# WinXP SP1 - pros and cons

**URL:** <https://boards.straightdope.com/t/winxp-sp1-pros-and-cons/199609>\
**Category:** Factual Questions\
**Created:** [September 4, 2003, 9:50pm UTC](https://boards.straightdope.com/t/winxp-sp1-pros-and-cons/199609 "2003-09-04T21:50:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jake4](https://avatars.discourse-cdn.com/v4/letter/j/bc8723/32.png) [@Jake4](https://boards.straightdope.com/u/Jake4)\
**Post date:** [September 4, 2003, 9:50pm UTC](https://boards.straightdope.com/t/winxp-sp1-pros-and-cons/199609/1 "2003-09-04T21:50:30Z")

</div>

What are the pros and cons to installing the WinXP Service Pack 1? I remember when it came out about a year ago, there was an uproar over the new terms of the EULA and that it brought some users machines to a crawl. I still haven’t installed it, and I haven’t had any problems - instability, crashes, trojans, etc. I keep the OS otherwise fully updated with security patches from windowsupdate. Is there any benefit to SP1 that would/should make me change my mind? Are there any security updates or OS enhancements included that can’t be found elsewhere?

---

<div class="post-metadata">

**Author:** ![Jake4](https://avatars.discourse-cdn.com/v4/letter/j/bc8723/32.png) [@Jake4](https://boards.straightdope.com/u/Jake4)\
**Post date:** [September 4, 2003, 10:33pm UTC](https://boards.straightdope.com/t/winxp-sp1-pros-and-cons/199609/2 "2003-09-04T22:33:50Z")

</div>

Thanks to the crappy no-three-letter-word-search “feature” of the board, I had to wade through pages of topics and posts to find relevent info.

The only new feature I’ve found is ‘Set Program Access and Defaults.’ Woo-hoo.

These helped: [This thread](http://boards.straightdope.com/sdmb/showthread.php?s=&threadid=135067&highlight=service+AND+pack) and [this thread](http://boards.straightdope.com/sdmb/showthread.php?s=&threadid=134832&highlight=service+AND+pack) which led me to [this link](http://archives.neohapsis.com/archives/bugtraq/2002-08/0129.html). There is apparently a problem with allowing evil URLs to delete any files on your system.

From the neohapsis link:

> [@](#):
>
> The file (32,463 bytes);  
> %windir%\PCHEALTH\HELPCTR\System\DFS\uplddrvinfo.htm
> 
> Appears to be intended for use by the Help Center to upload hardware/driver  
> information collected on the local machine for use in troubleshooting  
> hardware issues. It also contains the fraction of script;
> 
> var oFSO = new ActiveXObject ( “Scripting.FileSystemObject” );  
> try  
> {  
> oFSO.DeleteFile( sFile );  
> }
> 
> Where ‘sFile’ is derived from the URL. The help center will load the  
> uplddrvinfo.htm file and render it with higher privileges, allowing such  
> script to run without prompts
> 
> By using the ‘hcp:’ protocol, its possible to launch this from a link. The  
> filename can also include wild cards. Thus, the following link will delete  
> all files in the ‘C:\windows’ directory when the launched window is closed.  
> (normal file permissions still apply as usual). Sub-directories are not  
> deleted.
> 
> hcp://system/DFS/uplddrvinfo.htm?file://c:\windows\*
> 
> \<snip\>
> 
> Temporary solutions may be;
> 
> - delete/move the uplddrvinfo.htm file
> - edit the script of uplddrvinfo.htm to remove the offending code
> - unregister the hcp protocol handler

So, am I to understand that deleting the offending 5 lines will completely remove this exploit? Sounds better to me than upgrading…

---

<div class="post-metadata">

**Author:** ![Early\_Out](https://avatars.discourse-cdn.com/v4/letter/e/6f9a4e/32.png) [@Early\_Out](https://boards.straightdope.com/u/Early_Out)\
**Post date:** [September 5, 2003, 2:12am UTC](https://boards.straightdope.com/t/winxp-sp1-pros-and-cons/199609/3 "2003-09-05T02:12:59Z")

</div>

It would appear that you haven’t read the threads very carefully. Do you honestly think that a 30Mb service pack would be required to fix one security hole, one that could be taken care of by deleting five lines? SP1, like any other MS service pack, contains fixes to dozens upon dozens of security holes, bugs, glitches, etc., etc. You can read more about it [here](http://www.microsoft.com/windowsxp/expertzone/columns/bowman/02september09.asp).

The inherent danger in ignoring the SP, of course, is that future patches may rely upon the presence of the fixes included in the earlier SP. I’ve seen this before, with other MS products: some later patches explicitly warn that they can’t be applied unless SP1, SP2, etc., have already been installed. Eventually, you’ll have to bite the bullet and install SP1. (I haven’t heard any horror stories about it, and it certainly didn’t do anything undesirable to my PC.)

I’m puzzled by this remark you made:

> [@](#):
>
> \*\*Are there any security updates or OS enhancements included that can’t be found elsewhere?  
> \*\*

Why would you think that getting the same updates or enhancements from somewhere else would be better than getting them from the source?

---

<div class="post-metadata">

**Author:** ![Hodge](https://avatars.discourse-cdn.com/v4/letter/h/5f9b8f/32.png) [@Hodge](https://boards.straightdope.com/u/Hodge)\
**Post date:** [September 5, 2003, 2:59am UTC](https://boards.straightdope.com/t/winxp-sp1-pros-and-cons/199609/4 "2003-09-05T02:59:05Z")

</div>

> [@](#):
>
> \*Originally posted by Early Out \*  
> It would appear that you haven’t read the threads very carefully. Do you honestly think that a 30Mb service pack would be required to fix one security hole

134Mb, actually

> [@](#):
>
> SP1, like any other MS service pack, contains fixes to dozens upon dozens of security holes, bugs, glitches, etc., etc.

324 fixes, to be exact. Here’s an [itemized list](http://support.microsoft.com/default.aspx?scid=%2fsupport%2fServicePacks%2fWindows%2fXP%2fSP1FixList.asp). Bottom line, install SP1. In fact, many people refuse to install new versions of windows until the first Service Pack is released. OS development is an ongoing thing and it’s critical to stay up-to-date or risk exposing yourself through unpatched security holes, etc.

---

<div class="post-metadata">

**Author:** ![Jake4](https://avatars.discourse-cdn.com/v4/letter/j/bc8723/32.png) [@Jake4](https://boards.straightdope.com/u/Jake4)\
**Post date:** [September 5, 2003, 2:59am UTC](https://boards.straightdope.com/t/winxp-sp1-pros-and-cons/199609/5 "2003-09-05T02:59:40Z")

</div>

Very helpful, thanks sooooo much.

I’m aware of the fact that the service pack contained many other security patches. Hence my statement, “I keep the OS otherwise fully updated with security patches from windowsupdate.”

I’m aware that in the future I may be forced to apply SP1 to apply other security patches. That’s not an issue now.

My remark about getting updates elsewhere should have perhaps been worded thusly: Are there any security updates other than the aforementioned uplddrvinfo.htm exploit that are contained only in SP1 and can be applied through no other method than installing SP1?

This question is the most important to me, so I’ll say it again:

Are there any security updates other than the aforementioned uplddrvinfo.htm exploit that are contained only in SP1 and can be applied through no other method than installing SP1?

---

<div class="post-metadata">

**Author:** ![Jake4](https://avatars.discourse-cdn.com/v4/letter/j/bc8723/32.png) [@Jake4](https://boards.straightdope.com/u/Jake4)\
**Post date:** [September 5, 2003, 3:00am UTC](https://boards.straightdope.com/t/winxp-sp1-pros-and-cons/199609/6 "2003-09-05T03:00:54Z")

</div>

simulpost.

Thanks for YOUR help, Hodge.

---

<div class="post-metadata">

**Author:** ![Jake4](https://avatars.discourse-cdn.com/v4/letter/j/bc8723/32.png) [@Jake4](https://boards.straightdope.com/u/Jake4)\
**Post date:** [September 5, 2003, 3:02am UTC](https://boards.straightdope.com/t/winxp-sp1-pros-and-cons/199609/7 "2003-09-05T03:02:13Z")

</div>

So my other question:

All horror stories about programs slowing down, system breaking, etc. are random occurances, and I’m pretty much the only one here still w/o SP1 installed? There’s no good reason not to?

---

<div class="post-metadata">

**Author:** ![Early\_Out](https://avatars.discourse-cdn.com/v4/letter/e/6f9a4e/32.png) [@Early\_Out](https://boards.straightdope.com/u/Early_Out)\
**Post date:** [September 5, 2003, 3:19am UTC](https://boards.straightdope.com/t/winxp-sp1-pros-and-cons/199609/8 "2003-09-05T03:19:39Z")

</div>

> [@](#):
>
> \*Originally posted by Jake4 \*  
> \*\* There’s no good reason not to? \*\*

No, there’s no good reason not to install SP1. The horror stories are just that - stories.
