Important
If nothing happens when you open Legacy Update setup on Windows XP, follow these steps to work around a Windows bug.
This release addresses a security issue in the Legacy Update ActiveX control. Please update as soon as possible.
- Security:
- Fixes a logic error that allowed any website to access the Legacy Update ActiveX control, rather than only legacyupdate.net. This may allow an attacker to cause disruption to your system, such as by installing updates without consent, causing unwanted dialog boxes to appear, or revealing your exact operating system build number. For more information, see our security advisory. (GHSA-f4g7-4gmx-jfgf)
- On installation of Legacy Update 1.13.2, your system will be configured to block earlier versions of the Legacy Update ActiveX control. This is also known as a “killbit”. To ensure the vulnerability remains mitigated, this block is not removed from the registry if you uninstall Legacy Update.
- Adds support for Internet Explorer’s “object safety” feature, which displays an Information Bar if an unauthorised website tries to access the Legacy Update ActiveX control.
- Adds a requirement that websites using the Legacy Update ActiveX control must be on the
http://orhttps://protocol, and in Internet Explorer’s Trusted Sites zone.
- Bug fixes:
- Allows the Legacy Update ActiveX control to be installed on Windows Server Core, in cases where Internet Explorer has been manually installed.
- Fixes Legacy Update offering to install Internet Explorer 9 on Windows Server 2008 for Itanium-based Systems, which is not supported.
- Fixes an unintended RegSvr32 dialog appearing during uninstallation.
- Various minor improvements to harden security of the Legacy Update codebase.
Thanks to @renodr and @nononymousse for helping with reviewing/testing security and bug fixes in this release.