AnswerWorks Runtime Update v. 4.0.102 and v. 5.0.8 Description of problem: ====================== It was found that there is a security vulnerability in version 4.0X and 5.0x of the AnswerWorks™ runtime. A malicious piece of code could use an unchecked buffer to execute arbitrary code on a user’s machine. There have been no known exploits or reports of this issue to Vantage, OEM customers, or end users. This patch is proactive to any efforts to exploit. Description of fix: ================== Versions 4.0.102 and 5.0.8 eliminate this vulnerability. The kill bit is also set in the computer’s registry to prevent the old code from ever running again. This has the effect that if the new build is uninstalled and an older version of AnswerWorks™ is reinstalled on the machine, the older version of AnswerWorks™ will not function but it will also prevent any security vulnerability. Description of files: ==================== There are multiple packagings of this fix to accomodate various integration strategies. awMinimalPatch.msi is a standalone installer designed to detect any vulnerability and apply the fix for all versions of Answerworks. After installing this, the installer's PC will not be vulnerable and their AnswerWorks software will continue to function properly. Note that nothing will appear in Add/Remove Programs as a result of this patch. It is irreversible however it can be run again to repair.