dll is less than 5.5.0.8513" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\jscript.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>5</minor>
					<build>0</build>
					<private>8513</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-122" check="at least one" comment="the version of msgsvc.dll is less than 5.0.2195.6861" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6861</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-123" check="at least one" comment="the version of wordpad.exe is less than 5.1.2600.1606" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Windows NT\Accessories\wordpad.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1606</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-124" check="all" comment="the version of srv.sys is less than 5.1.2600.2673" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SYSTEM32\DRIVERS\srv.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>2673</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-125" check="all" comment="the version of srv.sys is less than 5.2.3790.324" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SYSTEM32\DRIVERS\srv.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>324</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-126" check="all" comment="the version of srv.sys is less than 5.2.3790.2437" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SYSTEM32\DRIVERS\srv.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>2437</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-13" check="at least one" comment="the version of hh.exe is less than 5.2.3790.2427" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\hh.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>2427</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-130" check="at least one" comment="the version of outlook.exe is less than 10.00.5709.0000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE\Path</component>
					<component type="literal">outlook.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>00</minor>
					<build>5709</build>
					<private>0000</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-131" check="at least one" comment="the version of msgina.dll is less than 4.0.1381.7255" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgina.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7255</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-132" check="at least one" comment="the version of msgina.dll is less than 4.0.1381.33559" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgina.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33559</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-133" check="at least one" comment="the version of msgina.dll is less than 5.1.2600.136" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msjet40.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6895</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-134" check="at least one" comment="the version of msgina.dll is less than 5.1.2600.128" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgina.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>128</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-135" check="at least one" comment="the version of msgina.dll is less than 5.1.2600.1343" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgina.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1343</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-136" check="at least one" comment="the version of mf3216.dll is less than 4.0.1381.7263" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mf3216.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7263</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-137" check="at least one" comment="the version of mf3216.dll is less than 4.0.1381.33562" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mf3216.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33562</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-138" check="at least one" comment="the version of mf3216.dll is less than 5.0.2195.6898" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mf3216.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6898</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-139" check="at least one" comment="the version of mf3216.dll is less than 5.1.2600.132" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mf3216.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>132</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-14" check="at least one" comment="the version of excel.exe is less than 8.00.01.9904" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
					<component type="literal">excel.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>00</minor>
					<build>01</build>
					<private>9904</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-140" check="at least one" comment="the version of msdxm.ocx is less than 6.4.9.1124" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msdxm.ocx</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>4</minor>
					<build>9</build>
					<private>1124</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-141" check="at least one" comment="the version of wmpcore.dll is less than 8.0.0.4482" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wmpcore.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>0</build>
					<private>4482</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-142" check="at least one" comment="the version of wmplayer.exe is less than 8.0.0.4482" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Windows Media Player\wmplayer.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>0</build>
					<private>4482</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-143" check="at least one" comment="the version of msdxm.ocx is less than 6.4.9.1121" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msdxm.ocx</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>4</minor>
					<build>9</build>
					<private>1121</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-144" check="at least one" comment="the version of wmplayer.exe is less than 8.0.0.4490" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Windows Media Player\wmplayer.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>0</build>
					<private>4490</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-145" check="all" comment="the version of srv.sys is less than 5.0.2195.7044" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SYSTEM32\DRIVERS\srv.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7044</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-146" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7268" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7268</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-147" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33591" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33591</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-148" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6992" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6992</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-149" check="at least one" comment="the version of mf3216.dll is less than 5.1.2600.1331" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mf3216.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1331</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-15" check="at least one" comment="the version of excel.exe is less than 9.0.0.8216" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
					<component type="literal">excel.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>8216</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-150" check="at least one" comment="the version of h323.tsp is less than 5.0.2195.6901" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\h323.tsp</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6901</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-151" check="at least one" comment="the version of h323.tsp is less than 5.2.3790.132" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\h323.tsp</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>132</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-152" check="at least one" comment="the version of h323.tsp is less than 5.1.2600.1348" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\h323.tsp</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1348</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-153" check="at least one" comment="the version of h323.tsp is less than 5.1.2600.134" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\h323.tsp</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>134</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-154" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1605</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-156" check="at least one" comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Dhcpssvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7304</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-157" check="at least one" comment="the version of lsasrv.dll is less than 5.2.3790.134" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>134</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-158" check="at least one" comment="the version of lsasrv.dll is less than 5.1.2600.134" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>134</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-159" check="at least one" comment="the version of lsasrv.dll is less than 5.1.2600.1361" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1361</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-16" check="at least one" comment="the version of excel.exe is less than 10.0.5815.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
					<component type="literal">excel.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>5815</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-160" check="at least one" comment="the version of lsasrv.dll is less than 5.2.3790.220" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>220</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-161" check="at least one" comment="the version of webclnt.dll is less than 5.2.3790.316" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\webclnt.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>316</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-162" check="at least one" comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Dhcpssvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33587</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-163" check="at least one" comment="the version of wins.exe is less than 5.0.2195.7005" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7005</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-164" check="at least one" comment="the version of wins.exe is less than 4.0.1381.7329" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7329</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-165" check="at least one" comment="the version of wins.exe is less than 4.0.1381.33618" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33618</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-167" check="at least one" comment="the version of webclnt.dll is less than 5.2.3790.1673" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\webclnt.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>1673</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-169" check="at least one" comment="the version of hypertrm.dll is less than 5.2.3790.233" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hypertrm.dll </component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>233</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-17" check="at least one" comment="the version of winword.exe is less than 8.0.0.9315" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">winword.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>0</build>
					<private>9315</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-170" check="at least one" comment="the version of schannel.dll is less than 4.87.1964.1880" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\schannel.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>87</minor>
					<build>1964</build>
					<private>1880</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-171" check="at least one" comment="the version of schannel.dll is less than 5.1.2195.6899" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\schannel.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2195</build>
					<private>6899</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-172" check="at least one" comment="the version of schannel.dll is less than 5.2.3790.132" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\schannel.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>132</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-173" check="at least one" comment="the version of schannel.dll is less than 5.1.2600.136" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\schannel.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>136</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-174" check="at least one" comment="the version of schannel.dll is less than 5.1.2600.1347" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\schannel.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1347</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-175" check="at least one" comment="the version of hypertrm.dll is less than 5.1.2600.1609" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hypertrm.dll </component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1609</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-176" check="at least one" comment="the version of hypertrm.dll is less than 5.1.2600.2563" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hypertrm.dll </component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>2563</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-177" check="at least one" comment="the version of comsvcs.dll is less than 2000.2.3511.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\comsvcs.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>2</minor>
					<build>3511</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-178" check="at least one" comment="the version of comsvcs.dll is less than 2001.12.4414.53" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\comsvcs.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2001</major>
					<minor>12</minor>
					<build>4414</build>
					<private>53</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-179" check="at least one" comment="the version of comsvcs.dll is less than 2001.12.4720.130" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\comsvcs.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2001</major>
					<minor>12</minor>
					<build>4720</build>
					<private>130</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-18" check="at least one" comment="the version of winword.exe is less than 8.0.0.9716" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">\winword.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>0</build>
					<private>9716</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-180" check="at least one" comment="the version of msjet40.dll is less than 4.0.8618.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msjet40.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>8618</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-181" check="at least one" comment="the version of wmsjet40.dll is less than 4.0.8618.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wmsjet40.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>8618</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-182" check="at least one" comment="the version of inetcomm.dll is less than 5.50.4939.300" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4939</build>
					<private>300</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-183" check="at least one" comment="the version of inetcomm.dll is less than 6.00.2739.300" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>00</minor>
					<build>2739</build>
					<private>300</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-184" check="at least one" comment="the version of inetcomm.dll is less than 6.00.3790.137" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>00</minor>
					<build>37909</build>
					<private>137</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-185" check="at least one" comment="the version of inetcomm.dll is less than 6.00.2800.1409" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>00</minor>
					<build>2800</build>
					<private>1409</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-186" check="at least one" comment="the version of rpcrt4.dll is less than 5.0.2195.6904" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6904</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-187" check="at least one" comment="the version of rpcrt4.dll is less than 5.1.2600.135" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>135</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-188" check="at least one" comment="the version of rpcrt4.dll is less than 5.1.2600.1361" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1361</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-189" check="at least one" comment="the version of rpcss.dll is less than 5.0.2195.6906" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6906</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-19" check="at least one" comment="the version of winword.exe is less than 9.0.0.8216" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">winword.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>8216</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-190" check="at least one" comment="the version of wintrust.dll is less than 5.131.1880.14" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wintrust.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>1880</build>
					<private>14</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-191" check="at least one" comment="the version of wintrust.dll is less than 5.131.2195.6824" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wintrust.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>2195</build>
					<private>6824</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-192" check="at least one" comment="the version of lsasrv.dll is less than 5.0.2195.6902" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6902</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-193" check="at least one" comment="the version of msasn1.dll is less than 5.0.2195.6905" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6905</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-194" check="at least one" comment="the version of msasn1.dll is less than 5.2.3790.139" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>139</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-195" check="at least one" comment="the version of msasn1.dll is less than 5.1.2600.137" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>137</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-196" check="at least one" comment="the version of msasn1.dll is less than 5.1.2600.1362" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1362</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-197" check="at least one" comment="the version of rpcss.dll is less than 5.1.2600.135" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>135</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-198" check="at least one" comment="the version of rpcss.dll is less than 5.1.2600.1361" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1361</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-199" check="at least one" comment="the version of rpcss.dll is less than 5.2.3790.146" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>142</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-2" check="at least one" comment="the version of helpctr.exe is less than 5.1.2600.137" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>137</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-20" check="at least one" comment="the version of wkssvc.dll is less than 5.1.2600.120" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wkssvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>120</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-200" check="at least one" comment="the version of hypertrm.dll is less than 5.0.2195.7000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hypertrm.dll </component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7000</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-201" check="at least one" comment="the version of mshtml.dll is less than 5.50.4913.1100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4913</build>
					<private>1100</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-202" check="at least one" comment="the version of w3svc.dll is less than 4.2.775.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>775</build>
					<private>1</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-203" check="at least one" comment="the version of mshtml.dll is less than 6.0.2713.1100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2713</build>
					<private>1100</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-204" check="at least one" comment="the version of mshtml.dll is less than 6.0.2716.2200" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2716</build>
					<private>2200</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-205" check="at least one" comment="the version of w3svc.dll is less than 5.0.2195.5269" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5269</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-206" check="at least one" comment="the version of mshtml.dll is less than 5.50.4725.2100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4725</build>
					<private>2100</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-207" check="at least one" comment="the version of netman.dll is less than 5.0.2195.5974" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netman.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5974</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-208" check="at least one" comment="the version of mshtml.dll is less than 5.0.3504.2500" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3504</build>
					<private>2500</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-209" check="at least one" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\ism.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5671</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-21" check="at least one" comment="the version of wkssvc.dll is less than 5.1.2600.1301" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wkssvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1301</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-210" check="at least one" comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\smtpsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>4905</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-211" check="at least one" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\ism.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>764</build>
					<private>1</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-212" check="at least one" comment="the version of srvsvc.dll is less than 5.00.2195.4980" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\srvsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>4980</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-213" check="at least one" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>2103</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-214" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3513</build>
					<private>900</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-215" check="at least one" comment="the version of mshtml.dll is less than 5.0.3502.4856" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3502</build>
					<private>4856</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-216" check="at least one" comment="the version of mshtml.dll is less than 6.0.2723.2500" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2723</build>
					<private>2500</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-217" check="at least one" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6106</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-218" check="at least one" comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rasman.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7140</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-219" check="at least one" comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rasman.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>4983</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-22" check="at least one" comment="the version of winword.exe is less than 10.0.5815.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">winword.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>5815</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-220" check="at least one" comment="File %windir%\system32\netlogon.dll version is less than 5.00.0893.1105" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netlogon.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>893</build>
					<private>1105</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-221" check="at least one" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\asp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6672</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-222" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.296.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlservr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>296</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-223" check="at least one" comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\smss.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5695</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-224" check="at least one" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\ism.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>3407</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-225" check="at least one" comment="the version of ssmsrp70.dll is less than 2000.80.213.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\ssmsrp70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>213</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-226" check="at least one" comment="the version of hypertrm.dll is less than 4.0.1381.7323" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hypertrm.dll </component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7323</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-227" check="at least one" comment="File sqlservr.exe version3 less than 428" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlservr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>428</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-228" check="at least one" comment="the version of snmp.exe is less than 4.0.1381.7134" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\snmp.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7134</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-229" check="at least one" comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\mup.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5080</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-23" check="at least one" comment="the version of mshtml.dll is less than 5.0.3523.1700" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3523</build>
					<private>1700</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-230" check="at least one" comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\httpext.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>0</major>
					<minor>9</minor>
					<build>3940</build>
					<private>20</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-231" check="at least one" comment="the version of mshtml.dll is less than 6.0.2715.400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2715</build>
					<private>400</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-232" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2719</build>
					<private>2200</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-233" check="at least one" comment="the version of locator.exe is less than 4.0.1381.7202" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Locator.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7202</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-234" check="at least one" comment="the version of ntdll.dll is less than 5.0.2195.6685" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ntdll.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6685</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-235" check="at least one" comment="File %windir%\system32\Drivers\SRV.SYS is less than 5.0.2195.6699" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Drivers\SRV.SYS</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6699</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-236" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.608.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlservr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>608</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-237" check="at least one" comment="the version of odsole70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\odsole70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-238" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1264" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1264</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-239" check="at least one" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6802</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-24" check="at least one" comment="the version of mshtml.dll is less than 5.0.3810.1700" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3810</build>
					<private>1700</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-240" check="at least one" comment="File %windir%\system32\shdocvw.dll version is less than 5.0.3214.2000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shdocvw.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3214</build>
					<private>2000</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-241" check="at least one" comment="the version of mshtml.dll is less than 6.0.2722.900" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2722</build>
					<private>900</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-242" check="at least one" comment="the version of snmp.exe is less than 5.0.2195.4919" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\snmp.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>4919</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-243" check="at least one" comment="the version of mup.sys is less than 4.0.1381.7125" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\mup.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7125</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-244" check="at least one" comment="the version of shell32.dll is less than 5.00.3502.4718" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3502</build>
					<private>4718</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-245" check="at least one" comment="the version of smss.exe is less than 4.0.1381.7152" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\smss.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7152</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-246" check="at least one" comment="the version of netlogon.dll is less than 4.0.1381.7092" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netlogon.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7092</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-247" check="at least one" comment="the version of mshtml.dll is less than 5.50.4923.2500" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4923</build>
					<private>2500</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-248" check="at least one" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.776.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\ism.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>776</build>
					<private>1</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-249" check="at least one" comment="the version of cryptui.dll is less than 5.131.2600.117" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cryptui.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>2600</build>
					<private>117</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-25" check="at least one" comment="the version of mshtml.dll is less than 5.50.4934.1600" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4934</build>
					<private>1600</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-250" check="at least one" comment="the version of cryptui.dll is less than 5.131.2600.1243" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cryptui.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>2600</build>
					<private>1243</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-251" check="at least one" comment="the version of xactsrv.dll is less than 5.0.2195.5971" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\xactsrv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5971</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-252" check="at least one" comment="the version of xenroll.dll is less than 5.131.3659.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\xenroll.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>3659</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-253" check="at least one" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2784" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>2784</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-254" check="at least one" comment="File %windir%\system32\idq.dll version is less than 5.0.2195.3645" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\idq.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>3645</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-255" check="at least one" comment="File %windir%\system32\cryptui.dll version is less than 5.131.2195.6758" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cryptui.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>2195</build>
					<private>6758</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-256" check="at least one" comment="File %windir%\system32\drivers\rdpwd.sys version is less than 5.0.2195.5880" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\rdpwd.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5880</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-257" check="at least one" comment="the version of jscript.dll is less than 5.6.0.8513" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\jscript.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>6</minor>
					<build>0</build>
					<private>8513</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-258" check="at least one" comment="the version of user32.dll is less than 5.1.2600.118" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>118</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-259" check="at least one" comment="the version of user32.dll is less than 5.1.2600.1255" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1255</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-26" check="at least one" comment="the version of mshtml.dll is less than 6.0.2734.1600" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2734</build>
					<private>1600</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-260" check="at least one" comment="the version of wkssvc.dll is less than 5.0.2195.6861" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wkssvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6861</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-261" check="at least one" comment="the version of itircl.dll is less than 5.2.3790.80" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\itircl.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>80</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-262" check="at least one" comment="the version of mshtml.dll is less than 5.50.4922.900" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4922</build>
					<private>900</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-263" check="at least one" comment="the version of hypertrm.dll is less than 4.0.1381.842" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hypertrm.dll </component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>842</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-264" check="at least one" comment="the version of mswrd664.wpc is less than 2004.10.25.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\Microsoft Shared\TextConv\mswrd664.wpc</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2004</major>
					<minor>10</minor>
					<build>25</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-265" check="at least one" comment="the version of wmswrd632.wpc is less than 2004.10.25.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\Microsoft Shared\TextConv\wmswrd632.wpc</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2004</major>
					<minor>10</minor>
					<build>25</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-266" check="at least one" comment="the version of mshtml.dll is less than 6.00.3790.191" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>191</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-267" check="at least one" comment="the version of mshtml.dll is less than 6.00.2800.1458" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1458</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-268" check="at least one" comment="the version of mshtml.dll is less than 6.00.2743.600" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2743</build>
					<private>600</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-269" check="at least one" comment="the version of mshtml.dll is less than 5.50.4943.400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4943</build>
					<private>400</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-27" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1276" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1276</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-270" check="at least one" comment="the version of mshtml.dll is less than 5.0.3532.300" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3532</build>
					<private>300</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-271" check="at least one" comment="the version of tshoot.ocx is less than 1.0.1.2125" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\tshoot.ocx</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>0</minor>
					<build>1</build>
					<private>2125</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-272" check="at least one" comment="the version of msgsvc.dll is less than 5.1.2600.120" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>120</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-273" check="at least one" comment="the version of msgsvc.dll is less than 5.1.2600.1301" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1301</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-274" check="at least one" comment="File sqlservr.exe version3 is less than 578" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlservr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>578</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-275" check="at least one" comment="File xpstar.dll version3 is less than 561" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xpstar.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>561</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-276" check="at least one" comment="the version of srvsvc.dll is less than 5.0.2195.6110" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\srvsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-277" check="at least one" comment="the version of dxmasf.dll is less than 6.4.9.1121" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dxmasf.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>4</minor>
					<build>9</build>
					<private>1121</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-278" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.650.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlservr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>650</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-279" check="at least one" comment="the version of mshtml.dll is less than 5.00.3819.300" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3819</build>
					<private>300</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-28" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.94" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>94</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-280" check="at least one" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6753" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6753</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-281" check="at least one" comment="the version of mswrd632.wpc is less than 2004.10.25.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\Microsoft Shared\TextConv\mswrd632.wpc</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2004</major>
					<minor>10</minor>
					<build>25</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-282" check="at least one" comment="the version of kernel32.dll is less than 4.0.1381.7224" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\kernel32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7224</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-283" check="at least one" comment="the version of nntpsvc.dll is less than 5.0.2195.3881" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nntpsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>3881</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-284" check="at least one" comment="machine has followed the GDR update path and rpcproxy.dll is less than 5.2.3790.137" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcproxy.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>137</private>
				</version>
				<development_class operator="not equal">srv03_qfe</development_class>
			</data>
		</file_test>
		<file_test id="wft-285" check="at least one" comment="File %windir%\system32\user32.dll version is less than 5.00.2195.6799" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6799</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-286" check="at least one" comment="the version of hhctrl.ocx is less than 5.2.3669.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hhctrl.ocx</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3669</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-287" check="at least one" comment="the version of hhsetup.dll is less than 5.2.3644.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hhsetup.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3644</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-288" check="at least one" comment="machine has followed the QFE update path and rpcproxy.dll is less than 5.2.3790.141" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcproxy.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>141</private>
				</version>
				<development_class>srv03_qfe</development_class>
			</data>
		</file_test>
		<file_test id="wft-289" check="at least one" comment="the version of rpcproxy.dll is less than 5.0.2195.6904" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcproxy.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6904</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-29" check="all" comment="the version of telnet.exe is less than 7.0.1701.44" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\telnet.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>7</major>
					<minor>0</minor>
					<build>1701</build>
					<private>44</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-290" check="at least one" comment="the version of tlntsvr.exe is less than 5.0.33668.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\tlntsvr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>33668</build>
					<private>1</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-291" check="at least one" comment="the version of sp3res.dll is less than 5.0.2195.6713" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sp3res.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6713</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-292" check="at least one" comment="the version of umandlg.dll is less than 1.0.0.3" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\umandlg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>0</minor>
					<build>0</build>
					<private>3</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-293" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3510.1100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3510</build>
					<private>1100</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-294" check="at least one" comment="the version of helpctr.exe is less than 5.2.3790.161" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>161</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-295" check="at least one" comment="the version of ole32.dll is less than 4.0.1381.7263" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ole32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7263</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-296" check="at least one" comment="File %windir%\system32\inetsrv\ssinc.dll version is less than 5.0.2195.6624" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\ssinc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6624</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-297" check="at least one" comment="the version of ole32.dll is less than 4.0.1381.33562" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ole32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33562</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-298" check="at least one" comment="the version of rpcproxy.dll is less than 4.0.1381.7255" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcproxy.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7255</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-299" check="at least one" comment="the version of rpcproxy.dll is less than 4.0.1381.33559" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcproxy.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33559</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-3" check="at least one" comment="the version of helpctr.exe is less than 5.1.2600.1515" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1515</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-30" check="at least one" comment="the version of msgsc.dll is less than 6.1.0.211" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\MSN Messenger\msgsc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>1</minor>
					<build>0</build>
					<private>211</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-300" check="at least one" comment="the version of mswrd6.wpc is less than 10.0.803.2" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\Microsoft Shared\TextConv\mswrd6.wpc</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>803</build>
					<private>2</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-301" check="at least one" comment="the version of msjava.dll is less than 5.0.3810.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msjava.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3810</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-302" check="at least one" comment="the version of msjava.dll is less than 5.0.3809.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msjava.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3809</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-303" check="at least one" comment="the version of helpctr.exe is less than 5.2.3790.125" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>125</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-304" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 4.2.769.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>769</build>
					<private>1</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-305" check="at least one" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.3649" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Msw3prt.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>3649</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-306" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>164</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-307" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4613.1700" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4613</build>
					<private>1700</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-308" check="at least one" comment="the version of mshtml.dll is less than 6.0.2712.0300" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2712</build>
					<private>0300</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-309" check="at least one" comment="the version of mshtml.dll is less than 5.50.4926.2500" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4926</build>
					<private>2500</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-31" check="at least one" comment="the version of fp4areg.dll is less than 4.0.02.7523" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\web server extensions\40\bin\fp4areg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>00</minor>
					<build>02</build>
					<private>7523</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-310" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2716.2200" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2716</build>
					<private>2200</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-311" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2713</build>
					<private>1100</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-312" check="at least one" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4927.2100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4927</build>
					<private>2100</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-313" check="at least one" comment="File %windir%\system32\snmp.exe is less than 4.0.1381.133" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\snmp.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>133</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-314" check="at least one" comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>70</minor>
					<build>11</build>
					<private>40</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-315" check="at least one" comment="File %windir%\System32\odbcbcp.dll is less than 2000.80.746.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>746</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-316" check="at least one" comment="the version of helpctr.exe is less than 5.1.2600.128" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>128</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-317" check="at least one" comment="the version of helpctr.exe is less than 5.1.2600.1340" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1340</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-318" check="at least one" comment="the version of evtgprov.dll is less than 5.1.2600.136" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\evtgprov.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>136</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-319" check="at least one" comment="the version of evtgprov.dll is less than 5.1.2600.1363" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\evtgprov.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1363</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-32" check="at least one" comment="the version of fp5areg.dll is less than 10.00.4205.0000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\web server extensions\50\bin\fp5areg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>00</minor>
					<build>4205</build>
					<private>0000</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-320" check="at least one" comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9001.40" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9001</build>
					<private>40</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-321" check="at least one" comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9041.40" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9041</build>
					<private>40</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-322" check="at least one" comment="the version of umandlg.dll is less than 1.0.0.4" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\umandlg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>0</minor>
					<build>0</build>
					<private>4</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-323" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4616.200" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4616</build>
					<private>200</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-324" check="at least one" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4701.2400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4701</build>
					<private>2400</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-325" check="at least one" comment="the version of mswd6_32.wpc is less than 2004.10.21.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Windows NT\Accessories\mswd6_32.wpc</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2004</major>
					<minor>10</minor>
					<build>21</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-326" check="at least one" comment="the version of mswrd632.wpc is less than 2004.10.21.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Windows NT\Accessories\mswrd632.wpc</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2004</major>
					<minor>10</minor>
					<build>21</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-327" check="at least one" comment="the version of lsasrv.dll is less than 5.1.2600.2525" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>2525</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-328" check="at least one" comment="the version of lsasrv.dll is less than 5.0.2195.6987" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6987</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-329" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>780</build>
					<private>1</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-33" check="at least one" comment="the version of h32fltr.dll is less than 3.0.1200.291" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fpc\InstallDirectory</component>
					<component type="literal">h323fltr.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>0</minor>
					<build>1200</build>
					<private>291</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-330" check="at least one" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\msw3prt.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5807</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-331" check="at least one" comment="File %windir%\System32\code.asp is less than 4.0.1381.279" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\code.asp</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>279</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-332" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 5.0.2195.6672" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>5</minor>
					<build>2195</build>
					<private>6672</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-333" check="at least one" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3931" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\nsiislog.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>1</minor>
					<build>0</build>
					<private>3931</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-334" check="at least one" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3932" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\nsiislog.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>1</minor>
					<build>0</build>
					<private>3932</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-335" check="at least one" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3861" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\nsiislog.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>1</minor>
					<build>0</build>
					<private>3861</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-336" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1125</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-337" check="at least one" comment="File %windir%\system\vserver.vxd version is less than 4.10.2001" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system\vserver.vxd</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>10</minor>
					<build>2001</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-338" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 4.2.764.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>764</build>
					<private>1</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-339" check="at least one" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.3649" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\msw3prt.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>3649</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-34" check="at least one" comment="the version of exprox.dll is less than 6.5.6980.57" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Setup\Services</component>
					<component type="literal">\bin\exprox.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>5</minor>
					<build>6980</build>
					<private>57</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-340" check="at least one" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.2956" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Msw3prt.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>2956</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-341" check="at least one" comment="the version of CrystalDecisions.Web.dll is less than 9.1.9800.9" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Crystal Decisions\1.1\Managed\CrystalDecisions.Web.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>1</minor>
					<build>9800</build>
					<private>9</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-342" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6902" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6902</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-343" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7265" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7265</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-344" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33563" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33563</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-345" check="at least one" comment="The version of Ipnathlp.dll is less than 5.0.2195.6902" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Ipnathlp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6902</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-346" check="at least one" comment="The version of Ipnathlp.dll is less than 5.1.2600.137" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ipnathlp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>137</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-347" check="at least one" comment="The version of Ipnathlp.dll is less than 5.1.2600.1364" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ipnathlp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1364</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-348" check="at least one" comment="The version of ipnathlp.dll is less than 5.2.3790.142" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ipnathlp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>142</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-349" check="at least one" comment="the version of lsasrv.dll is less than 5.1.2600.1597" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1597</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-35" check="at least one" comment="the version of sqlsrv32.dll is less than 3.70.11.46" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sqlsrv32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>70</minor>
					<build>11</build>
					<private>46</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-350" check="at least one" comment="the version of wins.exe is less than 5.2.3790.239" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>239</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-351" check="at least one" comment="the version of user32.dll is less than 4.0.1381.7342" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7342</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-352" check="at least one" comment="the version of user32.dll is less than 4.0.1381.33630" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33630</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-353" check="at least one" comment="the version of user32.dll is less than 5.0.2195.7017" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7017</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-354" check="at least one" comment="the version of user32.dll is less than 5.1.2600.1617" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1617</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-355" check="at least one" comment="the version of user32.dll is less than 5.2.3790.245" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>245</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-356" check="all" comment="Indexing Service ciodm.dll is less than 5.2.3790.220" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ciodm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>220</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-357" check="all" comment="Indexing Service ciodm.dll is less than 5.1.2600.1596" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ciodm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1596</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-358" check="at least one" comment="the version of rpcrt4.dll is less than 5.2.3790.76" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>76</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-359" check="at least one" comment="the version of rpcrt4.dll is less than 5.1.2600.109" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>109</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-36" check="at least one" comment="the version of sqlsrv32.dll is less than 2000.80.747.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sqlsrv32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>747</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-360" check="at least one" comment="the version of dplayx.dll is less than 5.1.2600.148" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>148</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-361" check="at least one" comment="the version of dplayx.dll is less than 5.1.2600.1517" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1517</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-362" check="at least one" comment="the version of dplayx.dll is less than 5.2.3677.144" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3677</build>
					<private>144</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-363" check="at least one" comment="the version of dplayx.dll is less than 5.3.0.903" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>3</minor>
					<build>0</build>
					<private>903</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-364" check="at least one" comment="the version of dplayx.dll is less than 5.2.3790.163 on 64-bit edition" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>163</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-365" check="at least one" comment="the version of dplayx.dll is less than 5.2.3790.163" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>163</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-366" check="at least one" comment="the version of rpcrt4.dll is less than 5.1.2600.1254" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1254</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-368" check="at least one" comment="the version of winword.exe is less than 10.00.6764.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths</component>
					<component type="literal">winword.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>00</minor>
					<build>6764</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-369" check="all" comment="the version of hlink.dll is less than 5.2.3790.227" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hlink.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>227</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-37" check="at least one" comment="the version of sqlsrv32.dll is less than 2000.81.9002.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sqlsrv32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9002</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-370" check="at least one" comment="machine has followed the QFE update path and hlink.dll is less than 5.2.3790.227" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hlink.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>227</private>
				</version>
				<development_class operator="equals">srv03_qfe</development_class>
			</data>
		</file_test>
		<file_test id="wft-371" check="at least one" comment="machine has followed the GDR update path and hlink.dll is less than 5.2.3790.225" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hlink.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>225</private>
				</version>
				<development_class operator="not equal">srv03_qfe</development_class>
			</data>
		</file_test>
		<file_test id="wft-372" check="at least one" comment="the version of srvsvc.dll is less than 5.1.2600.1613" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\srvsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1613</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-373" check="at least one" comment="the version of srvsvc.dll is less than 5.1.2600.2577" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\srvsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>2577</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-374" check="at least one" comment="the version of wmp.dll is les than 9.0.0.3250" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wmp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>3250</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-375" check="all" comment="the version of dhtmled.ocx is less than 6.1.0.9232" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\microsoft shared\triedit\dhtmled.ocx</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>1</minor>
					<build>0</build>
					<private>9232</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-376" check="all" comment="the version of dhtmled.ocx is less than 6.1.0.9231" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\microsoft shared\triedit\dhtmled.ocx</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>1</minor>
					<build>0</build>
					<private>9231</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-377" check="at least one" comment="the version of mso.dll is less than 10.0.6735.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\OFFICE10\MSO.DLL</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>6735</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-378" check="all" comment="the version of wdhtmled.ocx is less than 6.1.0.9231" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\microsoft shared\triedit\wdhtmled.ocx</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>1</minor>
					<build>0</build>
					<private>9231</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-38" check="at least one" comment="the version of sqlsrv32.dll is less than 2000.81.9042.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sqlsrv32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9042</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-380" check="at least one" comment="the version of mrxsmb.sys is less than 5.1.2600.2598" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\mrxsmb.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>2598</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-381" check="at least one" comment="the version of mrxsmb.sys is less than 5.2.3790.252" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\mrxsmb.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>252</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-382" check="at least one" comment="the version of mrxsmb.sys is less than 5.1.2600.1620" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\mrxsmb.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1620</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-383" check="all" comment="the version of wdhtmled.ocx is less than 6.1.0.9232" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\microsoft shared\triedit\wdhtmled.ocx</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>1</minor>
					<build>0</build>
					<private>9232</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-385" check="at least one" comment="the version of mrxsmb.sys is less than 5.0.2195.7023" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\mrxsmb.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7023</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-386" check="at least one" comment="the version of ole32.dll is less than 5.0.2195.7021" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ole32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7021</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-387" check="at least one" comment="the version of ole32.dll is less than 5.1.2600.1619" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ole32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1619</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-388" check="at least one" comment="the version of ole32.dll is less than 5.1.2600.2595" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ole32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>2595</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-389" check="at least one" comment="the version of ole32.dll is less than 5.2.3790.250" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ole32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>250</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-39" check="at least one" comment="the version of sqlsrv32.dll is less than 2000.85.1025.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sqlsrv32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>85</minor>
					<build>1025</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-390" check="at least one" comment="the version of hhctrl.ocx is less than 5.2.3790.233" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hhctrl.ocx</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>233</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-391" check="at least one" comment="the version of hhctrl.ocx is less than 5.2.3790.1280" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hhctrl.ocx</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>1280</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-392" check="at least one" comment="the version of Llssrv.exe is less than 4.0.1381.7345" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\llssrv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7345</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-393" check="at least one" comment="the version of Llssrv.exe is less than 4.0.1381.33632" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\llssrv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33632</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-394" check="at least one" comment="the version of Llssrv.exe is less than 5.0.2195.7021" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\llssrv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7021</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-395" check="at least one" comment="the version of Llssrv.exe is less than 5.2.3790.242" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\llssrv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>242</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-396" check="at least one" comment="the version of mscms.dll is less than 5.0.2195.7054" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mscms.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7054</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-397" check="at least one" comment="the version of System.web.dll is less than 1.0.3705.6021" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\Microsoft.NET\Framework\System.web.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>0</minor>
					<build>3705</build>
					<private>6021</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-4" check="at least one" comment="the version of hh.exe is less than 5.2.3790.309" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\hh.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>309</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-40" check="at least one" comment="the version of odbcbcp.dll is less than 3.70.11.46" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>70</minor>
					<build>11</build>
					<private>46</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-400" check="at least one" comment="the version of shell32.dll is less than 5.0.3900.7009" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3900</build>
					<private>7009</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-401" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.241" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>241</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-403" check="all" comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1491" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1491</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-404" check="all" comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1492" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1492</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-405" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.259" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>259</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-406" check="at least one" comment="the version of mshtml.dll is less than 5.0.3528.700" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3528</build>
					<private>700</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-407" check="at least one" comment="the version of mshtml.dll is less than 5.0.3825.700" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3825</build>
					<private>700</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-409" check="at least one" comment="the version of mscms.dll is less than 5.1.2600.2709" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mscms.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>2709</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-41" check="at least one" comment="the version of odbcbcp.dll is less than 2000.80.747.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>747</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-410" check="all" comment="the version of msmsgs.exe is less than 5.1.0.639" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">Program Files\Messengermsmsgs.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>0</build>
					<private>639</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-411" check="at least one" comment="the version of mscms.dll is less than 5.1.2600.1710" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mscms.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1710</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-414" check="at least one" comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7064" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\tcpcfg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7064</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-415" check="at least one" comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7097" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\tcpcfg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7097</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-416" check="at least one" comment="File %windir%\system32\winlogon.exe version is less than 4.0.1381.7058" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\winlogon.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7058</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-417" check="at least one" comment="File %ExchangeInstallDir%\bin\mad.exe is less than 6.0.5770.21" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Setup\Services</component>
					<component type="literal">\bin\mad.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>5</minor>
					<build>5700</build>
					<private>21</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-418" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.650.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlservr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>650</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-419" check="at least one" comment="the version of odsole70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\odsole70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-42" check="at least one" comment="the version of odbcbcp.dll is less than 2000.81.9002.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9002</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-420" check="at least one" comment="the version of xpstar.dll is less than 2000.80.628.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xpstar.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>628</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-421" check="at least one" comment="File %windir%\system32\dplayx.dll version is less than 5.0.2195.6927" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6927</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-422" check="at least one" comment="File %windir%\system32\dplayx.dll version is less than 5.0.2258.410" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2258</build>
					<private>410</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-423" check="at least one" comment="File %windir%\system32\dplayx.dll version is less than 5.1.2600.891" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>891</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-424" check="at least one" comment="File %windir%\system32\dplayx.dll version is less than 5.2.3677.144" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3677</build>
					<private>144</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-425" check="at least one" comment="File %windir%\system32\dplayx.dll version is less than 5.3.0.903" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>3</minor>
					<build>0</build>
					<private>903</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-426" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.636.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlservr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>636</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-427" check="at least one" comment="the version of ssnetlib.dll is less than 2000.80.636.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\ssnetlib.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>636</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-428" check="at least one" comment="the version of xpqueue.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xpqueue.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-429" check="at least one" comment="the version of xprepl.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xprepl.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-43" check="at least one" comment="the version of odbcbcp.dll is less than 2000.81.9042.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9042</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-430" check="at least one" comment="the version of xplog70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xplog70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-431" check="at least one" comment="the version of xpweb70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xpweb70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-432" check="at least one" comment="the version of crypt32.dll is less than 5.131.2600.1123" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\crypt32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>2600</build>
					<private>1123</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-433" check="at least one" comment="the version of cryptdlg.dll is less than 5.0.1558.6608" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cryptdlg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>1558</build>
					<private>6608</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-434" check="at least one" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cryptdlg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>1558</build>
					<private>6072</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-435" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6159" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6159</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-436" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7203</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-437" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33545" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33545</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-438" check="at least one" comment="the version of System.web.dll is less than 1.0.3705.556" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\Microsoft.NET\Framework\System.web.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>0</minor>
					<build>3705</build>
					<private>556</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-439" check="at least one" comment="the version of Sp3res.dll is less than 5.0.2195.6928" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Sp3res.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6928</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-44" check="at least one" comment="the version of odbcbcp.dll is less than 2000.85.1025.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>85</minor>
					<build>1025</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-440" check="at least one" comment="the version of psxss.exe is less than 4.0.1381.33567" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\psxss.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33567</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-441" check="at least one" comment="the version of psxss.exe is less than 5.0.2195.6929" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\psxss.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6929</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-442" check="at least one" comment="the version of Umandlg.dll is less than 1.0.0.5" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Umandlg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>0</minor>
					<build>0</build>
					<private>5</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-443" check="at least one" comment="the version of psxss.exe is less than 4.0.1381.7269" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\psxss.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7269</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-444" check="at least one" comment="the version of itss.dll is less than 5.2.3790.185" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\itss.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>185</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-445" check="at least one" comment="the version of mstask.dll is less than 4.71.2195.6920" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mstask.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>71</minor>
					<build>2195</build>
					<private>6920</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-446" check="at least one" comment="the version of w3svc.dll is less than 4.2.788.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\w3svc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>788</build>
					<private>1</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-447" check="at least one" comment="the version of shell32.dll is less than 5.0.3900.6922" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3900</build>
					<private>6922</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-448" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.168" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>168</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-449" check="at least one" comment="the version of shell32.dll is less than 6.0.2800.1517" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1517</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-45" check="at least one" comment="the version of msgsc.dll is greater than 6.0.0.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\MSN Messenger\msgsc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="greater than">
					<major>6</major>
					<minor>0</minor>
					<build>0</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-450" check="at least one" comment="the version of shell32.dll is less than 6.0.2800.1556" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1556</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-451" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.163" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>163</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-452" check="at least one" comment="the version of shell32.dll is less than 4.72.3841.1100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>72</minor>
					<build>3841</build>
					<private>1100</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-453" check="at least one" comment="the version of mstask.dll is less than 5.1.2600.155" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mstask.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>155</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-454" check="at least one" comment="the version of mstask.dll is less than 5.1.2600.1564" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mstask.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1564</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-455" check="at least one" comment="the version of mstask.dll is less than 5.1.2600.1555" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mstask.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1555</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-456" check="at least one" comment="the version of System.web.dll is less than 1.1.4322.1085" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\Microsoft.NET\Framework\System.web.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>1</minor>
					<build>4322</build>
					<private>1085</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-457" check="at least one" comment="the version of mstask.dll is less than 4.71.1979.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mstask.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>71</minor>
					<build>1979</build>
					<private>1</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-458" check="at least one" comment="the version of shell32.dll is less than 6.0.2800.1233 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1233</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-459" check="at least one" comment="the version of shell32.dll is less than 6.0.2600.115 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2600</build>
					<private>115</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-46" check="at least one" comment="the version of nscm.exe is less than 4.1.0.3934" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Windows Media\Server\nscm.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>1</minor>
					<build>0</build>
					<private>3934</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-460" check="at least one" comment="the version of System.web.dll is less than 1.1.4322.2037" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\Microsoft.NET\Framework\System.web.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>1</minor>
					<build>4322</build>
					<private>2037</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-461" check="at least one" comment="the version of inetcomm.dll is less than 6.0.2742.200" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2742</build>
					<private>200</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-462" check="at least one" comment="machine has followed the GDR update path and inetcomm.dll is less than 6.0.3790.181" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>181</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-463" check="at least one" comment="the version of netbt.sys is less than 5.1.2600.117" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\netbt.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>117</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-464" check="at least one" comment="the version of netbt.sys is less than 5.1.2600.1243" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\netbt.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1243</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-465" check="at least one" comment="File %windir%system32DriversSRV.SYS is less than 5.1.2600.112" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Drivers\SRV.SYS</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>112</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-466" check="at least one" comment="File %windir%system32DriversSRV.SYS is less than 5.1.2600.1193" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Drivers\SRV.SYS</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1193</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-467" check="at least one" comment="the version of inetcomm.dll is less than 6.0.2800.1441" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1441</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-468" check="at least one" comment="machine has followed the QFE update path and inetcomm.dll is less than 6.0.3790.185" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>185</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-469" check="at least one" comment="the version of inetcomm.dll is less than 5.50.4942.400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4942</build>
					<private>400</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-47" check="at least one" comment="the version of nspmon.exe is less than 4.1.0.3934" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Windows Media\Server\nspmon.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>1</minor>
					<build>0</build>
					<private>3934</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-470" check="at least one" comment="the version of winword.exe is less than 9.0.0.7924" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">winword.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>7924</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-471" check="at least one" comment="the version of shell32.dll is less than 4.0.1381.7267" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7267</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-474" check="at least one" comment="the version of user32.dll is less than 4.0.1381.7177" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7177</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-475" check="at least one" comment="the version of gdi32.dll is less than 4.0.1381.7177" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\gdi32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7177</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-476" check="at least one" comment="the version of winsrv.dll is less than 4.0.1381.7202" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\winsrv.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7202</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-477" check="at least one" comment="the version of win32k.sys is less than 4.0.1381.7207" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\win32k.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7207</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-478" check="at least one" comment="the version of winword.exe is less than 9.0.0.6926" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">winword.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>6926</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-48" check="all" comment="the version of telnet.exe is less than 8.0.1969.33" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\telnet.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>1969</build>
					<private>33</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-480" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1151" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path>
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version>
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1151</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-481" check="at least one" comment="the version of msadco.dll is less than 2.62.9119.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\System\msadc\msadco.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2</major>
					<minor>62</minor>
					<build>9119</build>
					<private>1</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-482" check="at least one" comment="the version of msadco.dll is less than 2.53.6202.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\System\msadc\msadco.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2</major>
					<minor>53</minor>
					<build>6202</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-483" check="at least one" comment="the version of msadco.dll is less than 2.12.5118.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\System\msadc\msadco.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2</major>
					<minor>12</minor>
					<build>5118</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-484" check="at least one" comment="the version of msohev.dll less than 10.0.2609.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\10.0\Common\InstallRoot\Path</component>
					<component type="literal">msohev.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>2609</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-485" check="at least one" comment="the version of cdo.dll is less than 5.5.2558.10" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cdo.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>5</minor>
					<build>2558</build>
					<private>10</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-486" check="at least one" comment="the version of winword.exe is less than 9.0.0.6328" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">winword.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>6328</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-489" check="at least one" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\TextConv\MSCONV97.DLL</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2003</major>
					<minor>1100</minor>
					<build>6252</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-49" check="at least one" comment="the version of msasn1.dll is less than 5.0.2195.6823" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6823</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-490" check="at least one" comment="the version of shell32.dll is less than 4.0.1381.7116" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7116</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-491" check="at least one" comment="the version of sqlisapi.dll is less than 2000.80.309.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System\Ole DB folder\sqlisapi.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>309</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-492" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.760.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlservr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>760</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-493" check="at least one" comment="the version of sxs.dll is less than 5.2.3790.121" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sxs.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>121</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-494" check="at least one" comment="the version of sxs.dll is less than 5.1.2600.1363" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sxs.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1363</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-495" check="at least one" comment="the version of gdiplus.dll is less than 6.0.3264.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\OFFICE11\GDIPLUS.DLL</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3264</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-496" check="at least one" comment="the version of mso.dll is less than 10.0.6714.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\OFFICE11\MSO.DLL</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>6714</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-499" check="at least one" comment="the version of shell32.dll is less than 5.0.3900.6970" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3900</build>
					<private>6970</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-5" check="all" comment="the version of telnet.exe is less than 5.3000.2073.13" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\telnet.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>3000</minor>
					<build>2073</build>
					<private>13</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-50" check="at least one" comment="the version of dbmslpcn.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dbmslpcn.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-500" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2604" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2900</build>
					<private>2604</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-501" check="at least one" comment="the version of httpext.dll is less than 5.0.2195.6958" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\httpext.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6958</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-502" check="at least one" comment="The version of smtpsvc.dll is less than 6.0.3790.211" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\smtpsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>211</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-503" check="at least one" comment="the version of httpext.dll is less than 6.0.2600.165" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\httpext.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2600</build>
					<private>165</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-504" check="at least one" comment="the version of httpext.dll is less than 6.0.2600.1579" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\httpext.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2600</build>
					<private>1579</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-505" check="at least one" comment="the version of vdmdbg.dll is less than 5.0.2195.6946" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\vdmdbg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6946</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-506" check="at least one" comment="the version of nntpsvc.dll is less than 6.0.3790.206" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nntpsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>206</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-507" check="at least one" comment="the version of gdi32.dll is less than 5.0.2195.6945" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\gdi32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6945</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-508" check="at least one" comment="the version of win32k.sys is less than 5.2.3790.198" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\win32k.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>198</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-509" check="at least one" comment="the version of shell32.dll (WOW64) is less than 6.0.2800.1580" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>9</minor>
					<build>2800</build>
					<private>1580</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-51" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlservr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-510" check="at least one" comment="the version of shell32.dll is less than 6.0.2800.1580" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1580</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-511" check="at least one" comment="the version of gdi32.dll is less than 4.0.1381.33566" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\gdi32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33566</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-512" check="at least one" comment="the version of gdi32.dll is less than 4.0.1381.7270" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\gdi32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7270</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-514" check="at least one" comment="the version of shell32.dll is less than 6.0.2750.166" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2750</build>
					<private>166</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-515" check="at least one" comment="the version of httpext.dll is less than 6.0.3790.212" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\httpext.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>212</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-516" check="at least one" comment="the version of shell32.dll is less than 4.72.3843.3100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>72</minor>
					<build>3843</build>
					<private>3100</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-517" check="at least one" comment="the version of shell32.dll is less than 4.0.1381.33564" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>3356</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-518" check="at least one" comment="the version of nddenb32.dll is less than 4.0.1381.7268" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\nddenb32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7268</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-519" check="at least one" comment="the version of grpconv.exe (system32) is less than 5.0.2195.6966" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6966</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-52" check="at least one" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\ssmslpcn.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-520" check="at least one" comment="the version of nddenb32.dll is less than 4.0.1381.33565" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\nddenb32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33565</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-521" check="at least one" comment="the version of netdde.exe is less than 4.0.1381.33574" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netdde.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33574</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-522" check="at least one" comment="the version of netdde.exe is less than 4.0.1381.7280" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netdde.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7280</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-523" check="at least one" comment="the version of grpconv.exe (system32) is less than 4.0.1381.7286" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7286</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-524" check="at least one" comment="the version of grpconv.exe (system32) is less than 4.0.1381.33577" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33577</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-525" check="at least one" comment="the version of grpconv.exe (system32) is less than 5.2.3790.205" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>205</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-526" check="at least one" comment="the version of grpconv.exe (syswow64) is less than 5.2.3790.205" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\syswow64\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>205</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-527" check="at least one" comment="the version of netdde.exe is less than 5.0.2195.6952" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netdde.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6952</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-528" check="at least one" comment="the version of nddenb32.dll is less than 5.0.2195.6922" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netdde.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6922</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-529" check="at least one" comment="the version of grpconv.exe is less than 5.1.2600.166" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>166</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-53" check="at least one" comment="the version of ssnetlib.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\ssnetlib.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-530" check="at least one" comment="the version of grpconv.exe is less than 5.1.2600.1580" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1580</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-531" check="at least one" comment="the version of grpconv.exe (syswow64) is less than 5.1.2600.1580" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\syswow64\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1580</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-532" check="at least one" comment="the 32-bit version of zipfldr.dll is less than 6.0.2750.167" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\zipfldr.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2750</build>
					<private>167</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-533" check="at least one" comment="the version of nntpsvc.dll is less than 5.0.2195.6972" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nntpsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6972</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-534" check="at least one" comment="the 32-bit version of zipfldr.dll is less than 6.0.2800.1584" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\zipfldr.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1584</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-535" check="at least one" comment="the version of vdmdbg.dll is less than 5.1.2600.1560" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\vdmdbg.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1560</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-536" check="at least one" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.2800.1584" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\zipfldr.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1584</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-537" check="at least one" comment="the 32-bit version of zipfldr.dll is less than 6.0.3790.198" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\zipfldr.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>198</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-538" check="at least one" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.3790.198" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\zipfldr.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>198</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-539" check="at least one" comment="the version of nntpsvc.dll is less than 5.5.1877.79" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nntpsvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>5</minor>
					<build>1877</build>
					<private>79</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-54" check="at least one" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\ssnmpn70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-540" check="at least one" comment="the version of nddenb32.dll is less than 5.2.3790.173" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nddenb32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>173</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-541" check="at least one" comment="the version of netdde.exe is less than 5.2.3790.184" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\netdde.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>184</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-542" check="at least one" comment="the 64-bit WOW version of nddenb32.dll is less than 5.2.3790.193" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\nddenb32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>193</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-543" check="at least one" comment="the 64-bit WOW version of netdde.exe is less than 5.2.3790.193" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\netdde.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>193</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-544" check="at least one" comment="the version of netdde.exe is less than 5.1.2600.1567" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\netdde.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1567</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-545" check="at least one" comment="the version of nddenb32.dll is less than 5.1.2600.1555" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nddenb32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1555</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-546" check="at least one" comment="the version of nddenb32.dll is less than 5.1.2600.149" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nddenb32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>149</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-547" check="at least one" comment="the version of netdde.exe is less than 5.1.2600.158" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\netdde.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>158</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-548" check="at least one" comment="the 64-bit WOW version of netdde.exe is less than 5.1.2600.1567" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\netdde.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1567</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-549" check="at least one" comment="the 64-bit WOW version of nddenb32.dll is less than 5.1.2600.1555" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\nddenb32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1555</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-55" check="at least one" comment="the version of msgprox.dll is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode</component>
					<component type="literal">msgprox.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-550" check="at least one" comment="machine has followed the GDR update path and mshtml.dll is less than  6.0.2900.2523 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2900</build>
					<private>2523</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-551" check="at least one" comment="machine has followed the QFE update path and mshtml.dll is less than  6.0.2900.2524 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2900</build>
					<private>2524</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-552" check="at least one" comment="the version of rpcrt4.dll is less than 4.0.1381.7299" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7299</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-558" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.219" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>219</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-559" check="at least one" comment="the version of rpcrt4.dll is less than 4.0.1381.33578" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33578</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-56" check="at least one" comment="the version of replrec.dll is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode</component>
					<component type="literal">replrec.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-560" check="at least one" comment="the version of mshtml.dll is less than 5.0.3821.2800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3821</build>
					<private>2800</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-561" check="at least one" comment="the version of mshtml.dll is less than 5.0.3534.2800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3534</build>
					<private>2800</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-562" check="at least one" comment="the version of mshtml.dll is less than 5.5.4945.2800 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>4945</build>
					<private>2800</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-563" check="at least one" comment="the version of mshtml.dll is less than 6.0.2745.2800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2745</build>
					<private>2800</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-564" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1476   " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2745</build>
					<private>2800</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-566" check="at least one" comment="The version of srv.sys is less than 4.0.1381.7214" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Drivers\SRV.SYS</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7214</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-567" check="at least one" comment="the version of rpcss.dll is less than 4.0.1381.7203" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7224</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-568" check="at least one" comment="the version of rpcss.dll is less than 5.0.2195.6810" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6810</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-569" check="at least one" comment="the version of quartz.dll is less than 6.1.5.132" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\quartz.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>1</minor>
					<build>5</build>
					<private>132</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-57" check="at least one" comment="the version of sqlvdi.dll is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode</component>
					<component type="literal">sqlvdi.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-570" check="at least one" comment="the version of kernel32.dll is less than 5.0.2195.6011" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\kernel32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6011</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-571" check="at least one" comment="the version of winword.exe is less than 9.0.0.8930" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">winword.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>8930</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-572" check="at least one" comment="the version of mscms.dll is less than 5.2.3790.359" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mscms.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>359</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-573" check="at least one" comment="the version of mscms.dll is less than 5.2.3790.2476" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mscms.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>2476</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-575" check="at least one" comment="the version of xlsasink.dll is less than 6.5.6981.3" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Setup\Services</component>
					<component type="literal">\bin\xlsasink.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>5</minor>
					<build>6981</build>
					<private>3</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-576" check="at least one" comment="the version of mqrt.dll is less than 5.0.0.799" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mqrt.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>0</build>
					<private>799</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-577" check="at least one" comment="the version of mqrt.dll is less than 5.1.0.1044" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mqrt.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>0</build>
					<private>1044</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-579" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7035</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-58" check="at least one" comment="the version of impprov.dll is less than 2000.80.650.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\impprov.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>650</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-580" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1634" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1634</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-581" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>2622</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-583" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>280</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-588" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.280" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>280</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-589" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.274" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>274</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-59" check="at least one" comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dbmsrpcn.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>213</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-590" check="at least one" comment="the version of shell32.dll is less than 6.0.2800.1643" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1643</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-591" check="at least one" comment="the version of shell32.dll is less than 6.0.2900.2620" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2900</build>
					<private>2620</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-592" check="at least one" comment="the version of shell32.dll is less than 5.0.3900.7032" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3900</build>
					<private>7032</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-593" check="at least one" comment="the version of Tcpip.sys is less than 5.0.2195.7035" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\tcpip.sys</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7035</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-594" check="at least one" comment="the version of mshtml.dll is less than 6.00.3790.279" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>279</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-595" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2627" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2900</build>
					<private>2627</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-596" check="all" comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1498</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-597" check="all" comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1499</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-598" check="at least one" comment="the version of mshtml.dll is less than 5.0.3539.2400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3539</build>
					<private>2400</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-599" check="at least one" comment="the version of mshtml.dll is less than 5.0.3826.2400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3826</build>
					<private>2400</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-6" check="at least one" comment="the version of msphlpr.dll is less than 3.0.1200.408" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">Program Files\Microsoft ISA Server\msphlpr.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>0</minor>
					<build>1200</build>
					<private>408</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-60" check="at least one" comment="the version of xpweb70.dll is less than 2000.80.778.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xpweb70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>778</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-603" check="all" comment="Adobe Acrobat Reader eBook.api plug-in software installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Acrobat Reader\6.0\Installer\Path</component>
					<component type="literal">Reader\plug_ins\eBook.api</component>
				</path>
			</object>
		</file_test>
		<file_test id="wft-61" check="at least one" comment="File msgprox.dll version3 is less than 765" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\msgprox.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-613" check="at least one" comment="the version of webvw.dll is less than 5.0.3900.7036" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\webvw.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3900</build>
					<private>7036</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-62" check="at least one" comment="the version of replprov.dll is less than 2000.80.798.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode</component>
					<component type="literal">replprov.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>798</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-63" check="at least one" comment="File replrec.dll version3 is less than 765" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\replrec.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-64" check="at least one" comment="File sqlvdi.dll version3 is less than 765" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlvdi.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-65" check="at least one" comment="the version of xpqueue.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xpqueue.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-66" check="at least one" comment="the version of xprepl.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xprepl.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-67" check="at least one" comment="the version of xplog70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xplog70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-68" check="at least one" comment="the version of xpweb70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xpweb70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-69" check="at least one" comment="the version of xpstar.dll is less than 2000.80.628.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xpstar.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>628</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-7" check="at least one" comment="the version of w3proxy.dll is less than 2.0.390.16" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">InetPub\scripts\proxy\w3proxy.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2</major>
					<minor>0</minor>
					<build>390</build>
					<private>16</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-70" check="at least one" comment="File console.exe version3 is less than 818" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\console.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-71" check="at least one" comment="File dbmslpcn.dll version3 is less than 818" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dbmslpcn.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-72" check="at least one" comment="File sqlmap70.dll version3 is less than 811" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlmap70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>811</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-73" check="at least one" comment="File sqlrepss.dll version3 is less than 765" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlrepss.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-74" check="all" comment="the version of telnet.exe is less than 5.2.3790.2442" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\telnet.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>2442</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-75" check="all" comment="the version of telnet.exe is less than 5.2.3790.329" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\telnet.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>329</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-76" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.1.2600.160" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>160</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-77" check="all" comment="the version of telnet.exe is less than 5.1.2600.1684" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\telnet.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1684</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-78" check="at least one" comment="the version of ums.dll is less than 2000.80.816.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\ums.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>816</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-79" check="at least one" comment="the version of odsole70.dll is less than 2000.80.800.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\odsole70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>800</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-8" check="at least one" comment="the version of wkssvc.dll is less than 5.00.2195.6862" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wkssvc.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>00</minor>
					<build>2195</build>
					<private>6862</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-81" check="at least one" comment="the version of w3proxy.exe is less than 3.0.1200.430" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server\</component>
					<component type="literal">\w3proxy.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>0</minor>
					<build>1200</build>
					<private>430</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-85" check="at least one" comment="File odsole70.dll Version3 is less than 223" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\odsole70.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>223</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-86" check="at least one" comment="File xpqueue.dll Version3 is less than 223" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xpqueue.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>223</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-87" check="at least one" comment="File xprepl.dll Version3 is less than 223" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xprepl.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>223</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-88" check="at least one" comment="File xpstar.dll Version3 is less than 223" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\xpstar.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>223</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-89" check="at least one" comment="File sqlservr.exe version3 greater than or equal to 384" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">\sqlservr.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="greater than or equal">
					<major>2000</major>
					<minor>80</minor>
					<build>384</build>
					<private>0</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-9" check="at least one" comment="the version of hh.exe is less than 5.2.3790.315" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\hh.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>315</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-90" check="at least one" comment="the version of mshtml.dll is less than 5.00.3526.800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3526</build>
					<private>800</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-91" check="at least one" comment="the version of mshtml.dll is less than 5.00.3813.800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3813</build>
					<private>800</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-92" check="at least one" comment="the version of mshtml.dll is less than 5.50.4937.800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4937</build>
					<private>800</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-93" check="at least one" comment="the version of mshtml.dll is less than 6.00.2737.800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2737</build>
					<private>800</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-94" check="at least one" comment="the version of mshtml.dll is less than 6.00.2800.1400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1400</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-95" check="at least one" comment="the version of mshtml.dll is less than 6.00.3790.118" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>118</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-96" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.327" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>327</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-97" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.2440" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>2440</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-98" check="at least one" comment="the version of wins.exe is less than 5.0.2195.6870" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6870</private>
				</version>
			</data>
		</file_test>
		<file_test id="wft-99" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2668" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
			</object>
			<data operation="AND">
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2900</build>
					<private>2668</private>
				</version>
			</data>
		</file_test>
		<metabase_test id="wmt-2" check="at least one" comment="SmartHTML interpreter is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<key>LM\W3SVC</key>
				<id datatype="int">6014</id>
			</object>
			<data operation="AND"/>
		</metabase_test>
		<metabase_test id="wmt-201" check="at least one" comment="asp.dll mapping exists" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<key operator="equals">LM\W3SVC</key>
				<id datatype="int" operator="equals">6014</id>
			</object>
			<data operation="AND">
				<data operator="pattern match">^.*asp\.dll.*$</data>
			</data>
		</metabase_test>
		<metabase_test id="wmt-202" check="at least one" comment="FTP Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<key operator="pattern match">^LM\\MSFTPSVC\\.*$</key>
				<id datatype="int" operator="equals">1016</id>
			</object>
			<data operation="AND">
				<data datatype="int" operator="not equal">4</data>
			</data>
		</metabase_test>
		<metabase_test id="wmt-203" check="at least one" comment="ism.dll mapping exists" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<key operator="equals">LM\W3SVC</key>
				<id datatype="int" operator="equals">6014</id>
			</object>
			<data operation="AND">
				<data operator="pattern match">^.*ism\.dll.*$</data>
			</data>
		</metabase_test>
		<metabase_test id="wmt-205" check="at least one" comment="idq.dll mapping exists" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<key operator="equals">LM\W3SVC</key>
				<id datatype="int" operator="equals">6014</id>
			</object>
			<data operation="AND">
				<data operator="pattern match">^.*idq\.dll.*$</data>
			</data>
		</metabase_test>
		<metabase_test id="wmt-206" check="at least one" comment="Negotiate is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<key>LM\W3SVC</key>
				<id datatype="int">6032</id>
			</object>
			<data operation="AND"/>
		</metabase_test>
		<metabase_test id="wmt-207" check="at least one" comment="Permanent redirects enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<key operator="pattern match">LM\\W3SVC\\/d*\\ROOT</key>
				<id datatype="int">6011</id>
			</object>
			<data operation="AND">
				<name>HttpRedirect</name>
				<data operator="pattern match">^http:*,PERMANENT,*</data>
			</data>
		</metabase_test>
		<metabase_test id="wmt-5" check="at least one" comment="SSL is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<key operator="pattern match">^LM\\W3SVC\\.*$</key>
				<id datatype="int" operator="equals">5506</id>
			</object>
		</metabase_test>
		<registry_test id="wrt-1" check="at least one" comment="Windows 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CurrentVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-10" check="at least one" comment="the patch kb840374 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840374</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-100" check="at least one" comment="MDAC 2.5 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^2\.5.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-101" check="at least one" comment="MDAC 2.6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^2\.6.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-102" check="at least one" comment="MDAC 2.7 (RTM) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^2\.70.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-103" check="at least one" comment="MDAC 2.7 (SP1) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^2\.71.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-104" check="at least one" comment="MDAC 2.8 (RTM) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^2\.8.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-105" check="at least one" comment="ISA Server 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server</key>
				<name>VersionMajor</name>
			</object>
			<data operation="AND">
				<value operator="equals">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-106" check="at least one" comment="HTTP connection reuse is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\MSExchangeWEB\DAV</key>
				<name>ReuseConnections</name>
			</object>
			<data operation="AND">
				<value operator="equals">0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-107" check="at least one" comment="Microsoft Firewall Service is not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\Fwsrv</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-108" check="at least one" comment="H.323 filter is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Fpc\\Arrays\\\{[^\\]+\}\\Extensions\\Proxy-Plugins\\\{FE440D49-AB26-11D2-A101-00C04FB6CFB6\}$</key>
				<name>msFPCEnabled</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-109" check="at least one" comment="the patch KB832759 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Exchange Server 2003\SP1\832759</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-11" check="at least one" comment="ISA Server 2000 SP2 (or earlier) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server SP</key>
				<name operator="equals">DisplayName</name>
			</object>
			<data operation="AND">
				<value operator="equals">Microsoft ISA Server 2000 Updates</value>
			</data>
		</registry_test>
		<registry_test id="wrt-110" check="at least one" comment="the patch q832483 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\DataAccess\Q832483</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-111" check="at least one" comment="the patch q832483 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB832483</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-112" check="at least one" comment="the patch q816458 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\291</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-113" check="all" comment="Exchange Server 2003 (gold edition) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Exchange\Setup</key>
				<name>Services Version</name>
			</object>
			<data>
				<value operator="equals">65</value>
			</data>
		</registry_test>
		<registry_test id="wrt-116" check="all" comment="Is the .NET Framework 1.0 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\.NETFramework\policy\v1.0</key>
				<name operator="equals"/>
			</object>
		</registry_test>
		<registry_test id="wrt-117" check="all" comment="Is the .NET Framework 1.1 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\.NETFramework\policy\v1.1</key>
				<name operator="equals"/>
			</object>
		</registry_test>
		<registry_test id="wrt-118" check="all" comment="Is Service Pack 1 for .NET Framework 1.1 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals"/>
				<name operator="equals">Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">1,0,4322,0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-12" check="at least one" comment="the HCP Protocol is registered" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CLASSES_ROOT</hive>
				<key operator="equals">HCP</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-120" check="at least one" comment="ActiveX controls are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1200</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-121" check="at least one" comment="ActiveX controls are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1200</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-122" check="all" comment="Is Service Pack 2 for .NET Framework 1.0 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">\SOFTWARE\Microsoft\Active Setup\Installed Components\{78705f0d-e8db-4b2d-8193-982bdda15ecd}</key>
				<name operator="equals">Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">1,0,3705,2</value>
			</data>
		</registry_test>
		<registry_test id="wrt-123" check="all" comment="Is Service Pack 3 for .NET Framework 1.0 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{78705f0d-e8db-4b2d-8193-982bdda15ecd}</key>
				<name operator="equals">Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">1,0,3705,3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-124" check="at least one" comment="the patch kb896426 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896426</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-125" check="at least one" comment="active scripting is enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1400</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-126" check="at least one" comment="active scripting is enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1400</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-128" check="at least one" comment="the patch KB901214 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB901214</key>
				<name operator="equals">IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-13" check="at least one" comment="the patch KB888258 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\408</key>
				<name operator="equals">Kbs</name>
			</object>
			<data operation="AND">
				<value operator="equals">KB888258</value>
			</data>
		</registry_test>
		<registry_test id="wrt-132" check="at least one" comment="Word 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Office\9.0\Word\InstallRoot</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-133" check="at least one" comment="Word 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Office\10.0\Word\InstallRoot</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-137" check="at least one" comment="Excel 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Office\9.0\Excel\InstallRoot</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-138" check="at least one" comment="Excel 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Office\10.0\Excel\InstallRoot</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-14" check="at least one" comment="the patch KB888258 for Proxy Server 2.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB888258</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-140" check="at least one" comment="the patch q832894 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB832894</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-141" check="at least one" comment="the patch q832894 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{eddbec60-89cb-44ef-8291-0850fd28ff6a}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-143" check="all" comment="Is the KB886903 patch installed for .NET Framework v1.1 sp 1?" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\.NETFramework Setup\1.1\M886903</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-144" check="all" comment="Is the KB886904 patch installed for .NET Framework v1.1 Gold?" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\.NETFramework Setup\1.1\M886904</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-145" check="all" comment="Is the KB886905 patch installed for .NET Framework v1.0 sp 2?" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\NET Framework Setup\1.0\M886905</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-146" check="all" comment="Is the KB886906 patch installed for .NET Framework v1.0 sp 3?" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\.NETFramework Setup\1.0\M886906</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-149" check="at least one" comment="the patch kb832359 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows Media Services\KB832359</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-155" check="at least one" comment="the patch kb890047 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB890047 </key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-156" check="at least one" comment="the patch kb834707(wildcard*) is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<oval:notes>
				<oval:note>This will match any KB834707 rather give a list such as KB834707-ie501sp3-20040929.121357,etc</oval:note>
			</oval:notes>
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\ NT\\CurrentVersion\\Hotfix\\[Kk][Bb]834707[-a-zA-Z0-9.]*$</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-157" check="at least one" comment="Drag-and-Drop disabled when set to 3" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\[13]$</key>
				<name datatype="boolean" operator="equals">1802</name>
			</object>
			<data operation="AND">
				<value operator="equals">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-158" check="at least one" comment="the patch kb867282 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB867282\Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-159" check="at least one" comment="the patch kb867282 is installed (XP SP2 Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB867282\Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-160" check="at least one" comment="the Windows Media Station service is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SYSTEM\CurrentControlSet\Services\nsstation</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-161" check="at least one" comment="the Windows Media Monitor service is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows Media Services\KB832359</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-162" check="at least one" comment="Windows Media Services 4.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetShow</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">4.1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-163" check="at least one" comment="the patch kb867282 is installed (XP Win2K Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB867282-ie6sp1-20050127.163319</key>
				<name datatype="int" operator="equals">Installed </name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-164" check="at least one" comment="the patch kb867282 is installed (Win2K SP3  Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB867282-ie501sp3-20050107.164329</key>
				<name datatype="int" operator="equals">Installed </name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-165" check="at least one" comment="PCT support is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server</key>
				<name>Enabled</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-166" check="at least one" comment="the patch kb867282 is installed (Win2K SP4  Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SSOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB867282-ie501sp4-20050107.164742</key>
				<name datatype="int" operator="equals">Installed </name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-167" check="at least one" comment="The patch KB885492 is installed on Windows Server 2003" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows Media Player 9\KB885492</key>
				<name operator="equals">PackageVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">1.1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-168" check="at least one" comment=".asx EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">\SOFTWARE\Classes\.asx</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-169" check="at least one" comment=".wax EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">\SOFTWARE\Classes\.wax</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-17" check="at least one" comment="the software Services for UNIX is installed and the version is 2.2" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Services for UNIX</key>
				<name operator="equals">Current_Release</name>
			</object>
			<data operation="AND">
				<value operator="equals">2.2</value>
			</data>
		</registry_test>
		<registry_test id="wrt-170" check="at least one" comment="Outlook Express 5.5 SP2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
				<name>Current</name>
			</object>
			<data operation="AND">
				<value operator="equals">5,50,4807,1700</value>
			</data>
		</registry_test>
		<registry_test id="wrt-171" check="at least one" comment="Outlook Express 6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
				<name>Current</name>
			</object>
			<data operation="AND">
				<value operator="equals">6,0,2600,0000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-172" check="at least one" comment="Outlook Express 6 for Windows 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
				<name>Current</name>
			</object>
			<data operation="AND">
				<value operator="equals">6,0,3790,0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-173" check="at least one" comment="Outlook Express 6 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
				<name>Current</name>
			</object>
			<data operation="AND">
				<value operator="equals">6,0,2800,1106</value>
			</data>
		</registry_test>
		<registry_test id="wrt-174" check="at least one" comment=".wvx EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">\SOFTWARE\Classes\.wvx</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-175" check="at least one" comment=".wpl EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">\SOFTWARE\Classes\.wpl</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-176" check="at least one" comment=".wmx EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">\SOFTWARE\Classes\.wmx</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-177" check="at least one" comment=".wms EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">\SOFTWARE\Classes\.wms</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-178" check="at least one" comment=".wmz EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">\SOFTWARE\Classes\.wmz</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-179" check="all" comment="Windows Messenger 5.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">\SOFTWARE\Microsoft\CurrentVersion\Uninstall\{C3A6819F-62D3-4750-AF1C-28206DDF2C2E}</key>
				<name operator="equals">Windows Messenger 5.1</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">5.1.0639</value>
			</data>
		</registry_test>
		<registry_test id="wrt-18" check="at least one" comment="Internet Explorer 6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">6.00.2600.0000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-183" check="at least one" comment="MDAC 2.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\DataAccess</key>
				<name operator="equals">FullInstallVer</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^2\.1.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-184" check="at least one" comment="the patch Q890175 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q890175</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-185" check="at least one" comment="the patch kb837001 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB837001</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-186" check="at least one" comment="the patch kb837009 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB837009</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-187" check="at least one" comment="the patch kb835732 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB835732</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-188" check="at least one" comment="the patch kb837009 is installed (installed components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2cc9d512-6db6-4f1c-8979-9a41fae88de0}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-189" check="at least one" comment="the patch kb828741 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828741</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-19" check="at least one" comment="the patch q824145 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{057997dd-71e4-43cc-b161-3f8180691a9e}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-190" check="at least one" comment="downloading of signed ActiveX controls is enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1001</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-191" check="at least one" comment="file downloads are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1803</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-192" check="at least one" comment="persistent cookies that are stored on your computer are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1A02</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-193" check="at least one" comment="per-session cookies (not stored) are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1A03</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-194" check="at least one" comment="per-session cookies (not stored) are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1A03</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-195" check="all" comment="MSN Messenger 6.2.0205 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ABEB838C-A1A7-4C5D-B7E1-8B4314600205}</key>
				<name operator="equals">MSN Messenger 6.2</name>
			</object>
			<data operation="AND">
				<value operator="equals">6.2.0205</value>
			</data>
		</registry_test>
		<registry_test id="wrt-196" check="at least one" comment="machine is a member of a domain" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\Netlogon</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">2</value>
			</data>
		</registry_test>
		<registry_test id="wrt-197" check="at least one" comment="Outlook 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Office\10.0\Outlook\InstallRoot</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-198" check="at least one" comment="the patch kb828040 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
				<name>DisplayVersion</name>
			</object>
			<data operation="AND">
				<value>10.0.4333.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-199" check="at least one" comment="Microsoft Office XP Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
				<name>DisplayVersion</name>
			</object>
			<data operation="AND">
				<value>10.0.6626.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-2" check="at least one" comment="Windows XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CurrentVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-20" check="at least one" comment="the software Services for UNIX is installed and the version is 3.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Services for UNIX</key>
				<name operator="equals">Current_Release</name>
			</object>
			<data operation="AND">
				<value operator="equals">3.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-200" check="at least one" comment="Internet Explorer 6.0 Installed XP SP2" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Internet Explorer</key>
				<name operator="equals">Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">6.0.2900.2180</value>
			</data>
		</registry_test>
		<registry_test id="wrt-202" check="at least one" comment="the patch q316059 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{E81659DF-28E1-4C60-B4B9-00A4BC5FA76D}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-203" check="at least one" comment="the patch q319282 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2D5974C5-5185-4f5b-80B6-28015ACDD74C}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-204" check="at least one" comment="the patch q321232 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{D7B44F3E-77D3-44C5-8E03-4222D9A18B7B}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-205" check="at least one" comment="the patch q323759 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{61E6EAE5-7821-4AC1-9BBD-AED032A8E273}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-206" check="at least one" comment="the patch q328970 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{FF4DD9CD-F25E-425a-8B5C-A2D062781FBB}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-207" check="at least one" comment="the patch q324929 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2757B1D6-0367-4663-877C-93ECC5C01BF6}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-208" check="at least one" comment="the patch q810847 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{C34F4917-ED43-439f-9023-97B0024A2B3B}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-209" check="at least one" comment="the patch q813489 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{F9C174E3-3E87-40bc-AA94-B8974F2B9222}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-21" check="at least one" comment="the software Services for UNIX is installed and the version is 3.5" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Services for UNIX</key>
				<name operator="equals">Current_Release</name>
			</object>
			<data operation="AND">
				<value operator="equals">3.5</value>
			</data>
		</registry_test>
		<registry_test id="wrt-210" check="at least one" comment="the patch q818529 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{f5de1b93-9d38-416b-b09e-aa85a8e84309}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-211" check="at least one" comment="the patch q822925 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{377483c2-e4b4-4ee8-b577-9aed264c8735}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-212" check="at least one" comment="the patch q828750 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{96543d59-497a-4801-a1f3-5936aacaf7b1}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-214" check="at least one" comment="IIS 4.0 Major Version" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\INetStp</key>
				<name>MajorVersion</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-215" check="at least one" comment="IIS minor version equals 0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\INetStp</key>
				<name>MinorVersion</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-217" check="at least one" comment="Patch Q319733 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q319733</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-218" check="at least one" comment="Patch Q327696 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q327696</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-219" check="at least one" comment="Patch Q811114 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q811114</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-22" check="at least one" comment="64-Bit (x64 architecture) version of Windows is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SYSTEM\CurrentControlSet\Control\Session Manager\Environment</key>
				<name operator="equals">PROCESSOR_ARCHITECTURE</name>
			</object>
			<data operation="AND">
				<value operator="equals">x64</value>
			</data>
		</registry_test>
		<registry_test id="wrt-220" check="at least one" comment="Internet Explorer 6.0 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">6.0.2600.0000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-222" check="at least one" comment="SP4 or later Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name operator="equals">CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^Service Pack [4-9]|\d{2,}$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-223" check="at least one" comment="IIS major version equals 5" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\INetStp</key>
				<name>MajorVersion</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">5</value>
			</data>
		</registry_test>
		<registry_test id="wrt-224" check="at least one" comment="Win2K/XP/2003 service pack 3 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^Service Pack [3-9]|\d{2,}$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-225" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.50.4134.0100</value>
			</data>
		</registry_test>
		<registry_test id="wrt-226" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.50.4134.0600</value>
			</data>
		</registry_test>
		<registry_test id="wrt-227" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.50.4522.1800</value>
			</data>
		</registry_test>
		<registry_test id="wrt-229" check="at least one" comment="Patch Q326886 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q326886</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-23" check="at least one" comment="the patch kb889293 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{839117ee-2132-4bae-a56a-42b50204c9b9}</key>
				<name operator="equals">IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-230" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.00.2919.800</value>
			</data>
		</registry_test>
		<registry_test id="wrt-231" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.00.2919.3800</value>
			</data>
		</registry_test>
		<registry_test id="wrt-232" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.00.2919.6307</value>
			</data>
		</registry_test>
		<registry_test id="wrt-233" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.00.2920.0000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-234" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.00.3103.1000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-235" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.00.3105.0106</value>
			</data>
		</registry_test>
		<registry_test id="wrt-236" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.00.3314.2101</value>
			</data>
		</registry_test>
		<registry_test id="wrt-237" check="at least one" comment="the patch kb867801 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB867801</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-238" check="at least one" comment="Patch Q321599 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Windows 2000\SP4\Q321599</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-239" check="at least one" comment="Patch Q313450" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q313450</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-24" check="at least one" comment="the patch kb889293 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB889293</key>
				<name operator="equals">IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-240" check="at least one" comment="SMTP Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SYSTEM\CurrentControlSet\Services\SMTPSVC</key>
				<name operator="equals">Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-241" check="at least one" comment="Patch Q295534 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q295534</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-242" check="at least one" comment="Patch Q301625 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q301625</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-243" check="at least one" comment="Windows NT 4.0 Security Roll-up Package" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q299444</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-245" check="at least one" comment="the patch kb832894 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2298d453-bcae-4519-bf33-1cbf3faf1524}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-246" check="at least one" comment="Patch Q318593 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q318593</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-247" check="at least one" comment="Patch Q269862 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q269862</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-248" check="at least one" comment="Patch Q277873 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q277873</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-249" check="at least one" comment="Patch Q293826 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q293826</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-25" check="at least one" comment="the patch kb885836 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885836</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-250" check="at least one" comment="Win2K/XP/2003 service pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">Service Pack 2</value>
			</data>
		</registry_test>
		<registry_test id="wrt-252" check="at least one" comment="the patch q813489 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{F9C174E3-3E87-40bc-AA94-B8974F2B9222}</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-253" check="at least one" comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q331953</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-254" check="at least one" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB823980</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-256" check="at least one" comment="RAS Phonebook" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Ras\CurrentVersion</key>
				<name>PathName</name>
			</object>
			<data operation="AND">
				<value operator="equals">RASPHONE.PBK</value>
			</data>
		</registry_test>
		<registry_test id="wrt-257" check="at least one" comment="Patch Q318138 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q318138</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-258" check="at least one" comment="RAS Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\RasMan</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-259" check="at least one" comment="Windows 2000 Security Roll-up 1 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\SP2SRP1</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-260" check="at least one" comment="SQL Server 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\MSSQLServer\MSSQLServer\CurrentVersion</key>
				<name>CurrentVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">8.00.194</value>
			</data>
		</registry_test>
		<registry_test id="wrt-261" check="at least one" comment="Mixed Mode Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\MSSQLServer\MSSQLServer</key>
				<name>LoginMode</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">2</value>
			</data>
		</registry_test>
		<registry_test id="wrt-262" check="at least one" comment="Patch Q320206 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q320206</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-263" check="at least one" comment="Patch Q314147 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q314147</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-264" check="at least one" comment="the SNMP service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\SNMP</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-265" check="at least one" comment="Patch Q311967 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q311967</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-266" check="at least one" comment="Patch Q291845 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q291845</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-27" check="at least one" comment="the patch KB896428 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896428</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-270" check="at least one" comment="persistent cookies that are stored on your computer are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1A02</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-271" check="at least one" comment="Gopher Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes</key>
				<name>gopher</name>
			</object>
			<data operation="AND">
				<value operator="equals">gopher://</value>
			</data>
		</registry_test>
		<registry_test id="wrt-272" check="at least one" comment="Patch Q810833 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q810833</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-273" check="at least one" comment="Locator Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\RPCLocator</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-274" check="at least one" comment="the patch q815021 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q815021</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-276" check="at least one" comment="ISA2000-KB816456-x86.exe" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\277</key>
				<name>Kbs</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">816456</value>
			</data>
		</registry_test>
		<registry_test id="wrt-277" check="at least one" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB817606</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-28" check="at least one" comment="Win2K/XP/2003 service pack 4 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^Service Pack [4-9]|\d{2,}$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-280" check="at least one" comment=".hta applications are enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Classes\MIME\Database\Content Type\application/hta</key>
				<name>Extension</name>
			</object>
			<data operation="AND">
				<value operator="equals">.hta</value>
			</data>
		</registry_test>
		<registry_test id="wrt-281" check="at least one" comment="the patch kb824146 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB824146</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-283" check="at least one" comment="DCOM is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Ole</key>
				<name>EnableDCOM</name>
			</object>
			<data operation="AND">
				<value operator="equals">Y</value>
			</data>
		</registry_test>
		<registry_test id="wrt-284" check="at least one" comment="the patch q290108 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{90A2A715-D986-4EAB-8C73-4D06114EF760}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-285" check="at least one" comment="the patch q295106 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{754D29C1-0C97-405F-98D0-21B212CA7FF1}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-286" check="at least one" comment="file downloads are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1803</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-287" check="at least one" comment="Patch Q312895 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q312895</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-288" check="at least one" comment="Patch Q313829 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q313829</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-289" check="at least one" comment="Patch Q321599 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q321599</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-29" check="at least one" comment="Win2K/XP/2003 service pack 2 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^Service Pack [2-9]|\d{2,}$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-293" check="at least one" comment="Patch WindowsXP-KB823182-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB823182</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-294" check="at least one" comment="downloading of signed ActiveX controls is enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1001</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-295" check="at least one" comment="Patch Q326830 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q326830</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-296" check="at least one" comment="Lanman enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\lanmanserver</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">2</value>
			</data>
		</registry_test>
		<registry_test id="wrt-297" check="at least one" comment="Patch Q323172 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q323172</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-298" check="at least one" comment="ActiveX Enabled In At Least One Zone" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name datatype="int">1200</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-299" check="at least one" comment="Patch Q300972 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q300972</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-3" check="at least one" comment="a Win2K/XP/2003 service pack is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
			</object>
		</registry_test>
		<registry_test id="wrt-30" check="at least one" comment="use machine settings rather than individual user settings" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</key>
				<name>Security_HKLM_only</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-300" check="at least one" comment="Terminal Server Version" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\Terminal Server</key>
				<name>ProductVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-301" check="at least one" comment="Patch Q324380 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q324380</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-302" check="at least one" comment="RDP Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\RDPWD</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-304" check="at least one" comment="the patch kb824141 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB824141</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-305" check="at least one" comment="the utility manager Service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\UtilMan</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-307" check="at least one" comment="the messenger service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\Messenger</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-308" check="at least one" comment="Patch KB825119 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB825119</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-309" check="at least one" comment="HCP Protocol" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_CLASSES_ROOT</hive>
				<key>HCP</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-31" check="at least one" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents</key>
				<name>fp_extensions</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-310" check="at least one" comment="the patch kb826232 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB826232</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-312" check="at least one" comment="Patch Q305601 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q305601</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-314" check="at least one" comment="Patch Q329170 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329170</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-315" check="at least one" comment="SMB Signing enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\lanmanserver\parameters</key>
				<name>enablesecuritysignature</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-316" check="at least one" comment="Windows Media Player for Windows XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\MediaPlayer\8.0\Registration</key>
				<name>UDBVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">8.0.0.4477</value>
			</data>
		</registry_test>
		<registry_test id="wrt-317" check="at least one" comment="Patch wm320920_8.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Windows Media Player\wm320920</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-318" check="at least one" comment="Patch wm308567 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Windows Media Player\wm308567</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-32" check="at least one" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\5.0\Setup Packages</key>
				<name operator="equals">Microsoft FrontPage Server Extensions 2002</name>
			</object>
		</registry_test>
		<registry_test id="wrt-323" check="at least one" comment="Patch Q823803 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q823803</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-324" check="at least one" comment="Patch WindowsMedia8-KB817787-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Windows Media Player\wm817787</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-325" check="at least one" comment="Patch Q303984 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q303984</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-326" check="at least one" comment="the NNTP service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\NntpSvc</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-328" check="at least one" comment="the patch q323255 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q323255</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-33" check="at least one" comment="FrontPage Server Extensions 2000 are enabled (WinNT)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\Setup Packages</key>
				<name operator="equals">FrontPage 2000 Server Extensions SR</name>
			</object>
		</registry_test>
		<registry_test id="wrt-331" check="at least one" comment="Patch isahf257 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\257</key>
				<name>Kbs</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">331066</value>
			</data>
		</registry_test>
		<registry_test id="wrt-332" check="at least one" comment="Microsoft Firewall Service Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\Fwsrv</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">2</value>
			</data>
		</registry_test>
		<registry_test id="wrt-333" check="at least one" comment="Patch Q307298 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q307298</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-334" check="at least one" comment="the telnet service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\Tlntsvr</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-335" check="at least one" comment="Patch KB822679 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB822679</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-34" check="at least one" comment="SharePoint Team Services are enabled (2K, XP, 2003)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\Setup Packages</key>
				<name>SharePoint</name>
			</object>
			<data operation="AND">
				<value operator="equals">Installed</value>
			</data>
		</registry_test>
		<registry_test id="wrt-344" check="at least one" comment="license logging service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SYSTEM\CurrentControlSet\Services\LicenseService</key>
				<name operator="equals">Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-347" check="at least one" comment="Service Pack 6 Installed (or later)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">Service Pack 6</value>
			</data>
		</registry_test>
		<registry_test id="wrt-348" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.50.4134.0100</value>
			</data>
		</registry_test>
		<registry_test id="wrt-349" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.50.4134.0600</value>
			</data>
		</registry_test>
		<registry_test id="wrt-35" check="at least one" comment="Word for Windows 6.0 Converter is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Wordpad</key>
				<name operator="equals">EnableLegacyConverters</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-350" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.50.4522.1800</value>
			</data>
		</registry_test>
		<registry_test id="wrt-351" check="at least one" comment="Patch Q286045 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Active Setup\Installed Components\{A954CDD5-A95F-414F-B3FE-FBEF9D2AECEA}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-352" check="at least one" comment="Patch Q295106 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Active Setup\Installed Components\{754D29C1-0C97-405F-98D0-21B212CA7FF1}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-353" check="at least one" comment="Internet Explorer 6.0 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">6.0.2600.0000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-354" check="at least one" comment="Patch Q313675 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Active Setup\Installed Components\{716E024F-7F74-47F3-B93B-9FF7F3CBF94C}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-355" check="at least one" comment="Patch Q316059.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Active Setup\Installed Components\{E81659DF-28E1-4C60-B4B9-00A4BC5FA76D}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-356" check="at least one" comment="Patch Q319282 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Active Setup\Installed Components\{2D5974C5-5185-4f5b-80B6-28015ACDD74C}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-36" check="at least one" comment="the patch kb885835is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885835</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-368" check="at least one" comment="Use Machine Settings" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</key>
				<name>Security_HKLM_only</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-369" check="at least one" comment="File Downloads Allowed In At Least One Zone" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name datatype="int">1803</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-37" check="at least one" comment="the patch KB885249 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885249</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-371" check="at least one" comment="Run ActiveX Controls and Plugins Allowed In At Least One Zone" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name datatype="int">1200</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-376" check="at least one" comment="Patch Q823718 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\DataAccess\Q823718</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-377" check="at least one" comment="DataAccess Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^2\.6.*</value>
			</data>
		</registry_test>
		<registry_test id="wrt-38" check="at least one" comment="the patch KB870763 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB870763</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-380" check="all" comment="Enable Path MTU Discovery is Disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SYSTEM\CurrentControlSet\Services\Tcpip\Parameters</key>
				<name operator="equals">EnablePMTUDiscovery</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-382" check="at least one" comment="DataAccess Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^2\.7.*</value>
			</data>
		</registry_test>
		<registry_test id="wrt-385" check="at least one" comment="COM Internet Services are enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Ole</key>
				<name>EnableDCOMHTTP</name>
			</object>
			<data operation="AND">
				<value operator="equals">Y</value>
			</data>
		</registry_test>
		<registry_test id="wrt-386" check="at least one" comment="Patch Q232449 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q232449 </key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-387" check="at least one" comment="Patch Q811114 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\Hotfix\Q811114</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-388" check="at least one" comment="Patch KB817772 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB817772</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-389" check="at least one" comment="Patch KB822343 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB822343</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-39" check="none exist" comment="If key present hyperterminal will automatically open session files" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CLASSES_ROOT</hive>
				<key operator="equals">htfile</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-390" check="at least one" comment="IIS 5.1 Minor Version" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\INetStp</key>
				<name>MinorVersion</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-391" check="at least one" comment="Windows 98 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">Windows 98</value>
			</data>
		</registry_test>
		<registry_test id="wrt-392" check="at least one" comment="Patch 273991USA8.EXE Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\UtilMan{5c773859-bb96- 48fa-875b-6a58aae072f4}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-393" check="at least one" comment="NetBIOS Bind not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
				<name>Bind</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-394" check="at least one" comment="NetBIOS Export not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
				<name>Export</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-395" check="at least one" comment="NetBIOS Route not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
				<name>Route</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-396" check="at least one" comment="Windows 95 or 98 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^Windows.*</value>
			</data>
		</registry_test>
		<registry_test id="wrt-397" check="at least one" comment="TCP/IP NetBIOS not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\LmHosts</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-398" check="at least one" comment="WINS Client binding not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\Interfaces\\Tcpip.*$</key>
				<name operator="equals">NetbiosOptions</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">2</value>
			</data>
		</registry_test>
		<registry_test id="wrt-399" check="at least one" comment="Remote access to registry not controlled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-4" check="at least one" comment="Win2K/XP/2003 service pack 1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">Service Pack 1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-40" check="at least one" comment="this is an NT Workstation" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\ProductOptions</key>
				<name>ProductType</name>
			</object>
			<data operation="AND">
				<value operator="equals">WinNT</value>
			</data>
		</registry_test>
		<registry_test id="wrt-400" check="at least one" comment="the w3svc service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SYSTEM\CurrentControlSet\Services\w3svc</key>
				<name operator="equals">Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-404" check="at least one" comment="DirectX 8.1x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^4\.08\.01.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-405" check="at least one" comment="DirectX 8.2 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^4\.08\.02.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-406" check="at least one" comment="DirectX 9.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^4\.09.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-407" check="at least one" comment="the patch kb839643 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-408" check="at least one" comment="Patch DirectX82-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643-DirectX82</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-409" check="at least one" comment="Patch DirectX90-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643-DirectX9</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-41" check="at least one" comment="this is an NT Server (stand-alone)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\Product\Options</key>
				<name>ProductType</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^.*ServerNT.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-410" check="at least one" comment="Win2K/XP/2003 service pack 1 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^Service Pack [1-9]|\d{2,}$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-413" check="at least one" comment="Windows XP or Windows Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CurrentVersion</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^5\.[1-2]$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-42" check="at least one" comment="this is an NT Server (domain controller)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\Product\Options</key>
				<name>ProductType</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^.*LanmanNT.*$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-423" check="at least one" comment="the patch KB894549 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Exchange Server 2003\SP1\KB894549</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-425" check="at least one" comment="Message Queuing Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\MSMQ</key>
				<name operator="equals"/>
			</object>
		</registry_test>
		<registry_test id="wrt-426" check="at least one" comment="the patch KB892944 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB892944</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-427" check="at least one" comment="the patch KB890859 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB890859</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-43" check="at least one" comment="this is an NT Terminal Server" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\ProductOptions</key>
				<name>ProductSuite</name>
			</object>
			<data operation="AND">
				<value operator="equals">Terminal Server</value>
			</data>
		</registry_test>
		<registry_test id="wrt-431" check="all" comment="MSN Messenger 6.2.0208 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ABEB838C-A1A7-4C5D-B7E1-8B4314600208}</key>
				<name operator="equals">MSN Messenger 6.2</name>
			</object>
			<data operation="AND">
				<value operator="equals">6.2.0208</value>
			</data>
		</registry_test>
		<registry_test id="wrt-434" check="at least one" comment="the patch  KB893086 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB893086\ Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-435" check="at least one" comment="the patch  KB893086 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB893086\Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-436" check="at least one" comment="the patch  KB893086 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB893086\Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-438" check="at least one" comment="the patch kb890923 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB890923 \Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-439" check="at least one" comment="the patch kb890923  is installed (XP SP2 Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB890923 \Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-44" check="at least one" comment="the patch Windows 2003 kb873339 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB873339\ Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-440" check="at least one" comment="the patch kb890923  is installed (XP Win2K Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB890923-IE6SP1-20050225.103456</key>
				<name datatype="int" operator="equals">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-441" check="at least one" comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB890923 -ie501sp3-20050225.100153</key>
				<name datatype="int" operator="equals">Installed </name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-442" check="at least one" comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SSOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB890923 -ie501sp4-20050225.100310</key>
				<name datatype="int" operator="equals">Installed </name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-443" check="at least one" comment="the patch KB893066 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB893066</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-45" check="at least one" comment="the patch WindowsXP-KB87339-x86-ENU.exe is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CLASSES_ROOT</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB873339\Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-454" check="at least one" comment="Patch Q265714 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q265714</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-455" check="at least one" comment="MTS Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Transaction Server\Packages</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-456" check="at least one" comment="Windows NT Server 4.0, Terminal Server Edition Security Rollup Package" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q317636</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-457" check="at least one" comment="Microsoft Exchange 2000 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\.*</key>
				<name>DisplayName</name>
			</object>
			<data operation="AND">
				<value operator="equals">Microsoft Exchange 2000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-458" check="at least one" comment="Patch Q316056 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Updates\Exchange Server 2000\SP3\Q316056</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-459" check="at least one" comment="Everyone group given remote access permissions" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg</key>
				<name>Everyone</name>
			</object>
		</registry_test>
		<registry_test id="wrt-46" check="at least one" comment="the patch Windows2000-KB873339-x86-ENU.EXE is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CLASSES_ROOT</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB873339\ Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-460" check="at least one" comment="SQL Server 2000 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\MSSQLServer\MSSQLServer\CurrentVersion</key>
				<name>CurrentVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">8.00.194</value>
			</data>
		</registry_test>
		<registry_test id="wrt-461" check="at least one" comment="DirectX 7.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^4\.07.*</value>
			</data>
		</registry_test>
		<registry_test id="wrt-462" check="at least one" comment="Patch Windows2000-KB839643-x86-ENU.EXE Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-463" check="at least one" comment="DirectX 8.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^4\.08\.00.*</value>
			</data>
		</registry_test>
		<registry_test id="wrt-464" check="at least one" comment="Patch DirectX80-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX8</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-465" check="at least one" comment="DirectX 8.1x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^4\.08\.01.*</value>
			</data>
		</registry_test>
		<registry_test id="wrt-466" check="at least one" comment="Patch DirectX81-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX81</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-467" check="at least one" comment="DirectX 8.2x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^4\.08\.02.*</value>
			</data>
		</registry_test>
		<registry_test id="wrt-468" check="at least one" comment="Patch DirectX82-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX82</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-469" check="at least one" comment="DirectX 9.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^4\.09\.00.*</value>
			</data>
		</registry_test>
		<registry_test id="wrt-47" check="at least one" comment="the patch NT Server kb873339 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CLASSES_ROOT</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix \KB873339\Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-470" check="at least one" comment="Patch DirectX90-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX9</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-471" check="at least one" comment="RestrictAnonymous registry value allows anonymous connections" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\LSA</key>
				<name>RestrictAnonymous</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-472" check="at least one" comment="Veritas Backup Exec 8.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">Software\VERITAS\Backup Exec\Server</key>
				<name operator="equals">CurrentVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">8.5</value>
			</data>
		</registry_test>
		<registry_test id="wrt-475" check="at least one" comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP1\KB824105\Filelist</key>
				<name operator="equals">installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-476" check="at least one" comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed on XP SP1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP2\KB824105\Filelist</key>
				<name operator="equals">installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-477" check="at least one" comment="the patch Q329115 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329115</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-478" check="at least one" comment="the patch Q811493 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q811493</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-479" check="at least one" comment="POSIX is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SYSTEM\CurrentControlSet\Control\Session Manager\Subsystem</key>
				<name operator="equals">Posix</name>
			</object>
		</registry_test>
		<registry_test id="wrt-480" check="at least one" comment="the patch kb841872 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841872</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-481" check="at least one" comment="the patch kb842526 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB842526</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals"/>
			</data>
		</registry_test>
		<registry_test id="wrt-482" check="at least one" comment="the patch kb840315 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840315</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-483" check="at least one" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB841873</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-484" check="at least one" comment="the patch q841373 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q841373</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-485" check="at least one" comment="MaxClientRequestBufferData less than or equal to 16384" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>System\CurrentControlSet\Services\w3svc\parameters</key>
				<name>MaxClientRequestBufferData</name>
			</object>
			<data operation="AND">
				<value operator="less than or equal">16384</value>
			</data>
		</registry_test>
		<registry_test id="wrt-488" check="at least one" comment="the patch kb839645 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839645</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-49" check="all" comment="the patch KB896428 for Services for UNIX is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Microsoft Services for UNIX\KB896428</key>
				<name operator="equals">Installed</name>
			</object>
		</registry_test>
		<registry_test id="wrt-490" check="at least one" comment="Active Desktop  is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4395}</key>
				<name operator="equals">IsInstalled</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-491" check="at least one" comment="HTML Help is registered" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Classes\ITSProtocol</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-492" check="at least one" comment="Patch IE-KB841873-WindowsNT4sp6-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{bfb56e60-5895-496c-bd6b-459b97142e4c}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-493" check="at least one" comment="Patch KB821557 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB821557</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-494" check="at least one" comment="the patch kb823353 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_CLASSES_ROOT</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\kb823353</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value>1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-495" check="at least one" comment="all users have the preview pane disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_USERS</hive>
				<key operator="pattern match">^S-[-0-9]+\\Identities\\\{[-0-9A-Z]+\}\\Software\\Microsoft\\Outlook\ Express\\5\.0\\Mail$</key>
				<name>ShowHybridView</name>
			</object>
			<data operation="AND">
				<value>0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-499" check="at least one" comment="the patch js56nen.exe (5.6.0.8513 version) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value>5,6,0,8513</value>
			</data>
		</registry_test>
		<registry_test id="wrt-50" check="at least one" comment="Internet Explorer 6 Service Pack 1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">6.00.2800.1106</value>
			</data>
		</registry_test>
		<registry_test id="wrt-500" check="at least one" comment="the patch js56nen.exe (5.1.0.8513 version) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value>5,1,0,8513</value>
			</data>
		</registry_test>
		<registry_test id="wrt-501" check="at least one" comment="the patch js56nen.exe (5.5.0.8513 version) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value>5,5,0,8513</value>
			</data>
		</registry_test>
		<registry_test id="wrt-502" check="at least one" comment="Patch Q328310 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q328310</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value>1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-503" check="at least one" comment="Patch Q329414 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329414</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value>1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-504" check="at least one" comment="Exchange 5.5 with SP4 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Exchange\Setup</key>
				<name>ServicePackBuild</name>
			</object>
			<data operation="AND">
				<value>2653</value>
			</data>
		</registry_test>
		<registry_test id="wrt-505" check="at least one" comment="the  patch kb842436 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Exchange Server 5.5\SP5\842436a</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value>2</value>
			</data>
		</registry_test>
		<registry_test id="wrt-506" check="at least one" comment="Outlook Web Access exists" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\MSExchangeweb</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-51" check="at least one" comment="Internet Explorer 6  for Windows Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Internet Explorer</key>
				<name operator="equals">Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">6.00.3790.0000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-512" check="at least one" comment="the patch KB833987 is installed (for Windows Server 2003)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB833987</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-513" check="at least one" comment="the patch KB833987 is installed (for Windows XP)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB833987</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-514" check="at least one" comment="Microsoft Office XP Service Pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
				<name>DisplayVersion</name>
			</object>
			<data operation="AND">
				<value>10.0.4330.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-515" check="at least one" comment="Microsoft Office 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90110409-6000-11D3-8CFE-0150048383C9}</key>
				<name>DisplayVersion</name>
			</object>
			<data operation="AND">
				<value>11.0.6252.7</value>
			</data>
		</registry_test>
		<registry_test id="wrt-516" check="at least one" comment="Patch KB873378 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Patches\9FEC06657760FC84499ED532196D45EE2</key>
				<name operator="equals">Security Update for Office 2003: Wordperfect 5.x Converter (KB873378)</name>
			</object>
			<data operation="AND">
				<value operator="equals">Installed</value>
			</data>
		</registry_test>
		<registry_test id="wrt-517" check="at least one" comment="Patch KB838905 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Patches\FC3FF5BA5FE5D1B4A9B9CD3698A34B89</key>
				<name operator="pattern match">.*</name>
			</object>
			<data operation="AND">
				<value>Installed</value>
			</data>
		</registry_test>
		<registry_test id="wrt-518" check="at least one" comment="The patch KB830348 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Visual Studio\7.1\M8303481037</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-519" check="at least one" comment="Microsoft Visual Studio .NET 2003 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">Software\Microsoft\VisualStudio\7.1</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-52" check="at least one" comment="the patch KB899753 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\FPC\Hotfixes\SP1\430</key>
				<name operator="equals">kbs</name>
			</object>
			<data operation="AND">
				<value operator="equals">KB899753</value>
			</data>
		</registry_test>
		<registry_test id="wrt-521" check="at least one" comment="Project Professional 2003 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0150048383C9}</key>
				<name>DisplayVersion</name>
			</object>
			<data operation="AND">
				<value>11.0.5614.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-522" check="at least one" comment="Patch KB838344 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040B30900063D11C\Patches\69B0450262BC7F44E8D4B683A49E437A</key>
				<name>Installed</name>
			</object>
		</registry_test>
		<registry_test id="wrt-523" check="at least one" comment="Windows Project Professional 2002 Service Pack 1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0050048383C9}</key>
				<name>DisplayVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">10.0.8326.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-524" check="at least one" comment="Patch KB831931 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040B30900063D11C8EF00054038389C\Patches\1F6752D69ABCD9F4B8021B9163826CAC</key>
				<name>Installed</name>
			</object>
		</registry_test>
		<registry_test id="wrt-525" check="at least one" comment="Visio Professional 2002 with service pack 2" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6D54-11D4-BEE3-00C04F990354}</key>
				<name>DisplayVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">10.2.5110</value>
			</data>
		</registry_test>
		<registry_test id="wrt-526" check="at least one" comment="Patch KB831932 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040150945D64D11EB3E000CF4993045\Patches\A75085E78F7F14244A464F09F6543C6C</key>
				<name>Installed</name>
			</object>
		</registry_test>
		<registry_test id="wrt-527" check="at least one" comment="Visio Professional 2003 is Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6000-11D3-8CFE-0150048383C9}</key>
				<name>DisplayVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">11.0.3216.5614</value>
			</data>
		</registry_test>
		<registry_test id="wrt-528" check="at least one" comment="Patch KB838345 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040150900063D11C8EF10054038389C\Patches\6B94DD4A71ECBDE43822F9D47D963102</key>
				<name>Installed</name>
			</object>
		</registry_test>
		<registry_test id="wrt-529" check="at least one" comment="Microsoft Office 2000 Premium Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00000409-78E1-11D2-B60F-006097C998E7}</key>
				<name>DisplayVersion</name>
			</object>
			<data operation="AND">
				<value>9.00.9327</value>
			</data>
		</registry_test>
		<registry_test id="wrt-53" check="at least one" comment="Internet Explorer 5.5 Service Pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.50.4807.2300</value>
			</data>
		</registry_test>
		<registry_test id="wrt-530" check="at least one" comment="the patch kb873380 for Office 2000 SP3 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Patches\A1334AC428B43BF4E9547C55D3DFE977</key>
				<name operator="pattern match">.*</name>
			</object>
			<data operation="AND">
				<value>Installed</value>
			</data>
		</registry_test>
		<registry_test id="wrt-531" check="at least one" comment="Microsoft Visual Studio .NET 2002 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">Software\Microsoft\VisualStudio\7.0</key>
				<name operator="pattern match">.*</name>
			</object>
		</registry_test>
		<registry_test id="wrt-532" check="at least one" comment="Patch KB830348 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040F50095765D115AF4000972A8B18B\Patches\4A3C9366F1471A7479BB3FDBC1FE3B31</key>
				<name operator="equals">Installed</name>
			</object>
		</registry_test>
		<registry_test id="wrt-533" check="at least one" comment="Patch KB832332 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040820900063D11C\Patches\4461EFFBCC9338645A85657DBDEB9E61</key>
				<name>Installed</name>
			</object>
		</registry_test>
		<registry_test id="wrt-534" check="at least one" comment="the patch q833989 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{dc0d5f50-5F0b-46bf-8683-93ac61c67001}</key>
				<name operator="equals">ComponentID</name>
			</object>
			<data operation="AND">
				<value operator="equals">Q833989</value>
			</data>
		</registry_test>
		<registry_test id="wrt-535" check="at least one" comment="Microsoft Office 2000 Professional Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00010409-78E1-11D2-B60F-006097C998E7}</key>
				<name>DisplayVersion</name>
			</object>
			<data operation="AND">
				<value>9.00.9327</value>
			</data>
		</registry_test>
		<registry_test id="wrt-536" check="at least one" comment="Windows NT Service Pack 6a is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q246009</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-537" check="at least one" comment="the patch q841356 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">Software\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841356</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-538" check="at least one" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^Service Pack [0-4]$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-539" check="at least one" comment="Win2K/XP/2003 service pack 5 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^Service Pack [5-9]|\d{2,}$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-54" check="at least one" comment="Internet Explorer 5.01 Service Pack 4 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.00.3700.1000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-541" check="at least one" comment="WebDav is disabled(for iis 5.0)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SYSTEM\CurrentControlSet\Services\W3SVC\Parameters</key>
				<name operator="equals">DisableWebDAV</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-542" check="at least one" comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885881</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-544" check="at least one" comment="the patch WindowsServer2003-KB885881-ia64-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885881</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-547" check="at least one" comment="the patch KB840987 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840987</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-548" check="at least one" comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB883935</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-549" check="at least one" comment="the patch KB824151 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB824151</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-55" check="at least one" comment="Internet Explorer 5.01 Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.00.3502.1000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-550" check="at least one" comment="Windows ME Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion</key>
				<name operator="equals">Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">Windows ME</value>
			</data>
		</registry_test>
		<registry_test id="wrt-551" check="at least one" comment="the patch KB841533 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841533</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-552" check="at least one" comment="the patch WindowsServer2003-KB883935-x86-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB883935</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-553" check="at least one" comment="the patch q873376 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873376</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-554" check="at least one" comment="Compressed Folders with zipfldr.dll are enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Classes\CompressedFolder</key>
				<name operator="equals">FriendlyTypeName</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">.*zipfldr\.dll.*</value>
			</data>
		</registry_test>
		<registry_test id="wrt-555" check="at least one" comment="Patch Windows2000-KB883935-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB883935</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-556" check="at least one" comment="Patch WindowsNT4OptionPack-KB883935-x86-enu.EXE" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB883935</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-557" check="at least one" comment="the patch kb834707 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-558" check="at least one" comment="Patch KB873350 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873350</key>
				<name operator="equals">File</name>
			</object>
			<data operation="AND">
				<value datatype="binary" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-559" check="at least one" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie501sp3-20040929.121357</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-56" check="at least one" comment="Internet Explorer 5.01 Service Pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.00.3315.1000</value>
			</data>
		</registry_test>
		<registry_test id="wrt-560" check="at least one" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie501sp4-20040929.111451</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-561" check="at least one" comment="the patch kb834707 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{ 3e7bb08a-a7a3-4692-8eac-ac5e7895755b}</key>
				<name>IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-562" check="at least one" comment="the patch kb834707 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie6-20040929.115007 </key>
				<name operator="equals">IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-564" check="at least one" comment="the patch kb834707  is installed (Installed Components key) " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707</key>
				<name operator="equals">IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-565" check="at least one" comment="Internet Explorer 6 Service Pack 2 for XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Internet Explorer</key>
				<name operator="equals">Version</name>
			</object>
			<data operation="AND">
				<value operator="equals">6.00.2900.2180</value>
			</data>
		</registry_test>
		<registry_test id="wrt-566" check="at least one" comment="Exchange Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\9161A261-6ABE-4668-BBFA-AD06B3F642CF</key>
				<name>Microsoft Exchange</name>
			</object>
		</registry_test>
		<registry_test id="wrt-567" check="at least one" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings$</key>
				<name>DisableCachingOfSSLPages</name>
			</object>
			<data operation="AND">
				<value operator="not equal">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-569" check="at least one" comment="Patch Q817606 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q817606</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-57" check="at least one" comment="the patch kb896358 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885836</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-570" check="at least one" comment="Patch Q823980 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q823980</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-571" check="at least one" comment="Patch Q19696 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q19696</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-578" check="all" comment="the software Adobe Acrobat Reader 6, major version 6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Adobe\Acrobat Reader\6.0\Installer</key>
				<name operator="equals">VersionMax</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">6</value>
			</data>
		</registry_test>
		<registry_test id="wrt-579" check="all" comment="the software Adobe Acrobat Reader 6, minor version less than 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Adobe\Acrobat Reader\6.0\Installer</key>
				<name operator="equals">VersionMin</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="less than">3</value>
			</data>
		</registry_test>
		<registry_test id="wrt-59" check="all" comment="PNG image rendering enabled in Internet Explorer" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\CLASSES</key>
				<name operator="equals">PNGFilter.CoPNGFilter</name>
			</object>
			<data operation="AND">
				<value operator="equals">CoPNGFilter Class</value>
			</data>
		</registry_test>
		<registry_test id="wrt-60" check="at least one" comment="the patch q824145 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB824245</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-608" check="at least one" comment="the patch KB894320 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB894320\Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-609" check="at least one" comment="Webview is  Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CURRENT_USER</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced</key>
				<name operator="equals">WebView</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-61" check="at least one" comment="Windows Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CurrentVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">5.2</value>
			</data>
		</registry_test>
		<registry_test id="wrt-62" check="at least one" comment="the patch kb883939 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB883939</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-63" check="at least one" comment="the patch KB896422 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896422</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-64" check="at least one" comment="the patch kb890046 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB890046</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-67" check="all" comment="If the Hyperterminal client is registered as the default telnet client" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_CLASSES_ROOT</hive>
				<key operator="equals">telnet\shell\open</key>
				<name operator="equals">command</name>
			</object>
			<data operation="AND">
				<value operator="equals">C:\Program Files\Windows NT\hypertrm.exe /t %1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-68" check="at least one" comment="the patch kb891711 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB891711</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-69" check="at least one" comment="the patch Windows 2003 KB871250 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB871250\Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-70" check="at least one" comment="64-Bit version of Windows is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\Session Manager\Environment</key>
				<name>PROCESSOR_ARCHITECTURE</name>
			</object>
			<data operation="AND">
				<value operator="equals">ia64</value>
			</data>
		</registry_test>
		<registry_test id="wrt-71" check="at least one" comment="the workstation service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\lanmanworkstation</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-72" check="at least one" comment="32-Bit version of Windows is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\Session Manager\Environment</key>
				<name>PROCESSOR_ARCHITECTURE</name>
			</object>
			<data operation="AND">
				<value operator="equals">x86</value>
			</data>
		</registry_test>
		<registry_test id="wrt-74" check="at least one" comment="the patch Windows XP KB871250 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP2\KB871250\Filelist</key>
				<name operator="pattern match">^.*$</name>
			</object>
		</registry_test>
		<registry_test id="wrt-77" check="at least one" comment="Windows NT 4.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CurrentVersion</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">4.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-78" check="at least one" comment="the patch kb888113 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB888113</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-79" check="at least one" comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name operator="equals">CSDVersion</name>
			</object>
			<data operation="AND">
				<value operator="pattern match">^Service Pack [0-2]$</value>
			</data>
		</registry_test>
		<registry_test id="wrt-81" check="at least one" comment="the patch kb888302 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB888302</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-82" check="at least one" comment="Windows Media Player 9.0 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\MediaPlayer\9.0\Registration</key>
				<name operator="equals">UDBVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">9.00.00.2980</value>
			</data>
		</registry_test>
		<registry_test id="wrt-83" check="at least one" comment="the patch q828035 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828035</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-84" check="at least one" comment="The patch KB885492 is installed on Windows XP" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows Media Player 9\SP0\KB885492</key>
				<name operator="equals">PackageVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">1.1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-85" check="at least one" comment="The patch KB885492 is installed on Windows 2000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows Media Player 9\KB885492</key>
				<name operator="equals">PackageVersion</name>
			</object>
			<data operation="AND">
				<value operator="equals">1.1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-86" check="at least one" comment="the patch q828748 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828749</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-87" check="at least one" comment="the patch kb891781 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB891781</key>
				<name operator="equals">IsInstalled</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-88" check="at least one" comment="the patch q810217 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB810217</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-89" check="at least one" comment="Patch KB873354 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6D54-11D4-BEE3-00C04F990354}</key>
				<name operator="equals">WindowsInstaller</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-9" check="at least one" comment="Microsoft Proxy Server 2.0 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Proxy Server</key>
				<name operator="equals">Microsoft Proxy Server</name>
			</object>
		</registry_test>
		<registry_test id="wrt-90" check="at least one" comment="the patch KB885250 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885250</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-91" check="at least one" comment="the patch KB873333 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873333</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-93" check="at least one" comment="the patch kb890175 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB890175</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-94" check="at least one" comment="Patch KB873355 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0050048383C9}}</key>
				<name operator="equals">DisplayVersion</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">10.0.8326.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-95" check="at least one" comment="Patch KB873352 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
				<name operator="equals">DisplayVersion</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">10.0.6626.0</value>
			</data>
		</registry_test>
		<registry_test id="wrt-96" check="at least one" comment="the patch kb885834 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885834</key>
				<name operator="equals">Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-97" check="at least one" comment="the patch kb830352 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB830352</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<registry_test id="wrt-98" check="at least one" comment="the wins service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\wins</key>
				<name>Start</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="not equal">4</value>
			</data>
		</registry_test>
		<registry_test id="wrt-99" check="at least one" comment="the patch kb828028 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828028</key>
				<name>Installed</name>
			</object>
			<data operation="AND">
				<value datatype="int" operator="equals">1</value>
			</data>
		</registry_test>
		<wmi_test id="wwt-1" check="none exist" comment="Integrated Windows Authentication is used for all directories" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<object>
				<namespace operator="equals">root\MicrosoftIIsv2</namespace>
				<wql operator="equals">SELECT AuthNTLM from IIsWebDirectorySetting where AuthNTLM = FALSE</wql>
			</object>
		</wmi_test>
		<wmi_test id="wwt-2" check="all" comment="Review whether anonymous HTTP access is allowed through IIS" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
			<oval:notes>
				<oval:note>Non-pejorative check</oval:note>
			</oval:notes>
			<object>
				<namespace operator="equals">root\MicrosoftIISv2</namespace>
				<wql operator="equals">SELECT AuthAnonymous from IIsWebDirectorySetting</wql>
			</object>
		</wmi_test>
	</tests>
</oval>
