This from IT: I previously made a comment (been a year or so) about this issue XML Core Services 4.0 Vuln on Windows 7 – unpatched and vulnerable for
[See the full post at: XML Core Services 4.0 vulnerability on Windows 7 – unpatched and vulnerable for several years]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
XML Core Services 4.0 vulnerability on Windows 7 – unpatched and vulnerable for several years
Home » Forums » Newsletter and Homepage topics » XML Core Services 4.0 vulnerability on Windows 7 – unpatched and vulnerable for several years
- This topic has 20 replies, 4 voices, and was last updated 9 years, 1 month ago by
IT.
AuthorTopicwoody
ManagerMay 9, 2016 at 7:32 am #43083Viewing 19 reply threadsAuthorReplies-
rc primak
GuestMay 9, 2016 at 8:10 am #43084I remember this one. Secunia PSI was detecting it well before a year ago. I removed it from my Win 7 Home laptop long ago. At the time, it did appear it was either Quicken or QuickBooks which were among the top offenders in installing this old and insecure version. The original source seems to have been IE5 or IE6.
This ranks up there with Adobe’s Flash Player and Apple’s QuickTime as among the most chronic security offenders in the Windows ecosystem. If possible, all readers should run a vulnerability checker and remove all instances of this version ASAP.
-
woody
Manager -
Jackie
Guest -
Ed
GuestMay 9, 2016 at 12:31 pm #43087How would I know what program invited this in? I don’t want to “break” something I’m using by uninstalling it and I’d also like to know if whatever program it came with will still function properly after updating this to SP3? Can somebody answer these questions?
Looking in Programs and Features I see three entries with “MSXML 4.0 SP2” in them. Sorting by date I see only one other entry installed on the same day as one of them. There are no other programs installed for 8 months prior.
Here’s what I’m seeing followed by the installed on date…
MS Visual Studio 2005 Tools for Office Runtime – 3/15/2010
MSXML 4.0 SP2 Parser and SDK – 3/15/2010
MSXML 4.0 SP2 (KB954430) – 3/17/2010
MSXML 4.0 SP2 (KB973688) – 3/17/2010
-
Steve
GuestMay 9, 2016 at 12:35 pm #43088If you’re not sure I would leave it but upgrade it to the SP3 version and then run Windows Update to get the security patches for SP3. Download link to SP3 is here, https://www.microsoft.com/en-us/download/details.aspx?id=15697.
-
ch100
AskWoody_MVPMay 9, 2016 at 3:05 pm #43089Thanks for the info. Yes it is an older issue almost forgotten by everyone. It may be considered by Microsoft as part of the legacy products like Windows XP or older versions of other discontinued products and the vulnerability not serious enough to deserve an update.
If still needed, it would be a good idea to update to the latest version available. -
RCPete
GuestMay 9, 2016 at 4:24 pm #43090First off, thanks for the information! I found your site in the early days of GWX and it’s saved me a lot of heartburn.
It looks like MSXML SP2 came onto my machine from a 2012 version of Quicken Home. (Judging by the install date.) 2015 Home and Business doesn’t seem to use MSXML at all, going from the task manager lists of running and available services.
NOTE: I found that installing SP3 does NOT remove SP2. It must be uninstalled manually through “Programs and Features”. Only one update for SP3, KB2758694. Now to check the other computer…
-
RCPete
Guest -
a
Guest -
ch100
AskWoody_MVPMay 9, 2016 at 7:38 pm #43093This looks like a new QuickTime type of issue, discussed not long ago.
I think there is no need for panic, but a little extra care and common sense while browsing the web is needed. This is not unusual advise and useful at any time.
If known that is not needed, the known insecure software should be uninstalled.
If still needed, update to the latest version available, which is presumably more secure than the previous one. -
doktornotor
GuestMay 10, 2016 at 6:28 am #43094Except that you actually can *really* uninstall QuickTime. With MSXML4, you are stuck with tons of different versions of the abandoned junk (due to the horrible side-by-side idea, acknowledged as complete brainfart by MS themselves and abandoned with MSXML6) and uninstalling the one version available in the control panel does nothing useful to remove the rest. :-(((
-
John
GuestMay 10, 2016 at 7:02 am #43095MSXML4 has reached end of life. That includes MSXML4 SP3. It’s been out of support since April 2014.
https://msdn.microsoft.com/en-us/library/jj152146(v=vs.85).aspx
Apps are supposed to use MSXML6 instead.
I think you should remove all instances of MSXML4 on your machine unless you require it for something. That is, uninstall all KBs that are listed as MSXML4 (SP2 or SP3). There can be many listed.
Here are some more resources:
-
walker
AskWoody LoungerMay 10, 2016 at 11:53 am #43096I purchased a custom made Win7 Home Premium several years ago. When I checked the updates that were listed and ran PSI (Secunia), it listed this one as being insecure. I asked the tech about it, and he stated that it was best to leave it there because there could possibly be “updates” that needed it.
Being the novice that I am I just left it there, where it still remains. Also had that
advice from other techs subsequently. I’m very confused about it. I uninstalled Quick Time ages ago. That’s all I know, and it isn’t much. 🙁Here is an old reference I had in my bookmarks from “way back when”:
-
walker
AskWoody Lounger -
poohsticks
GuestMay 10, 2016 at 12:45 pm #43098To a non-techie, this issue seems to be pretty complicated, and there are several quite-different versions of advice above on how best to deal with it.
The Secunia article linked to in the main blog post above is from October 2013. Is this issue still a major problem in May 2016? Not trying to be flippant, just trying to figure out how much time I, as a non-techie, should spend in trying to understand this and in tinkering with my computer.
Is there a site that explains in a basic way what exactly to look for in one’s computer and what to do, step-by-careful-step, about curbing the risks that this problem seems to introduce?
In the meantime, it feels that, at least for someone like me who does not have an advanced level of computer knowledge, the safest action would be to leave things as they are, and not start uninstalling a number of kbs and programs, and downloading standalone updates from the MS site which are now apparently for an obsolete program.
-
ch100
AskWoody_MVPMay 10, 2016 at 3:25 pm #43099Except that after uninstalling QuickTime, components of what used to be exclusively in QuickTime are now in iTunes. There are dependencies everywhere and difficult to control without having full information and the time and tools to do it.
Yes, it is a lot of junk left behind when uninstalling and OS upgrades in place are not very helpful in eliminating it. -
walker
AskWoody Lounger -
Frahaleah
Guest -
woody
Manager -
IT
GuestMay 12, 2016 at 6:52 pm #43103Following up on this post: I had this issue: I even had it yesterday when inserting a CD from one of those Imaging centers to view the results of some MRI/CT studies I had! From only a few years ago. It required XML core services SP2 (from before 2009) to run. I am on Windows 10 64-bit now. Do a Google search to find out what it is and how they work.
The programs listed in the comments are likely a reason it was installed on your PC. Program developers were encouraged to use MSXML 6 to code, but some are legacy products, etc……
Quicken 2013 Deluxe
QuickTime
Visual Studio Older versions (Likely the 2005 version someone mentioned)-I am willing to bet that it was Visual Studio 2005 that installed it on your Windows 7 PC. Windows 7 does not natively ship with MSMXL v4, but programs install it. They were likely built on older versions. Note that trying to install MSXML v6 over this one won’t fix the issue.
If you read in the MSFT KB article, SP3 is a complete replacement of all of the previous versions. When you install the msxml.msi file (2.3mb), it is in essence replacing all of the previous updates (v4 SP!, SP2, etc. After installing SP3 (which for some reason Microsoft decided must be manually installed) – reboot your PC, then run Windows update. Once you have installed all of the Security Updates and rebooted – that’s all you can do. It is an EOL’D software. But, by not updating to SP3, you are opening yourself to more vulnerabilities (those Affecting MSXML 4 SP2 and above.
Ok here’s why I think it is a problem: There are Enabled Add-ons in IE. Reports of exploitation are likely due to this. Open up Internet Explorer, Click on Tools, Manage Add-One, then on the left middle part of the Manage Add-ons Window, Click the dropdown menu and select:
Run Without Permission.
If you have v4 installed you will likely see some or all of the following below:
XML DOM Document 4.0
FreeThreaded XML DOM Document
XML Schema Cache 4.0
XSL Template 4.0
XML Data Source Document 4.0
XML HTTP Document 4.0So, essentially you have these unpatched EOL’D add-ons in Internet Explorer. That puts you at risk for Exploitation, and that’s likely why it’s #2 on Secunia/Flexera’s list of the Top 50 Vulnerabilities.
I suppose you could try disabling them
Reference:
https://technet.microsoft.com/en-us/library/security/ms13-002.aspx
http://secunia.com/community/forum/thread/show/13191/are_you_trying_to_fix_a_problem_with_msxml_4
http://searchsecurity.techtarget.com/answer/How-can-Microsoft-XML-vulnerabilities-be-mitigated
Disclaimer: I am not a professional, and am not responsible for any errors, lost files, or any problems with your PC that may result from anything in this article and comment. Just CMA here.
Viewing 19 reply threads - This topic has 20 replies, 4 voices, and was last updated 9 years, 1 month ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Win 11 24H2 June 2025 Update breaks WIFI
by
dportenlanger
52 minutes ago -
Update from WinPro 10 v. 1511 on T460p?
by
CatoRenasci
50 minutes ago -
System Restore and Updates Paused
by
veteran
3 hours, 23 minutes ago -
Windows 10/11 clock app
by
Kathy Stevens
5 hours, 5 minutes ago -
Turn off right-click draw
by
Charles Billow
6 hours, 37 minutes ago -
Introducing ChromeOS M137 to The Stable Channel
by
Alex5723
10 hours, 8 minutes ago -
Brian Wilson (The Beach Boys) R.I.P
by
Alex5723
11 hours, 19 minutes ago -
Master patch listing for June 10, 2025
by
Susan Bradley
11 hours, 45 minutes ago -
Suggestions for New All in One Printer and a Photo Printer Windows 10
by
Win7and10
3 hours, 46 minutes ago -
Purchasing New Printer. Uninstall old Printer Software First?
by
Win7and10
17 hours, 46 minutes ago -
KB5060842 Issue (Minor)
by
AC641
22 hours, 19 minutes ago -
EchoLeak : Zero Click M365 Copilot leak sensitive information
by
Alex5723
1 day ago -
24H2 may not be offered June updates
by
Susan Bradley
7 hours, 16 minutes ago -
Acronis : Tracking Chaos RAT’s evolution (Windows, Linux)
by
Alex5723
1 day, 13 hours ago -
June 2025 updates are out
by
Susan Bradley
1 hour, 43 minutes ago -
Mozilla shutting Deep Fake Detector
by
Alex5723
2 days, 4 hours ago -
Windows-Maintenance-Tool (.bat)
by
Alex5723
1 day, 13 hours ago -
Windows 11 Insider Preview build 26200.5641 released to DEV
by
joep517
2 days, 6 hours ago -
Windows 11 Insider Preview build 26120.4250 (24H2) released to BETA
by
joep517
2 days, 6 hours ago -
Install Office 365 Outlook classic on new Win11 machine
by
WSrcull999
2 days, 6 hours ago -
win 10 to win 11 with cpu/mb replacement
by
aquatarkus
1 day, 22 hours ago -
re-install Windows Security
by
CWBillow
2 days, 10 hours ago -
WWDC 2025 Recap: All of Apple’s NEW Features in 10 Minutes!
by
Alex5723
2 days, 13 hours ago -
macOS Tahoe 26
by
Alex5723
2 days, 7 hours ago -
Migrating from win10 to win11, instructions coming?
by
astro46
19 hours, 3 minutes ago -
Device Eligibility for Apple 2026 Operating Systems due this Fall
by
PKCano
1 day, 22 hours ago -
Recommended watching : Mountainhead movie
by
Alex5723
1 day, 23 hours ago -
End of support for Windows 10
by
Old enough to know better
3 hours, 13 minutes ago -
What goes on inside an LLM
by
Michael Covington
1 day, 17 hours ago -
The risk of remote access
by
Susan Bradley
12 hours, 59 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.