Since installing the latest batch of Security updates on our 2003 Server, any user created since the update, or that has never logged on to Terminal Services before the update, can not execute a file over a network drive in a Terminal Services session. Local files (on the server) are OK.
These are the updates that were applied:
KB923694 – Cumulative Security Update for Outlook Express
KB928843 – Vulnerability in HTML Help ActiveX Control Could Allow Remote Code Execution
KB928255 – Vulnerability in Windows Shell Could Allow Elevation of Privilege
KB926436 – Vulnerability in Microsoft OLE Dialog Could Allow Remote Code Execution
KB918118 – Vulnerability in Microsoft RichEdit Could Allow Remote Code Execution
KB924667 – Vulnerability in Microsoft MFC Could Allow Remote Code Execution
The error message received is:
“Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.”
The affected users do not have the access problem from their desktop workstations, only in a TS session.
Since users that have established TS sessions already do not have the problem, it seems to me it must be something new – i.e. the recent security updates – adding something to the Terminal services user’s profile when it is created.
We will try rolling back the security updates, but need to do so when other users are not logged on and, of course, at a time when we can reboot the server. That won’t be for several days, unless this becomes an emergency, which is not likely. We are not 100% certain one or more of the security updates generated the problem, but have not come up with an alternative scenario.
Any suggestions that do not require a reboot or interruption of other users working are most welcome.
3/1/07 We rolled back the updates, to no effect.