<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:win-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5"
   xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 http://oval.mitre.org/language/download/schema/version5.3/ovaldefinition/complete/oval-common-schema.xsd    http://oval.mitre.org/XMLSchema/oval-definitions-5 http://oval.mitre.org/language/download/schema/version5.3/ovaldefinition/complete/oval-definitions-schema.xsd    http://oval.mitre.org/XMLSchema/oval-definitions-5#windows http://oval.mitre.org/language/download/schema/version5.3/ovaldefinition/complete/windows-definitions-schema.xsd    http://oval.mitre.org/XMLSchema/oval-definitions-5#independent http://oval.mitre.org/language/download/schema/version5.3/ovaldefinition/complete/independent-definitions-schema.xsd">
   <generator>
      <oval:product_name>National Institute of Standards and Technology</oval:product_name>
      <oval:schema_version>5.3</oval:schema_version>
      <oval:timestamp>2011-09-23T09:24:53.844-04:00</oval:timestamp>
   </generator>
   <!-- ==================================================================================================== -->
   <!-- =========================================== DEFINITIONS ============================================ -->
   <!-- ==================================================================================================== -->
   <definitions>
      <definition id="oval:gov.nist.fdcc.patch:def:5" version="1" class="patch">
         <metadata>
            <title>MS05-013: Vulnerability in the DHTML Editing Component ActiveX Control Could Allow Remote Code Execution (891781)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS05-013" ref_url="http://www.microsoft.com/technet/security/bulletin/ms05-013.mspx"/>
            <reference source="Microsoft" ref_id="KB891781" ref_url="http://support.microsoft.com/kb/891781"/>
            <reference source="Bugtraq ID" ref_id="11950" ref_url="http://www.securityfocus.com/bid/11950"/>
            <reference source="CERT-VN" ref_id="VU#356600" ref_url="http://www.kb.cert.org/vuls/id/356600"/>
            <reference source="CIAC" ref_id="p-126" ref_url="http://www.ciac.org/ciac/bulletins/p-126.shtml"/>
            <reference source="CVE" ref_id="CVE-2004-1319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1319"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3851" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3851"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1701" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1701"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4758" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4758"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1114" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1114"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3464" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3464"/>
            <description>Microsoft has released MS05-013 to address security issues in Microsoft Internet Explorer as documented by CVE-2004-1319.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Dhtmled.ocx version is less than 6.1.0.9232" test_ref="oval:org.mitre.oval:tst:427"/>
            <criterion comment="the patch kb891781 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1151"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:7" version="1" class="patch">
         <metadata>
            <title>MS05-018: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege and Denial of Service (890859)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Windows kernel</product>
            </affected>
            <reference source="Microsoft" ref_id="MS05-018" ref_url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx"/>
            <reference source="Microsoft" ref_id="KB890859" ref_url="http://support.microsoft.com/kb/890859"/>
            <reference source="BID" ref_id="13109" ref_url="http://www.securityfocus.com/brefId/13109"/>
            <reference source="BID" ref_id="13110" ref_url="http://www.securityfocus.com/brefId/13110"/>
            <reference source="BID" ref_id="13115" ref_url="http://www.securityfocus.com/brefId/13115"/>
            <reference source="BID" ref_id="13121" ref_url="http://www.securityfocus.com/brefId/13121"/>
            <reference source="CIAC" ref_id="p-180" ref_url="http://www.ciac.org/ciac/bulletins/p-180.shtml"/>
            <reference source="CVE" ref_id="CVE-2005-0060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0060"/>
            <reference source="CVE" ref_id="CVE-2005-0061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0061"/>
            <reference source="CVE" ref_id="CVE-2005-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0550"/>
            <reference source="CVE" ref_id="CVE-2005-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0551"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:266" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:266"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4593" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4593"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4797" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4797"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3994" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3994"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:777" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:777"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3544" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3544"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2043" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2043"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1271" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1271"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3941" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3941"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4832" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4832"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1761" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1761"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1656" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1656"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2562" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2562"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4397" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4397"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2731" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2731"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1822" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1822"/>
            <description>Microsoft has released MS05-018 to address security issues in Windows kernel as documented by CVE-2005-0060, CVE-2005-0061, CVE-2005-0550, and CVE-2005-0551.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Ntoskrnl.exe version is less than 5.1.2600.2622" test_ref="oval:org.mitre.oval:tst:2738"/>
            <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:9" version="1" class="patch">
         <metadata>
            <title>MS05-026: Vulnerability in HTML Help Could Allow Remote Code Execution (896358)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>HTML Help Facility</product>
            </affected>
            <reference source="Microsoft" ref_id="MS05-026" ref_url="http://www.microsoft.com/technet/security/bulletin/ms05-026.mspx"/>
            <reference source="Microsoft" ref_id="KB896358" ref_url="http://support.microsoft.com/kb/896358"/>
            <reference source="BID" ref_id="13953" ref_url="http://www.securityfocus.com/brefId/13953"/>
            <reference source="CERT-VN" ref_id="VU#851869" ref_url="http://www.kb.cert.org/vuls/id/851869"/>
            <reference source="CIAC" ref_id="p-223" ref_url="http://www.ciac.org/ciac/bulletins/p-223.shtml"/>
            <reference source="CVE" ref_id="CVE-2005-1208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1208"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:381" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:381"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1057" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1057"/>
            <reference ref_id="http://www.microsoft.com/technet/security/bulletin/ms05-026.mspx" source="VENDOR" ref_url="http://www.microsoft.com/technet/security/bulletin/ms05-026.mspx"/>
            <description>Microsoft has released MS05-026 to address security issues in HTML Help Facility as documented by CVE-2005-1208.</description>
         </metadata>
         <criteria operator="AND" comment="for Windows XP (32-bit) SP2 a vulnerable version of hh.exe exists">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Hh.exe version is less than 5.2.3790.2453" test_ref="oval:org.mitre.oval:tst:1230"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:12" version="1" class="patch">
         <metadata>
            <title>MS05-033: Vulnerability in Telnet Client Could Allow Information Disclosure (896428)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Services for UNIX</product>
            </affected>
            <reference source="Microsoft" ref_id="MS05-033" ref_url="http://www.microsoft.com/technet/Security/bulletin/ms05-033.mspx"/>
            <reference source="Microsoft" ref_id="KB896428" ref_url="http://support.microsoft.com/kb/896428"/>
            <reference source="BID" ref_id="13940" ref_url="http://www.securityfocus.com/brefId/13940"/>
            <reference source="CERT-VN" ref_id="VU#800829" ref_url="http://www.kb.cert.org/vuls/id/800829"/>
            <reference source="CIAC" ref_id="p-230" ref_url="http://www.ciac.org/ciac/bulletins/p-230.shtml"/>
            <reference source="CVE" ref_id="CVE-2005-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1205"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1132" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1132"/>
            <description>Microsoft has released MS05-033 to address security issues in Services for UNIX as documented by CVE-2005-1205.</description>
         </metadata>
         <criteria operator="AND" comment="Software section">
            <criterion comment="Telnet.exe version is less than 5.1.2600.2674" test_ref="oval:org.mitre.oval:tst:1136"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:13" version="1" class="patch">
         <metadata>
            <title>MS05-036: Vulnerability in Microsoft Color Management Module Could Allow Remote Code Execution (901214)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Color Management Module</product>
            </affected>
            <reference source="Microsoft" ref_id="MS05-036" ref_url="http://www.microsoft.com/technet/Security/bulletin/ms05-036.mspx"/>
            <reference source="Microsoft" ref_id="KB901214" ref_url="http://support.microsoft.com/kb/901214"/>
            <reference source="BID" ref_id="14214" ref_url="http://www.securityfocus.com/brefId/14214"/>
            <reference source="CERT-VN" ref_id="VU#720742" ref_url="http://www.kb.cert.org/vuls/id/720742"/>
            <reference source="CIAC" ref_id="p-248" ref_url="http://www.ciac.org/ciac/bulletins/p-248.shtml"/>
            <reference source="CVE" ref_id="CVE-2005-1219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1219"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1125" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1125"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:440" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:440"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:330" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:330"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1280" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1280"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:769" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:769"/>
            <description>Microsoft has released MS05-036 to address security issues in Microsoft Color Management Module as documented by CVE-2005-1219.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Mscms.dll version is less than 5.1.2600.2709" test_ref="oval:org.mitre.oval:tst:2698"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:14" version="1" class="patch">
         <metadata>
            <title>MS05-040: Vulnerability in Telephony Service Could Allow Remote Code Execution (893756)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS05-040" ref_url="http://www.microsoft.com/technet/Security/bulletin/ms05-040.mspx"/>
            <reference source="Microsoft" ref_id="KB893756" ref_url="http://support.microsoft.com/kb/893756"/>
            <reference source="BID" ref_id="14518" ref_url="http://www.securityfocus.com/brefId/14518"/>
            <reference source="CIAC" ref_id="p-268" ref_url="http://www.ciac.org/ciac/bulletins/p-268.shtml"/>
            <reference source="CVE" ref_id="CVE-2005-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0058"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1297" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1297"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100084" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100084"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1075" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1075"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1213" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1213"/>
            <description>Microsoft has released MS05-040 to address security issues in the operating system as documented by CVE-2005-0058.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Tapisrv.dll version is less than 5.1.2600.2716" test_ref="oval:org.mitre.oval:tst:1194"/>
            <criterion comment="the Telephony service is enabled" test_ref="oval:org.mitre.oval:tst:1191"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:15" version="1" class="patch">
         <metadata>
            <title>MS05-041: Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (899591)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS05-041" ref_url="http://www.microsoft.com/technet/security/bulletin/ms05-041.mspx"/>
            <reference source="Microsoft" ref_id="KB899591" ref_url="http://support.microsoft.com/kb/899591"/>
            <reference source="BID" ref_id="14259" ref_url="http://www.securityfocus.com/brefId/14259"/>
            <reference source="CERT-VN" ref_id="VU#490628" ref_url="http://www.kb.cert.org/vuls/id/490628"/>
            <reference source="CVE" ref_id="CVE-2005-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1218"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:180" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:180"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:618" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:618"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100092" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100092"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:609" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:609"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:376" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:376"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:346" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:346"/>
            <description>Microsoft has released MS05-041 to address security issues in the operating system as documented by CVE-2005-1218.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion test_ref="oval:gov.nist.fdcc.patch:tst:11" comment="Rdpwd.sys version is less than 5.1.2600.2695"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:28" version="1" class="patch">
         <metadata>
            <title>MS06-002: Vulnerability in Embedded Web Fonts Could Allow Remote Code Execution (908519)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-002" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-002.mspx"/>
            <reference source="Microsoft" ref_id="KB908519" ref_url="http://support.microsoft.com/kb/908519"/>
            <reference source="BID" ref_id="16194" ref_url="http://www.securityfocus.com/brefId/16194"/>
            <reference source="CERT" ref_id="VU#915930" ref_url="http://www.kb.cert.org/vuls/refId/915930"/>
            <reference source="CVE" ref_id="CVE-2006-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0010"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1185" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1185"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1126" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1126"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1491" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1491"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1462" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1462"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:698" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:698"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:714" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:714"/>
            <description>Microsoft has released MS06-002 to address security issues in the operating system as documented by CVE-2006-0010.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criteria operator="OR" comment="Fontsub.dll &lt; 5.1.2600.2777 or T2embed.dll &lt;5.1.2600.2777 (WinXP,SP2)">
               <criterion comment="Fontsub.dll version is less than 5.1.2600.2777" test_ref="oval:org.mitre.oval:tst:2416"/>
               <criterion comment="T2embed.dll version is less than 5.1.2600.2777" test_ref="oval:org.mitre.oval:tst:2415"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:31" version="1" class="patch">
         <metadata>
            <title>MS06-009: Vulnerability in the Korean Input Method Editor Could Allow Elevation of Privilege (901190)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-009" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-009.mspx"/>
            <reference source="Microsoft" ref_id="KB901190" ref_url="http://support.microsoft.com/kb/901190"/>
            <reference source="Bugtraq ID" ref_id="16643" ref_url="http://www.securityfocus.com/bid/16643"/>
            <reference source="CERT-VN" ref_id="VU#739844" ref_url="http://www.kb.cert.org/vuls/id/739844"/>
            <reference source="CVE" ref_id="CVE-2006-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0008"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1688" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1688"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:727" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:727"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1650" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1650"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1595" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1595"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1664" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1664"/>
            <description>Microsoft has released MS06-009 to address security issues in the operating system as documented by CVE-2006-0008.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Imekr61.ime version is less than 6.1.2600.3 (WinXP)" test_ref="oval:org.mitre.oval:tst:783"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:38" version="1" class="patch">
         <metadata>
            <title>MS06-018: Vulnerability in Microsoft Distributed Transaction Coordinator Could Allow Denial of Service (913580)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-018" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-018.mspx"/>
            <reference source="Microsoft" ref_id="KB913580" ref_url="http://support.microsoft.com/kb/913580"/>
            <reference source="BID" ref_id="17905" ref_url="http://www.securityfocus.com/brefId/17905"/>
            <reference source="BID" ref_id="17906" ref_url="http://www.securityfocus.com/brefId/17906"/>
            <reference source="CVE" ref_id="CVE-2006-0034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0034"/>
            <reference source="CVE" ref_id="CVE-2006-1184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1184"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1477" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1477"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1912" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1912"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1908" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1908"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1222" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1222"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1779" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1779"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1990" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1990"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1295" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1295"/>
            <description>Microsoft has released MS06-018 to address security issues in the operating system as documented by CVE-2006-0034 and CVE-2006-1184.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Msdtctm.dll version is less than 2001.12.4414.311" test_ref="oval:org.mitre.oval:tst:670"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:41" version="1" class="patch">
         <metadata>
            <title>MS06-022: Vulnerability in ART Image Rendering Could Allow Remote Code Execution (918439)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-022" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-022.mspx"/>
            <reference source="Microsoft" ref_id="KB918439" ref_url="http://support.microsoft.com/kb/918439"/>
            <reference source="Bugtraq ID" ref_id="18394" ref_url="http://www.securityfocus.com/bid/18394"/>
            <reference source="CERT-VN" ref_id="VU#923236" ref_url="http://www.kb.cert.org/vuls/id/923236"/>
            <reference source="CVE" ref_id="CVE-2006-2378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2378"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1866" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1866"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1756" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1756"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1668" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1668"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1640" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1640"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1590" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1590"/>
            <description>Microsoft has released MS06-022 to address security issues in the operating system as documented by CVE-2006-2378.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Jgdw400.dll version is less than 106.0.0.0" test_ref="oval:org.mitre.oval:tst:835"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:44" version="1" class="patch">
         <metadata>
            <title>MS06-025: Vulnerability in Routing and Remote Access Could Allow Remote Code Execution (911280)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-025" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-025.mspx"/>
            <reference source="Microsoft" ref_id="KB911280" ref_url="http://support.microsoft.com/kb/911280"/>
            <reference source="Bugtraq ID" ref_id="18358" ref_url="http://www.securityfocus.com/bid/18358"/>
            <reference source="Bugtraq ID" ref_id="18325" ref_url="http://www.securityfocus.com/bid/18325"/>
            <reference source="CERT-VN" ref_id="VU#631516" ref_url="http://www.kb.cert.org/vuls/id/631516"/>
            <reference source="CERT-VN" ref_id="VU#814644" ref_url="http://www.kb.cert.org/vuls/id/814644"/>
            <reference source="CVE" ref_id="CVE-2006-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2370"/>
            <reference source="CVE" ref_id="CVE-2006-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2371"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1851" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1851"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2061" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2061"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1741" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1741"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1587" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1587"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1720" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1720"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1674" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1674"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1983" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1983"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1846" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1846"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1907" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1907"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1936" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1936"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1857" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1857"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1823" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1823"/>
            <description>Microsoft has released MS06-025 to address security issues in the operating system as documented by CVE-2006-2370 and CVE-2006-2371.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Rasmans.dll version is less than 5.1.2600.2908" test_ref="oval:org.mitre.oval:tst:705"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:48" version="1" class="patch">
         <metadata>
            <title>MS06-030: Vulnerability in Server Message Block Could Allow Elevation of Privilege (914389)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-030" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-030.mspx"/>
            <reference source="Microsoft" ref_id="KB914389" ref_url="http://support.microsoft.com/kb/914389"/>
            <reference source="BID" ref_id="18357" ref_url="http://www.securityfocus.com/brefId/18357"/>
            <reference source="BID" ref_id="18356" ref_url="http://www.securityfocus.com/brefId/18356"/>
            <reference source="CVE" ref_id="CVE-2006-2373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2373"/>
            <reference source="CVE" ref_id="CVE-2006-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2374"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1979" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1979"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1792" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1792"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1841" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1841"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2007" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2007"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1942" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1942"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1730" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1730"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2060" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2060"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2030" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2030"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1827" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1827"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1904" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1904"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1137" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1137"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1850" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1850"/>
            <description>Microsoft has released MS06-030 to address security issues in the operating system as documented by CVE-2006-2373 and CVE-2006-2374.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Mrxsmb.sys version is less than 5.1.2600.2902" test_ref="oval:org.mitre.oval:tst:692"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:57" version="1" class="patch">
         <metadata>
            <title>MS06-041: Vulnerabilities in DNS Resolution Could Allow Remote Code Execution (920683)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-041" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-041.mspx"/>
            <reference source="Microsoft" ref_id="KB920683" ref_url="http://support.microsoft.com/kb/920683"/>
            <reference source="CERT-VN" ref_id="VU#794580" ref_url="http://www.kb.cert.org/vuls/id/794580"/>
            <reference source="CERT-VN" ref_id="VU#908276" ref_url="http://www.kb.cert.org/vuls/id/908276"/>
            <reference source="CVE" ref_id="CVE-2006-3440" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3440"/>
            <reference source="CVE" ref_id="CVE-2006-3441" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3441"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:747" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:747"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:723" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:723"/>
            <description>Microsoft has released MS06-041 to address security issues in the operating system as documented by CVE-2006-3440 and CVE-2006-3441.</description>
         </metadata>
         <criteria comment="WinXP,SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Dnsapi.dll version is less than 5.1.2600.2938" test_ref="oval:org.mitre.oval:tst:198"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:163" version="1" class="patch">
         <metadata>
            <title>MS05-042: Vulnerabilities in Kerberos Could Allow Denial of Service, Information Disclosure, and Spoofing (899587)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS05-042" ref_url="http://www.microsoft.com/technet/Security/bulletin/ms05-042.mspx"/>
            <reference source="Microsoft" ref_id="KB899587" ref_url="http://support.microsoft.com/kb/899587"/>
            <reference source="BID" ref_id="14519" ref_url="http://www.securityfocus.com/brefId/14519"/>
            <reference source="BID" ref_id="14520" ref_url="http://www.securityfocus.com/brefId/14520"/>
            <reference source="CVE" ref_id="CVE-2005-1981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1981"/>
            <reference source="CVE" ref_id="CVE-2005-1982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1982"/>
            <reference source="CERT-VN" ref_id="VU#477341" ref_url="http://www.kb.cert.org/vuls/id/477341"/>
            <reference source="CERT-VN" ref_id="VU#610133" ref_url="http://www.kb.cert.org/vuls/id/610133"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100106" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100106"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100105" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100105"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100104" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100104"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100103" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100103"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100102" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100102"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100101" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100101"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100100" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100100"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100099" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100099"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100098" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100098"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100097" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100097"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100096" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100096"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100095" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100095"/>
            <description>Microsoft has released MS05-042 to address security issues in the operating system as documented by CVE-2005-1981 and CVE-2005-1982.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Kerberos.dll version is less than 5.1.2600.2698" test_ref="oval:org.mitre.oval:tst:220"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:173" version="1" class="patch">
         <metadata>
            <title>MS05-043: Vulnerability in Print Spooler Service Could Allow Remote Code Execution (896423)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Print Spooler Service</product>
            </affected>
            <reference source="Microsoft" ref_id="MS05-043" ref_url="http://www.microsoft.com/technet/Security/bulletin/ms05-043.mspx"/>
            <reference source="Microsoft" ref_id="KB896423" ref_url="http://support.microsoft.com/kb/896423"/>
            <reference source="BID" ref_id="14514" ref_url="http://www.securityfocus.com/brefId/14514"/>
            <reference source="CERT" ref_id="TA05-221A" ref_url="http://www.kb.cert.org/vuls/refId/5-221A"/>
            <reference source="CERT-VN" ref_id="VU#220821" ref_url="http://www.kb.cert.org/vuls/id/220821"/>
            <reference source="CIAC" ref_id="p-267" ref_url="http://www.ciac.org/ciac/bulletins/p-267.shtml"/>
            <reference source="CVE" ref_id="CVE-2005-1984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1984"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:256" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:256"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1045" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1045"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1405" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1405"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:100077" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100077"/>
            <description>Microsoft has released MS05-043 to address security issues in Print Spooler Service as documented by CVE-2005-1984.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Spoolsv.exe version is less than 5.1.2600.2696" test_ref="oval:gov.nist.fdcc.patch:tst:21"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:214" version="1" class="patch">
         <metadata>
            <title>MS05-047: Vulnerability in Plug and Play Could Allow Remote Code Execution and Local Elevation of Privilege (905749)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS05-047" ref_url="http://www.microsoft.com/technet/security/bulletin/ms05-047.mspx"/>
            <reference source="Microsoft" ref_id="KB905749" ref_url="http://support.microsoft.com/kb/905749"/>
            <reference source="Bugtraq ID" ref_id="15065" ref_url="http://www.securityfocus.com/bid/15065"/>
            <reference source="CERT-VN" ref_id="VU#214572" ref_url="http://www.kb.cert.org/vuls/id/214572"/>
            <reference source="CVE" ref_id="CVE-2005-2120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2120"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1328" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1328"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1519" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1519"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1244" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1244"/>
            <description>Microsoft has released MS05-047 to address security issues in the operating system as documented by CVE-2005-2120.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Umpnpmgr.dll version is less than 5.1.2600.2744" test_ref="oval:org.mitre.oval:tst:882"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:221" version="1" class="patch">
         <metadata>
            <title>MS05-048: Vulnerability in the Microsoft Collaboration Data Objects Could Allow Remote Code Execution (907245)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS05-048" ref_url="http://www.microsoft.com/technet/security/bulletin/ms05-048.mspx"/>
            <reference source="Microsoft" ref_id="KB907245" ref_url="http://support.microsoft.com/kb/907245"/>
            <reference source="Bugtraq ID" ref_id="15067" ref_url="http://www.securityfocus.com/bid/15067"/>
            <reference source="CERT-VN" ref_id="VU#883460" ref_url="http://www.kb.cert.org/vuls/id/883460"/>
            <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1130" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1130"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1420" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1420"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:581" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:581"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1201" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1201"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1515" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1515"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1406" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1406"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:848" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:848"/>
            <description>Microsoft has released MS05-048 to address security issues in the operating system as documented by CVE-2005-1987.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Cdosys.dll version is less than 6.2.4.0" test_ref="oval:org.mitre.oval:tst:884"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:229" version="3" class="patch">
         <metadata>
            <title>MS06-078: Vulnerability in Windows Media Format Could Allow Remote Code Execution (923689)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-078" ref_url="http://www.microsoft.com/technet/security/bulletin/MS06-078.mspx"/>
            <reference source="Microsoft" ref_id="KB923689" ref_url="http://support.microsoft.com/kb/923689"/>
            <reference source="CVE" ref_id="CVE-2006-4702" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4702"/>
            <reference source="CVE" ref_id="CVE-2006-6134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6134"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:536" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:536"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:669" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:669"/>
            <description>Microsoft has released MS06-078 to address security issues in Windows Media Player as documented by CVE-2006-4702 and CVE-2006-6134.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion test_ref="oval:org.mitre.oval:tst:100" comment="Media Player 8 (v6.4) is installed."/>
               <criterion test_ref="oval:org.mitre.oval:tst:96" comment="Dxmasf.dll version is less than 6.4.9.1133"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion test_ref="oval:org.mitre.oval:tst:125" comment="Wmvcore.dll for Windows Media Format 9.0 is installed."/>
               <criterion test_ref="oval:org.mitre.oval:tst:112" comment="Wmvcore.dll version is less than 9.0.0.3265"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion test_ref="oval:org.mitre.oval:tst:125" comment="Wmvcore.dll for Windows Media Format 9.0 is installed."/>
               <criterion test_ref="oval:gov.nist.fdcc.patch:tst:2291" comment="Wmvcore.dll version is greater than or equal to 9.0.0.3300"/>
               <criterion test_ref="oval:gov.nist.fdcc.patch:tst:2292" comment="Wmvcore.dll version is less than 9.0.0.3353"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
               <criterion test_ref="oval:org.mitre.oval:tst:191" comment="Wmvcore.dll version is less than 10.0.0.3702"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
               <criterion test_ref="oval:gov.nist.fdcc.patch:tst:2293" comment="Wmvcore.dll version is greater than or equal to 10.0.0.4000"/>
               <criterion test_ref="oval:gov.nist.fdcc.patch:tst:2294" comment="Wmvcore.dll version is less than 10.0.0.4054"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
               <criterion test_ref="oval:gov.nist.fdcc.patch:tst:2295" comment="Wmvcore.dll version is greater than or equal to 10.0.0.4300"/>
               <criterion test_ref="oval:gov.nist.fdcc.patch:tst:2296" comment="Wmvcore.dll version is less than 10.0.0.4357"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:230" version="1" class="patch">
         <metadata>
            <title>MS06-075: Vulnerability in Windows Could Allow Elevation of Privilege (926255)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-075" ref_url="http://www.microsoft.com/technet/security/bulletin/MS06-075.mspx"/>
            <reference source="Microsoft" ref_id="KB926255" ref_url="http://support.microsoft.com/kb/926255"/>
            <reference source="CVE" ref_id="CVE-2006-5585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5585"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:560" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:560"/>
            <description>Microsoft has released MS06-075 to address security issues in the operating system as documented by CVE-2006-5585.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Sxs.dll version is less than 5.1.2600.3019" test_ref="oval:org.mitre.oval:tst:137"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:231" version="1" class="patch">
         <metadata>
            <title>MS05-049: Vulnerabilities in Windows Shell Could Allow Remote Code Execution (900725)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS05-049" ref_url="http://www.microsoft.com/technet/security/bulletin/ms05-049.mspx"/>
            <reference source="Microsoft" ref_id="KB900725" ref_url="http://support.microsoft.com/kb/900725"/>
            <reference source="Bugtraq ID" ref_id="15064" ref_url="http://www.securityfocus.com/bid/15064"/>
            <reference source="Bugtraq ID" ref_id="15069" ref_url="http://www.securityfocus.com/bid/15069"/>
            <reference source="Bugtraq ID" ref_id="15070" ref_url="http://www.securityfocus.com/bid/15070"/>
            <reference source="CERT-VN" ref_id="VU#922708" ref_url="http://www.kb.cert.org/vuls/id/922708"/>
            <reference source="CVE" ref_id="CVE-2005-2117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2117"/>
            <reference source="CVE" ref_id="CVE-2005-2118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2118"/>
            <reference source="CVE" ref_id="CVE-2005-2122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2122"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:708" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:708"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1291" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1291"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1551" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1551"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1517" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1517"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1329" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1329"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1116" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1116"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1488" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1488"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1537" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1537"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1192" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1192"/>
            <description>Microsoft has released MS05-049 to address security issues in the operating system as documented by CVE-2005-2117, CVE-2005-2118, and CVE-2005-2122.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Shell32.dll version is less than 6.0.2900.2763" test_ref="oval:org.mitre.oval:tst:883"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:232" version="1" class="patch">
         <metadata>
            <title>MS06-074: Vulnerability in SNMP Could Allow Remote Code Execution (926247)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-074" ref_url="http://www.microsoft.com/technet/security/bulletin/MS06-074.mspx"/>
            <reference source="Microsoft" ref_id="KB926247" ref_url="http://support.microsoft.com/kb/926247"/>
            <reference source="CVE" ref_id="CVE-2006-5583" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5583"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1047" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1047"/>
            <description>Microsoft has released MS06-074 to address security issues in the operating system as documented by CVE-2006-5583.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Snmp.exe version is less than 5.1.2600.3038" test_ref="oval:org.mitre.oval:tst:119"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:241" version="1" class="patch">
         <metadata>
            <title>MS05-050: Vulnerability in DirectShow Could Allow Remote Code Execution (904706)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>DirectX</product>
            </affected>
            <reference source="Microsoft" ref_id="MS05-050" ref_url="http://www.microsoft.com/technet/security/bulletin/MS05-050.mspx"/>
            <reference source="Microsoft" ref_id="KB904706" ref_url="http://support.microsoft.com/kb/904706"/>
            <reference source="Bugtraq ID" ref_id="15063" ref_url="http://www.securityfocus.com/bid/15063"/>
            <reference source="CERT-VN" ref_id="VU#995220" ref_url="http://www.kb.cert.org/vuls/id/995220"/>
            <reference source="CVE" ref_id="CVE-2005-2128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2128"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1231" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1231"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1149" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1149"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1434" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1434"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1424" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1424"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1267" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1267"/>
            <description>Microsoft has released MS05-050 to address security issues in DirectX as documented by CVE-2005-2128.</description>
         </metadata>
         <criteria operator="AND" comment="DirectX packaged with Windows XP,SP2 has DirectShow Vulnerability">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Quartz.dll version is greater than or equal to 6.5.2600.0" test_ref="oval:org.mitre.oval:tst:1064"/>
            <criterion comment="Quartz.dll version is less than 6.5.2600.2749" test_ref="oval:org.mitre.oval:tst:1063"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:267" version="1" class="patch">
         <metadata>
            <title>MS07-005: Vulnerability in Step-by-Step Interactive Training Could Allow Remote Code Execution (923723)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Interactive Training</product>
            </affected>
            <reference source="Microsoft" ref_id="MS07-005" ref_url="http://www.microsoft.com/technet/security/bulletin/MS07-005.mspx"/>
            <reference source="Microsoft" ref_id="KB923723" ref_url="http://support.microsoft.com/kb/923723"/>
            <reference source="CVE" ref_id="CVE-2006-3448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3448"/>
            <description>Microsoft has released MS07-005 to address security issues in Microsoft Interactive Training as documented by CVE-2006-3448.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <criterion comment="Orun32.dll version is less than 3.5.0.118" test_ref="oval:org.mitre.oval:tst:3436"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:268" version="1" class="patch">
         <metadata>
            <title>MS07-006: Vulnerability in Windows Shell Could Allow Elevation of Privilege (928255)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-006" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-006.mspx"/>
            <reference source="Microsoft" ref_id="KB928255" ref_url="http://support.microsoft.com/kb/928255"/>
            <reference source="CVE" ref_id="CVE-2007-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0211"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:224" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:224"/>
            <description>Microsoft has released MS07-006 to address security issues in Operating System as documented by CVE-2007-0211.</description>
         </metadata>
         <criteria comment="Microsoft Windows XP Service Pack 2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Shell32.dll version is less than 6.0.2900.3051" test_ref="oval:org.mitre.oval:tst:3365"/>
            <criterion comment="Shsvcs.dll version is less than 6.0.2900.3051" test_ref="oval:gov.nist.fdcc.patch:tst:115283"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:269" version="1" class="patch">
         <metadata>
            <title>MS07-007: Vulnerability in Windows Image Acquisition Service Could Allow Elevation of Privilege (927802)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-007" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-007.mspx"/>
            <reference source="Microsoft" ref_id="KB927802" ref_url="http://support.microsoft.com/kb/927802"/>
            <reference source="Bugtraq ID" ref_id="20704" ref_url="http://www.securityfocus.com/bid/20704"/>
            <reference source="CERT-VN" ref_id="VU#589272" ref_url="http://www.kb.cert.org/vuls/id/589272"/>
            <reference source="CVE" ref_id="CVE-2007-0210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0210"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:186" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:186"/>
            <description>Microsoft has released MS07-007 to address security issues in Operating System as documented by CVE-2007-0210.</description>
         </metadata>
         <criteria comment="Microsoft Windows XP Service Pack 2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Wiaservc.dll version is less than 5.1.2600.3051" test_ref="oval:org.mitre.oval:tst:3227"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:270" version="1" class="patch">
         <metadata>
            <title>MS07-008: Vulnerability in HTML Help ActiveX Control Could Allow Remote Code Execution (928843)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-008" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-008.mspx"/>
            <reference source="Microsoft" ref_id="KB928843" ref_url="http://support.microsoft.com/kb/928843"/>
            <reference source="CVE" ref_id="CVE-2007-0214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0214"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:125" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:125"/>
            <description>Microsoft has released MS07-008 to address security issues in Operating System as documented by CVE-2007-0214.</description>
         </metadata>
         <criteria comment="WinXP,SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Hhctrl.ocx version is less than 5.2.3790.2847" test_ref="oval:org.mitre.oval:tst:3154"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:271" version="1" class="patch">
         <metadata>
            <title>MS07-009: Vulnerability in Microsoft Data Access Components Could Allow Remote Code Execution (927779)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-009" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-009.mspx"/>
            <reference source="Microsoft" ref_id="KB927779" ref_url="http://support.microsoft.com/kb/927779"/>
            <reference source="CVE" ref_id="CVE-2006-5559" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5559"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:214" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:214"/>
            <description>Microsoft has released MS07-009 to address security issues in Operating System as documented by CVE-2006-5559.</description>
         </metadata>
         <criteria comment="Windows XP SP2 with MDAC 2.8 SP1" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Microsoft Data Access Components 2.8 (SP1) is installed" test_ref="oval:org.mitre.oval:tst:725"/>
            <criterion comment="Msado15.dll version is less than 2.81.1128.0" test_ref="oval:org.mitre.oval:tst:3821"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:272" version="1" class="patch">
         <metadata>
            <title>MS07-011: Vulnerability in Microsoft OLE Dialog Could Allow Remote Code Execution (926436)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Interactive Training</product>
            </affected>
            <reference source="Microsoft" ref_id="MS07-011" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-011.mspx"/>
            <reference source="Microsoft" ref_id="KB926436" ref_url="http://support.microsoft.com/kb/926436"/>
            <reference source="CVE" ref_id="CVE-2007-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0026"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:540" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:540"/>
            <description>Microsoft has released MS07-011 to address security issues in Microsoft Interactive Training as documented by CVE-2007-0026.</description>
         </metadata>
         <criteria comment="WinXP,SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Oledlg.dll version is less than 5.1.2600.3016" test_ref="oval:org.mitre.oval:tst:3286"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:273" version="1" class="patch">
         <metadata>
            <title>MS07-012: Vulnerability in Microsoft MFC Could Allow Remote Code Execution (924667)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-012" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-012.mspx"/>
            <reference source="Microsoft" ref_id="KB924667" ref_url="http://support.microsoft.com/kb/924667"/>
            <reference source="CVE" ref_id="CVE-2007-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0025"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:157" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:157"/>
            <description>Microsoft has released MS07-012 to address security issues in Operating System as documented by CVE-2007-0025.</description>
         </metadata>
         <criteria comment="Windows XP (32-bit) SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Mfc40u.dll version is less than 4.1.0.6141" test_ref="oval:org.mitre.oval:tst:3685"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:274" version="1" class="patch">
         <metadata>
            <title>MS07-013: Vulnerability in Microsoft RichEdit Could Allow Remote Code Execution (918118)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-013" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-013.mspx"/>
            <reference source="Microsoft" ref_id="KB918118" ref_url="http://support.microsoft.com/kb/918118"/>
            <reference source="CVE" ref_id="CVE-2006-1311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1311"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1090" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1090"/>
            <description>Microsoft has released MS07-013 to address security issues in Operating System as documented by CVE-2006-1311.</description>
         </metadata>
         <criteria comment="Windows XP (32-bit) SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Riched20.dll version is less than 5.30.23.1228" test_ref="oval:org.mitre.oval:tst:3159"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:287" version="1" class="patch">
         <metadata>
            <title>MS07-017: Vulnerabilities in GDI Could Allow Remote Code Execution (925902)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-017" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-017.mspx"/>
            <reference source="Microsoft" ref_id="KB925902" ref_url="http://support.microsoft.com/kb/925902"/>
            <reference source="CVE" ref_id="CVE-2006-5586" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5586"/>
            <reference source="CVE" ref_id="CVE-2006-5758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5758"/>
            <reference source="CVE" ref_id="CVE-2007-0038" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0038"/>
            <reference source="CVE" ref_id="CVE-2007-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1211"/>
            <reference source="CVE" ref_id="CVE-2007-1212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1212"/>
            <reference source="CVE" ref_id="CVE-2007-1215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1215"/>
            <reference source="Bugtraq ID" ref_id="20940" ref_url="http://www.securityfocus.com/bid/20940"/>
            <reference source="CERT-VN" ref_id="VU#191609" ref_url="http://www.kb.cert.org/vuls/id/191609"/>
            <description>Microsoft has released MS07-017 to address security issues in Operating System as documented by CVE-2006-5586, CVE-2006-5758, CVE-2007-0038, CVE-2007-1211, CVE-2007-1212, CVE-2007-1213, and CVE-2007-1215.</description>
         </metadata>
         <criteria operator="OR">
            <criteria comment="Windows XP (32-bit) SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Gdi32.dll version is less than 5.1.2600.3099" test_ref="oval:org.mitre.oval:tst:3215"/>
               <criterion comment="Win32k.sys version is less than 5.1.2600.3099" test_ref="oval:gov.nist.fdcc.patch:tst:115284"/>
            </criteria>
            <criteria comment="Windows XP (64-bit) SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Gdi32.dll version is less than 5.2.3790.4033" test_ref="oval:org.mitre.oval:tst:3612"/>
               <criterion comment="Win32k.sys version is less than 5.2.3790.4033" test_ref="oval:gov.nist.fdcc.patch:tst:115285"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:289" version="1" class="patch">
         <metadata>
            <title>MS07-019: Vulnerability in Universal Plug and Play Could Allow Remote Code Execution (931261)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-019" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-019.mspx"/>
            <reference source="Microsoft" ref_id="KB931261" ref_url="http://support.microsoft.com/kb/931261"/>
            <reference source="CVE" ref_id="CVE-2007-1204" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1204"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2049" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2049"/>
            <description>Microsoft has released MS07-019 to address security issues in Operating System as documented by CVE-2007-1204.</description>
         </metadata>
         <criteria operator="OR">
            <criteria comment="WinXP SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Upnphost.dll version is less than 5.1.2600.3077" test_ref="oval:org.mitre.oval:tst:3717"/>
            </criteria>
            <criteria comment="WinXP SP2 (64-bit)" operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Upnphost.dll version is less than 5.2.3790.4019" test_ref="oval:org.mitre.oval:tst:3573"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:290" version="1" class="patch">
         <metadata>
            <title>MS07-020: Vulnerability in Microsoft Agent Could Allow Remote Code Execution (932168)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2007-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1205"/>
            <reference source="Microsoft" ref_id="MS07-020" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-020.mspx"/>
            <reference source="Microsoft" ref_id="KB932168" ref_url="http://support.microsoft.com/kb/932168"/>
            <description>Microsoft has released MS07-020 to address security issues in Operating System as documented by CVE-2007-1205.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Agentdpv.dll version is less than 2.0.0.3425" test_ref="oval:org.mitre.oval:tst:4156"/>
            </criteria>
            <criteria comment="Windows XP Service Pack Service Pack 2(64-bit)" operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Agentdpv.dll version is less than 5.2.3790.1243" test_ref="oval:org.mitre.oval:tst:3462"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:291" version="2" class="patch">
         <metadata>
            <title>MS07-021: Vulnerabilities in CSRSS Could Allow Remote Code Execution (930178)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2006-6696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6696"/>
            <reference source="CVE" ref_id="CVE-2006-6797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6797"/>
            <reference source="Microsoft" ref_id="MS07-021" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-021.mspx"/>
            <reference source="Bugtraq ID" ref_id="21688" ref_url="http://www.securityfocus.com/bid/21688"/>
            <reference source="Microsoft" ref_id="KB930178" ref_url="http://support.microsoft.com/kb/930178"/>
            <description>Microsoft has released MS07-021 to address security issues in Microsoft Windows XP as documented by CVE-2006-6696, CVE-2006-6797, and CVE-2007-1209.</description>
         </metadata>
         <criteria operator="OR">
            <criteria comment="Windows XP SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Winsrv.dll version is less than 5.1.2600.3103" test_ref="oval:org.mitre.oval:tst:3654"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:293" version="1" class="patch">
         <metadata>
            <title>MS06-006: Vulnerability in Windows Media Player Plug-in with Non-Microsoft Internet Browsers Could Allow Remote Code Execution (911564)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Windows Media Player</product>
            </affected>
            <reference source="Microsoft" ref_id="MS06-006" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-006.mspx"/>
            <reference source="Microsoft" ref_id="KB911564" ref_url="http://support.microsoft.com/kb/911564"/>
            <reference source="Bugtraq ID" ref_id="16644" ref_url="http://www.securityfocus.com/bid/16644"/>
            <reference source="CERT-VN" ref_id="VU#692060" ref_url="http://www.kb.cert.org/vuls/id/692060"/>
            <reference source="CVE" ref_id="CVE-2006-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0005"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1559" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1559"/>
            <description>Microsoft has released MS06-006 to address security issues in Windows Media Player as documented by CVE-2006-0005.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Npdsplay.dll version is less than 3.0.2.629" test_ref="oval:org.mitre.oval:tst:858"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:301" version="1" class="patch">
         <metadata>
            <title>MS06-008: Vulnerability in Web Client Service Could Allow Remote Code Execution (911927)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-008" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-008.mspx"/>
            <reference source="Microsoft" ref_id="KB911927" ref_url="http://support.microsoft.com/kb/911927"/>
            <reference source="Bugtraq ID" ref_id="16636" ref_url="http://www.securityfocus.com/bid/16636"/>
            <reference source="CERT-VN" ref_id="VU#388900" ref_url="http://www.kb.cert.org/vuls/id/388900"/>
            <reference source="CVE" ref_id="CVE-2006-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0013"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1602" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1602"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:683" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:683"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1547" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1547"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1220" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1220"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:716" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:716"/>
            <description>Microsoft has released MS06-008 to address security issues in the operating system as documented by CVE-2006-0013.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Webclnt.dll version is less than 5.1.2600.2821 (XP,SP2)" test_ref="oval:org.mitre.oval:tst:830"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:341" version="1" class="patch">
         <metadata>
            <title>MS06-014: Vulnerability in the Microsoft Data Access Components (MDAC) Function Could Allow Code Execution (911562)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>MDAC</product>
            </affected>
            <reference source="Microsoft" ref_id="MS06-014" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-014.mspx"/>
            <reference source="Microsoft" ref_id="KB911562" ref_url="http://support.microsoft.com/kb/911562"/>
            <reference source="BID" ref_id="17462" ref_url="http://www.securityfocus.com/brefId/17462"/>
            <reference source="CERT" ref_id="VU#234812" ref_url="http://www.kb.cert.org/vuls/refId/234812"/>
            <reference source="CVE" ref_id="CVE-2006-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0003"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1204" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1204"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1511" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1511"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1778" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1778"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1323" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1323"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1742" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1742"/>
            <description>Microsoft has released MS06-014 to address security issues in MDAC as documented by CVE-2006-0003.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Msadco.dll version is less than 2.81.1124.0" test_ref="oval:org.mitre.oval:tst:1079"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:351" version="1" class="patch">
         <metadata>
            <title>MS06-015: Vulnerability in Windows Explorer Could Allow Remote Code Execution (908531)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-015" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-015.mspx"/>
            <reference source="Microsoft" ref_id="KB908531" ref_url="http://support.microsoft.com/kb/908531"/>
            <reference source="BID" ref_id="17464" ref_url="http://www.securityfocus.com/brefId/17464"/>
            <reference source="CERT" ref_id="VU#641460" ref_url="http://www.kb.cert.org/vuls/refId/641460"/>
            <reference source="CVE" ref_id="CVE-2006-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0012"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1448" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1448"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1764" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1764"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1679" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1679"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1743" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1743"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1191" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1191"/>
            <description>Microsoft has released MS06-015 to address security issues in the operating system as documented by CVE-2006-0012.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Shell32.dll version is less than 6.0.2900.2869" test_ref="oval:org.mitre.oval:tst:925"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:371" version="1" class="patch">
         <metadata>
            <title>MS06-017: Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting (917627)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>FrontPage Server Extensions</product>
            </affected>
            <reference source="Microsoft" ref_id="MS06-017" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS06-017.mspx"/>
            <reference source="Microsoft" ref_id="KB917627" ref_url="http://support.microsoft.com/kb/917627"/>
            <reference source="Bugtraq ID" ref_id="17452" ref_url="http://www.securityfocus.com/bid/17452"/>
            <reference source="CVE" ref_id="CVE-2006-0015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0015"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1748" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1748"/>
            <description>Microsoft has released MS06-017 to address security issues in FrontPage Server Extensions as documented by CVE-2006-0015.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Fpadmdll.dll version is less than 10.0.6790.0" test_ref="oval:org.mitre.oval:tst:744"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:400" version="4" class="patch">
         <metadata>
            <title>MS08-030: Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (951376)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-1453" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1453"/>
            <reference source="Microsoft" ref_id="MS08-030" ref_url="http://www.microsoft.com/technet/security/bulletin/MS08-030.mspx"/>
            <reference source="Microsoft" ref_id="KB951376" ref_url="http://support.microsoft.com/kb/951376"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4730" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4730"/>
            <description>Microsoft has released MS08-030 to address security issues in Internet Explorer as documented by CVE-2008-1453.</description>
         </metadata>
         <criteria operator="AND">
            <criterion comment="Bthport.sys does exist" negate="true" test_ref="oval:org.mitre.oval:tst:7805"/>
            <criteria operator="OR">
               <criteria operator="AND" comment="Windows XP (32-bit) SP2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <criterion comment="Bthport.sys version is less than 5.1.2600.3351" test_ref="oval:org.mitre.oval:tst:7093"/>
               </criteria>
               <criteria operator="AND" comment="Windows XP (64-bit) SP2">
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <criterion comment="Bthport.sys version is less than 5.2.3790.4274" test_ref="oval:gov.nist.fdcc.patch:tst:115281"/>
               </criteria>
               <criteria operator="AND" comment="Windows XP Service Pack 3">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <criterion comment="Bthport.sys version is less than 5.1.2600.5580" test_ref="oval:org.mitre.oval:tst:8009"/>
               </criteria>
               <criteria operator="AND" comment="Windows Vista Service Pack 1 - GDR">
                  <criteria operator="OR">
                     <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                     <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  </criteria>
                  <criterion comment="Bthport.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:7492"/>
                  <criterion comment="Bthport.sys version is less than 6.0.6001.18064" test_ref="oval:org.mitre.oval:tst:7491"/>
               </criteria>
               <criteria operator="AND" comment="Windows Vista Service Pack 1 - LDR">
                  <criteria operator="OR">
                     <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                     <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  </criteria>
                  <criterion comment="Bthport.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:7493"/>
                  <criterion comment="Bthport.sys version is less than 6.0.6001.22168" test_ref="oval:org.mitre.oval:tst:7494"/>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:402" version="1" class="patch">
         <metadata>
            <title>MS08-032: Cumulative Security Update of ActiveX Kill Bits (950760)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS08-032" ref_url="http://www.microsoft.com/technet/security/bulletin/MS08-032.mspx"/>
            <reference source="Microsoft" ref_id="KB950760" ref_url="http://support.microsoft.com/kb/950760"/>
            <reference source="CVE" ref_id="CVE-2007-0675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0675"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5489" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5489"/>
            <description>Microsoft has released MS08-032 to address security issues in Internet Explorer as documented by CVE-2007-0675.</description>
         </metadata>
         <criteria operator="AND">
            <criteria operator="OR">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
               <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
               <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            </criteria>
            <criteria operator="OR">
               <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{40F23EB7-B397-4285-8F3C-AACE4FA40309}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:7937"/>
               <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{40F23EB7-B397-4285-8F3C-AACE4FA40309}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:7734"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:405" version="1" class="patch">
         <metadata>
            <title>MS08-036: Vulnerabilities in Pragmatic General Multicast (PGM) Could Allow Denial of Service (950762)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS08-036" ref_url="http://www.microsoft.com/technet/security/bulletin/MS08-036.mspx"/>
            <reference source="Microsoft" ref_id="KB950762" ref_url="http://support.microsoft.com/kb/950762"/>
            <reference source="CVE" ref_id="CVE-2008-1440" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1440"/>
            <reference source="CVE" ref_id="CVE-2008-1441" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1441"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5473" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5473"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5604" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5604"/>
            <description>Microsoft has released MS08-036 to address security issues in Internet Explorer as documented by CVE-2008-1440 and CVE-2008-1441.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Rmcast.sys version is less than 5.1.2600.3369." test_ref="oval:org.mitre.oval:tst:8091"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Rmcast.sys version is less than 5.1.2600.5598." test_ref="oval:org.mitre.oval:tst:7565"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Rmcast.sys version is less than 5.2.3790.4290." test_ref="oval:org.mitre.oval:tst:7634"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criterion comment="Rmcast.sys version is greater than or equal to 6.0.6001.18000." test_ref="oval:gov.nist.fdcc.patch:tst:115266"/>
               <criterion comment="Rmcast.sys version is less than 6.0.6001.18069." test_ref="oval:gov.nist.fdcc.patch:tst:115267"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criterion comment="Rmcast.sys version is greater than or equal to 6.0.6001.22000." test_ref="oval:gov.nist.fdcc.patch:tst:115268"/>
               <criterion comment="Rmcast.sys version is less than 6.0.6001.22176." test_ref="oval:gov.nist.fdcc.patch:tst:115269"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:431" version="1" class="patch">
         <metadata>
            <title>MS07-031: Vulnerability in the Windows Schannel Security Package Could Allow Remote Code Execution (935840)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-031" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-031.mspx"/>
            <reference source="Microsoft" ref_id="KB935840" ref_url="http://support.microsoft.com/kb/935840"/>
            <reference source="CVE" ref_id="CVE-2007-2218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2218"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1895" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1895"/>
            <description>Microsoft has released MS07-031 to address security issues in Operating System as documented by CVE-2007-2218.</description>
         </metadata>
         <criteria operator="OR">
            <criteria comment="Windows XP (32-bit) SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Schannel.dll version is less than 5.1.2600.3126" test_ref="oval:org.mitre.oval:tst:3933"/>
            </criteria>
            <criteria comment="Windows XP (64-bit) SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Schannel.dll version is less than 5.2.3790.4068" test_ref="oval:org.mitre.oval:tst:3754"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:449" version="2" class="patch">
         <metadata>
            <title>MS07-040: Vulnerabilities in .NET Framework Could Allow Remote Code Execution (931212)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>.NET Framework</product>
            </affected>
            <reference source="Microsoft" ref_id="MS07-040" ref_url="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx"/>
            <reference source="Microsoft" ref_id="KB931212" ref_url="http://support.microsoft.com/kb/931212"/>
            <reference source="CVE" ref_id="CVE-2007-0041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0041"/>
            <reference source="CVE" ref_id="CVE-2007-0042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0042"/>
            <reference source="CVE" ref_id="CVE-2007-0043" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0043"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2070" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2070"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2093" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2093"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1873" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1873"/>
            <description>Microsoft has released MS07-040 to address security issues in .NET Framework as documented by CVE-2007-0041, CVE-2007-0042, and CVE-2007-0043.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed" definition_ref="oval:org.mitre.oval:def:2136"/>
               <criterion comment="System.web.dll version is less than 1.0.3705.6060" test_ref="oval:org.mitre.oval:tst:4154"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
               <criterion comment="System.web.dll version is less than 2.0.50727.832" test_ref="oval:org.mitre.oval:tst:3378"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:450" version="1" class="patch">
         <metadata>
            <title>MS07-041: Vulnerability in Microsoft Internet Information Services Could Allow Remote Code Execution (939373)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>IIS</product>
            </affected>
            <reference source="Microsoft" ref_id="MS07-041" ref_url="http://www.microsoft.com/technet/security/Bulletin/ms07-041.mspx"/>
            <reference source="Microsoft" ref_id="KB939373" ref_url="http://support.microsoft.com/kb/939373"/>
            <reference source="BID" ref_id="15921" ref_url="http://www.securityfocus.com/bid/15921"/>
            <reference source="CVE" ref_id="CVE-2005-4360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4360"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1703" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1703"/>
            <description>Microsoft has released MS07-041 to address security issues in IIS as documented by CVE-2005-4360.</description>
         </metadata>
         <criteria>
            <criteria comment="Windows XP SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
               <criterion comment="The iis optional component is installed" test_ref="oval:gov.nist.fdcc.patch:tst:4600001"/>
               <criterion comment="w3svc.dll version is less than 5.1.2600.3163" test_ref="oval:org.mitre.oval:tst:4030"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:464" version="2" class="patch">
         <metadata>
            <title>MS07-047: Vulnerabilities in Windows Media Player Could Allow Remote Code Execution (936782)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Windows Media Player</product>
            </affected>
            <reference source="Microsoft" ref_id="MS07-047" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-047.mspx"/>
            <reference source="Microsoft" ref_id="KB936782" ref_url="http://support.microsoft.com/kb/936782"/>
            <reference source="CVE" ref_id="CVE-2007-3035" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3035"/>
            <reference source="CVE" ref_id="CVE-2007-3037" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3037"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2207" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2207"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1352" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1352"/>
            <description>Microsoft has released MS07-047 to address security issues in Windows Media Player as documented by CVE-2007-3035 and CVE-2007-3037.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="OR">
               <criteria comment="Media Player v10 on XP">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
                  <criterion test_ref="oval:org.mitre.oval:tst:4138" comment="Wmp.dll version is less than 10.0.0.4058"/>
               </criteria>
               <criteria comment="Media Player v11 on XP">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
                  <criterion test_ref="oval:org.mitre.oval:tst:4010" comment="Wmp.dll version is less than 11.0.5721.5230"/>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:482" version="1" class="patch">
         <metadata>
            <title>MS07-053: Vulnerability in Windows Services for UNIX Could Allow Elevation of Privilege (939778)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-053" ref_url="http://www.microsoft.com/technet/security/bulletin/MS07-053.mspx"/>
            <reference source="Microsoft" ref_id="KB939778" ref_url="http://support.microsoft.com/kb/939778"/>
            <reference source="CVE" ref_id="CVE-2007-3036" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3036"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1275" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1275"/>
            <description>Microsoft has released MS07-053 to address security issues in Operating System as documented by CVE-2007-3036.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <criterion comment="POSIX is enabled" test_ref="oval:org.mitre.oval:tst:609"/>
               <criteria operator="OR">
                  <criteria operator="AND" comment="UNIX 3.0 version on Windows XP SP2">
                     <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                     <criterion comment="Psxss.exe version is less than 7.0.1701.46" test_ref="oval:org.mitre.oval:tst:3240"/>
                     <criteria operator="AND" comment="The major version of Psxss.exe 7.">
                        <criterion comment="Psxss.exe version is greater than or equal to 7." test_ref="oval:org.mitre.oval:tst:3242"/>
                        <criterion comment="Psxss.exe version is less than 8." test_ref="oval:org.mitre.oval:tst:3405"/>
                     </criteria>
                  </criteria>
                  <criteria operator="AND" comment="UNIX 3.5 version on Windows XP SP2">
                     <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                     <criterion comment="Psxss.exe version is less than 8.0.1969.58" test_ref="oval:org.mitre.oval:tst:4052"/>
                     <criterion comment="Psxss.exe version is greater than or equal to 8" test_ref="oval:org.mitre.oval:tst:3247"/>
                     <criteria operator="AND" comment="The major version of Psxss.exe 8.">
                        <criterion comment="Psxss.exe version is greater than or equal to 8" test_ref="oval:org.mitre.oval:tst:3247"/>
                        <criterion comment="Psxss.exe version is less than 9." test_ref="oval:org.mitre.oval:tst:3845"/>
                     </criteria>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:483" version="1" class="patch">
         <metadata>
            <title>MS07-054: Vulnerability in MSN Messenger and Windows Live Messenger Could Allow Remote Code Execution (942099)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>MSN Messenger</product>
            </affected>
            <reference source="Microsoft" ref_id="MS07-054" ref_url="http://www.microsoft.com/technet/security/bulletin/MS07-054.mspx"/>
            <reference source="Microsoft" ref_id="KB942099" ref_url="http://support.microsoft.com/kb/942099"/>
            <reference source="CVE" ref_id="CVE-2007-2931" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2931"/>
            <reference source="BID" ref_id="25461" ref_url="http://www.securityfocus.com/bid/25461"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2063" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2063"/>
            <description>Microsoft has released MS07-054 to address security issues in MSN Messenger as documented by CVE-2007-2931.</description>
         </metadata>
         <criteria operator="AND" comment="MSN Messenger on Windows XP">
            <criteria operator="OR">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            </criteria>
            <criteria operator="OR">
               <extend_definition comment="MSN Messenger 6.2 is installed" definition_ref="oval:org.mitre.oval:def:2187"/>
               <extend_definition comment="MSN Messenger 7.0 is installed" definition_ref="oval:org.mitre.oval:def:2047"/>
               <extend_definition comment="MSN Messenger 7.5 is installed" definition_ref="oval:org.mitre.oval:def:2087"/>
               <extend_definition comment="MSN Messenger 8.0 is installed" definition_ref="oval:org.mitre.oval:def:2209"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:500" version="1" class="patch">
         <metadata>
            <title>MS07-055: Vulnerability in Kodak Image Viewer Could Allow Remote Code Execution (923810)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Kodak Image Viewer</product>
            </affected>
            <reference source="Microsoft" ref_id="MS07-055" ref_url="http://www.microsoft.com/technet/security/bulletin/MS07-055.mspx"/>
            <reference source="Microsoft" ref_id="KB923810" ref_url="http://support.microsoft.com/kb/923810"/>
            <reference source="CVE" ref_id="CVE-2007-2217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2217"/>
            <description>Microsoft has released MS07-055 to address security issues in their software as documented by CVE-2007-2217.</description>
         </metadata>
         <criteria operator="AND" comment="WinXP">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Kodakimg.exe version is less than 5.0.2195.7138" test_ref="oval:org.mitre.oval:tst:3517"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:516" version="1" class="patch">
         <metadata>
            <title>MS07-061: Vulnerability in Windows URI Handling Could Allow Remote Code Execution (943460)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS07-061" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-061.mspx"/>
            <reference source="Microsoft" ref_id="KB943460" ref_url="http://support.microsoft.com/kb/943460"/>
            <reference source="CVE" ref_id="CVE-2007-3896" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3896"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4581" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4581"/>
            <reference source="CERT-VN" ref_id="VU#403150" ref_url="http://www.kb.cert.org/vuls/id/403150"/>
            <description>Microsoft has released MS07-061 to address security issues in Operating System as documented by CVE-2007-3896.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Shell32.dll version is less than 6.0.2900.3241" test_ref="oval:org.mitre.oval:tst:6859"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Shell32.dll version is less than 6.0.3790.4184" test_ref="oval:org.mitre.oval:tst:6786"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:525" version="1" class="patch">
         <metadata>
            <title>MS07-067: Vulnerability in Macrovision Driver Could Allow Local Elevation of Privilege (944653)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Macrovision</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2007-5587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5587"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4584" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4584"/>
            <reference source="BID" ref_id="26121" ref_url="http://www.securityfocus.com/bid/26121"/>
            <reference source="Microsoft" ref_id="MS07-067" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-067.mspx"/>
            <reference source="Microsoft" ref_id="KB944653" ref_url="http://support.microsoft.com/kb/944653"/>
            <description>Microsoft has released MS07-067 to address security issues in Macrovision as documented by CVE-2007-5587.</description>
         </metadata>
         <criteria operator="AND" comment="XP and S03">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <criterion comment="Secdrv.sys version is less than 4.3.86.0" test_ref="oval:org.mitre.oval:tst:6816"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:526" version="1" class="patch">
         <metadata>
            <title>MS07-068: Vulnerability in Windows Media File Format Could Allow Remote Code Execution (941569 and 944275)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Windows Media Player</product>
            </affected>
            <reference source="Microsoft" ref_id="MS07-068" ref_url="http://www.microsoft.com/technet/security/bulletin/MS07-068.mspx"/>
            <description>Microsoft has released MS07-068 to address security issues in their software as documented by .</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Wmvcore.dll for Windows Media Format 9.0 is installed." test_ref="oval:org.mitre.oval:tst:125"/>
               <criterion comment="Wmasf.dll version is less than 9.0.0.3267" test_ref="oval:org.mitre.oval:tst:6447"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Wmvcore.dll for Windows Media Format 9.5 is installed." test_ref="oval:org.mitre.oval:tst:115"/>
               <criterion comment="Wmasf.dll version is less than 10.0.0.4060" test_ref="oval:org.mitre.oval:tst:6402"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Wmvcore.dll for Windows Media Format 9.5 is installed." test_ref="oval:org.mitre.oval:tst:115"/>
               <criterion comment="Wmasf.dll version is less than 10.0.0.3811" test_ref="oval:gov.nist.fdcc.patch:tst:115277"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Wmvcore.dll for Windows Media Format 11.0 is installed." test_ref="oval:org.mitre.oval:tst:6765"/>
               <criterion comment="Wmasf.dll version is less than 11.0.5721.5238" test_ref="oval:org.mitre.oval:tst:6614"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:531" version="1" class="patch">
         <metadata>
            <title>MS06-036: Vulnerability in DHCP Client Service Could Allow Remote Code Execution (914388)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>DHCP Client</product>
            </affected>
            <reference source="Microsoft" ref_id="MS06-036" ref_url="http://www.microsoft.com/technet/security/bulletin/ms06-036.mspx"/>
            <reference source="Microsoft" ref_id="KB914388" ref_url="http://support.microsoft.com/kb/914388"/>
            <reference source="Bugtraq ID" ref_id="18923" ref_url="http://www.securityfocus.com/bid/18923"/>
            <reference source="CERT-VN" ref_id="VU#257164" ref_url="http://www.kb.cert.org/vuls/id/257164"/>
            <reference source="CVE" ref_id="CVE-2006-2372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2372"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:232" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:232"/>
            <description>Microsoft has released MS06-036 to address security issues in DHCP Client as documented by CVE-2006-2372.</description>
         </metadata>
         <criteria comment="Windows XP (32-bit) SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Dhcpcsvc.dll version is less than 5.1.2600.2912" test_ref="oval:org.mitre.oval:tst:5"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:539" version="1" class="patch">
         <metadata>
            <title>MS08-001: Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (941644)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS08-001" ref_url="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx"/>
            <reference source="Microsoft" ref_id="KB941644" ref_url="http://support.microsoft.com/kb/941644"/>
            <reference source="BID" ref_id="27100" ref_url="http://www.securityfocus.com/bid/27100"/>
            <reference source="CERT-VN" ref_id="VU#115083" ref_url="http://www.kb.cert.org/vuls/id/115083"/>
            <reference source="CVE" ref_id="CVE-2007-0069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0069"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5370" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5370"/>
            <description>Microsoft has released MS08-001 to address security issues in Operating System as documented by CVE-2007-0069.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Tcpip.sys version is less than 5.1.2600.3244" test_ref="oval:org.mitre.oval:tst:7452"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Tcpip.sys version is less than 5.2.3790.4179" test_ref="oval:org.mitre.oval:tst:7335"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:556" version="1" class="patch">
         <metadata>
            <title>MS08-003: Vulnerability in Active Directory Could Allow Denial of Service (946538)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS08-003" ref_url="http://www.microsoft.com/technet/security/bulletin/ms08-003.mspx"/>
            <reference source="Microsoft" ref_id="KB946538" ref_url="http://support.microsoft.com/kb/946538"/>
            <reference source="BID" ref_id="27638" ref_url="http://www.securityfocus.com/bid/27638"/>
            <reference source="CVE" ref_id="CVE-2008-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0088"/>
            <reference source="HP" ref_id="HPSBST02314" ref_url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5181" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5181"/>
            <description>Microsoft has released MS08-003 to address security issues in Operating System as documented by CVE-2008-0088.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <criterion comment="Adamdsa.dll version is less than 1.1.3790.4188" test_ref="oval:org.mitre.oval:tst:7403"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:557" version="1" class="patch">
         <metadata>
            <title>MS08-005: Vulnerability in Internet Information Services Could Allow Elevation of Privilege (942831)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>IIS</product>
            </affected>
            <reference source="Microsoft" ref_id="MS08-005" ref_url="http://www.microsoft.com/technet/security/bulletin/ms08-005.mspx"/>
            <reference source="Microsoft" ref_id="KB942831" ref_url="http://support.microsoft.com/kb/942831"/>
            <reference source="BID" ref_id="27101" ref_url="http://www.securityfocus.com/bid/27101"/>
            <reference source="CVE" ref_id="CVE-2008-0074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0074"/>
            <reference source="HP" ref_id="HPSBST02314" ref_url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5389" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5389"/>
            <description>Microsoft has released MS08-005 to address security issues in IIS as documented by CVE-2008-0074.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
               <criterion comment="The iis optional component is installed" test_ref="oval:gov.nist.fdcc.patch:tst:4600001"/>
               <criterion comment="Infocomm.dll version is less than 6.0.2600.3290" test_ref="oval:org.mitre.oval:tst:7363"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
               <criterion comment="Infocomm.dll version is less than 6.0.3790.4215" test_ref="oval:org.mitre.oval:tst:7802"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:558" version="1" class="patch">
         <metadata>
            <title>MS08-006: Vulnerability in Internet Information Services Could Allow Remote Code Execution (942830)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>IIS</product>
            </affected>
            <reference source="Microsoft" ref_id="MS08-006" ref_url="http://www.microsoft.com/technet/security/bulletin/ms08-006.mspx"/>
            <reference source="Microsoft" ref_id="KB942830" ref_url="http://support.microsoft.com/kb/942830"/>
            <reference source="BID" ref_id="27676" ref_url="http://www.securityfocus.com/bid/27676"/>
            <reference source="CVE" ref_id="CVE-2008-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0075"/>
            <reference source="HP" ref_id="HPSBST02314" ref_url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5308" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5308"/>
            <description>Microsoft has released MS08-006 to address security issues in IIS as documented by CVE-2008-0075.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
               <criterion comment="The iis optional component is installed" test_ref="oval:gov.nist.fdcc.patch:tst:4600001"/>
               <criterion comment="Asp51.dll version is less than 5.1.2600.3291" test_ref="oval:org.mitre.oval:tst:7861"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
               <criterion comment="Asp.dll version is less than 6.0.3790.4195" test_ref="oval:org.mitre.oval:tst:7785"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:559" version="1" class="patch">
         <metadata>
            <title>MS08-007: Vulnerability in WebDAV Mini-Redirector Could Allow Remote Code Execution (946026)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS08-007" ref_url="http://www.microsoft.com/technet/security/bulletin/ms08-007.mspx"/>
            <reference source="Microsoft" ref_id="KB946026" ref_url="http://support.microsoft.com/kb/946026"/>
            <reference source="BID" ref_id="27670" ref_url="http://www.securityfocus.com/bid/27670"/>
            <reference source="CVE" ref_id="CVE-2008-0080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0080"/>
            <reference source="HP" ref_id="HPSBST02314" ref_url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5381" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5381"/>
            <description>Microsoft has released MS08-007 to address security issues in Operating System as documented by CVE-2008-0080.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Mrxdav.sys version is less than 5.1.2600.3276" test_ref="oval:org.mitre.oval:tst:7454"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mrxdav.sys version is less than 5.2.3790.4221" test_ref="oval:org.mitre.oval:tst:7633"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:560" version="2" class="patch">
         <metadata>
            <title>MS08-008: Vulnerability in OLE Automation Could Allow Remote Code Execution (947890)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Visual Basic 6.0</product>
            </affected>
            <reference source="Microsoft" ref_id="MS08-008" ref_url="http://www.microsoft.com/technet/security/bulletin/ms08-008.mspx"/>
            <reference source="Microsoft" ref_id="KB947890" ref_url="http://support.microsoft.com/kb/947890"/>
            <reference source="BID" ref_id="27661" ref_url="http://www.securityfocus.com/bid/27661"/>
            <reference source="CVE" ref_id="CVE-2007-0065" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0065"/>
            <reference source="HP" ref_id="HPSBST02314" ref_url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5388" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5388"/>
            <description>Microsoft has released MS08-008 to address security issues in Microsoft Visual Basic 6.0 as documented by CVE-2007-0065.</description>
         </metadata>
         <!--<criteria operator="OR">-->
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Oleaut32.dll version is less than 5.1.2600.3266" test_ref="oval:org.mitre.oval:tst:7828"/>
         </criteria>
         <!--<criteria operator="AND">
                   <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                   <criterion comment="Oleaut32.dll version is less than 5.2.3790.4202" test_ref="oval:org.mitre.oval:tst:7548"/>
                </criteria>
             </criteria>-->
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:602" version="2" class="patch">
         <metadata>
            <title>MS08-020: Vulnerability in DNS Client Could Allow Spoofing (945553)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS08-020" ref_url="http://www.microsoft.com/technet/security/bulletin/ms08-020.mspx"/>
            <reference source="Microsoft" ref_id="KB945553" ref_url="http://support.microsoft.com/kb/945553"/>
            <reference source="BID" ref_id="28553" ref_url="http://www.securityfocus.com/bid/28553"/>
            <reference source="CVE" ref_id="CVE-2008-0087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0087"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5314" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5314"/>
            <description>Microsoft has released MS08-020 to address security issues in Operating System as documented by CVE-2008-0087.</description>
         </metadata>
         <!--<criteria operator="OR">-->
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Dnsapi.dll version is less than 5.1.2600.3316" test_ref="oval:org.mitre.oval:tst:7425"/>
            <criterion comment="Dnsrslvr.dll version is less than 5.1.2600.3316" test_ref="oval:gov.nist.fdcc.patch:tst:115298"/>
         </criteria>
         <!--<criteria operator="AND">
                   <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                   <criterion comment="Dnsapi.dll version is less than 5.2.3790.4238" test_ref="oval:org.mitre.oval:tst:6999"/>
                   <criterion comment="Dnsrslvr.dll version is less than 5.2.3790.4238" test_ref="oval:gov.nist.fdcc.patch:tst:115299"/>
                </criteria>
             </criteria>-->
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:604" version="1" class="patch">
         <metadata>
            <title>MS08-022: Vulnerability in VBScript and JScript Scripting Engines Could Allow Remote Code Execution (944338)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS08-022" ref_url="http://www.microsoft.com/technet/security/bulletin/ms08-022.mspx"/>
            <reference source="Microsoft" ref_id="KB944338" ref_url="http://support.microsoft.com/kb/944338"/>
            <reference source="BID" ref_id="28551" ref_url="http://www.securityfocus.com/bid/28551"/>
            <reference source="CVE" ref_id="CVE-2008-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0083"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5495" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5495"/>
            <description>Microsoft has released MS08-022 to address security issues in Operating System as documented by CVE-2008-0083.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <criterion comment="Jscript.dll version is less than 5.6.0.8835" test_ref="oval:org.mitre.oval:tst:7025"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:631" version="1" class="patch">
         <metadata>
            <title>MS06-050: Vulnerabilities in Microsoft Windows Hyperlink Object Library Could Allow Remote Code Execution (920670)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-050" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS06-050.mspx"/>
            <reference source="Microsoft" ref_id="KB920670" ref_url="http://support.microsoft.com/kb/920670"/>
            <reference source="Bugtraq ID" ref_id="18500" ref_url="http://www.securityfocus.com/bid/18500"/>
            <reference source="CERT-VN" ref_id="VU#394444" ref_url="http://www.kb.cert.org/vuls/id/394444"/>
            <reference source="CERT-VN" ref_id="VU#683612" ref_url="http://www.kb.cert.org/vuls/id/683612"/>
            <reference source="CVE" ref_id="CVE-2006-3086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3086"/>
            <reference source="CVE" ref_id="CVE-2006-3438" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3438"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:115" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:115"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:999" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:999"/>
            <description>Microsoft has released MS06-050 to address security issues in the operating system as documented by CVE-2006-3086 and CVE-2006-3438.</description>
         </metadata>
         <criteria comment="Windows XP (32-bit) SP2" operator="AND">
            <criteria operator="OR">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            </criteria>
            <criterion comment="Hlink.dll version is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:741" version="1" class="patch">
         <metadata>
            <title>MS04-043: Vulnerability in HyperTerminal Could Allow Code Execution (873339)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>HyperTerminal</product>
            </affected>
            <reference source="Microsoft" ref_id="MS04-043" ref_url="http://www.microsoft.com/technet/security/bulletin/MS04-043.mspx"/>
            <reference source="Microsoft" ref_id="KB873339" ref_url="http://support.microsoft.com/kb/873339"/>
            <reference source="CIAC" ref_id="p-056" ref_url="http://www.ciac.org/ciac/bulletins/p-056.shtml"/>
            <reference source="CVE" ref_id="CVE-2004-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0568"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1603" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1603"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2545" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2545"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3138" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3138"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4741" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4741"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3973" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3973"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4508" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4508"/>
            <description>Microsoft has released MS04-043 to address security issues in HyperTerminal as documented by CVE-2004-0568.</description>
         </metadata>
         <criteria operator="AND">
            <criteria comment="Software section" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Hypertrm.dll version is less than 5.1.2600.2563" test_ref="oval:org.mitre.oval:tst:516"/>
            </criteria>
            <criteria comment="Configuration section" operator="OR">
               <criterion comment="If key present hyperterminal will automatically open session files" test_ref="oval:org.mitre.oval:tst:827"/>
               <criterion comment="If the Hyperterminal client is registered as the default telnet client" test_ref="oval:org.mitre.oval:tst:826"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:751" version="1" class="patch">
         <metadata>
            <title>MS04-044: Vulnerabilities in Windows Kernel and LSASS Could Allow Elevation of Privilege (885835)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Local Security Authority Subsystem Service (LSASS)</product>
            </affected>
            <reference source="Microsoft" ref_id="MS04-044" ref_url="http://www.microsoft.com/technet/security/bulletin/MS04-044.mspx"/>
            <reference source="Microsoft" ref_id="KB885835" ref_url="http://support.microsoft.com/kb/885835"/>
            <reference source="CVE" ref_id="CVE-2004-0893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0893"/>
            <reference source="CVE" ref_id="CVE-2004-0894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0894"/>
            <reference source="CIAC" ref_id="p-057" ref_url="http://www.ciac.org/ciac/bulletins/p-057.shtml"/>
            <reference source="BID" ref_id="11914" ref_url="http://www.securityfocus.com/brefId/11914"/>
            <reference source="BID" ref_id="11913" ref_url="http://www.securityfocus.com/brefId/11913"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:450" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:450"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4021" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4021"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2062" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2062"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4458" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4458"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3312" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3312"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:778" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:778"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1321" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1321"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3325" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3325"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1561" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1561"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1888" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1888"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4368" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4368"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2008" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2008"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1886" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1886"/>
            <description>Microsoft has released MS04-044 to address security issues in Local Security Authority Subsystem Service (LSASS) as documented by CVE-2004-0893 and CVE-2004-0894.</description>
         </metadata>
         <criteria>
            <criteria comment="Software section" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="lsasrv.dll version is less than 5.1.2600.2525" test_ref="oval:org.mitre.oval:tst:2623"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:791" version="1" class="patch">
         <metadata>
            <title>MS06-057: Vulnerability in Windows Explorer Could Allow Remote Execution (923191)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-057" ref_url="http://www.microsoft.com/technet/security/bulletin/MS06-057.mspx"/>
            <reference source="Microsoft" ref_id="KB923191" ref_url="http://support.microsoft.com/kb/923191"/>
            <reference source="CVE" ref_id="CVE-2006-3730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3730"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:339" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:339"/>
            <description>Microsoft has released MS06-057 to address security issues in the operating system as documented by CVE-2006-3730.</description>
         </metadata>
         <criteria comment="WinXP,SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Comctl32.dll version is less than 5.82.2900.2982" test_ref="oval:org.mitre.oval:tst:54"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:861" version="1" class="patch">
         <metadata>
            <title>MS06-064: Vulnerabilities in TCP/IP IPv6 Could Allow Denial of Service (922819)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-064" ref_url="http://www.microsoft.com/technet/security/bulletin/MS06-064.mspx"/>
            <reference source="Microsoft" ref_id="KB922819" ref_url="http://support.microsoft.com/kb/922819"/>
            <reference source="CVE" ref_id="CVE-2004-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0230"/>
            <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
            <reference source="CVE" ref_id="CVE-2005-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0688"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:270" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:270"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:53" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:53"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:482" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:482"/>
            <description>Microsoft has released MS06-064 to address security issues in the operating system as documented by CVE-2004-0230, CVE-2004-0790, and CVE-2005-0688.</description>
         </metadata>
         <criteria comment="WinXP,SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Tcpip6.sys version is less than 5.1.2600.2975" test_ref="oval:org.mitre.oval:tst:86"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:871" version="1" class="patch">
         <metadata>
            <title>MS06-065: Vulnerability in Windows Object Packager Could Allow Remote Execution (924496)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-065" ref_url="http://www.microsoft.com/technet/security/bulletin/MS06-065.mspx"/>
            <reference source="Microsoft" ref_id="KB924496" ref_url="http://support.microsoft.com/kb/924496"/>
            <reference source="CVE" ref_id="CVE-2006-4692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4692"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:496" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:496"/>
            <description>Microsoft has released MS06-065 to address security issues in the operating system as documented by CVE-2006-4692.</description>
         </metadata>
         <criteria comment="WinXP,SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Shdocvw.dll version is less than 6.0.2900.2987" test_ref="oval:org.mitre.oval:tst:48"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:881" version="1" class="patch">
         <metadata>
            <title>MS06-066: Vulnerabilities in Client Service for NetWare Could Allow Remote Code Execution (923980)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>NetWare</product>
            </affected>
            <reference source="Microsoft" ref_id="MS06-066" ref_url="http://www.microsoft.com/technet/security/bulletin/MS06-066.mspx"/>
            <reference source="Microsoft" ref_id="KB923980" ref_url="http://support.microsoft.com/kb/923980"/>
            <reference source="CVE" ref_id="CVE-2006-4688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4688"/>
            <reference source="CVE" ref_id="CVE-2006-4689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4689"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:413" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:413"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:404" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:404"/>
            <description>Microsoft has released MS06-066 to address security issues in NetWare as documented by CVE-2006-4688 and CVE-2006-4689.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Nwrdr.sys version is less than 5.1.2600.3015" test_ref="oval:org.mitre.oval:tst:75"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:901" version="1" class="patch">
         <metadata>
            <title>MS06-068: Vulnerability in Microsoft Agent Could Allow Remote Code Execution (920213)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-068" ref_url="http://www.microsoft.com/technet/security/bulletin/MS06-068.mspx"/>
            <reference source="Microsoft" ref_id="KB920213" ref_url="http://support.microsoft.com/kb/920213"/>
            <reference source="CVE" ref_id="CVE-2006-3445" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3445"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:154" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:154"/>
            <description>Microsoft has released MS06-068 to address security issues in Microsoft Internet Explorer as documented by CVE-2006-3445.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Agentdpv.dll version is less than 2.0.0.3424" test_ref="oval:org.mitre.oval:tst:195"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:921" version="1" class="patch">
         <metadata>
            <title>MS06-070: Vulnerability in Workstation Service Could Allow Remote Code Execution (924270)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS06-070" ref_url="http://www.microsoft.com/technet/security/bulletin/MS06-070.mspx"/>
            <reference source="Microsoft" ref_id="KB924270" ref_url="http://support.microsoft.com/kb/924270"/>
            <reference source="CVE" ref_id="CVE-2006-4691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4691"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:908" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:908"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:607" ref_url="http://oval.mitre.org/repository/data/getDef?oval:org.mitre.oval:def:607"/>
            <description>Microsoft has released MS06-070 to address security issues in the operating system as documented by CVE-2006-4691.</description>
         </metadata>
         <criteria comment="WinXP,SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Wkssvc.dll version is less than 5.1.2600.2976" test_ref="oval:org.mitre.oval:tst:113"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:1784" version="2" class="patch">
         <metadata>
            <title>MS07-050: Vulnerability in Vector Markup Language Could Allow Remote Code Execution (938127)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>Microsoft Internet Explorer 6</product>
               <product>Microsoft Internet Explorer 7</product>
            </affected>
            <reference source="Microsoft" ref_id="MS07-050" ref_url="http://www.microsoft.com/technet/security/bulletin/MS07-050.mspx"/>
            <reference source="Microsoft" ref_id="938127" ref_url="http://support.microsoft.com/kb/938127"/>
            <reference source="CVE" ref_id="CVE-2007-1749" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1749"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1784" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1784"/>
            <description>Microsoft has released MS07-050 to address security issues in the Vector Markup Language (VML) implementation in Windows as documented by CVE-2007-1749.</description>
         </metadata>
         <criteria operator="OR">
            <criteria comment="IE 6 on Win XP SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
               <criterion comment="Vgx.dll version is less than 6.0.2900.3164" test_ref="oval:org.mitre.oval:tst:3856"/>
            </criteria>
            <criteria comment="IE 7 on Win XP SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
               <criterion comment="Vgx.dll version is less than 7.0.6000.20628" test_ref="oval:org.mitre.oval:tst:4182"/>
            </criteria>
            <criteria comment="IE 6 on Win XP SP2 (64-bit)" operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
               <criterion comment="Vgx.dll version is less than 6.0.3790.4106" test_ref="oval:org.mitre.oval:tst:3422"/>
            </criteria>
            <criteria comment="IE 7 on Win XP SP2 (64-bit)" operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
               <criterion comment="Vgx.dll version is less than 7.0.6000.20628" test_ref="oval:org.mitre.oval:tst:4182"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:1911" version="1" class="patch">
         <metadata>
            <title>MS05-045: Vulnerability in Network Connection Manager Could Allow Denial of Service (905414)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS05-045" ref_url="http://www.microsoft.com/technet/security/bulletin/MS05-045.mspx"/>
            <reference source="Microsoft" ref_id="KB905414" ref_url="http://support.microsoft.com/kb/905414"/>
            <reference source="Bugtraq ID" ref_id="14260" ref_url="http://www.securityfocus.com/bid/14260"/>
            <reference source="CVE" ref_id="CVE-2005-2307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2307"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:786" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:786"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1532" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1532"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1254" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1254"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1289" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1289"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1250" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1250"/>
            <description>Microsoft has released MS05-045 to address security issues in the operating system as documented by CVE-2005-2307.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Netman.dll is less than 5.1.2600.2743" test_ref="oval:org.mitre.oval:tst:879"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:5578" version="1" class="patch">
         <metadata>
            <title>MS08-028: Vulnerability in Microsoft Jet Database Engine Could Allow Remote Code Execution (950749)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Jet 4.0 Database Engine</product>
            </affected>
            <reference source="Microsoft" ref_id="MS08-028" ref_url="http://www.microsoft.com/technet/security/bulletin/MS08-028.mspx"/>
            <reference source="Microsoft" ref_id="KB950749" ref_url="http://support.microsoft.com/kb/950749"/>
            <reference source="CVE" ref_id="CVE-2007-6026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6026"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5578" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5578"/>
            <description>Microsoft has released MS08-028 to address security issues in the Microsoft Jet Database Engine (Jet) in Windows as documented by CVE-2007-6026.</description>
         </metadata>
         <criteria operator="AND" comment="Windows XP">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Msjet40.dll version is is less than 4.0.9511.0" test_ref="oval:org.mitre.oval:tst:7888"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11441" version="1" class="patch">
         <metadata>
            <title> MS08-046: Vulnerability in Microsoft Windows Image Color Management System Could Allow Remote Code Execution (952954)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-2245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2245"/>
            <reference source="Microsoft" ref_id="MS08-046" ref_url="http://www.microsoft.com/technet/security/bulletin/MS08-046.mspx"/>
            <reference source="Microsoft" ref_id="KB952954" ref_url="http://support.microsoft.com/kb/952954"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5923" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5923"/>
            <description>Microsoft has released MS08-046 to address security issues in Microsoft Windows 2000, Windows XP and Windows Server 2003 as documented by CVE-2008-2245.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Mscms.dll version is less than 5.1.2600.3396" test_ref="oval:org.mitre.oval:tst:8739"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Mscms.dll version is less than 5.1.2600.5627" test_ref="oval:org.mitre.oval:tst:8660"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mscms.dll version is less than 5.2.3790.4320" test_ref="oval:org.mitre.oval:tst:9047"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11443" version="2" class="patch">
         <metadata>
            <title>MS08-048: Security Update for Outlook Express and Windows Mail (951066)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <!--<platform>Microsoft Windows Vista</platform>
                    <platform>Microsoft Windows Server 2008</platform>-->
               <product>Microsoft Outlook Express</product>
               <product>Microsoft Mail</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-1448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1448"/>
            <reference source="Microsoft" ref_id="MS08-048" ref_url="http://www.microsoft.com/technet/security/bulletin/MS08-048.mspx"/>
            <reference source="Microsoft" ref_id="KB951066" ref_url="http://support.microsoft.com/kb/951066"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5886" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5886"/>
            <description>Microsoft has released MS08-048 to address security issues in Windows XP and Windows Vista, Windows Server 2003, and Windows Server 2008 as documented by CVE-2008-1448.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Outlook Express 6 on Win XP SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.2900.3350" test_ref="oval:org.mitre.oval:tst:8951"/>
            </criteria>
            <criteria operator="AND" comment="Outlook Express 6 on Win XP SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.2900.5579" test_ref="oval:org.mitre.oval:tst:8248"/>
            </criteria>
            <criteria operator="AND" comment="Outlook Express 6 on Win XP SP2 (64-bit)">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.3790.4325" test_ref="oval:org.mitre.oval:tst:9185"/>
            </criteria>
            <!--<criteria operator="AND">
                   <criteria operator="OR">
                       <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                       <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                       <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                       <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                       <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                   </criteria>
                   <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
                   <criterion comment="Inetcomm.dll version is less than 6.0.6001.18049" test_ref="oval:org.mitre.oval:tst:9051"/>
                </criteria>-->
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11444" version="1" class="patch">
         <metadata>
            <title>MS08-049: Vulnerabilities in Event System Could Allow Remote Code Execution (950974)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-1456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1456"/>
            <reference source="CVE" ref_id="CVE-2008-1457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1457"/>
            <reference source="Microsoft" ref_id="MS08-049" ref_url="http://www.microsoft.com/technet/security/bulletin/MS08-049.mspx"/>
            <reference source="Microsoft" ref_id="KB950974" ref_url="http://support.microsoft.com/kb/950974"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5630" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5630"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6095" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6095"/>
            <description>Microsoft has released MS08-049 to address security issues in Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 as documented by CVE-2008-1456 and CVE-2008-1457.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Es.dll version is less than 2001.12.4414.320" test_ref="oval:org.mitre.oval:tst:9013"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Es.dll version is less than 2001.12.4414.706" test_ref="oval:org.mitre.oval:tst:9019"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Es.dll version is less than 2001.12.4720.4282" test_ref="oval:org.mitre.oval:tst:8200"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criterion comment="Es.dll version is less than 2001.12.6931.18057" test_ref="oval:org.mitre.oval:tst:8968"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11445" version="1" class="patch">
         <metadata>
            <title>MS08-050: Vulnerability in Windows Messenger Could Allow Information Disclosure (955702)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Windows Messenger 4.7</product>
               <product>Windows Messenger 5.1</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0082"/>
            <reference source="Microsoft" ref_id="MS08-050" ref_url="http://www.microsoft.com/technet/security/bulletin/MS08-050.mspx"/>
            <reference source="Microsoft" ref_id="KB955702" ref_url="http://support.microsoft.com/kb/955702"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5995" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5995"/>
            <description>Microsoft has released MS08-050 to address security issues in Microsoft Windows 2000 and Windows XP, and Windows Server 2003 as documented by CVE-2008-0082.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Windows Messenger 4.7 is installed" definition_ref="oval:org.mitre.oval:def:6101"/>
               <criterion comment="Msgsc.dll version isless than 4.7.0.3002" test_ref="oval:org.mitre.oval:tst:9100"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Windows Messenger 5.1 is installed" definition_ref="oval:org.mitre.oval:def:5691"/>
               <criterion comment="Msgsc.dll version isless than 5.1.0715" test_ref="oval:org.mitre.oval:tst:8944"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11447" version="1" class="patch">
         <metadata>
            <title>MS08-054: Vulnerability in Windows Media Player Could Allow Remote Code Execution (954154)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <product>Microsoft Media Player</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-2253" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2253"/>
            <reference source="Microsoft" ref_id="MS08-054" ref_url="http://www.microsoft.com/technet/security/bulletin/MS08-054.mspx"/>
            <reference source="Microsoft" ref_id="KB954154" ref_url="http://support.microsoft.com/kb/954154"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5615" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5615"/>
            <description>Microsoft has released MS08-054 to address security issues in Windows Media Player 11 as documented by CVE-2008-2253.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <extend_definition comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
               <criterion comment="Wmpeffects.dll version is less than 11.0.5721.5252" test_ref="oval:org.mitre.oval:tst:9036"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <extend_definition comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
               <criterion comment="Wmpeffects.dll version is less than 11.0.6001.7002" test_ref="oval:org.mitre.oval:tst:8662"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11449" version="2" class="patch">
         <metadata>
            <title>MS08-053: Vulnerability in Windows Media Encoder 9 Could Allow Remote Code Execution (954156)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <!--<platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>-->
               <product>Microsoft Media Encoder</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-3008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3008"/>
            <reference source="Microsoft" ref_id="MS08-053" ref_url="http://www.microsoft.com/technet/security/bulletin/MS08-053.mspx"/>
            <reference source="Microsoft" ref_id="KB954156" ref_url="http://support.microsoft.com/kb/954156"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6018" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6018"/>
            <description>Microsoft has released MS08-053 to address security issues in Microsoft Windows 2000, Windows XP, and Windows Vista, Windows Server 2003 and Windows Server 2008 as documented by CVE-2008-3008.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <!--<criteria operator="OR">-->
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <!--<extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
               </criteria>-->
               <criterion comment="Wmex.dll version is greater than or equal to  9.0.0.0" test_ref="oval:org.mitre.oval:tst:8780"/>
               <criterion comment="Wmex.dll version is less than   10.0.0.0" test_ref="oval:org.mitre.oval:tst:8858"/>
               <criterion comment="Wmex.dll version is less than 9.0.0.3359" test_ref="oval:org.mitre.oval:tst:8469"/>
            </criteria>
            <!--<criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criterion comment="Wmex.dll version is greater than or equal to  10.0.0.0" test_ref="oval:org.mitre.oval:tst:8587"/>
               <criterion comment="Wmex.dll version is less than   11.0.0.0" test_ref="oval:org.mitre.oval:tst:8887"/>
               <criterion comment="Wmex.dll version is less than 10.0.0.3817" test_ref="oval:org.mitre.oval:tst:9030"/>
            </criteria>-->
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11501" version="1" class="patch">
         <metadata>
            <title>MS08-061: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-2250 " ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2250"/>
            <reference source="CVE" ref_id="CVE-2008-2251 " ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2251"/>
            <reference source="CVE" ref_id="CVE-2008-2252 " ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2252"/>
            <reference source="Microsoft" ref_id="MS08-061" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS08-061.mspx"/>
            <reference source="Microsoft" ref_id="KB954211" ref_url="http://support.microsoft.com/kb/954211"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5902" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5902"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6010" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6010"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6045" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6045"/>
            <description>Microsoft has released MS08-061 to address security issues in Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 as documented by CVE-2008-2250, CVE-2008-2251, and CVE-2008-2252.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Win32k.sys version is less than 5.1.2600.3446" test_ref="oval:org.mitre.oval:tst:8612"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Win32k.sys version is less than 5.1.2600.5676" test_ref="oval:org.mitre.oval:tst:9293"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Win32k.sys version is less than 5.2.3790.4375" test_ref="oval:org.mitre.oval:tst:9112"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Win32k.sys version is less than 6.0.6001.18141" test_ref="oval:org.mitre.oval:tst:8928"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11502" version="3" class="patch">
         <metadata>
            <title>MS08-062: Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-1446 " ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1446"/>
            <reference source="Microsoft" ref_id="MS08-062" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS08-062.mspx"/>
            <reference source="Microsoft" ref_id="KB953155" ref_url="http://support.microsoft.com/kb/953155"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5764" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5764"/>
            <description>Microsoft has released MS08-062 to address security issues in Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 as documented by CVE-2008-1446.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Printers Virtual Directory for Microsoft IIS is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115279"/>
               <criterion comment="Win32spl.dll version is less than 5.1.2600.3435" test_ref="oval:org.mitre.oval:tst:9281"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Printers Virtual Directory for Microsoft IIS is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115279"/>
               <criterion comment="Win32spl.dll version is less than 5.1.2600.5664" test_ref="oval:org.mitre.oval:tst:9352"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Printers Virtual Directory for Microsoft IIS is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115279"/>
               <criterion comment="Win32spl.dll version is less than 5.2.3790.4371" test_ref="oval:org.mitre.oval:tst:8857"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <extend_definition comment="The Internet Printing Client is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115294"/>
               <criterion comment="Win32spl.dll version is less than 6.0.6001.18119" test_ref="oval:org.mitre.oval:tst:9011"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11505" version="2" class="patch">
         <metadata>
            <title>MS08-066: Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (956803)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-3464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3464"/>
            <reference source="Microsoft" ref_id="MS08-066" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS08-066.mspx"/>
            <reference source="Microsoft" ref_id="KB956803" ref_url="http://support.microsoft.com/kb/956803"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5825" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5825"/>
            <description>Microsoft has released MS08-066 to address security issues in Windows XP and Windows Server 2003 as documented by CVE-2008-3464.</description>
         </metadata>
         <!--<criteria operator="OR">-->
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Afd.sys version is less than 5.1.2600.3427." test_ref="oval:org.mitre.oval:tst:9248"/>
         </criteria>
         <!--<criteria operator="AND">
                   <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                   <criterion comment="Afd.sys version is less than 5.1.2600.5657." test_ref="oval:org.mitre.oval:tst:9065"/>
                </criteria>
                <criteria operator="AND">
                   <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                   <criterion comment="Afd.sys version is less than 5.2.3790.4355." test_ref="oval:org.mitre.oval:tst:9331"/>
                </criteria>
             </criteria>-->
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11507" version="1" class="patch">
         <metadata>
            <title>MS08-067: Vulnerability in Server Service Could Allow Remote Code Execution (958644)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-4250" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4250"/>
            <reference source="Microsoft" ref_id="MS08-067" ref_url="http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx"/>
            <reference source="Microsoft" ref_id="KB958644" ref_url="http://support.microsoft.com/kb/958644"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6093" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6093"/>
            <description>Microsoft has released MS08-061 to address security issues in Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 as documented by CVE-2008-4250</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Netapi32.dll version is less than 5.1.2600.3462" test_ref="oval:org.mitre.oval:tst:9314"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Netapi32.dll version is less than 5.1.2600.5694" test_ref="oval:org.mitre.oval:tst:9266"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Netapi32.dll version is less than 5.2.3790.4392" test_ref="oval:org.mitre.oval:tst:9058"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND">
                     <criterion comment="Netapi32.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115306"/>
                     <criterion comment="Netapi32.dll version is less than 6.0.6001.18157" test_ref="oval:org.mitre.oval:tst:9140"/>
                  </criteria>
                  <criteria operator="AND">
                     <criterion comment="Netapi32.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115307"/>
                     <criterion comment="Netapi32.dll version is less than 6.0.6001.22288" test_ref="oval:org.mitre.oval:tst:9090"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11520" version="1" class="patch">
         <metadata>
            <title>MS08-071: Vulnerabilities in GDI Could Allow Remote Code Execution (956802)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-2249" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2249"/>
            <reference source="CVE" ref_id="CVE-2008-3465" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3465"/>
            <reference source="Microsoft" ref_id="MS08-071" ref_url="http://www.microsoft.com/technet/security/Bulletin/ms08-071.mspx"/>
            <reference source="Microsoft" ref_id="KB956802" ref_url="http://support.microsoft.com/default.aspx/kb/956802"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5984" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5984"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6062" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6062"/>
            <description>Microsoft has released MS08-071to address security issues in Windows XP and Windows Vista, CVE-2008-2249 and CVE-2008-3465</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Gdi32.dll version is less than 5.1.2600.3466" test_ref="oval:gov.nist.fdcc.patch:tst:115201"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Gdi32.dll version is less than 5.1.2600.5698" test_ref="oval:gov.nist.fdcc.patch:tst:115202"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Gdi32.dll version is less than 5.2.3790.4396" test_ref="oval:gov.nist.fdcc.patch:tst:115203"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criterion comment="Gdi32.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115308"/>
               <criterion comment="Gdi32.dll version is less than 6.0.6001.18159" test_ref="oval:org.mitre.oval:tst:9510"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criterion comment="Gdi32.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115309"/>
               <criterion comment="Gdi32.dll version is less than 6.0.6001.22291" test_ref="oval:gov.nist.fdcc.patch:tst:115310"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11523" version="2" class="patch">
         <metadata>
            <title>MS08-076: Vulnerabilities in Windows Media Components Could Allow Remote Code Execution (959807)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2008-3009" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3009"/>
            <reference source="CVE" ref_id="CVE-2008-3010" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3010"/>
            <reference source="Microsoft" ref_id="MS08-076" ref_url="http://www.microsoft.com/technet/security/Bulletin/ms08-076.mspx"/>
            <reference source="Microsoft" ref_id="KB959807" ref_url="http://support.microsoft.com/default.aspx/kb/959807"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5942" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5942"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5689" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5689"/>
            <description>Microsoft has released MS08-076 to address security issues in Windows XP and Windows Vista as documented by CVE-2008-3009 and CVE-2008-3010</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND">
                     <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
                     <criterion comment="Wmnetmgr.dll version is less than 9.0.0.3268" test_ref="oval:gov.nist.fdcc.patch:tst:115231"/>
                  </criteria>
                  <criteria operator="AND">
                     <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
                     <criterion comment="Wmnetmgr.dll version is less than 10.0.0.3703" test_ref="oval:gov.nist.fdcc.patch:tst:115232"/>
                  </criteria>
                  <criteria operator="AND">
                     <extend_definition comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
                     <criterion comment="Wmnetmgr.dll version is less than 11.0.5721.5251" test_ref="oval:gov.nist.fdcc.patch:tst:115233"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
               </criteria>
               <extend_definition comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
               <criterion comment="Wmnetmgr.dll version is less than 11.0.6001.7001" test_ref="oval:gov.nist.fdcc.patch:tst:115234"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11526" version="1" class="patch">
         <metadata>
            <title>MS03-011: Flaw in Microsoft VM Could Enable System Compromise (816093) </title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Virtual Machine (VM)</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2003-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0111"/>
            <reference source="Microsoft" ref_id="MS03-011" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS03-011.mspx"/>
            <reference source="Microsoft" ref_id="KB816093" ref_url="http://support.microsoft.com/default.aspx/kb/816093"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:136" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:136"/>
            <description>Microsoft has released MS03-011 to address security issues in Microsoft Virtual Machine (VM) build 5.0.3809 and earlier on Microsoft Windows XP (32-bit) SP2 as documented by CVE-2003-0111.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Msjava.dll version is less than 5.0.3810.0" test_ref="oval:org.mitre.oval:tst:2898"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11527" version="1" class="patch">
         <metadata>
            <title>MS04-041: Vulnerability in WordPad Could Allow Code Execution (885836)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Word for Windows 6.0 Converter</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2004-0571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0571"/>
            <reference source="CVE" ref_id="CVE-2004-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0901"/>
            <reference source="Microsoft" ref_id="MS04-041" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS04-041.mspx"/>
            <reference source="Microsoft" ref_id="KB885836" ref_url="http://support.microsoft.com/default.aspx/kb/885836"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1959" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1959"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3882" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3882"/>
            <description>Microsoft has released MS04-041 to address security issues in Microsoft Word for Windows 6.0 Converter on Microsoft Windows XP (32-bit) SP2 as documented by CVE-2004-0571 and CVE-2004-0901.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criteria operator="OR">
               <criterion comment="...TextConv\mswrd6.wpc version is less than 10.0.803.2" test_ref="oval:org.mitre.oval:tst:2422"/>
               <criterion comment="...Accessories\mswrd6.wpc version is less than 10.0.803.2" test_ref="oval:gov.nist.fdcc.patch:tst:115301"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11528" version="2" class="patch">
         <metadata>
            <title>MS05-004: ASP.NET Path Validation Vulnerability (887219)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>.NET Framework</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2004-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0847"/>
            <reference source="Microsoft" ref_id="MS05-004" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS05-004.mspx"/>
            <reference source="Microsoft" ref_id="KB887219" ref_url="http://support.microsoft.com/default.aspx/kb/887219"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:3556" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3556"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:4987" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4987"/>
            <description>Microsoft has released MS05-004 to address security issues in Microsoft .NET Framework 1.0 and 1.1 on Microsoft Windows XP Service Pack 2 as documented by CVE-2004-0847.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criteria operator="OR" comment="A vulnerable version of .NET Framework v1.1 is installed.">
               <criteria operator="AND" comment="A vulnerable version of .NET Framework v1.1 (Gold) is installed.">
                  <extend_definition comment="Microsoft .NET Framework 1.1 (Gold) is Installed" definition_ref="oval:gov.nist.fdcc.patch:def:115273"/>
                  <criterion comment="System.web.dll version is less than 1.1.4322.1085" test_ref="oval:org.mitre.oval:tst:408"/>
               </criteria>
               <criteria operator="AND" comment="A vulnerable version of .NET Framework v1.1 (SP 1) is installed.">
                  <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
                  <criterion comment="System.web.dll version is less than 1.1.4322.2037" test_ref="oval:org.mitre.oval:tst:410"/>
               </criteria>
            </criteria>
            <criteria operator="OR" comment="A vulnerable version of .NET Framework v1.0 is installed.">
               <criteria operator="AND" comment="A vulnerable version of .NET Framework v1.0 (SP 2) is installed.">
                  <extend_definition comment="Microsoft .NET Framework 1.0 Service Pack 2 is Installed" definition_ref="oval:gov.nist.fdcc.patch:def:115271"/>
                  <criterion comment="System.web.dll version is less than 1.0.3705.556" test_ref="oval:org.mitre.oval:tst:290"/>
               </criteria>
               <criteria operator="AND" comment="A vulnerable version of .NET Framework v1.0 (SP3 or later) is installed.">
                  <extend_definition comment="Microsoft .NET Framework 1.0 Service Pack 3, or later, is Installed" definition_ref="oval:org.mitre.oval:def:2136"/>
                  <criterion comment="System.web.dll version is less than 1.0.3705.6021" test_ref="oval:org.mitre.oval:tst:287"/>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11529" version="1" class="patch">
         <metadata>
            <title>MS05-007: Vulnerability in Windows Could Allow Information Disclosure (888302)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2005-0051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0051"/>
            <reference source="Microsoft" ref_id="MS03-011" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS03-011.mspx"/>
            <reference source="Microsoft" ref_id="KB888302" ref_url="http://support.microsoft.com/default.aspx/kb/888302"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2292" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2292"/>
            <description>Microsoft has released MS05-007 to address security issues in Microsoft Windows XP (32-bit) SP2 as documented by CVE-2005-0051.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Srvsvc.dll version is less than 5.1.2600.2577" test_ref="oval:org.mitre.oval:tst:560"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11530" version="1" class="patch">
         <metadata>
            <title>MS05-032: Vulnerability in Microsoft Agent Could Allow Spoofing (890046)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Agent</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2005-1214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1214"/>
            <reference source="Microsoft" ref_id="MS05-032" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS05-032.mspx"/>
            <reference source="Microsoft" ref_id="KB890046" ref_url="http://support.microsoft.com/default.aspx/kb/890046"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1194" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1194"/>
            <description>Microsoft has released MS05-032 to address security issues in Microsoft Agent on Microsoft Windows XP (32-bit) SP2 as documented by CVE-2005-1214.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Agentdpv.dll version is less than 2.0.0.3423" test_ref="oval:org.mitre.oval:tst:2425"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11531" version="1" class="patch">
         <metadata>
            <title>MS05-051: Vulnerabilities in MSDTC and COM+ Could Allow Remote Code Execution (902400)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2005-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1978"/>
            <reference source="CVE" ref_id="CVE-2005-1979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1979"/>
            <reference source="CVE" ref_id="CVE-2005-1980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1980"/>
            <reference source="Microsoft" ref_id="MS05-051" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx"/>
            <reference source="Microsoft" ref_id="KB902400" ref_url="http://support.microsoft.com/default.aspx/kb/902400"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1499" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1499"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1134" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1134"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1182" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1182"/>
            <description>Microsoft has released MS05-051 to address security issues in COM+ on Microsoft Windows XP (32-bit) SP2 as documented by CVE-2005-1978, CVE-2005-1979, and CVE-2005-1980.</description>
         </metadata>
         <criteria comment="Software section" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.2726">
               <criterion comment="Ole32.dll version is less than 5.1.2600.2726" test_ref="oval:org.mitre.oval:tst:1134"/>
               <criterion comment="Rpcss.dll version is less than 5.1.2600.2726" test_ref="oval:org.mitre.oval:tst:1133"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11532" version="2" class="patch">
         <metadata>
            <title>MS06-005: Vulnerability in Windows Media Player Could Allow Remote Code Execution (911565)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Windows Media Player</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2006-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0006"/>
            <reference source="Microsoft" ref_id="MS06-005" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS06-005.mspx"/>
            <reference source="Microsoft" ref_id="KB911565" ref_url="http://support.microsoft.com/default.aspx/kb/911565"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1598" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1598"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1256" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1256"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1661" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1661"/>
            <description>Microsoft has released MS06-005 to address security issues in Media Player 9 or Media Player 10 on Microsoft Windows XP (32-bit) SP2 as documented by CVE-2006-0006.</description>
         </metadata>
         <criteria operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criteria operator="OR">
               <criteria comment="Windows Media Player 9" operator="AND">
                  <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
                  <criterion comment="Wmp.dll version is less than 9.0.0.3344" test_ref="oval:org.mitre.oval:tst:785"/>
               </criteria>
               <criteria comment="Windows Media Player 10" operator="AND">
                  <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
                  <criterion comment="Wmp.dll version is less than 10.0.0.4019" test_ref="oval:org.mitre.oval:tst:832"/>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11534" version="1" class="patch">
         <metadata>
            <title>MS06-042: Cumulative Security Update for Internet Explorer (918899)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Internet Explorer 6</product>
            </affected>
            <reference ref_id="CVE-2004-1166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1166" source="CVE"/>
            <reference ref_id="CVE-2006-3280" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3280" source="CVE"/>
            <reference ref_id="CVE-2006-3450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3450" source="CVE"/>
            <reference ref_id="CVE-2006-3451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3451" source="CVE"/>
            <reference ref_id="CVE-2006-3637" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3637" source="CVE"/>
            <reference ref_id="CVE-2006-3638" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3638" source="CVE"/>
            <reference ref_id="CVE-2006-3639" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3639" source="CVE"/>
            <reference ref_id="CVE-2006-3640" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3640" source="CVE"/>
            <reference source="Microsoft" ref_id="MS06-042" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS06-042.mspx"/>
            <reference source="Microsoft" ref_id="KB918899" ref_url="http://support.microsoft.com/default.aspx/kb/918899"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:462" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:462"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:738" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:738"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:433" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:433"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:502" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:502"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:719" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:719"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:577" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:577"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:171" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:171"/>
            <description>Microsoft has released MS06-042 to address security issues in Microsoft Internet Explorer 6 on Microsoft Windows XP (32-bit) SP2 as documented by CVE-2004-1166, CVE-2006-3280, CVE-2006-3450, CVE-2006-3451, CVE-2006-3637, CVE-2006-3638, CVE-2006-3639, and CVE-2006-3640.</description>
         </metadata>
         <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
            <criterion comment="Mshtml.dll version is less than 6.0.2900.2963" test_ref="oval:org.mitre.oval:tst:95"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11536" version="1" class="patch">
         <metadata>
            <title>MS06-069: Vulnerabilities in Macromedia Flash Player from Adobe Could Allow Remote Code Execution (923789)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Flash Player</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2006-3014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3014"/>
            <reference source="CVE" ref_id="CVE-2006-3311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3311"/>
            <reference source="CVE" ref_id="CVE-2006-3587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3587"/>
            <reference source="CVE" ref_id="CVE-2006-3588" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3588"/>
            <reference source="Microsoft" ref_id="MS06-069" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS06-069.mspx"/>
            <reference source="Microsoft" ref_id="KB923789" ref_url="http://support.microsoft.com/default.aspx/kb/923789"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:538" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:538"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:394" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:394"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1050" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1050"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:709" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:709"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:432" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:432"/>
            <description>Microsoft has released MS06-069 to address security issues in Macromedia Flash Player from Adobe, version 6.0.84.0 and earlier, on Microsoft Windows XP (32-bit) SP2 as documented by CVE-2006-3014, CVE-2006-3311, CVE-2006-3587, and CVE-2006-3588.</description>
         </metadata>
         <criteria comment="Flash.ocx exists without upgrades to Flash8 or Flash9" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Flash.ocx exists" test_ref="oval:org.mitre.oval:tst:79"/>
            <criterion negate="true" comment="Flash8.ocx version is greater than or equal 8.0.22.0" test_ref="oval:org.mitre.oval:tst:83"/>
            <criterion negate="true" comment="Flash9.ocx version is greater than or equal 9.0.16.0" test_ref="oval:org.mitre.oval:tst:85"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11537" version="1" class="patch">
         <metadata>
            <title>MS06-072: Cumulative Security Update for Internet Explorer (925454)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Internet Explorer 6</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2006-5577" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5577"/>
            <reference source="CVE" ref_id="CVE-2006-5578" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5578"/>
            <reference source="CVE" ref_id="CVE-2006-5579" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5579"/>
            <reference source="CVE" ref_id="CVE-2006-5581" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5581"/>
            <reference source="Microsoft" ref_id="MS06-072" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS06-072.mspx"/>
            <reference source="Microsoft" ref_id="KB925454" ref_url="http://support.microsoft.com/default.aspx/kb/925454"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:313" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:313"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:337" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:337"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:761" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:761"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:116" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:116"/>
            <description>Microsoft has released MS06-072 to address security issues in Microsoft Internet Explorer 6 on Microsoft Windows XP (32-bit) SP2 as documented by CVE-2006-5577, CVE-2006-5578, CVE-2006-5579, and CVE-2006-5581.</description>
         </metadata>
         <criteria comment="IE 6 on Windows XP (32-bit) SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
            <criterion comment="Mshtml.dll version is less than 6.0.2900.3020" test_ref="oval:org.mitre.oval:tst:132"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11538" version="1" class="patch">
         <metadata>
            <title>MS07-034: Cumulative Security Update for Outlook Express and Windows Mail (929123)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Outlook Express</product>
            </affected>
            <reference ref_id="CVE-2006-2111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2111" source="CVE"/>
            <reference ref_id="CVE-2007-2225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2225" source="CVE"/>
            <reference ref_id="CVE-2007-2227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2227" source="CVE"/>
            <reference source="Microsoft" ref_id="MS07-034" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS07-034.mspx"/>
            <reference source="Microsoft" ref_id="KB929123" ref_url="http://support.microsoft.com/default.aspx/kb/929123"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:1605" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1605"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2045" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2045"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:2085" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2085"/>
            <description>Microsoft has released MS06-072 to address security issues in Microsoft Outlook Express 6 on Microsoft Windows XP Service Pack 2 as documented by CVE-2006-2111, CVE-2007-2225, and CVE-2007-2227.</description>
         </metadata>
         <criteria operator="OR">
            <criteria comment="Outlook Express 6 on Windows XP (32-bit) SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.2900.3138" test_ref="oval:org.mitre.oval:tst:3908"/>
               <criterion comment="Directdb.dll version is less than 6.0.2900.3138" test_ref="oval:gov.nist.fdcc.patch:tst:115290"/>
               <criterion comment="Wab32.dll version is less than 6.0.2900.3138" test_ref="oval:gov.nist.fdcc.patch:tst:115291"/>
               <criterion comment="Msoe.dll version is less than 6.0.2900.3138" test_ref="oval:gov.nist.fdcc.patch:tst:115292"/>
               <criterion comment="Wabimp.dll version is less than 6.0.2900.3138" test_ref="oval:gov.nist.fdcc.patch:tst:115293"/>
            </criteria>
            <criteria comment="Outlook Express 6 on Windows XP (64-bit) SP2" operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.3790.4073" test_ref="oval:org.mitre.oval:tst:4092"/>
               <criterion comment="Directdb.dll version is less than 6.0.3790.4073" test_ref="oval:gov.nist.fdcc.patch:tst:115294"/>
               <criterion comment="Wab32.dll version is less than 6.0.3790.4073" test_ref="oval:gov.nist.fdcc.patch:tst:115295"/>
               <criterion comment="Msoe.dll version is less than 6.0.3790.4073" test_ref="oval:gov.nist.fdcc.patch:tst:115296"/>
               <criterion comment="Wabimp.dll version is less than 6.0.3790.4073" test_ref="oval:gov.nist.fdcc.patch:tst:115297"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11539" version="1" class="patch">
         <metadata>
            <title>MS05-009: Vulnerability in PNG Processing Could Allow Remote Code Execution (890261)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Windows Messenger 4.7</product>
            </affected>
            <reference source="CVE" ref_id="CVE-2004-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597"/>
            <reference source="Microsoft" ref_id="MS05-009" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS05-009.mspx"/>
            <reference source="Microsoft" ref_id="KB890261" ref_url="http://support.microsoft.com/default.aspx/kb/890261"/>
            <description>Microsoft has released MS05-009 to address security issues in Microsoft Windows Messenger version 4.7 on Microsoft Windows XP (32-bit) SP2 as documented by CVE-2004-0597.</description>
         </metadata>
         <criteria comment="Windows XP (32-bit) SP2" operator="AND">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Windows Messenger 4.7 is installed" definition_ref="oval:org.mitre.oval:def:6101"/>
            <criterion comment="Msmsgs.exe version is less than 4.7.0.3000" test_ref="oval:gov.nist.fdcc.patch:tst:115276"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11548" version="1" class="patch">
         <metadata>
            <title>MS09-007: Vulnerability in SChannel could allow spoofing (960225)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2009-0085" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0085"/>
            <reference source="Microsoft" ref_id="MS09-007" ref_url="http://www.microsoft.com/technet/security/Bulletin/ms09-007.mspx"/>
            <reference source="Microsoft" ref_id="KB960225" ref_url="http://support.microsoft.com/default.aspx/kb/960225"/>
            <description>Microsoft has released MS09-007 to address security issues in Windows XP and Windows Vista, CVE-2009-0085</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="WinXP,SP2 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Schannel.sys version is less than 5.1.2600.3487" test_ref="oval:gov.nist.fdcc.patch:tst:115481"/>
            </criteria>
            <criteria operator="AND" comment="WinXP,SP3 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Schannel.sys version is less than 5.1.2600.5721" test_ref="oval:gov.nist.fdcc.patch:tst:115482"/>
            </criteria>
            <criteria operator="AND" comment="WinXP,SP2 (64-bit)">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Schannel.sys version is less than 5.2.3790.4458" test_ref="oval:gov.nist.fdcc.patch:tst:115483"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
               </criteria>
               <criterion comment="Schannel.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115577"/>
               <criterion comment="Schannel.sys version is less than 6.0.6001.18175" test_ref="oval:gov.nist.fdcc.patch:tst:115484"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
               </criteria>
               <criterion comment="Schannel.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115578"/>
               <criterion comment="Schannel.sys version is less than 6.0.6001.22320" test_ref="oval:gov.nist.fdcc.patch:tst:115485"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11549" version="1" class="patch">
         <metadata>
            <title>MS09-010: Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product/>
            </affected>
            <reference source="Microsoft" ref_id="MS09-010" ref_url="http://www.microsoft.com/technet/security/bulletin/MB09-010"/>
            <reference source="Microsoft" ref_id="KB960477" ref_url="http://support.microsoft.com/kb/960477"/>
            <reference source="CVE" ref_id="CVE-2008-4841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4841"/>
            <reference source="CVE" ref_id="CVE-2009-0087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0087"/>
            <reference source="CVE" ref_id="CVE-2009-0235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0235"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6050" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6050"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5799" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5799"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5893" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5893"/>
            <description>Microsoft has released MS09-010 to address security issues in Microsoft Windows XP as documented by CVE-2008-4841, CVE-2009-0087, and CVE-2009-0235.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Mswrd8.wpc version is less than 10.0.803.10" test_ref="oval:gov.nist.fdcc.patch:tst:115315"/>
               <criterion comment="Wordpad.exe version is less than 5.1.2600.3355" test_ref="oval:gov.nist.fdcc.patch:tst:115317"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Mswrd8.wpc version is less than 2007.10.31.10" test_ref="oval:gov.nist.fdcc.patch:tst:115316"/>
               <criterion comment="Wordpad.exe version is less than 5.1.2600.5584" test_ref="oval:gov.nist.fdcc.patch:tst:115318"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mswrd8.wpc version is less than 10.0.803.10" test_ref="oval:gov.nist.fdcc.patch:tst:115315"/>
               <criterion comment="Wordpad.exe version is less than 5.2.3790.4282" test_ref="oval:gov.nist.fdcc.patch:tst:115319"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11550" version="2" class="patch">
         <metadata>
            <title>MS09-012: Vulnerabilities in Windows Could Allow Elevation of Privilege</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-012" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-012"/>
            <reference source="Microsoft" ref_id="KB959454" ref_url="http://support.microsoft.com/kb/959454"/>
            <reference source="CVE" ref_id="CVE-2008-1436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1436"/>
            <reference source="CVE" ref_id="CVE-2009-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0078"/>
            <reference source="CVE" ref_id="CVE-2009-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0079"/>
            <reference source="CVE" ref_id="CVE-2009-0080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0080"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5891" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5891"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6193" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6193"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6147" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6147"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6177" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6177"/>
            <description>Microsoft has released MS09-012 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2008-1436, CVE-2009-0078, CVE-2009-0079 and CVE-2009-0080.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criteria operator="OR">
                  <criterion comment="Msdtcprx.dll version is less than 2001.12.4414.320" test_ref="oval:gov.nist.fdcc.patch:tst:115320"/>
                  <criterion comment="Ntoskrnl.exe version is less than 5.1.2600.3520" test_ref="oval:gov.nist.fdcc.patch:tst:115321"/>
               </criteria>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criteria operator="OR">
                  <criterion comment="Msdtcprx.dll version is less than 2001.12.4414.706" test_ref="oval:gov.nist.fdcc.patch:tst:115322"/>
                  <criterion comment="Ntoskrnl.exe version is less than 5.1.2600.5755" test_ref="oval:gov.nist.fdcc.patch:tst:115323"/>
               </criteria>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Msdtcprx.dll version is less than 2001.12.4720.4340" test_ref="oval:gov.nist.fdcc.patch:tst:115324"/>
               <criterion comment="Ntoskrnl.exe version is less than 5.2.3790.4478" test_ref="oval:gov.nist.fdcc.patch:tst:115325"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND">
                     <criterion comment="Msdtcprx.dll version is greater than or equal to 2001.12.6931.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115326"/>
                     <criterion comment="Msdtcprx.dll version is less than 2001.12.6931.18085" test_ref="oval:gov.nist.fdcc.patch:tst:115328"/>
                  </criteria>
                  <criteria operator="AND">
                     <criterion comment="Ntoskrnl.exe version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115327"/>
                     <criterion comment="Ntoskrnl.exe version is less than 6.0.6001.18226" test_ref="oval:gov.nist.fdcc.patch:tst:115329"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND">
                     <criterion comment="Msdtcprx.dll version is greater than or equal to 2001.12.6931.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115330"/>
                     <criterion comment="Msdtcprx.dll version is less than 2001.12.6931.22197" test_ref="oval:gov.nist.fdcc.patch:tst:115332"/>
                  </criteria>
                  <criteria operator="AND">
                     <criterion comment="Ntoskrnl.exe version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115331"/>
                     <criterion comment="Ntoskrnl.exe version is less than 6.0.6001.22389" test_ref="oval:gov.nist.fdcc.patch:tst:115333"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11551" version="2" class="patch">
         <metadata>
            <title>MS09-013: Vulnerabilities in Windows HTTP Services Could Allow Remote Code Execution</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-013" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-013"/>
            <reference source="Microsoft" ref_id="KB960803" ref_url="http://support.microsoft.com/kb/960803"/>
            <reference source="CVE" ref_id="CVE-2009-0086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0086"/>
            <reference source="CVE" ref_id="CVE-2009-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0089"/>
            <reference source="CVE" ref_id="CVE-2009-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0550"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6149" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6149"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6027" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6027"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:7569" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7569"/>
            <description>Microsoft has released MS09-013 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2009-0086, CVE-2009-0089, and CVE-2009-0550.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Winhttp.dll version is less than 5.1.2600.3494" test_ref="oval:gov.nist.fdcc.patch:tst:115334"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Winhttp.dll version is less than 5.1.2600.5727" test_ref="oval:gov.nist.fdcc.patch:tst:115335"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Winhttp.dll version is less than 5.2.3790.4427" test_ref="oval:gov.nist.fdcc.patch:tst:115336"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Winhttp.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115337"/>
               <criterion comment="Winhttp.dll version is less than 6.0.6001.18178" test_ref="oval:gov.nist.fdcc.patch:tst:115338"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Winhttp.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115339"/>
               <criterion comment="Winhttp.dll version is less than 6.0.6001.22323" test_ref="oval:gov.nist.fdcc.patch:tst:115340"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11553" version="1" class="patch">
         <metadata>
            <title>MS09-011: Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (961373)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2009-0084" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0084"/>
            <reference source="Microsoft" ref_id="MS09-011" ref_url="http://www.microsoft.com/technet/security/Bulletin/ms09-011.mspx"/>
            <reference source="Microsoft" ref_id="KB961373" ref_url="http://support.microsoft.com/default.aspx/kb/961373"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6011" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6011"/>
            <description>Microsoft has released MS09-011 to address security issues in Windows XP as documented in CVE-2009-0085</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Quartz.dll version is less than 6.5.2600.3497" test_ref="oval:gov.nist.fdcc.patch:tst:115531"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Quartz.dll version is less than 6.5.2600.5731" test_ref="oval:gov.nist.fdcc.patch:tst:115532"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Quartz.dll version is less than 6.5.3790.4431" test_ref="oval:gov.nist.fdcc.patch:tst:115533"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11554" version="1" class="patch">
         <metadata>
            <title>MS09-015: Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (959426)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-015" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-015"/>
            <reference source="Microsoft" ref_id="KB959426" ref_url="http://support.microsoft.com/kb/959426"/>
            <reference source="CVE" ref_id="CVE-2008-2540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2540"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:8509" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8509"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:5782" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5782"/>
            <reference source="OVAL" ref_id="oval:org.mitre.oval:def:6108" ref_url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6108"/>
            <description>Microsoft has released MS09-015 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2008-2540.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Kernel32.dll version is less than 5.1.2600.3541" test_ref="oval:gov.nist.fdcc.patch:tst:115541"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Kernel32.dll version is less than 5.1.2600.5781" test_ref="oval:gov.nist.fdcc.patch:tst:115542"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Kernel32.dll version is less than 5.2.3790.4480" test_ref="oval:gov.nist.fdcc.patch:tst:115543"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Kernel32.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115544"/>
               <criterion comment="Kernel32.dll version is less than 6.0.6001.18215" test_ref="oval:gov.nist.fdcc.patch:tst:115545"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Kernel32.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115546"/>
               <criterion comment="Kernel32.dll version is less than 6.0.6001.22376" test_ref="oval:gov.nist.fdcc.patch:tst:115547"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11555" version="1" class="patch">
         <metadata>
            <title>MS09-020: Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Microsoft Internet Information Services 5.1</product>
               <product>Microsoft Internet Information Services 6.0</product>
            </affected>
            <reference source="Microsoft" ref_id="MS09-020" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS09-020.mspx"/>
            <reference source="Microsoft" ref_id="KB970483" ref_url="http://support.microsoft.com/kb/970483"/>
            <reference source="CVE" ref_id="CVE-2009-1535" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1535"/>
            <description>Microsoft has released MS09-020 to address security issues in Microsoft Internet Information Services (IIS) 5.1 and 6.0 as documented by CVE-2009-1535.</description>
         </metadata>
         <criteria operator="AND">
            <criteria operator="OR">
               <criteria operator="AND" comment="WinXP,SP2 (32-bit)">
                  <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <criterion comment="The iis optional component is installed" test_ref="oval:gov.nist.fdcc.patch:tst:4600001"/>
                  <criterion comment="Httpext.dll version is less than 6.0.2600.3574" test_ref="oval:gov.nist.fdcc.patch:tst:115579"/>
               </criteria>
               <criteria operator="AND" comment="WinXP,SP2 (64-bit)">
                  <criteria operator="OR">
                     <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
                     <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
                  </criteria>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <criterion comment="Httpext.dll version is less than 6.0.3790.4518" test_ref="oval:gov.nist.fdcc.patch:tst:115580"/>
               </criteria>
               <criteria operator="AND" comment="WinXP,SP3 (32-bit)">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
                  <criterion comment="The iis optional component is installed" test_ref="oval:gov.nist.fdcc.patch:tst:4600001"/>
                  <criterion comment="Httpext.dll version is less than 6.0.2600.5817" test_ref="oval:gov.nist.fdcc.patch:tst:115581"/>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11557" version="2" class="patch">
         <metadata>
            <title>MS09-026: Vulnerability in RPC Could Allow Elevation of Privilege (970238)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-026" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS09-026.mspx"/>
            <reference source="Microsoft" ref_id="KB970238" ref_url="http://support.microsoft.com/kb/970238"/>
            <reference source="CVE" ref_id="CVE-2009-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0568"/>
            <description>Microsoft has released MS09-026 to address security issues in Microsoft Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2009-0568.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="WinXP,SP2 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Rpcrt4.dll version is less than 5.1.2600.3555" test_ref="oval:gov.nist.fdcc.patch:tst:115593"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Rpcrt4.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115596"/>
               <criterion comment="Rpcrt4.dll version is less than 6.0.6001.18247" test_ref="oval:gov.nist.fdcc.patch:tst:115597"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Rpcrt4.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115598"/>
               <criterion comment="Rpcrt4.dll version is less than 6.0.6001.22417" test_ref="oval:gov.nist.fdcc.patch:tst:115599"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Rpcrt4.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115600"/>
               <criterion comment="Rpcrt4.dll version is less than 6.0.6002.18024" test_ref="oval:gov.nist.fdcc.patch:tst:115601"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Rpcrt4.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115602"/>
               <criterion comment="Rpcrt4.dll version is less than 6.0.6002.22120" test_ref="oval:gov.nist.fdcc.patch:tst:115603"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11566" version="2" class="patch">
         <metadata>
            <title>MS09-022: Vulnerabilities in Windows Print Spooler Could Allow Remote Code Execution (961501)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-022" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx"/>
            <reference source="Microsoft" ref_id="KB961501" ref_url="http://support.microsoft.com/kb/961501"/>
            <reference source="CVE" ref_id="CVE-2009-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0228"/>
            <reference source="CVE" ref_id="CVE-2009-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0229"/>
            <reference source="CVE" ref_id="CVE-2009-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0230"/>
            <description>Microsoft has released MS09-22 to address security issues in Microsoft Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2009-0228, CVE-2009-0229, and CVE-2009-0230.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="WinXP,SP2 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Localspl.dll version is less than 5.1.2600.3569" test_ref="oval:gov.nist.fdcc.patch:tst:115661"/>
            </criteria>
            <criteria operator="AND" comment="WinXP,SP2 (64-bit)">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Localspl.dll version is less than 5.2.3790.4509" test_ref="oval:gov.nist.fdcc.patch:tst:115662"/>
            </criteria>
            <criteria operator="AND" comment="WinXP,SP3 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Localspl.dll version is less than 5.1.2600.5809" test_ref="oval:gov.nist.fdcc.patch:tst:115663"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Localspl.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115667"/>
               <criterion comment="Localspl.dll version is less than 6.0.6001.18247" test_ref="oval:gov.nist.fdcc.patch:tst:1156631"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Localspl.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115668"/>
               <criterion comment="Localspl.dll version is less than 6.0.6001.22417" test_ref="oval:gov.nist.fdcc.patch:tst:115664"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Localspl.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115669"/>
               <criterion comment="Localspl.dll version is less than 6.0.6002.18024" test_ref="oval:gov.nist.fdcc.patch:tst:115665"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Localspl.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115660"/>
               <criterion comment="Localspl.dll version is less than 6.0.6002.22120" test_ref="oval:gov.nist.fdcc.patch:tst:115666"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11573" version="1" class="patch">
         <metadata>
            <title>MS09-040: Vulnerability in Message Queuing Could Allow Elevation of Privilege (971032)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-040" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-040.mspx"/>
            <reference source="Microsoft" ref_id="KB971032" ref_url="http://support.microsoft.com/kb/971032"/>
            <reference source="CVE" ref_id="CVE-2009-1922" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1922"/>
            <description>Microsoft has released MS09-040 to address security issues in Windows XP as documented by CVE-2009-1922</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Mqsvc.dll version is less than 5.1.0.1111" test_ref="oval:gov.nist.fdcc.patch:tst:115730"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Mqsvc.dll version is less than 5.1.0.1111" test_ref="oval:gov.nist.fdcc.patch:tst:115730"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mqsvc.dll version is less than 5.2.2007.4530" test_ref="oval:gov.nist.fdcc.patch:tst:115731"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11574" version="1" class="patch">
         <metadata>
            <title>MS09-041: Vulnerability in Workstation Service Could Allow Elevation of Privilege (971657)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-041" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-041.mspx"/>
            <reference source="Microsoft" ref_id="KB971657" ref_url="http://support.microsoft.com/kb/971657"/>
            <reference source="CVE" ref_id="CVE-2009-1544" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1544"/>
            <description>Microsoft has released MS09-041 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2009-1544</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Wkssvc.dll version is less than 5.1.2600.3584" test_ref="oval:gov.nist.fdcc.patch:tst:115740"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Wkssvc.dll version is less than 5.1.2600.5826  " test_ref="oval:gov.nist.fdcc.patch:tst:115741"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Wkssvc.dll version is less than 5.2.3790.4530  " test_ref="oval:gov.nist.fdcc.patch:tst:115742"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Wkssvc.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115743"/>
               <criterion comment="Wkssvc.dll version is less than 6.0.6001.18270" test_ref="oval:gov.nist.fdcc.patch:tst:115744"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Wkssvc.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115745"/>
               <criterion comment="Wkssvc.dll version is less than 6.0.6001.22447" test_ref="oval:gov.nist.fdcc.patch:tst:115746"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Wkssvc.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115747"/>
               <criterion comment="Wkssvc.dll version is less than 6.0.6002.18049" test_ref="oval:gov.nist.fdcc.patch:tst:115748"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Wkssvc.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115749"/>
               <criterion comment="Wkssvc.dll version is less than 6.0.6002.22150" test_ref="oval:gov.nist.fdcc.patch:tst:1157491"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11575" version="2" class="patch">
         <metadata>
            <title>MS09-042: Vulnerability in Telnet Could Allow Remote Code Execution (960859)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-042" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-042.mspx"/>
            <reference source="Microsoft" ref_id="KB960859" ref_url="http://support.microsoft.com/kb/960859"/>
            <reference source="CVE" ref_id="CVE-2009-1930" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1930"/>
            <description>Microsoft has released MS09-042 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2009-1930</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Telnet.exe version is less than 5.1.2600.3587" test_ref="oval:gov.nist.fdcc.patch:tst:115750"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Telnet.exe version is less than 5.1.2600.5829  " test_ref="oval:gov.nist.fdcc.patch:tst:115751"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Telnet.exe version is less than 5.2.3790.4528  " test_ref="oval:gov.nist.fdcc.patch:tst:115752"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Telnet.exe version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115753"/>
               <criterion comment="Telnet.exe version is less than 6.0.6001.18270" test_ref="oval:gov.nist.fdcc.patch:tst:115754"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Telnet.exe version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115755"/>
               <criterion comment="Telnet.exe version is less than 6.0.6001.22447" test_ref="oval:gov.nist.fdcc.patch:tst:115756"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Telnet.exe version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115757"/>
               <criterion comment="Telnet.exe version is less than 6.0.6002.18049" test_ref="oval:gov.nist.fdcc.patch:tst:115758"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Telnet.exe version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115759"/>
               <criterion comment="Telnet.exe version is less than 6.0.6002.22150" test_ref="oval:gov.nist.fdcc.patch:tst:1157591"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11576" version="2" class="patch">
         <metadata>
            <title>MS09-044: Vulnerabilities in Remote Desktop Connection Could Allow Remote Code Execution (970927)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-044" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-044.mspx"/>
            <reference source="Microsoft" ref_id="KB970927" ref_url="http://support.microsoft.com/kb/970927"/>
            <reference source="Microsoft" ref_id="KB958470" ref_url="http://support.microsoft.com/kb/958470"/>
            <reference source="Microsoft" ref_id="KB958469" ref_url="http://support.microsoft.com/kb/958469"/>
            <reference source="CVE" ref_id="CVE-2009-1133" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1133"/>
            <reference source="CVE" ref_id="CVE-2009-1929" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1929"/>
            <description>Microsoft has released MS09-044 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2009-1133 and CVE-2009-1929</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Mstscax.dll version is less than 5.1.2600.3581" test_ref="oval:gov.nist.fdcc.patch:tst:115761"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Mstscax.dll version is less than 5.1.2600.3581" test_ref="oval:gov.nist.fdcc.patch:tst:115761"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mstscax.dll version is less than 5.1.2600.3581" test_ref="oval:gov.nist.fdcc.patch:tst:115761"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="2k3mstsc.dll version is less than 5.2.3790.4522" test_ref="oval:gov.nist.fdcc.patch:tst:115762"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="2k3mstsc.dll version is less than 5.2.3790.4522 " test_ref="oval:gov.nist.fdcc.patch:tst:115762"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="2k3mstsc.dll version is less than 5.2.3790.4524" test_ref="oval:gov.nist.fdcc.patch:tst:115763"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6000.16000" test_ref="oval:gov.nist.fdcc.patch:tst:115764"/>
               <criterion comment="Mstscax.dll version is less than 6.0.6000.16865" test_ref="oval:gov.nist.fdcc.patch:tst:115765"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6000.21000" test_ref="oval:gov.nist.fdcc.patch:tst:115766"/>
               <criterion comment="Mstscax.dll version is less than 6.0.6000.21061" test_ref="oval:gov.nist.fdcc.patch:tst:115767"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115768"/>
               <criterion comment="Mstscax.dll version is less than 6.0.6001.18266" test_ref="oval:gov.nist.fdcc.patch:tst:115769"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1157691"/>
               <criterion comment="Mstscax.dll version is less than 6.0.6001.22443" test_ref="oval:gov.nist.fdcc.patch:tst:1157692"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6000.16000" test_ref="oval:gov.nist.fdcc.patch:tst:115764"/>
               <criterion comment="Mstscax.dll version is less than 6.0.6000.16865" test_ref="oval:gov.nist.fdcc.patch:tst:115765"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6000.21000" test_ref="oval:gov.nist.fdcc.patch:tst:115766"/>
               <criterion comment="Mstscax.dll version is less than 6.0.6000.21061" test_ref="oval:gov.nist.fdcc.patch:tst:115767"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115768"/>
               <criterion comment="Mstscax.dll version is less than 6.0.6001.18266" test_ref="oval:gov.nist.fdcc.patch:tst:115769"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1157691"/>
               <criterion comment="Mstscax.dll version is less than 6.0.6001.22443" test_ref="oval:gov.nist.fdcc.patch:tst:1157692"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1157693"/>
               <criterion comment="Mstscax.dll version is less than 6.0.6002.18045" test_ref="oval:gov.nist.fdcc.patch:tst:1157694"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1157695"/>
               <criterion comment="Mstscax.dll version is less than 6.0.6002.22146" test_ref="oval:gov.nist.fdcc.patch:tst:1157696"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11585" version="5" class="patch">
         <metadata>
            <title>MS09-045: Vulnerability in JScript Scripting Engine Could Allow Remote Code Execution (971961)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <!--<platform>Microsoft Windows Vista</platform>
                    <platform>Microsoft Windows Server 2008</platform>-->
            </affected>
            <reference source="Microsoft" ref_id="MS09-045" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-045.mspx"/>
            <reference source="Microsoft" ref_id="KB971961" ref_url="http://support.microsoft.com/kb/971961"/>
            <reference source="CVE" ref_id="CVE-2009-1920" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1920"/>
            <description>Microsoft has released MS09-045 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2009-1920</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Microsoft XP (32-bit SP2 or SP3, 64-bit SP2)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <!--<extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>-->
               </criteria>
               <criterion comment="Jscript.dll version is greater than or equal to 5.6.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:115851"/>
               <criterion comment="Jscript.dll version is less than 5.6.0.8837" test_ref="oval:gov.nist.fdcc.patch:tst:115852"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft XP (32-bit SP2 or SP3, 64-bit SP2)">
               <!--<criteria operator="OR">-->
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <!--<extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                        <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                    </criteria>-->
               <criterion comment="Jscript.dll version is greater than or equal to 5.7.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:115853"/>
               <criterion comment="Jscript.dll version is less than 5.7.6002.22145" test_ref="oval:gov.nist.fdcc.patch:tst:115854"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft XP (32-bit SP2 or SP3, 64-bit SP2)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <criterion comment="Jscript.dll version is greater than or equal to 5.8.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:115855"/>
               <criterion comment="Jscript.dll version is less than 5.8.6001.22886" test_ref="oval:gov.nist.fdcc.patch:tst:115856"/>
            </criteria>
            <!--<criteria operator="AND" comment="Vista, Server 2008 SP1 or SP2 (32-bit, 64-bit, ia-64) - GDR">
                   <criteria operator="OR">
                      <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                      <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                      <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                      <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                      <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                      <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                   </criteria>
                   <criterion comment="Jscript.dll version is greater than or equal to 5.7.0.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115857"/>
                   <criterion comment="Jscript.dll version is less than 5.7.0.18266" test_ref="oval:gov.nist.fdcc.patch:tst:115858"/>
                </criteria>-->
            <!--<criteria operator="AND" comment="Vista, Server 2008 SP1 or SP2 (32-bit, 64-bit, ia-64) - LDR">
                   <criteria operator="OR">
                      <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                      <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                      <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                      <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                      <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                      <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                   </criteria>
                   <criterion comment="Jscript.dll version is greater than or equal to 5.7.0.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115859"/>
                   <criterion comment="Jscript.dll version is less than 5.7.0.22443" test_ref="oval:gov.nist.fdcc.patch:tst:1158591"/>
                </criteria>-->
            <!--<criteria operator="AND" comment="Vista, Server 2008 SP1 or SP2 (32-bit, 64-bit, ia-64) - GDR">
                   <criteria operator="OR">
                      <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                      <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                      <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                      <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                      <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                      <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                   </criteria>
                   <criterion comment="Jscript.dll version is greater than or equal to 5.7.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1158592"/>
                   <criterion comment="Jscript.dll version is less than 5.7.6002.18045" test_ref="oval:gov.nist.fdcc.patch:tst:1158593"/>
                </criteria>-->
            <!--<criteria operator="AND" comment="Vista, Server 2008 SP1 or SP2 (32-bit, 64-bit, ia-64) - LDR">
                   <criteria operator="OR">
                      <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                      <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                      <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                      <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                      <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                      <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                   </criteria>
                   <criterion comment="Jscript.dll version is greater than or equal to 5.7.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1158531"/>
                   <criterion comment="Jscript.dll version is less than 5.7.6002.22146" test_ref="oval:gov.nist.fdcc.patch:tst:1158594"/>
                </criteria>-->
            <!--<criteria operator="AND" comment="Vista, Server 2008 SP1 or SP2 (32-bit, 64-bit, ia-64) - GDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Jscript.dll version is greater than or equal to 5.8.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1158595"/>
                    <criterion comment="Jscript.dll version is less than 5.8.6001.18795" test_ref="oval:gov.nist.fdcc.patch:tst:1158596"/>
                </criteria>-->
            <!--<criteria operator="AND" comment="Vista, Server 2008 SP1 or SP2 (32-bit, 64-bit, ia-64) - LDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Jscript.dll version is greater than or equal to 5.8.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1158551"/>
                    <criterion comment="Jscript.dll version is less than 5.8.6001.22886" test_ref="oval:gov.nist.fdcc.patch:tst:115856"/>
                </criteria>-->
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11586" version="1" class="patch">
         <metadata>
            <title>MS09-046: Vulnerability in DHTML Editing Component ActiveX Control Could Allow Remote Code Execution (956844)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-046" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-046.mspx"/>
            <reference source="Microsoft" ref_id="KB956844" ref_url="http://support.microsoft.com/kb/956844"/>
            <reference source="CVE" ref_id="CVE-2009-2519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2519"/>
            <description>Microsoft has released MS09-046 to address security issues in Windows XP as documented by CVE-2009-2519</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Triedit.dll version is less than 6.1.0.9246" test_ref="oval:gov.nist.fdcc.patch:tst:115860"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Triedit.dll version is less than 6.1.0.9246" test_ref="oval:gov.nist.fdcc.patch:tst:115860"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Triedit.dll version is less than 6.1.0.9246" test_ref="oval:gov.nist.fdcc.patch:tst:115860"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11590" version="4" class="patch">
         <metadata>
            <title>MS09-056: Vulnerabilities in Windows CryptoAPI Could Allow Spoofing (974571)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-056" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-056.mspx"/>
            <reference source="Microsoft" ref_id="KB974571" ref_url="http://support.microsoft.com/kb/974571"/>
            <reference source="CVE" ref_id="CVE-2009-2510" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2510"/>
            <reference source="CVE" ref_id="CVE-2009-2511" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2511"/>
            <description>Microsoft has released MS09-056 to address security issues in Windows XP, Windows Vista, Windows Server 2008, and Windows 7 as documented by CVE-2009-2510 and CVE-2009-2511.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Msasn1.dll version is less than 5.1.2600.3624" test_ref="oval:gov.nist.fdcc.patch:tst:1159000"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Msasn1.dll version is less than 5.1.2600.5875" test_ref="oval:gov.nist.fdcc.patch:tst:1159001"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Msasn1.dll version is less than 5.2.3790.4584" test_ref="oval:gov.nist.fdcc.patch:tst:1159002"/>
            </criteria>
            <criteria operator="AND" comment="The OS is Windows Vista or Server 2008 (Gold, SP1, or SP2) and the GDR or LDR patch is installed">
               <criteria operator="OR" comment="Either Windows Vista or Server 2008 is installed">
                  <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="The Gold, SP1, or SP2 GDR or LDR patch is installed">
                  <criteria operator="AND" comment="Vista, Server 2008 Gold (32-bit, 64-bit, ia-64) - GDR">
                     <criterion comment="Msasn1.dll version is less than  6.0.6000.16922" test_ref="oval:gov.nist.fdcc.patch:tst:1159015"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 Gold (32-bit, 64-bit, ia-64) - LDR">
                     <criterion comment="Msasn1.dll version is greater than or equal to 6.0.6000.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1159016"/>
                     <criterion comment="Msasn1.dll version is less than  6.0.6000.21122" test_ref="oval:gov.nist.fdcc.patch:tst:1159017"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR">
                     <criterion comment="Msasn1.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1159003"/>
                     <criterion comment="Msasn1.dll version is less than  6.0.6001.18326" test_ref="oval:gov.nist.fdcc.patch:tst:1159007"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
                     <criterion comment="Msasn1.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1159004"/>
                     <criterion comment="Msasn1.dll version is less than  6.0.6001.22515" test_ref="oval:gov.nist.fdcc.patch:tst:1159008"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
                     <criterion comment="Msasn1.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1159005"/>
                     <criterion comment="Msasn1.dll version is less than  6.0.6002.18106" test_ref="oval:gov.nist.fdcc.patch:tst:1159009"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
                     <criterion comment="Msasn1.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1159006"/>
                     <criterion comment="Msasn1.dll version is less than  6.0.6002.22218" test_ref="oval:gov.nist.fdcc.patch:tst:1159010"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="The OS is Windows 7 or Server 2008 R2 (Gold) and the  GDR or LDR patch is installed">
               <criteria operator="OR" comment="Either Windows 7 or Server 2008 R2 is installed">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="The (Gold) GDR or LDR patch is installed">
                  <criteria operator="AND" comment="7, Server 2008 R2 (Gold) - GDR">
                     <criterion comment="Msasn1.dll version is greater than or equal to 6.1.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1159011"/>
                     <criterion comment="Msasn1.dll version is less than  6.1.7600.16415" test_ref="oval:gov.nist.fdcc.patch:tst:1159013"/>
                  </criteria>
                  <criteria operator="AND" comment="7, Server 2008 R2 (Gold) - LDR">
                     <criterion comment="Msasn1.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1159012"/>
                     <criterion comment="Msasn1.dll version is less than  6.1.7600.20518" test_ref="oval:gov.nist.fdcc.patch:tst:1159014"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11591" version="1" class="patch">
         <metadata>
            <title>MS09-057: Vulnerability in Indexing Service Could Allow Remote Code Execution (969059)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-057" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-057.mspx"/>
            <reference source="Microsoft" ref_id="KB969059" ref_url="http://support.microsoft.com/kb/969059"/>
            <reference source="CVE" ref_id="CVE-2009-2507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2507"/>
            <description>Microsoft has released MS09-057 to address security issues in Windows XP as documented by CVE-2009-2507</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Query.dll version is less than 5.1.2600.3602" test_ref="oval:gov.nist.fdcc.patch:tst:1159100"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Query.dll version is less than 5.1.2600.5847" test_ref="oval:gov.nist.fdcc.patch:tst:1159101"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Query.dll version is less than 5.2.3790.4554" test_ref="oval:gov.nist.fdcc.patch:tst:1159102"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11593" version="1" class="patch">
         <metadata>
            <title>MS09-059: Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (975467)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-059" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-059.mspx"/>
            <reference source="Microsoft" ref_id="KB975467" ref_url="http://support.microsoft.com/kb/975467"/>
            <reference source="CVE" ref_id="CVE-2009-2524" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2524"/>
            <description>Microsoft has released MS09-059 to address security issues in Windows XP, Windows Vista, Windows Server 2008, and Windows 7 as documented by CVE-2009-2524</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Msv1_0.dll version is less than 5.1.2600.3625" test_ref="oval:gov.nist.fdcc.patch:tst:1159300"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Msv1_0.dll version is less than 5.1.2600.5876" test_ref="oval:gov.nist.fdcc.patch:tst:1159301"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Msv1_0.dll version is less than 5.2.3790.4587" test_ref="oval:gov.nist.fdcc.patch:tst:1159302"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Msv1_0.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1159303"/>
               <criterion comment="Msv1_0.dll version is less than  6.0.6001.18330" test_ref="oval:gov.nist.fdcc.patch:tst:1159307"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Msv1_0.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1159304"/>
               <criterion comment="Msv1_0.dll version is less than  6.0.6001.22518" test_ref="oval:gov.nist.fdcc.patch:tst:1159308"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Msv1_0.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1159305"/>
               <criterion comment="Msv1_0.dll version is less than  6.0.6002.18111" test_ref="oval:gov.nist.fdcc.patch:tst:1159309"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Msv1_0.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1159306"/>
               <criterion comment="Msv1_0.dll version is less than  6.0.6002.22223" test_ref="oval:gov.nist.fdcc.patch:tst:1159310"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Msv1_0.dll version is greater than or equal to 6.1.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1159311"/>
               <criterion comment="Msv1_0.dll version is less than  6.1.7600.16420" test_ref="oval:gov.nist.fdcc.patch:tst:1159313"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Msv1_0.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1159312"/>
               <criterion comment="Msv1_0.dll version is less than  6.1.7600.20524" test_ref="oval:gov.nist.fdcc.patch:tst:1159314"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11595" version="4" class="patch">
         <metadata>
            <title>MS09-062: Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <!--<platform>Microsoft Windows Vista</platform>
                    <platform>Microsoft Windows Server 2008</platform>-->
            </affected>
            <reference source="Microsoft" ref_id="MS09-062" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-062.mspx"/>
            <reference source="Microsoft" ref_id="kb957488" ref_url="http://support.microsoft.com/kb/957488"/>
            <reference source="CVE" ref_id="CVE-2009-2500" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2500"/>
            <reference source="CVE" ref_id="CVE-2009-2501" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2501"/>
            <reference source="CVE" ref_id="CVE-2009-2502" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2502"/>
            <reference source="CVE" ref_id="CVE-2009-2503" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2503"/>
            <reference source="CVE" ref_id="CVE-2009-2504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2504"/>
            <reference source="CVE" ref_id="CVE-2009-2504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2518"/>
            <reference source="CVE" ref_id="CVE-2009-2504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2528"/>
            <reference source="CVE" ref_id="CVE-2009-2504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3126"/>
            <description>Microsoft has released MS09-062 to address security issues in Windows XP; Windows Vista and Windows Vista Service Pack 1; Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1; Windows Server 2008 for 32-bit Systems, Windows Server 2008 for x64-based Systems, and Windows Server 2008 for Itanium-based Systems as documented by CVE-2009-2500, CVE-2009-2501, CVE-2009-2502, CVE-2009-2503, CVE-2009-2504, CVE-2009-2518, CVE-2009-2528, and CVE-2009-3126</description>
         </metadata>
         <!--<criteria operator="OR">-->
         <criteria operator="AND" comment="XP SP2/SP3 (32-bit/64-bit)">
            <!--<criteria operator="OR">-->
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <!--<extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                        <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                   </criteria>-->
            <criterion comment="Gdiplus.dll version is less than 5.2.6001.22319" test_ref="oval:gov.nist.fdcc.patch:tst:1159503"/>
         </criteria>
         <!--<criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
                   <criteria operator="OR">
                      <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                      <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                   </criteria>
                   <criterion comment="Gdiplus.dll version is greater than or equal to 5.2.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1159500"/>
                   <criterion comment="Gdiplus.dll version is less than  5.2.6001.18175" test_ref="oval:gov.nist.fdcc.patch:tst:1159502"/>
                </criteria>
                <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
                   <criteria operator="OR">
                      <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                      <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                      <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                   </criteria>
                   <criterion comment="Gdiplus.dll version is greater than or equal to 5.2.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1159501"/>
                   <criterion comment="Gdiplus.dll version is less than  5.2.6001.22319" test_ref="oval:gov.nist.fdcc.patch:tst:1159503"/>
                </criteria>
            </criteria>-->
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11601" version="3" class="patch">
         <metadata>
            <title>MS09-051: Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution (975682)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-051" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-051.mspx"/>
            <reference source="Microsoft" ref_id="KB975682" ref_url="http://support.microsoft.com/kb/975682"/>
            <reference source="CVE" ref_id="CVE-2009-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0555"/>
            <reference source="CVE" ref_id="CVE-2009-2525" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2525"/>
            <description>Microsoft has released MS09-051 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2009-0555 and CVE-2009-2525</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
               <criterion comment="Wmspdmod.dll version is less than 9.0.0.3269" test_ref="oval:gov.nist.fdcc.patch:tst:116010"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
               <criterion comment="Wmspdmod.dll version is less than 9.0.0.4505" test_ref="oval:gov.nist.fdcc.patch:tst:116011"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wmspdmod.dll version is less than 10.0.0.3704" test_ref="oval:gov.nist.fdcc.patch:tst:116012"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wmspdmod.dll version is greater than or equal to 10.0.0.4000" test_ref="oval:gov.nist.fdcc.patch:tst:116013"/>
               <criterion comment="Wmspdmod.dll version is less than 10.0.0.4070" test_ref="oval:gov.nist.fdcc.patch:tst:116014"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wmspdmod.dll version is greater than or equal to 10.0.0.4300" test_ref="oval:gov.nist.fdcc.patch:tst:116015"/>
               <criterion comment="Wmspdmod.dll version is less than 10.0.0.4365" test_ref="oval:gov.nist.fdcc.patch:tst:116016"/>
            </criteria>
            <criteria operator="AND">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <extend_definition comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
               <criterion comment="Wmspdmod.dll version is less than 11.0.5721.5263" test_ref="oval:gov.nist.fdcc.patch:tst:116017"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wmspdmod.dll version is less than 10.0.0.3819" test_ref="oval:gov.nist.fdcc.patch:tst:116018"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wmspdmod.dll version is greater than or equal to 10.0.0.4000" test_ref="oval:gov.nist.fdcc.patch:tst:116013"/>
               <criterion comment="Wmspdmod.dll version is less than 10.0.0.4004" test_ref="oval:gov.nist.fdcc.patch:tst:1160101"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
               <criterion comment="Wmspdmod.dll version is less than 11.0.5721.5263" test_ref="oval:gov.nist.fdcc.patch:tst:116017"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
               <criterion comment="Msaud32.acm version is less than 8.0.0.4502" test_ref="oval:gov.nist.fdcc.patch:tst:1160110"/>
            </criteria>
            <criteria operator="AND" comment="The OS is Windows Vista or Server 2008 (Gold, SP1, or SP2) and the GDR or LDR patch is installed">
               <criteria operator="OR" comment="Either Windows Vista or Server 2008 is installed">
                  <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="The Gold, SP1, or SP2 GDR or LDR patch is installed">
                  <criteria operator="AND" comment="Vista, Server 2008 Gold (32-bit, 64-bit, ia-64) - GDR">
                     <criterion comment="Wmspdmod.dll version is less than 11.0.6000.6350" test_ref="oval:gov.nist.fdcc.patch:tst:1160111"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 Gold (32-bit, 64-bit, ia-64) - LDR">
                     <criterion comment="Wmspdmod.dll version is greater than or equal to 11.0.6000.6500" test_ref="oval:gov.nist.fdcc.patch:tst:1160112"/>
                     <criterion comment="Wmspdmod.dll version is less than 11.0.6000.6509" test_ref="oval:gov.nist.fdcc.patch:tst:1160113"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR">
                     <criterion comment="Wmspdmod.dll version is greater than or equal to 11.0.6001.7000" test_ref="oval:gov.nist.fdcc.patch:tst:1160103"/>
                     <criterion comment="Wmspdmod.dll version is less than 11.0.6001.7005" test_ref="oval:gov.nist.fdcc.patch:tst:1160104"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
                     <criterion comment="Wmspdmod.dll version is greater than or equal to 11.0.6001.7100" test_ref="oval:gov.nist.fdcc.patch:tst:1160105"/>
                     <criterion comment="Wmspdmod.dll version is less than 11.0.6001.7111" test_ref="oval:gov.nist.fdcc.patch:tst:1160106"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
                     <criterion comment="Wmspdmod.dll version is greater than or equal to 11.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1160107"/>
                     <criterion comment="Wmspdmod.dll version is less than 11.0.6002.18034" test_ref="oval:gov.nist.fdcc.patch:tst:1160108"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
                     <criterion comment="Wmspdmod.dll version is greater than or equal to 11.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1160109"/>
                     <criterion comment="Wmspdmod.dll version is less than 11.0.6002.22131" test_ref="oval:gov.nist.fdcc.patch:tst:1160100"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11602" version="2" class="patch">
         <metadata>
            <title>MS09-053: Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution (975254)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-053" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-053.mspx"/>
            <reference source="Microsoft" ref_id="KB975254" ref_url="http://support.microsoft.com/kb/975254"/>
            <reference source="CVE" ref_id="CVE-2009-2521" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2521"/>
            <reference source="CVE" ref_id="CVE-2009-3023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3023"/>
            <description>Microsoft has released MS09-053 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2009-2521 and CVE-2009-3023</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="The FTP component is installed" test_ref="oval:gov.nist.fdcc.patch:tst:4600002"/>
               <criterion comment="Ftpsvc2.dll version is less than 6.0.2600.3624" test_ref="oval:gov.nist.fdcc.patch:tst:116020"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="The FTP component is installed" test_ref="oval:gov.nist.fdcc.patch:tst:4600002"/>
               <criterion comment="Ftpsvc2.dll version is less than  6.0.2600.5875" test_ref="oval:gov.nist.fdcc.patch:tst:116021"/>
            </criteria>
            <criteria operator="AND">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Ftpsvc2.dll version is less than 6.0.3790.4584  " test_ref="oval:gov.nist.fdcc.patch:tst:116022"/>
            </criteria>
            <criteria operator="AND" comment="The OS is Windows Vista or Server 2008 (Gold, SP1, or SP2) and the GDR or LDR patch is installed">
               <criteria operator="OR" comment="Either Windows Vista or Server 2008 is installed">
                  <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="The Gold, SP1, or SP2 GDR or LDR patch is installed">
                  <criteria operator="AND" comment="Vista, Server 2008 Gold (32-bit, 64-bit, ia-64) - GDR">
                     <criterion comment="Ftpsvc2.dll version is greater than or equal to 7.0.6000.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1160201"/>
                     <criterion comment="Ftpsvc2.dll version is less than 7.0.6000.16923" test_ref="oval:gov.nist.fdcc.patch:tst:1160202"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 Gold (32-bit, 64-bit, ia-64) - LDR">
                     <criterion comment="Ftpsvc2.dll version is greater than or equal to 7.0.6000.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1160203"/>
                     <criterion comment="Ftpsvc2.dll version is less than 7.0.6000.21123" test_ref="oval:gov.nist.fdcc.patch:tst:1160204"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR">
                     <criterion comment="Ftpsvc2.dll version is greater than or equal to 7.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116023"/>
                     <criterion comment="Ftpsvc2.dll version is less than 7.0.6001.18327" test_ref="oval:gov.nist.fdcc.patch:tst:116024"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
                     <criterion comment="Ftpsvc2.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116025"/>
                     <criterion comment="Ftpsvc2.dll version is less than 7.0.6001.22516" test_ref="oval:gov.nist.fdcc.patch:tst:116026"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
                     <criterion comment="Ftpsvc2.dll version is greater than or equal to 7.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116027"/>
                     <criterion comment="Ftpsvc2.dll version is less than 7.0.6002.18107" test_ref="oval:gov.nist.fdcc.patch:tst:116028"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
                     <criterion comment="Ftpsvc2.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116029"/>
                     <criterion comment="Ftpsvc2.dll version is less than 7.0.6002.22219" test_ref="oval:gov.nist.fdcc.patch:tst:1160200"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11603" version="1" class="patch">
         <metadata>
            <title>MS09-052: Vulnerability in Windows Media Player Could Allow Remote Code Execution (974112)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-052" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-052.mspx"/>
            <reference source="Microsoft" ref_id="KB974112" ref_url="http://support.microsoft.com/kb/974112"/>
            <reference source="CVE" ref_id="CVE-2009-2527" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2527"/>
            <description>Microsoft has released MS09-052 to address security issues in Windows XP as documented by CVE-2009-2527</description>
         </metadata>
         <criteria operator="AND">
            <criteria operator="OR">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            </criteria>
            <criterion comment="Strmdll.dll version is less than 4.1.0.3938" test_ref="oval:gov.nist.fdcc.patch:tst:116030"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11622" version="2" class="patch">
         <metadata>
            <title>MS09-066: Vulnerability in Active Directory Could Allow Denial of Service (973309)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-066" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-066.mspx"/>
            <reference source="Microsoft" ref_id="KB973309" ref_url="http://support.microsoft.com/kb/973309"/>
            <reference source="Microsoft" ref_id="KB973037" ref_url="http://support.microsoft.com/kb/973037"/>
            <reference source="Microsoft" ref_id="KB973039" ref_url="http://support.microsoft.com/kb/973039"/>
            <reference source="CVE" ref_id="CVE-2009-1928" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1928"/>
            <description>Microsoft has released MS09-066 to address security issues in Windows XP and Windows Server 2008 as documented by CVE-2009-1928</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP SP2 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="An Adam Instance has been created" test_ref="oval:gov.nist.fdcc.patch:tst:116229"/>
               <criterion comment="Adamdsa.dll version is less than 1.1.3790.4569" test_ref="oval:gov.nist.fdcc.patch:tst:116220"/>
            </criteria>
            <criteria operator="AND" comment="Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Ntdsai.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116221"/>
               <criterion comment="Ntdsai.dll version is less than  6.0.6001.18281" test_ref="oval:gov.nist.fdcc.patch:tst:116222"/>
            </criteria>
            <criteria operator="AND" comment="Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Ntdsai.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116223"/>
               <criterion comment="Ntdsai.dll version is less than  6.0.6001.22461" test_ref="oval:gov.nist.fdcc.patch:tst:116224"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11630" version="1" class="patch">
         <metadata>
            <title>MS09-069: Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-069" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-069.mspx"/>
            <reference source="Microsoft" ref_id="KB974392" ref_url="http://support.microsoft.com/kb/974392"/>
            <reference source="CVE" ref_id="CVE-2009-3675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3675"/>
            <description>Microsoft has released MS09-069 to address security issues in Windows XP as documented by CVE-2009-3675</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Oakley.dll version is less than 5.1.2600.3632" test_ref="oval:gov.nist.fdcc.patch:tst:116300"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Oakley.dll version is less than 5.1.2600.5886" test_ref="oval:gov.nist.fdcc.patch:tst:116301"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Oakley.dll version is less than 5.2.3790.4600" test_ref="oval:gov.nist.fdcc.patch:tst:116302"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11632" version="1" class="patch">
         <metadata>
            <title>MS09-071: Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-071" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-071.mspx"/>
            <reference source="Microsoft" ref_id="KB974318" ref_url="http://support.microsoft.com/kb/974318"/>
            <reference source="CVE" ref_id="CVE-2009-2505" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2505"/>
            <reference source="CVE" ref_id="CVE-2009-3677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3677"/>
            <description>Microsoft has released MS09-071 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2009-2505 and CVE-2009-3677</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Rastls.dll version is less than 5.1.2600.3632" test_ref="oval:gov.nist.fdcc.patch:tst:116320"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Rastls.dll version is less than 5.1.2600.5886" test_ref="oval:gov.nist.fdcc.patch:tst:116321"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Rastls.dll version is less than 5.2.3790.4600" test_ref="oval:gov.nist.fdcc.patch:tst:116322"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Rastls.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116323"/>
               <criterion comment="Rastls.dll version is less than  6.0.6001.18336" test_ref="oval:gov.nist.fdcc.patch:tst:116324"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Rastls.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116325"/>
               <criterion comment="Rastls.dll version is less than  6.0.6001.22536" test_ref="oval:gov.nist.fdcc.patch:tst:116326"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Rastls.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116327"/>
               <criterion comment="Rastls.dll version is less than  6.0.6002.18116" test_ref="oval:gov.nist.fdcc.patch:tst:116328"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Rastls.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116329"/>
               <criterion comment="Rastls.dll version is less than  6.0.6002.22240" test_ref="oval:gov.nist.fdcc.patch:tst:1163291"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11634" version="2" class="patch">
         <metadata>
            <title>MS09-073: Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS09-073" ref_url="http://www.microsoft.com/technet/security/bulletin/MS09-073.mspx"/>
            <reference source="Microsoft" ref_id="KB975539" ref_url="http://support.microsoft.com/kb/975539"/>
            <reference source="CVE" ref_id="CVE-2009-2506" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2506"/>
            <description>Microsoft has released MS09-073 to address security issues in Windows XP as documented by CVE-2009-2506</description>
         </metadata>
         <criteria operator="AND">
            <criteria operator="OR">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            </criteria>
            <criterion comment="Write32.wpc version is less than 2009.10.31.10" test_ref="oval:gov.nist.fdcc.patch:tst:116340"/>
            <criterion comment="Msconv97.dll version is less than 2003.1100.8165.0" test_ref="oval:gov.nist.fdcc.patch:tst:116341"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11640" version="1" class="patch">
         <metadata>
            <title>MS10-001: Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (972270)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-001" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-001.mspx"/>
            <reference source="Microsoft" ref_id="KB972270" ref_url="http://support.microsoft.com/kb/972270"/>
            <reference source="CVE" ref_id="CVE-2010-0018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0018"/>
            <description>Microsoft has released MS10-001 to address security issues in Windows XP, Windows Vista, Windows Server 2008, and Windows 7 as documented by CVE-2010-0018</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Fontsub.dll version is less than 5.1.2600.3634" test_ref="oval:gov.nist.fdcc.patch:tst:116400"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Fontsub.dll version is less than 5.1.2600.5888" test_ref="oval:gov.nist.fdcc.patch:tst:116401"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Fontsub.dll version is less than 5.2.3790.4603" test_ref="oval:gov.nist.fdcc.patch:tst:116402"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Fontsub.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116403"/>
               <criterion comment="Fontsub.dll version is less than  6.0.6001.18344" test_ref="oval:gov.nist.fdcc.patch:tst:116404"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Fontsub.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116405"/>
               <criterion comment="Fontsub.dll version is less than  6.0.6001.22544" test_ref="oval:gov.nist.fdcc.patch:tst:116406"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Fontsub.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116407"/>
               <criterion comment="Fontsub.dll version is less than  6.0.6002.18124" test_ref="oval:gov.nist.fdcc.patch:tst:116408"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Fontsub.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116409"/>
               <criterion comment="Fontsub.dll version is less than  6.0.6002.22247" test_ref="oval:gov.nist.fdcc.patch:tst:1164090"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Fontsub.dll version is greater than or equal to 6.1.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1164091"/>
               <criterion comment="Fontsub.dll version is less than  6.1.7600.16444" test_ref="oval:gov.nist.fdcc.patch:tst:1164092"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Fontsub.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1164093"/>
               <criterion comment="Fontsub.dll version is less than  6.1.7600.20553" test_ref="oval:gov.nist.fdcc.patch:tst:1164094"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11642" version="1" class="patch">
         <metadata>
            <title>MS10-005: Vulnerability in Microsoft Paint Could Allow Remote Code Execution (978706)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-005" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-005.mspx"/>
            <reference source="Microsoft" ref_id="KB978706" ref_url="http://support.microsoft.com/kb/978706"/>
            <reference source="CVE" ref_id="CVE-2010-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0028"/>
            <description>Microsoft has released MS10-005 to address security issues in Microsoft Paint on Windows XP as documented by CVE-2010-0028-</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Mspaint.exe version is less than 5.1.2600.3660" test_ref="oval:gov.nist.fdcc.patch:tst:1164201"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Mspaint.exe version is less than 5.1.2600.5918" test_ref="oval:gov.nist.fdcc.patch:tst:1164202"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mspaint.exe version is less than 5.2.3790.4638" test_ref="oval:gov.nist.fdcc.patch:tst:1164203"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11644" version="1" class="patch">
         <metadata>
            <title>MS10-007: Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (975713)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-007" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-007.mspx"/>
            <reference source="Microsoft" ref_id="KB975713" ref_url="http://support.microsoft.com/kb/975713"/>
            <reference source="CVE" ref_id="CVE-2010-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0027"/>
            <description>Microsoft has released MS10-007 to address security issues in Windows XP as documented by CVE-2010-0027</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Shlwapi.dll version is less than 6.0.3790.4603" test_ref="oval:gov.nist.fdcc.patch:tst:116440"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Shlwapi.dll version is less than 6.0.2900.3653" test_ref="oval:gov.nist.fdcc.patch:tst:116441"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Shlwapi.dll version is less than 6.0.2900.5912" test_ref="oval:gov.nist.fdcc.patch:tst:116442"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11648" version="2" class="patch">
         <metadata>
            <title>MS10-011: Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (978037)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-011" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-011.mspx"/>
            <reference source="Microsoft" ref_id="KB978037" ref_url="http://support.microsoft.com/kb/978037"/>
            <reference source="CVE" ref_id="CVE-2010-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0023"/>
            <description>Microsoft has released MS10-011 to address security issues in Windows XP as documented by CVE-2010-0023</description>
         </metadata>
         <!--<criteria operator="OR">-->
         <criteria operator="AND" comment="XP (32-bit) SP2">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Csrsrv.dll version is less than 5.1.2600.3657" test_ref="oval:gov.nist.fdcc.patch:tst:116480"/>
         </criteria>
         <!--<criteria operator="AND" comment="XP (32-bit) SP3">
					<extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
					<criterion comment="Csrsrv.dll version is less than 5.1.2600.5915" test_ref="oval:gov.nist.fdcc.patch:tst:116481"/>
				</criteria>
				<criteria operator="AND" comment="XP (64-bit) SP2">
					<extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
					<criterion comment="Csrsrv.dll version is less than 5.2.3790.4635" test_ref="oval:gov.nist.fdcc.patch:tst:116482"/>
				</criteria>
            </criteria>-->
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11650" version="2" class="patch">
         <metadata>
            <title>MS10-013: Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (977935)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-013" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-013.mspx"/>
            <reference source="Microsoft" ref_id="KB977935" ref_url="http://support.microsoft.com/kb/977935"/>
            <reference source="Microsoft" ref_id="KB975560" ref_url="http://support.microsoft.com/kb/975560"/>
            <reference source="Microsoft" ref_id="KB977914" ref_url="http://support.microsoft.com/kb/977914"/>
            <reference source="CVE" ref_id="CVE-2010-0250" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0250"/>
            <description>Microsoft has released MS10-013 to address security issues in Windows XP, Windows Vista, Windows Server 2008, and Windows 7 as documented by CVE-2010-0250</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criteria operator="OR">
                  <criterion comment="Quartz.dll version is less than 6.5.2600.3649" test_ref="oval:gov.nist.fdcc.patch:tst:116500"/>
                  <criterion comment="Avifil32.dll version is less than 5.1.2600.3649" test_ref="oval:gov.nist.fdcc.patch:tst:1165095"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criteria operator="OR">
                  <criterion comment="Quartz.dll version is less than 6.5.2600.5908" test_ref="oval:gov.nist.fdcc.patch:tst:116501"/>
                  <criterion comment="Avifil32.dll version is less than 5.1.2600.5908" test_ref="oval:gov.nist.fdcc.patch:tst:1165096"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criteria operator="OR">
                  <criterion comment="Quartz.dll version is less than 6.5.3790.4625" test_ref="oval:gov.nist.fdcc.patch:tst:116502"/>
                  <criterion comment="Avifil32.dll version is less than 5.2.3790.4625" test_ref="oval:gov.nist.fdcc.patch:tst:1165097"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Quartz.dll version is greater than or equal to 6.6.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116503"/>
               <criterion comment="Quartz.dll version is less than  6.6.6001.18389" test_ref="oval:gov.nist.fdcc.patch:tst:116504"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Quartz.dll version is greater than or equal to 6.6.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116505"/>
               <criterion comment="Quartz.dll version is less than  6.6.6001.22590" test_ref="oval:gov.nist.fdcc.patch:tst:116506"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Quartz.dll version is greater than or equal to 6.6.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116507"/>
               <criterion comment="Quartz.dll version is less than  6.6.6002.18158" test_ref="oval:gov.nist.fdcc.patch:tst:116508"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Quartz.dll version is greater than or equal to 6.6.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116509"/>
               <criterion comment="Quartz.dll version is less than  6.6.6002.22295" test_ref="oval:gov.nist.fdcc.patch:tst:1165090"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Quartz.dll version is greater than or equal to 6.6.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1165091"/>
               <criterion comment="Quartz.dll version is less than  6.6.7600.16490" test_ref="oval:gov.nist.fdcc.patch:tst:1165092"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Quartz.dll version is greater than or equal to 6.6.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1165093"/>
               <criterion comment="Quartz.dll version is less than  6.6.7600.20600" test_ref="oval:gov.nist.fdcc.patch:tst:1165094"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11655" version="2" class="patch">
         <metadata>
            <title>MS10-019: Vulnerabilities in Windows Could Allow Remote Code Execution (981210)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-019" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-019.mspx"/>
            <reference source="Microsoft" ref_id="KB981210" ref_url="http://support.microsoft.com/kb/981210"/>
            <reference source="CVE" ref_id="CVE-2010-0486" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0486"/>
            <reference source="CVE" ref_id="CVE-2010-0487" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0487"/>
            <description>Microsoft has released MS10-019 to address security issues in Windows Authenticode Verification as documented by CVE-2010-0486 and CVE-2010-0487</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criteria operator="OR">
                  <criterion comment="Wintrust.dll version is less than 5.131.2600.3661" test_ref="oval:gov.nist.fdcc.patch:tst:116551"/>
                  <criterion comment="Cabview.dll version is less than 6.0.2900.3663" test_ref="oval:gov.nist.fdcc.patch:tst:116552"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criteria operator="OR">
                  <criterion comment="Wintrust.dll version is less than 5.131.2600.5922" test_ref="oval:gov.nist.fdcc.patch:tst:116553"/>
                  <criterion comment="Cabview.dll version is less than 6.0.2900.5927" test_ref="oval:gov.nist.fdcc.patch:tst:116554"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criteria operator="OR">
                  <criterion comment="Wintrust.dll version is less than 5.131.3790.4642" test_ref="oval:gov.nist.fdcc.patch:tst:116555"/>
                  <criterion comment="Cabview.dll version is less than 6.0.3790.4649" test_ref="oval:gov.nist.fdcc.patch:tst:116556"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1/SP2 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND">
                     <criterion comment="Wintrust.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116557"/>
                     <criterion comment="Wintrust.dll version is less than 6.0.6001.18387" test_ref="oval:gov.nist.fdcc.patch:tst:116558"/>
                  </criteria>
                  <criteria operator="AND">
                     <criterion comment="Cabview.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116559"/>
                     <criterion comment="Cabview.dll version is less than 6.0.6001.18404" test_ref="oval:gov.nist.fdcc.patch:tst:1165510"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1/SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND">
                     <criterion comment="Wintrust.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165511"/>
                     <criterion comment="Wintrust.dll version is less than 6.0.6001.22588" test_ref="oval:gov.nist.fdcc.patch:tst:1165512"/>
                  </criteria>
                  <criteria operator="AND">
                     <criterion comment="Cabview.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165513"/>
                     <criterion comment="Cabview.dll version is less than 6.0.6001.22605" test_ref="oval:gov.nist.fdcc.patch:tst:1165514"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND">
                     <criterion comment="Wintrust.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1165515"/>
                     <criterion comment="Wintrust.dll version is less than 6.0.6002.18169" test_ref="oval:gov.nist.fdcc.patch:tst:1165516"/>
                  </criteria>
                  <criteria operator="AND">
                     <criterion comment="Cabview.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1165517"/>
                     <criterion comment="Cabview.dll version is less than 6.0.6002.18184" test_ref="oval:gov.nist.fdcc.patch:tst:1165518"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND">
                     <criterion comment="Wintrust.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165519"/>
                     <criterion comment="Wintrust.dll version is less than 6.0.6002.22293" test_ref="oval:gov.nist.fdcc.patch:tst:1165520"/>
                  </criteria>
                  <criteria operator="AND">
                     <criterion comment="Cabview.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165521"/>
                     <criterion comment="Cabview.dll version is less than 6.0.6002.22311" test_ref="oval:gov.nist.fdcc.patch:tst:1165522"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND">
                     <criterion comment="Wintrust.dll version is greater than or equal to 6.1.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1165523"/>
                     <criterion comment="Wintrust.dll version is less than 6.1.7600.16493" test_ref="oval:gov.nist.fdcc.patch:tst:1165524"/>
                  </criteria>
                  <criteria operator="AND">
                     <criterion comment="Cabview.dll version is greater than or equal to 6.1.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1165525"/>
                     <criterion comment="Cabview.dll version is less than 6.1.7600.16500" test_ref="oval:gov.nist.fdcc.patch:tst:1165526"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND">
                     <criterion comment="Wintrust.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1165527"/>
                     <criterion comment="Wintrust.dll version is less than 6.1.7600.20605" test_ref="oval:gov.nist.fdcc.patch:tst:1165528"/>
                  </criteria>
                  <criteria operator="AND">
                     <criterion comment="Cabview.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1165529"/>
                     <criterion comment="Cabview.dll version is less than 6.1.7600.20613" test_ref="oval:gov.nist.fdcc.patch:tst:1165530"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11657" version="4" class="patch">
         <metadata>
            <title>MS10-021: Vulnerabilities in Windows Kernel could allow Elevation of Privilege (979683)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-021" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-021.mspx"/>
            <reference source="Microsoft" ref_id="KB979683" ref_url="http://support.microsoft.com/kb/979683"/>
            <reference source="CVE" ref_id="CVE-2010-0234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0234"/>
            <reference source="CVE" ref_id="CVE-2010-0235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0235"/>
            <reference source="CVE" ref_id="CVE-2010-0236" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0236"/>
            <reference source="CVE" ref_id="CVE-2010-0237" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0237"/>
            <reference source="CVE" ref_id="CVE-2010-0238" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0238"/>
            <reference source="CVE" ref_id="CVE-2010-0481" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0481"/>
            <reference source="CVE" ref_id="CVE-2010-0482" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0482"/>
            <reference source="CVE" ref_id="CVE-2010-0810" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0810"/>
            <description>Microsoft has released MS10-021 to address security issues in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-0234, CVE-2010-0235, CVE-2010-0236, CVE-2010-0237, CVE-2010-0238, CVE-2010-0481, CVE-2010-0482, and CVE-2010-0810</description>
         </metadata>
         <!--<criteria operator="OR">-->
         <criteria operator="AND" comment="XP (32-bit) SP2">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Ntoskrnl.exe version is less than 5.1.2600.3670" test_ref="oval:gov.nist.fdcc.patch:tst:116571"/>
         </criteria>
         <!--<criteria operator="AND" comment="XP (64-bit) SP2">
					<extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
					<criterion comment="Ntoskrnl.exe version is less than 5.2.3790.4666" test_ref="oval:gov.nist.fdcc.patch:tst:116573"/>
				</criteria>
            </criteria>-->
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11658" version="4" class="patch">
         <metadata>
            <title>MS10-022: Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution (981169)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <!--<platform>Microsoft Windows Vista</platform>
                    <platform>Microsoft Windows Server 2008</platform>
                    <platform>Microsoft Windows 7</platform>
                    <platform>Microsoft Windows Server 2008 R2</platform>-->
            </affected>
            <reference source="Microsoft" ref_id="MS10-022" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-022.mspx"/>
            <reference source="Microsoft" ref_id="KB981169" ref_url="http://support.microsoft.com/kb/981169"/>
            <reference source="CVE" ref_id="CVE-2010-0483" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0483"/>
            <description>Microsoft has released MS10-022 to address security issues in Microsoft Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-0483</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit/64-bit) SP2 and VBScript 5.6">
               <!--<criteria operator="OR" comment="XP SP2 32-bit or 64-bit">-->
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <!--<extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                    </criteria>-->
               <criterion comment="Vbscript.dll version is less than 5.6.0.8838" test_ref="oval:gov.nist.fdcc.patch:tst:1165801"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit/64-bit) SP2, 32-bit SP3, and VBScript 5.7">
               <!--<criteria operator="OR" comment="XP SP2 (32-bit or 64-bit) or SP3 (32-bit)">-->
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <!--<extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                        <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                    </criteria>-->
               <criterion comment="Vbscript.dll version is greater than or equal to 5.7.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:1165802"/>
               <criterion comment="Vbscript.dll version is less than 5.7.6002.22354" test_ref="oval:gov.nist.fdcc.patch:tst:1165803"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit/64-bit) SP2, 32-bit SP3, and VBScript 5.8">
               <!--<criteria operator="OR" comment="XP SP2 (32-bit or 64-bit) or SP3 (32-bit)">-->
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <!--<extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                        <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                    </criteria>-->
               <criterion comment="Vbscript.dll version is greater than or equal to 5.8.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:1165804"/>
               <criterion comment="Vbscript.dll version is less than 5.8.6001.23000" test_ref="oval:gov.nist.fdcc.patch:tst:1165805"/>
            </criteria>
            <!--<criteria operator="AND" comment="Vista/Server 2008 SP1/SP2 (32-bit,64-bit, ia-64), and VBScript 5.7 - GDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Vbscript.dll version is greater than or equal to 5.7.0.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1165806"/>
                    <criterion comment="Vbscript.dll version is less than 5.7.0.18440" test_ref="oval:gov.nist.fdcc.patch:tst:1165807"/>
                </criteria>
                <criteria operator="AND" comment="Vista/Server 2008 SP1/SP2 (32-bit,64-bit, ia-64), and VBScript 5.8 - GDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Vbscript.dll version is greater than or equal to 5.8.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1165808"/>
                    <criterion comment="Vbscript.dll version is less than 5.8.6001.18909" test_ref="oval:gov.nist.fdcc.patch:tst:1165809"/>
                </criteria>
                <criteria operator="AND" comment="Vista/Server 2008 SP1/SP2 (32-bit, 64-bit, ia-64), and VBScript 5.7 - LDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Vbscript.dll version is greater than or equal to 5.7.0.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165810"/>
                    <criterion comment="Vbscript.dll version is less than 5.7.0.22648" test_ref="oval:gov.nist.fdcc.patch:tst:1165811"/>
                </criteria>
                <criteria operator="AND" comment="Vista/Server 2008 SP1/SP2 (32-bit, 64-bit, ia-64), and VBScript 5.8 - LDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Vbscript.dll version is greater than or equal to 5.8.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165812"/>
                    <criterion comment="Vbscript.dll version is less than 5.8.6001.23000" test_ref="oval:gov.nist.fdcc.patch:tst:1165805"/>
                </criteria>
                <criteria operator="AND" comment="Vista/Server 2008 SP2 (32-bit,64-bit, ia-64), and VBScript 5.7 - GDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Vbscript.dll version is greater than or equal to 5.7.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1165813"/>
                    <criterion comment="Vbscript.dll version is less than 5.7.6002.18222" test_ref="oval:gov.nist.fdcc.patch:tst:1165814"/>
                </criteria>
                <criteria operator="AND" comment="Vista/Server 2008 SP2 (32-bit, 64-bit, ia-64), and VBScript 5.7 - LDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Vbscript.dll version is greater than or equal to 5.7.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165815"/>
                    <criterion comment="Vbscript.dll version is less than 5.7.6002.22354" test_ref="oval:gov.nist.fdcc.patch:tst:1165803"/>
                </criteria>
                <criteria operator="AND" comment="7/Server 2008 R2 (32-bit, 64-bit, ia-64), and VBScript 5.8 - GDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                    </criteria>
                    <criterion comment="Vbscript.dll version is greater than or equal to 5.8.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1165816"/>
                    <criterion comment="Vbscript.dll version is less than 5.8.7600.16546" test_ref="oval:gov.nist.fdcc.patch:tst:1165817"/>
                </criteria>
                <criteria operator="AND" comment="7/Server 2008 R2 (32-bit, 64-bit, ia-64), and VBScript 5.8 - LDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                    </criteria>
                    <criterion comment="Vbscript.dll version is greater than or equal to 5.8.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1165818"/>
                    <criterion comment="Vbscript.dll version is less than 5.8.7600.20662" test_ref="oval:gov.nist.fdcc.patch:tst:1165819"/>
                </criteria>-->
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11659" version="2" class="patch">
         <metadata>
            <title>MS10-024: Vulnerabilities in Microsoft Exchange and Windows SMTP Service Could Allow Denial of Service (981832)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-024" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-024.mspx"/>
            <reference source="Microsoft" ref_id="KB981832" ref_url="http://support.microsoft.com/kb/981832"/>
            <reference source="CVE" ref_id="CVE-2010-0024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0024"/>
            <reference source="CVE" ref_id="CVE-2010-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0025"/>
            <description>Microsoft has released MS10-024 to address security issues in Microsoft Windows XP, Windows Server 2008, and Windows Server 2008 R2 as documented by CVE-2010-0024 and CVE-2010-0025.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Smtpsvc.dll version is less than 6.0.2600.3680" test_ref="oval:gov.nist.fdcc.patch:tst:1165901"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Smtpsvc.dll version is less than 6.0.2600.5949" test_ref="oval:gov.nist.fdcc.patch:tst:1165902"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Smtpsvc.dll version is less than 6.0.3790.4675" test_ref="oval:gov.nist.fdcc.patch:tst:1165903"/>
            </criteria>
            <criteria operator="AND" comment="Server 2008 SP1 (32-bit,64-bit) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criterion comment="Smtpsvc.dll version is greater than or equal to 7.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1165904"/>
               <criterion comment="Smtpsvc.dll version is less than 7.0.6001.18440" test_ref="oval:gov.nist.fdcc.patch:tst:1165905"/>
            </criteria>
            <criteria operator="AND" comment="Server 2008 SP1 (32-bit, 64-bit) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criterion comment="Smtpsvc.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165906"/>
               <criterion comment="Smtpsvc.dll version is less than 7.0.6001.22648" test_ref="oval:gov.nist.fdcc.patch:tst:1165907"/>
            </criteria>
            <criteria operator="AND" comment="Server 2008 SP2 (32-bit, 64-bit) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               </criteria>
               <criterion comment="Smtpsvc.dll version is greater than or equal to 7.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1165908"/>
               <criterion comment="Smtpsvc.dll version is less than 7.0.6002.18222" test_ref="oval:gov.nist.fdcc.patch:tst:1165909"/>
            </criteria>
            <criteria operator="AND" comment="Server 2008 SP2 (32-bit, 64-bit) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               </criteria>
               <criterion comment="Smtpsvc.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165910"/>
               <criterion comment="Smtpsvc.dll version is less than 7.0.6002.22354" test_ref="oval:gov.nist.fdcc.patch:tst:1165911"/>
            </criteria>
            <criteria operator="AND" comment="Server 2008 R2 (64-bit) - GDR">
               <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
               <criterion comment="Smtpsvc.dll version is greater than or equal to 7.5.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1165912"/>
               <criterion comment="Smtpsvc.dll version is less than 7.5.7600.16544" test_ref="oval:gov.nist.fdcc.patch:tst:1165913"/>
            </criteria>
            <criteria operator="AND" comment="Server 2008 R2 (64-bit) - LDR">
               <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
               <criterion comment="Smtpsvc.dll version is greater than or equal to 7.5.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1165914"/>
               <criterion comment="Smtpsvc.dll version is less than 7.5.7600.20660" test_ref="oval:gov.nist.fdcc.patch:tst:1165915"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11661" version="2" class="patch">
         <metadata>
            <title>MS10-027: Vulnerability in Windows Media Player Could Allow Remote Code Execution (979402)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Windows Media Player</product>
            </affected>
            <reference source="Microsoft" ref_id="MS10-027" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-027.mspx"/>
            <reference source="Microsoft" ref_id="KB979402" ref_url="http://support.microsoft.com/kb/979402"/>
            <reference source="CVE" ref_id="CVE-2010-0268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0268"/>
            <description>Microsoft has released MS10-027 to address security issues in as documented by CVE-2010-0268.</description>
         </metadata>
         <!--<criteria operator="OR">-->
         <criteria operator="AND" comment="XP (32-bit) SP2">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
            <criterion comment="Wmp.dll version is less than 9.0.0.3367" test_ref="oval:gov.nist.fdcc.patch:tst:116611"/>
         </criteria>
         <!--<criteria operator="AND" comment="XP (32-bit) SP3">
                    <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                    <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
                    <criterion comment="Wmp.dll version is less than 9.0.0.4508" test_ref="oval:gov.nist.fdcc.patch:tst:116612"/>
                </criteria>
            </criteria>-->
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11662" version="2" class="patch">
         <metadata>
            <title>MS10-026: Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (977816)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-026" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-026.mspx"/>
            <reference source="Microsoft" ref_id="KB977816" ref_url="http://support.microsoft.com/kb/977816"/>
            <reference source="CVE" ref_id="CVE-2010-0480" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0480"/>
            <description>Microsoft has released MS10-026 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2010-0480</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP SP2 or SP3">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <criterion comment="L3codeca.acm version is less than 1.9.0.306" test_ref="oval:gov.nist.fdcc.patch:tst:1166201"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Wl3codeca.acm version is less than 1.9.0.306" test_ref="oval:gov.nist.fdcc.patch:tst:1166202"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="L3codeca.acm version is less than 1.9.0.402" test_ref="oval:gov.nist.fdcc.patch:tst:1166203"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11665" version="3" class="patch">
         <metadata>
            <title>MS10-029: Vulnerability in Windows ISATAP Component Could Allow Spoofing (978338)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-029" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-029.mspx"/>
            <reference source="Microsoft" ref_id="KB978338" ref_url="http://support.microsoft.com/kb/978338"/>
            <reference source="CVE" ref_id="CVE-2010-0812" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0812"/>
            <description>Microsoft has released MS10-029 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2010-0812</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Tcpip6.sys version is less than 5.1.2600.3667" test_ref="oval:gov.nist.fdcc.patch:tst:1166501"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Tcpip6.sys version is less than 5.1.2600.5935" test_ref="oval:gov.nist.fdcc.patch:tst:1166502"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Tcpip6.sys version is less than 5.2.3790.4662" test_ref="oval:gov.nist.fdcc.patch:tst:1166503"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11666" version="2" class="patch">
         <metadata>
            <title>MS10-030: Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution (978542)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-030" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-030.mspx"/>
            <reference source="Microsoft" ref_id="KB978542" ref_url="http://support.microsoft.com/kb/978542"/>
            <reference source="CVE" ref_id="CVE-2010-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0816"/>
            <description>Microsoft has released MS10-030 to address security issues in as documented by CVE-2010-0816</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
               <criterion comment="Msoe.dll version is less than 6.0.2900.3664" test_ref="oval:gov.nist.fdcc.patch:tst:1166601"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
               <criterion comment="Msoe.dll version is less than 6.0.3790.4657" test_ref="oval:gov.nist.fdcc.patch:tst:1166602"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
               <criterion comment="Msoe.dll version is less than 6.0.2900.5931" test_ref="oval:gov.nist.fdcc.patch:tst:1166603"/>
            </criteria>
            <criteria operator="AND" comment="Windows Mail on Windows Vista (32-bit,64-bit) SP1, Server 2008 (32-bit,64-bit) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.6001.18416" test_ref="oval:gov.nist.fdcc.patch:tst:1166604"/>
            </criteria>
            <criteria operator="AND" comment="Windows Mail on Windows Vista (32-bit,64-bit) SP1, Server 2008 (32-bit,64-bit) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criterion comment="Inetcomm.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1166605"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.6001.22621" test_ref="oval:gov.nist.fdcc.patch:tst:1166606"/>
            </criteria>
            <criteria operator="AND" comment="Windows Mail on Windows Vista (32-bit,64-bit) SP2, Server 2008 (32-bit,64-bit) SP2 - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               </criteria>
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.6002.18197" test_ref="oval:gov.nist.fdcc.patch:tst:1166607"/>
            </criteria>
            <criteria operator="AND" comment="Windows Mail on Windows Vista (32-bit,64-bit) SP2, Server 2008 (32-bit,64-bit) SP2 - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               </criteria>
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criterion comment="Inetcomm.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1166608"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.6002.22325" test_ref="oval:gov.nist.fdcc.patch:tst:1166609"/>
            </criteria>
            <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia-64 - GDR">
               <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.6001.18427" test_ref="oval:gov.nist.fdcc.patch:tst:1166610"/>
            </criteria>
            <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia-64 - LDR">
               <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criterion comment="Inetcomm.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1166605"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.6001.22636" test_ref="oval:gov.nist.fdcc.patch:tst:1166612"/>
            </criteria>
            <criteria operator="AND" comment="Windows Mail on Windows Server 2008 SP2 ia-64 - GDR">
               <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.6002.18209" test_ref="oval:gov.nist.fdcc.patch:tst:1166613"/>
            </criteria>
            <criteria operator="AND" comment="Windows Mail on Windows Server 2008 SP2 ia-64 - LDR">
               <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criterion comment="Inetcomm.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1166608"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.6002.22341" test_ref="oval:gov.nist.fdcc.patch:tst:1166615"/>
            </criteria>
            <criteria operator="AND" comment="Windows Mail on Windows 7/Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criterion comment="Inetcomm.dll version is less than 6.1.7600.16543" test_ref="oval:gov.nist.fdcc.patch:tst:1166616"/>
            </criteria>
            <criteria operator="AND" comment="Windows Mail on Windows 7/Server 2008 R2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criterion comment="Inetcomm.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1166617"/>
               <criterion comment="Inetcomm.dll version is less than 6.1.7600.20659" test_ref="oval:gov.nist.fdcc.patch:tst:1166618"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11670" version="2" class="patch">
         <metadata>
            <title>MS10-032: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (979559)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-032" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-032.mspx"/>
            <reference source="Microsoft" ref_id="KB979559" ref_url="http://support.microsoft.com/kb/979559"/>
            <reference source="CVE" ref_id="CVE-2010-0484" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0484"/>
            <reference source="CVE" ref_id="CVE-2010-0485" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0485"/>
            <reference source="CVE" ref_id="CVE-2010-1255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1255"/>
            <description>Microsoft has released MS10-032 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-0484, CVE-2010-0485, and CVE-2010-1255</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Win32k.sys version is less than 5.1.2600.3706" test_ref="oval:gov.nist.fdcc.patch:tst:116700"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Win32k.sys version is less than 5.1.2600.5976" test_ref="oval:gov.nist.fdcc.patch:tst:116701"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Win32k.sys version is less than 5.2.3790.4702" test_ref="oval:gov.nist.fdcc.patch:tst:116702"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Win32k.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115476"/>
               <criterion comment="Win32k.sys version is less than  6.0.6001.18468" test_ref="oval:gov.nist.fdcc.patch:tst:116704"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Win32k.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115477"/>
               <criterion comment="Win32k.sys version is less than  6.0.6001.22682" test_ref="oval:gov.nist.fdcc.patch:tst:116706"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Win32k.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116217"/>
               <criterion comment="Win32k.sys version is less than  6.0.6002.18253" test_ref="oval:gov.nist.fdcc.patch:tst:116708"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Win32k.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116219"/>
               <criterion comment="Win32k.sys version is less than  6.0.6002.22396" test_ref="oval:gov.nist.fdcc.patch:tst:1167091"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Win32k.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1167092"/>
               <criterion comment="Win32k.sys version is less than 6.1.7600.16585" test_ref="oval:gov.nist.fdcc.patch:tst:1167093"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Win32k.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1167094"/>
               <criterion comment="Win32k.sys version is less than 6.1.7600.20704" test_ref="oval:gov.nist.fdcc.patch:tst:1167095"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11671" version="4" class="patch">
         <metadata>
            <title>MS10-033: Vulnerabilities in Media Decompression Could Allow Remote Code Execution (979902)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
               <product>Microsoft Media Encoder</product>
            </affected>
            <reference source="Microsoft" ref_id="MS10-033" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-033.mspx"/>
            <reference source="Microsoft" ref_id="KB979902" ref_url="http://support.microsoft.com/kb/979902"/>
            <reference source="Microsoft" ref_id="KB979482" ref_url="http://support.microsoft.com/kb/979482"/>
            <reference source="Microsoft" ref_id="KB978695" ref_url="http://support.microsoft.com/kb/978695"/>
            <reference source="Microsoft" ref_id="KB975562" ref_url="http://support.microsoft.com/kb/975562"/>
            <reference source="Microsoft" ref_id="KB979332" ref_url="http://support.microsoft.com/kb/979332"/>
            <reference source="CVE" ref_id="CVE-2010-1879" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1879"/>
            <reference source="CVE" ref_id="CVE-2010-1880" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1880"/>
            <description>Microsoft has released MS10-033 to address security issues in Microsoft Windows 2000, Windows XP, and Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-1879 and CVE-2010-1880.</description>
         </metadata>
         <criteria operator="OR">
            <!--<criteria operator="AND">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                        <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                        <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Wmenceng.dll version is less than 9.0.0.3369" test_ref="oval:gov.nist.fdcc.patch:tst:1167101"/>
                </criteria>-->
            <criteria operator="AND" comment="XP (32-bit) SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criteria operator="OR">
                  <criterion comment="Asycfilt.dll version is less than 5.1.2600.3680" test_ref="oval:gov.nist.fdcc.patch:tst:1167102"/>
                  <criterion comment="Quartz.dll version is less than 6.5.2600.3665" test_ref="oval:gov.nist.fdcc.patch:tst:1167117"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criteria operator="OR">
                  <criterion comment="Asycfilt.dll version is less than 5.1.2600.5949" test_ref="oval:gov.nist.fdcc.patch:tst:1167103"/>
                  <criterion comment="Quartz.dll version is less than 6.5.2600.5933" test_ref="oval:gov.nist.fdcc.patch:tst:1167118"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criteria operator="OR">
                  <criterion comment="Asycfilt.dll version is less than 5.2.3790.4676" test_ref="oval:gov.nist.fdcc.patch:tst:1167104"/>
                  <criterion comment="Quartz.dll version is less than 6.5.3790.4660" test_ref="oval:gov.nist.fdcc.patch:tst:1167119"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Asycfilt.dll version is less than  6.0.6001.18454" test_ref="oval:gov.nist.fdcc.patch:tst:1167106"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Asycfilt.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:11671081"/>
               <criterion comment="Asycfilt.dll version is less than  6.0.6001.22665" test_ref="oval:gov.nist.fdcc.patch:tst:1167108"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Asycfilt.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1167109"/>
               <criterion comment="Asycfilt.dll version is less than  6.0.6002.18236" test_ref="oval:gov.nist.fdcc.patch:tst:1167110"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Asycfilt.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:11671121"/>
               <criterion comment="Asycfilt.dll version is less than  6.0.6002.22377" test_ref="oval:gov.nist.fdcc.patch:tst:1167112"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Asycfilt.dll version is less than 6.1.7600.16544" test_ref="oval:gov.nist.fdcc.patch:tst:1167114"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Asycfilt.dll version is greater than or equal 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1167115"/>
               <criterion comment="Asycfilt.dll version is less than 6.1.7600.20660" test_ref="oval:gov.nist.fdcc.patch:tst:1167116"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Quartz.dll version is greater than or equal to 6.6.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116503"/>
               <criterion comment="Quartz.dll version is less than  6.6.6001.18461" test_ref="oval:gov.nist.fdcc.patch:tst:1167121"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Quartz.dll version is greater than or equal to 6.6.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116505"/>
               <criterion comment="Quartz.dll version is less than  6.6.6001.22672" test_ref="oval:gov.nist.fdcc.patch:tst:1167123"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP2 and Media Player v9.0">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
               <criterion comment="Wmvcore.dll version is greater than or equal to 9.0.0.3300" test_ref="oval:gov.nist.fdcc.patch:tst:2291"/>
               <criterion comment="Wmvcore.dll version is less than 9.0.0.3369" test_ref="oval:gov.nist.fdcc.patch:tst:1167125"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP3 and Media Player v9.0">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
               <criterion comment="Wmvcore.dll version is less than 9.0.0.4509" test_ref="oval:gov.nist.fdcc.patch:tst:1167126"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP2/SP3 and Media Player v10.0">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wmvcore.dll version is less than 10.0.0.3706" test_ref="oval:gov.nist.fdcc.patch:tst:1167127"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP2/SP3 and Media Player v10.0">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wmvcore.dll version is greater than or equal to 10.0.0.4000" test_ref="oval:gov.nist.fdcc.patch:tst:2293"/>
               <criterion comment="Wmvcore.dll version is less than 10.0.0.4078" test_ref="oval:gov.nist.fdcc.patch:tst:1167129"/>
            </criteria>
            <criteria operator="AND" comment="XP (32-bit) SP2/SP3 and Media Player v10.0">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               </criteria>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wmvcore.dll version is greater than or equal to 10.0.0.4300" test_ref="oval:gov.nist.fdcc.patch:tst:2295"/>
               <criterion comment="Wmvcore.dll version is less than 10.0.0.4374" test_ref="oval:gov.nist.fdcc.patch:tst:1167131"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2 and Media Player v10.0">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wmvcore.dll version is less than 10.0.0.4007" test_ref="oval:gov.nist.fdcc.patch:tst:1167132"/>
            </criteria>
            <criteria operator="AND" comment="XP (32/64-bit) SP2/SP3 and Media Player v11.0">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <extend_definition comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
               <criterion comment="Wmvcore.dll version is less than 11.0.5721.5275" test_ref="oval:gov.nist.fdcc.patch:tst:1167133"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11676" version="3" class="patch">
         <metadata>
            <title>MS10-041: Vulnerability in Microsoft .NET Framework Could Allow Tampering (981343)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-041" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-041.mspx"/>
            <reference source="Microsoft" ref_id="KB981343" ref_url="http://support.microsoft.com/kb/981343"/>
            <reference source="CVE" ref_id="CVE-2009-0217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217"/>
            <description>Microsoft has released MS10-041 to address security issues in Microsoft .NET Framework on Microsoft Windows XP, Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2 as documented by CVE-2009-0217. </description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="(vista sp1/2 (32/64) OR 2008 RTM/sp2 (32/64) OR xp sp2 OR xp x64 sp2 OR 7 OR 2008 R2) AND .net 1.1 sp1">
               <criteria operator="OR" comment="vista sp1/2 (32/64) OR 2008 RTM/sp2 (32/64) OR xp sp2 OR xp x64 sp2 OR 7 OR 2008 R2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <!--<extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>-->
                  <!--<extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>-->
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1, or later, is Installed" definition_ref="oval:gov.nist.fdcc.patch:def:115285"/>
               <criterion comment="system.security.dll version is less than 1.1.4322.2463" test_ref="oval:gov.nist.fdcc.patch:tst:1167600"/>
            </criteria>
            <criteria operator="AND" comment="(vista sp1 (32/64) OR 2008 RTM (32/64)) AND .net 2.0 sp1 OR .net 3.5 (Gold)">
               <criteria operator="OR" comment="vista sp1 (32/64) OR 2008 RTM (32/64)">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment=".net 2.0 sp1 OR .net 3.5">
                  <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6428"/>
                  <extend_definition comment="Microsoft .NET Framework 3.5 (Gold) is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11582"/>
               </criteria>
               <criterion comment="system.security.dll version is less than 2.0.50727.1878" test_ref="oval:gov.nist.fdcc.patch:tst:1167601"/>
            </criteria>
            <criteria operator="AND" comment="(xp sp2, xp sp3, OR xp x64 sp2) AND .net 3.5">
               <criteria operator="OR" comment="xp sp2, xp sp3, OR xp x64 sp2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 3.5 (Gold) is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11582"/>
               <criterion comment="system.security.dll version is less than 2.0.50727.1879" test_ref="oval:gov.nist.fdcc.patch:tst:1167602"/>
            </criteria>
            <criteria operator="AND" comment="(vista sp1 (32/64) OR 2008 RTM (32/64) OR xp sp2/3 OR xp x64 sp2) AND .net 2.0 sp2 OR 3.5 sp1">
               <criteria operator="OR" comment="vista sp1 (32/64) OR 2008 RTM (32/64) OR xp sp2/3 OR xp x64 sp2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment=".net 2.0 sp2 OR 3.5 sp1">
                  <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2, or later, is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
                  <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11583"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR update has been applied">
                  <criterion comment="system.security.dll version is less than 2.0.50727.3613" test_ref="oval:gov.nist.fdcc.patch:tst:1167603"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="system.security.dll version is greater than or equal to 2.0.50727.4400" test_ref="oval:gov.nist.fdcc.patch:tst:1167604"/>
                     <criterion comment="system.security.dll version is less than 2.0.50727.4434" test_ref="oval:gov.nist.fdcc.patch:tst:1167605"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="(vista sp2 (32/64) OR 2008 sp2 (32/64)) AND .net 2.0 sp2">
               <criteria operator="OR" comment="vista sp2 (32/64) OR 2008 sp2 (32/64)">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment=".net 2.0 sp2 OR 3.5 sp1">
                  <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2, or later, is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
                  <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11583"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR update has been applied">
                  <criterion comment="system.security.dll version is less than 2.0.50727.4204" test_ref="oval:gov.nist.fdcc.patch:tst:1167606"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="system.security.dll version is greater than or equal to 2.0.50727.4400" test_ref="oval:gov.nist.fdcc.patch:tst:1167604"/>
                     <criterion comment="system.security.dll version is less than 2.0.50727.4434" test_ref="oval:gov.nist.fdcc.patch:tst:1167605"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="(7 x86/x64 OR Server 2008 R2 x64/ia64) AND .NET 3.5 sp1">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11583"/>
               <criteria operator="OR" comment="GDR or LDR update has been applied">
                  <criterion comment="system.security.dll version is less than 2.0.50727.4951" test_ref="oval:gov.nist.fdcc.patch:tst:1167607"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="system.security.dll version is greater than or equal to 2.0.50727.5000" test_ref="oval:gov.nist.fdcc.patch:tst:1167608"/>
                     <criterion comment="system.security.dll version is less than 2.0.50727.5007" test_ref="oval:gov.nist.fdcc.patch:tst:1167609"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11677" version="2" class="patch">
         <metadata>
            <title>MS10-042: Vulnerability in Help and Support Center Could Allow Remote Code Execution (2229593)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-042" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-042.mspx"/>
            <reference source="Microsoft" ref_id="KB2229593" ref_url="http://support.microsoft.com/kb/2229593"/>
            <reference source="CVE" ref_id="CVE-2010-1885" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1885"/>
            <description>Microsoft has released MS10-042 to address security issues in as documented by CVE-2010-1885</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Helpsvc.exe version is less than 5.2.3790.4726" test_ref="oval:gov.nist.fdcc.patch:tst:116770"/>
            </criteria>
            <criteria operator="AND" comment="XP x86 SP2">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <criterion comment="Helpsvc.exe version is less than 5.1.2600.3720" test_ref="oval:gov.nist.fdcc.patch:tst:116771"/>
            </criteria>
            <criteria operator="AND" comment="XP x86 SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Helpsvc.exe version is less than 5.1.2600.5997" test_ref="oval:gov.nist.fdcc.patch:tst:116772"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11682" version="2" class="patch">
         <metadata>
            <title>MS10-049: Vulnerabilities in SChannel could allow Remote Code Execution (980436)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <!--<platform>Microsoft Windows Vista</platform>
                    <platform>Microsoft Windows Server 2008</platform>
                    <platform>Microsoft Windows 7</platform>
                    <platform>Microsoft Windows Server 2008 R2</platform>-->
            </affected>
            <reference source="Microsoft" ref_id="MS10-049" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS10-049.mspx"/>
            <reference source="Microsoft" ref_id="KB980436" ref_url="http://support.microsoft.com/default.aspx/kb/980436"/>
            <reference source="CVE" ref_id="CVE-2009-3555" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555"/>
            <reference source="CVE" ref_id="CVE-2010-2566" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2566"/>
            <description>Microsoft has released MS10-049 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2009-3555 and 2010-2566</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="WinXP,SP3 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Schannel.dll version is less than 5.1.2600.6006" test_ref="oval:gov.nist.fdcc.patch:tst:116820"/>
            </criteria>
            <criteria operator="AND" comment="WinXP,SP2 (64-bit)">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Schannel.dll version is less than 5.2.3790.4724" test_ref="oval:gov.nist.fdcc.patch:tst:116821"/>
            </criteria>
            <!--<criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                    </criteria>
                    <criterion comment="Schannel.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115577"/>
                    <criterion comment="Schannel.dll version is less than  6.0.6001.18490" test_ref="oval:gov.nist.fdcc.patch:tst:116823"/>
                </criteria>
                <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                    </criteria>
                    <criterion comment="Schannel.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115578"/>
                    <criterion comment="Schannel.dll version is less than  6.0.6001.22709" test_ref="oval:gov.nist.fdcc.patch:tst:116825"/>
                </criteria>
                <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Schannel.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116826"/>
                    <criterion comment="Schannel.dll version is less than  6.0.6002.18269" test_ref="oval:gov.nist.fdcc.patch:tst:116827"/>
                </criteria>
                <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                    </criteria>
                    <criterion comment="Schannel.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116828"/>
                    <criterion comment="Schannel.dll version is less than  6.0.6002.22422" test_ref="oval:gov.nist.fdcc.patch:tst:116829"/>
                </criteria>
                <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                    </criteria>
                    <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Schannel.dll version is less than 6.1.7600.16612" test_ref="oval:gov.nist.fdcc.patch:tst:1168290"/>
                        <criteria operator="AND" comment="LDR">
                            <criterion comment="Schannel.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1168291"/>
                            <criterion comment="Schannel.dll version is less than 6.1.7600.20735" test_ref="oval:gov.nist.fdcc.patch:tst:1168292"/>
                        </criteria>
                    </criteria>
                </criteria>-->
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11683" version="1" class="patch">
         <metadata>
            <title>MS10-050: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (981997)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>Movie Maker 2.1</product>
               <product>Movie Maker 6.0</product>
               <product>Microsoft Producer 2003</product>
            </affected>
            <reference source="Microsoft" ref_id="MS10-050" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-050.mspx"/>
            <reference source="Microsoft" ref_id="KB981997" ref_url="http://support.microsoft.com/kb/981997"/>
            <reference source="CVE" ref_id="CVE-2010-2564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2564"/>
            <description>Microsoft has released MS10-050 to address security issues in Windows XP and Windows Vista as documented by CVE-2010-2564</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Moviemk.exe version is less than 2.1.4028.0" test_ref="oval:gov.nist.fdcc.patch:tst:116830"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Windows Movie Maker 2.1 is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115291"/>
               <criterion comment="Wmoviemk.exe version is less than 2.1.40310" test_ref="oval:gov.nist.fdcc.patch:tst:116831"/>
            </criteria>
            <criteria operator="AND" comment="Vista SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
               </criteria>
               <extend_definition comment="Windows Movie Maker 6.0 is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115293"/>
               <criterion comment="Moviemk.exe version is less than 6.0.6001.18494" test_ref="oval:gov.nist.fdcc.patch:tst:116832"/>
            </criteria>
            <criteria operator="AND" comment="Vista SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
               </criteria>
               <extend_definition comment="Windows Movie Maker 6.0 is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115293"/>
               <criterion comment="Moviemk.exe version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116534"/>
               <criterion comment="Moviemk.exe version is less than 6.0.6001.22714" test_ref="oval:gov.nist.fdcc.patch:tst:116834"/>
            </criteria>
            <criteria operator="AND" comment="Vista SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
               </criteria>
               <extend_definition comment="Windows Movie Maker 6.0 is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115293"/>
               <criterion comment="Moviemk.exe version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116835"/>
               <criterion comment="Moviemk.exe version is less than 6.0.6002.18273" test_ref="oval:gov.nist.fdcc.patch:tst:116836"/>
            </criteria>
            <criteria operator="AND" comment="Vista SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
               </criteria>
               <extend_definition comment="Windows Movie Maker 6.0 is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115293"/>
               <criterion comment="Moviemk.exe version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116538"/>
               <criterion comment="Moviemk.exe version is less than 6.0.6002.22426" test_ref="oval:gov.nist.fdcc.patch:tst:116838"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11684" version="3" class="patch">
         <metadata>
            <title>MS10-051: Vulnerability in Microsoft XML Core Services 3.0 Could Allow Remote Code Execution (2079403)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="CVE" ref_id="CVE-2010-2561" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2561"/>
            <reference source="Microsoft" ref_id="MS10-051" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-051.mspx"/>
            <reference source="Microsoft" ref_id="KB2079403" ref_url="http://support.microsoft.com/kb/2079403"/>
            <description>Microsoft has released MS10-051 to address security issues in Windows 2000, Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-2561</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Msxml3.dll version is less than 8.100.1052.0" test_ref="oval:gov.nist.fdcc.patch:tst:116840"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Msxml3.dll version is less than 8.100.4002.0" test_ref="oval:gov.nist.fdcc.patch:tst:116841"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Msxml3.dll version is less than 8.100.5003.0" test_ref="oval:gov.nist.fdcc.patch:tst:116842"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Msxml3.dll version is less than 8.110.7600.16605" test_ref="oval:gov.nist.fdcc.patch:tst:116843"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="Msxml3.dll version is greater than or equal to 8.110.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:116844"/>
               <criterion comment="Msxml3.dll version is less than 8.110.7600.20728" test_ref="oval:gov.nist.fdcc.patch:tst:116845"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11685" version="1" class="patch">
         <metadata>
            <title>MS10-052: Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (2115168)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-052" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-052.mspx"/>
            <reference source="Microsoft" ref_id="KB2115168" ref_url="http://support.microsoft.com/kb/2115168"/>
            <reference source="CVE" ref_id="CVE-2010-1882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1882"/>
            <description>Microsoft has released MS10-052 to address security issues in Windows XP as documented by CVE-2010-1882</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP x86 SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="L3codecx.ax version is less than 1.6.0.52" test_ref="oval:gov.nist.fdcc.patch:tst:116850"/>
            </criteria>
            <criteria operator="AND" comment="XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Wl3codecx.ax version is less than 1.6.0.52" test_ref="oval:gov.nist.fdcc.patch:tst:116851"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11688" version="1" class="patch">
         <metadata>
            <title>MS10-055: Vulnerability in Cinepak Codec Could Allow Remote Code Execution (982665)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows 7</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-055" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-055.mspx"/>
            <reference source="Microsoft" ref_id="KB982665" ref_url="http://support.microsoft.com/kb/982665"/>
            <reference source="CVE" ref_id="CVE-2010-2553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2553"/>
            <description>Microsoft has released MS10-055 to address security issues in Windows XP, Windows Vista, and Windows 7 as documented by CVE-2010-2553</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
               <criteria operator="OR" comment="xp sp3 OR vista sp1/2 (32/64) OR 7">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
               </criteria>
               <criterion comment="Iccvid.dll version is less than 1.10.0.13" test_ref="oval:gov.nist.fdcc.patch:tst:1168800"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Wiccvid.dll version is less than 1.10.0.13" test_ref="oval:gov.nist.fdcc.patch:tst:1168801"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11692" version="1" class="patch">
         <metadata>
            <title>MS10-061: Vulnerability in Print Spooler Service Could Allow Remote Code Execution (2347290)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-061" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS10-061.mspx"/>
            <reference source="Microsoft" ref_id="KB2347290" ref_url="http://support.microsoft.com/default.aspx/kb/2347290"/>
            <reference source="CVE" ref_id="CVE-2010-2729" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2729"/>
            <description>Microsoft has released MS10-061 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-2729</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="WinXP,SP3 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Spoolsv.exe version is less than 5.1.2600.6024" test_ref="oval:gov.nist.fdcc.patch:tst:116920"/>
            </criteria>
            <criteria operator="AND" comment="WinXP,SP2 (64-bit)">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Spoolsv.exe version is less than 5.2.3790.4759" test_ref="oval:gov.nist.fdcc.patch:tst:116921"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Spoolsv.exe version is less than 6.0.6001.18511" test_ref="oval:gov.nist.fdcc.patch:tst:116923"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Spoolsv.exe version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116924"/>
               <criterion comment="Spoolsv.exe version is less than 6.0.6001.22743" test_ref="oval:gov.nist.fdcc.patch:tst:116925"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Spoolsv.exe version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116926"/>
               <criterion comment="Spoolsv.exe version is less than 6.0.6002.18294" test_ref="oval:gov.nist.fdcc.patch:tst:116927"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Spoolsv.exe version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116928"/>
               <criterion comment="Spoolsv.exe version is less than 6.0.6002.22468" test_ref="oval:gov.nist.fdcc.patch:tst:116929"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Spoolsv.exe version is less than 6.1.7600.16661" test_ref="oval:gov.nist.fdcc.patch:tst:1169290"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Spoolsv.exe version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1169291"/>
                     <criterion comment="Spoolsv.exe version is less than 6.1.7600.20785" test_ref="oval:gov.nist.fdcc.patch:tst:1169292"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11693" version="1" class="patch">
         <metadata>
            <title>MS10-062: Vulnerability in MPEG-4 Codec Could Allow Remote Code Execution (975558)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-062" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS10-062.mspx"/>
            <reference source="Microsoft" ref_id="KB975558" ref_url="http://support.microsoft.com/default.aspx/kb/975558"/>
            <reference source="CVE" ref_id="CVE-2010-0818" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0818"/>
            <description>Microsoft has released MS10-062 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2010-0818</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="WinXP,SP3 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criteria operator="OR" comment="GDR or QFE Service branch">
                  <criterion comment="Mp4sdmod.dll version is less than 9.0.0.4509" test_ref="oval:gov.nist.fdcc.patch:tst:116930"/>
                  <criteria operator="AND" comment="GDR or QFE">
                     <criterion comment="Mp4sdmod.dll version is greater than or equal to 10.0.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:116931"/>
                     <criterion comment="Mp4sdmod.dll version is less than 10.0.0.3706" test_ref="oval:gov.nist.fdcc.patch:tst:116932"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="WinXP,SP2 (64-bit)">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mp4sdmod.dll version is less than 10.0.0.4007" test_ref="oval:gov.nist.fdcc.patch:tst:116933"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Mp4sdecd.dll version is less than 11.0.6001.7009" test_ref="oval:gov.nist.fdcc.patch:tst:116934"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Mp4sdecd.dll version is greater than or equal to 11.0.6001.7100" test_ref="oval:gov.nist.fdcc.patch:tst:116935"/>
               <criterion comment="Mp4sdecd.dll version is less than 11.0.6001.7117" test_ref="oval:gov.nist.fdcc.patch:tst:116936"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Mp4sdecd.dll version is less than 11.0.6002.18236" test_ref="oval:gov.nist.fdcc.patch:tst:116938"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Mp4sdecd.dll version is greater than or equal to 11.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116939"/>
               <criterion comment="Mp4sdecd.dll version is less than 11.0.6002.22377" test_ref="oval:gov.nist.fdcc.patch:tst:1169390"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11694" version="1" class="patch">
         <metadata>
            <title>MS10-063: Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution (2320113)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-063" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS10-063.mspx"/>
            <reference source="Microsoft" ref_id="KB2320113" ref_url="http://support.microsoft.com/default.aspx/kb/2320113"/>
            <reference source="CVE" ref_id="CVE-2010-2738" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2738"/>
            <description>Microsoft has released MS10-063 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2010-2738</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="WinXP,SP3 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Usp10.dll version is less than 1.420.2600.5969" test_ref="oval:gov.nist.fdcc.patch:tst:116940"/>
            </criteria>
            <criteria operator="AND" comment="WinXP,SP2 (64-bit)">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Usp10.dll version is less than 1.422.3790.4695" test_ref="oval:gov.nist.fdcc.patch:tst:116941"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Usp10.dll version is less than 1.626.6001.18461" test_ref="oval:gov.nist.fdcc.patch:tst:116942"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Usp10.dll version is greater than or equal to 1.626.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116943"/>
               <criterion comment="Usp10.dll version is less than 1.626.6001.22672" test_ref="oval:gov.nist.fdcc.patch:tst:116944"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Usp10.dll version is greater than or equal to 1.626.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116945"/>
               <criterion comment="Usp10.dll version is less than 1.626.6002.18244" test_ref="oval:gov.nist.fdcc.patch:tst:116946"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Usp10.dll version is greater than or equal to 1.626.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116947"/>
               <criterion comment="Usp10.dll version is less than 1.626.6002.22384" test_ref="oval:gov.nist.fdcc.patch:tst:116948"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11695" version="2" class="patch">
         <metadata>
            <title>MS10-065: Vulnerabilities in Microsoft Internet Information Services (IIS) Could Allow Remote Code Execution (2267960)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-065" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS10-065.mspx"/>
            <reference source="Microsoft" ref_id="KB2267960" ref_url="http://support.microsoft.com/default.aspx/kb/2267960"/>
            <reference source="CVE" ref_id="CVE-2010-1899" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1899"/>
            <reference source="CVE" ref_id="CVE-2010-2730" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2730"/>
            <reference source="CVE" ref_id="CVE-2010-2731" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2731"/>
            <description>Microsoft has released MS10-065 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-1899, CVE-2010-2730, and CVE-2010-2731</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="WinXP,SP3 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="The iis optional component is installed" test_ref="oval:gov.nist.fdcc.patch:tst:4600001"/>
               <criteria operator="OR">
                  <criterion comment="asp.dll version is less than 5.1.2600.6007" test_ref="oval:gov.nist.fdcc.patch:tst:116950"/>
                  <criterion comment="infocomm.dll version is less than 6.0.2600.6018" test_ref="oval:gov.nist.fdcc.patch:tst:116951"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
               <criterion comment="Asp.dll version is less than 7.0.6001.18497" test_ref="oval:gov.nist.fdcc.patch:tst:116952"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
               <criterion comment="Asp.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116953"/>
               <criterion comment="Asp.dll version is less than 7.0.6001.22718" test_ref="oval:gov.nist.fdcc.patch:tst:116954"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
               <criterion comment="Asp.dll version is greater than or equal to 7.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:116955"/>
               <criterion comment="Asp.dll version is less than 7.0.6002.18276" test_ref="oval:gov.nist.fdcc.patch:tst:116956"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
               <criterion comment="Asp.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116957"/>
               <criterion comment="Asp.dll version is less than 7.0.6002.22431" test_ref="oval:gov.nist.fdcc.patch:tst:116958"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <extend_definition comment="Microsoft IIS 7.5 is installed" definition_ref="oval:org.mitre.oval:def:6856"/>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <!-- GDR Service branch -->
                  <criterion comment="Asp.dll version is less than 7.5.7600.16620" test_ref="oval:gov.nist.fdcc.patch:tst:116959"/>
                  <criterion comment="Cgi.dll version is less than 7.5.7600.16632" test_ref="oval:gov.nist.fdcc.patch:tst:1169590"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Asp.dll version is greater than or equal to 7.5.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1169591"/>
                     <criterion comment="Asp.dll version is less than 7.5.7600.20741" test_ref="oval:gov.nist.fdcc.patch:tst:1169592"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Cgi.dll version is greater than or equal to 7.5.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1169593"/>
                     <criterion comment="Cgi.dll version is less than 7.5.7600.20752" test_ref="oval:gov.nist.fdcc.patch:tst:1169594"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11696" version="2" class="patch">
         <metadata>
            <title>MS10-066: Vulnerability in Remote Procedure Call Could Allow Remote Code Execution (982802)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-066" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-066.mspx"/>
            <reference source="Microsoft" ref_id="KB982802" ref_url="http://support.microsoft.com/kb/982802"/>
            <reference source="CVE" ref_id="CVE-2010-2567" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2567"/>
            <description>Microsoft has released MS10-066 to address security issues in supported editions of Windows XP as documented by CVE-2010-2567</description>
         </metadata>
         <!--<criteria operator="OR">-->
         <criteria operator="AND" comment="Vulnerable Windows XP (x64) SP2">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <criterion comment="rpcrt4.dll version is less than 5.2.3790.4750" test_ref="oval:gov.nist.fdcc.patch:tst:116961"/>
         </criteria>
         <!--<criteria operator="AND" comment="Vulnerable Windows XP (x86) SP3">
                    <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                    <criterion comment="rpcrt4.dll version is less than 5.1.2600.6015" test_ref="oval:gov.nist.fdcc.patch:tst:116960"/>
                </criteria>
            </criteria>-->
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11698" version="1" class="patch">
         <metadata>
            <title>MS10-068: Vulnerability in Local Security Authority Subsystem Service Could Allow Elevation of Privilege (983539)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-068" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-068.mspx"/>
            <reference source="Microsoft" ref_id="KB983539" ref_url="http://support.microsoft.com/kb/983539"/>
            <reference source="CVE" ref_id="CVE-2010-0820" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0820"/>
            <description>Microsoft has released MS10-068 to address security issues in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) when installed on supported editions of Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-0820</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Vulnerable Windows XP (x86) SP3, Windows XP (x64) SP2, Windows Server 2003 x64/x86/ia64 SP2">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <criterion comment="An Adam Instance has been created" test_ref="oval:gov.nist.fdcc.patch:tst:116229"/>
               <criterion comment="adamdsa.dll version is less than 1.1.3790.4722" test_ref="oval:gov.nist.fdcc.patch:tst:116980"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64 SP1">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="ntdsai.dll version is less than 6.0.6001.18461" test_ref="oval:gov.nist.fdcc.patch:tst:116981"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="ntdsai.dll version is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10907"/>
                     <criterion comment="ntdsai.dll version is less than 6.0.6001.22672" test_ref="oval:gov.nist.fdcc.patch:tst:116982"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="ntdsai.dll version is less than 6.0.6002.18244" test_ref="oval:gov.nist.fdcc.patch:tst:116983"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="ntdsai.dll version is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10980"/>
                     <criterion comment="ntdsai.dll version is less than 6.0.6002.22384" test_ref="oval:gov.nist.fdcc.patch:tst:116984"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="ntdsai.dll version is less than 6.1.7600.16612" test_ref="oval:gov.nist.fdcc.patch:tst:116985"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="ntdsai.dll version is greater than or equal 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:116987"/>
                     <criterion comment="ntdsai.dll version is less than 6.1.7600.20735" test_ref="oval:gov.nist.fdcc.patch:tst:116986"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11700" version="3" class="patch">
         <metadata>
            <title>MS10-070: Vulnerability in ASP.NET Could Allow Information Disclosure (2418042)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-070" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-070.mspx"/>
            <reference source="Microsoft" ref_id="KB2418042" ref_url="http://support.microsoft.com/kb/2418042"/>
            <reference source="CVE" ref_id="CVE-2010-3332" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3332"/>
            <description>Microsoft has released MS10-070 to address security issues in as documented by CVE-2010-3332</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="(vista sp1/2 (32/64) OR 2008 RTM/sp2 (32/64) OR xp sp3 OR xp x64 sp2 OR 7 OR 2008 R2) AND .net 1.1 sp1">
               <criteria operator="OR" comment="vista sp1/2 (32/64) OR 2008 RTM/sp2 (32/64) OR xp sp2/3 OR xp x64 sp2 OR 7 OR 2008 R2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1, or later, is Installed" definition_ref="oval:gov.nist.fdcc.patch:def:115285"/>
               <criterion comment="Mscorsvr.dll version is less than 1.1.4322.2470" test_ref="oval:gov.nist.fdcc.patch:tst:1170000"/>
            </criteria>
            <criteria operator="AND" comment="(xp sp3 OR xp x64 sp2) AND (.net 3.5 OR 3.5 sp1)">
               <criteria operator="OR" comment="xp sp3 OR xp x64 sp2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <criteria operator="OR" comment=".net 3.5 or 3.5 sp1">
                  <criteria operator="AND" comment=".net 3.5">
                     <extend_definition comment="Microsoft .NET Framework 3.5 (Gold) is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11582"/>
                     <criteria operator="OR">
                        <criterion comment="System.Web.Extensions.dll version is less than 3.5.21022.239" test_ref="oval:gov.nist.fdcc.patch:tst:1170001"/>
                        <criterion comment="Aspnet_perf.dll version is less than 2.0.50727.1887" test_ref="oval:gov.nist.fdcc.patch:tst:1170003"/>
                     </criteria>
                  </criteria>
                  <criteria operator="AND" comment=".net 3.5 sp1">
                     <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11583"/>
                     <criterion comment="System.Web.Extensions.dll version is less than 3.5.30729.3644" test_ref="oval:gov.nist.fdcc.patch:tst:1170002"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="(vista sp1 (32/64) OR 2008 RTM (32/64)) AND .net 3.5 (Gold)">
               <criteria operator="OR" comment="vista sp1 (32/64) OR 2008 RTM (32/64)">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 3.5 (Gold) is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11582"/>
               <criterion comment="System.Web.Extensions.dll version is less than 3.5.21022.239" test_ref="oval:gov.nist.fdcc.patch:tst:1170001"/>
            </criteria>
            <criteria operator="AND" comment="(vista sp1 (32/64) OR 2008 RTM (32/64)) AND .net 2.0 sp1 AND 3.5 (Gold)">
               <criteria operator="OR" comment="vista sp1 (32/64) OR 2008 RTM (32/64)">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6428"/>
               <extend_definition comment="Microsoft .NET Framework 3.5 (Gold) is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11582"/>
               <criterion comment="Aspnet_wp.exe version is less than 2.0.50727.1887" test_ref="oval:gov.nist.fdcc.patch:tst:1170004"/>
            </criteria>
            <criteria operator="AND" comment="(vista sp2 (32/64) OR 2008 sp2 (32/64)) AND 3.5 sp1 - GDR">
               <criteria operator="OR" comment="vista sp2 (32/64) OR 2008 sp2 (32/64)">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115295"/>
               <criterion comment="Aspnet_wp.exe version is less than 2.0.50727.4209" test_ref="oval:gov.nist.fdcc.patch:tst:1170005"/>
            </criteria>
            <criteria operator="AND" comment="(vista sp1 (32/64) OR 2008 RTM (32/64) OR xp sp3 OR xp x64 sp2) AND .net 2.0 sp2 AND 3.5 sp1 - GDR">
               <criteria operator="OR" comment="vista sp1 (32/64) OR 2008 RTM (32/64) OR xp sp3 OR xp x64 sp2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR">
                  <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2, or later, is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
                  <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11583"/>
               </criteria>
               <criterion comment="Aspnet_wp.exe version is less than 2.0.50727.3618" test_ref="oval:gov.nist.fdcc.patch:tst:1170006"/>
            </criteria>
            <criteria operator="AND" comment="(7 x86/x64 OR Server 2008 R2 x64/ia64) AND .NET 3.5 sp1 - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11583"/>
               <criterion comment="Aspnet_wp.exe version is less than 2.0.50727.4955" test_ref="oval:gov.nist.fdcc.patch:tst:1170007"/>
            </criteria>
            <criteria operator="AND" comment="(vista sp2 (32/64) OR 2008 sp2 (32/64) OR 7 x86/x64 OR Server 2008 R2 x64/ia64) AND 3.5 sp1 - LDR">
               <criteria operator="OR" comment="vista sp2 (32/64) OR 2008 sp2 (32/64)">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:115295"/>
               <criteria operator="AND" comment="LDR">
                  <criterion comment="Aspnet_wp.exe version is greater than or equal to 2.0.50727.5000" test_ref="oval:gov.nist.fdcc.patch:tst:1170008"/>
                  <criterion comment="Aspnet_wp.exe version is less than 2.0.50727.5053" test_ref="oval:gov.nist.fdcc.patch:tst:1170009"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="(vista sp1/2 (32/64) OR 2008 RTM/sp2 (32/64) OR xp sp3 OR xp x64 sp2 OR 7 OR 2008 R2) AND .net 4.0">
               <criteria operator="OR" comment="vista sp1/2 (32/64) OR 2008 RTM/sp2 (32/64) OR xp sp2/3 OR xp x64 sp2 OR 7 OR 2008 R2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 4.0 is Installed" definition_ref="oval:gov.nist.fdcc.patch:def:115295"/>
               <criteria operator="OR" comment="GDR or LDR update has been applied">
                  <criterion comment="System.Web.dll version is less than 4.0.30319.206" test_ref="oval:gov.nist.fdcc.patch:tst:1170010"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="System.Web.dll version is greater than or equal to 4.0.30319.300" test_ref="oval:gov.nist.fdcc.patch:tst:1170011"/>
                     <criterion comment="System.Web.dll version is less than 4.0.30319.363" test_ref="oval:gov.nist.fdcc.patch:tst:1170012"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11703" version="1" class="patch">
         <metadata>
            <title>MS10-074: Vulnerability in Microsoft Foundation Classes Could Allow Remote Code Execution (2387149)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-074" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-074.mspx"/>
            <reference source="Microsoft" ref_id="KB2387149" ref_url="http://support.microsoft.com/kb/2387149"/>
            <reference source="CVE" ref_id="CVE-2010-3227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3227"/>
            <description>Microsoft has released MS10-074 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-3227.</description>
         </metadata>
         <criteria operator="AND" comment="Vulnerable Windows XP sp3, Windows XP x64 sp2, Windows Server 2003 x86/x64/ia64 sp2, Windows Vista x86/x64 sp1, Windows Vista x86/x64 sp2, Windows Server 2008 x86/x64/ia64, Windows Server x86/x64/ia64 sp2, Windows Server 2008 r2 x64/ia64, Windows 7 x86/x64">
            <criteria operator="OR">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
               <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
               <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
               <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
               <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
               <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
               <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
               <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criterion comment=" Mfc40u.dll version is less than 4.1.0.6151" test_ref="oval:gov.nist.fdcc.patch:tst:117030"/>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11705" version="1" class="patch">
         <metadata>
            <title>MS10-076: Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (982132)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-076" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-076.mspx"/>
            <reference source="Microsoft" ref_id="KB982132" ref_url="http://support.microsoft.com/kb/982132"/>
            <reference source="CVE" ref_id="CVE-2010-1883" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1883"/>
            <description>Microsoft has released MS10-076 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-1883.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="T2embed.dll version is less than 5.1.2600.6031" test_ref="oval:gov.nist.fdcc.patch:tst:1170500"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="T2embed.dll version is less than 5.2.3790.4766" test_ref="oval:gov.nist.fdcc.patch:tst:1170501"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="T2embed.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1170502"/>
               <criterion comment="T2embed.dll version is less than 6.0.6001.18520" test_ref="oval:gov.nist.fdcc.patch:tst:1170503"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="T2embed.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1170504"/>
               <criterion comment="T2embed.dll version is less than 6.0.6001.22750" test_ref="oval:gov.nist.fdcc.patch:tst:1170505"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="T2embed.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1170506"/>
               <criterion comment="T2embed.dll version is less than 6.0.6002.18301" test_ref="oval:gov.nist.fdcc.patch:tst:1170507"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="T2embed.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1170508"/>
               <criterion comment="T2embed.dll version is less than 6.0.6002.22475" test_ref="oval:gov.nist.fdcc.patch:tst:1170509"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="T2embed.dll version is less than 6.1.7600.16663" test_ref="oval:gov.nist.fdcc.patch:tst:1170510"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criterion comment="T2embed.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1170511"/>
               <criterion comment="T2embed.dll version is less than 6.1.7600.20788" test_ref="oval:gov.nist.fdcc.patch:tst:1170512"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11706" version="1" class="patch">
         <metadata>
            <title>MS10-077: Vulnerability in .NET Framework Could Allow Remote Code Execution (2160841)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-077" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-077.mspx"/>
            <reference source="Microsoft" ref_id="KB2160841" ref_url="http://support.microsoft.com/kb/2160841"/>
            <reference source="CVE" ref_id="CVE-2010-3228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3228"/>
            <description>Microsoft has released MS10-077 to address security issues in x64-based and Itanium-based editions of Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-3228.</description>
         </metadata>
         <criteria operator="AND" comment="(XP SP2 OR Vista SP1/SP2 OR Server 2008 RTM/SP2 OR 7 OR 2008 R2)(64-bit/ia-64) AND .Net 4.0">
            <criteria operator="OR">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
               <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
               <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <extend_definition comment="Microsoft .NET Framework 4.0 is Installed" definition_ref="oval:gov.nist.fdcc.patch:def:115295"/>
            <criteria operator="OR">
               <criteria operator="AND" comment="GDR">
                  <criterion comment="clrjit.dll version is less than 4.0.30319.202" test_ref="oval:gov.nist.fdcc.patch:tst:117060"/>
               </criteria>
               <criteria operator="AND" comment="LDR">
                  <criterion comment="clrjit.dll version is greater than or equal to 4.0.30319.300" test_ref="oval:gov.nist.fdcc.patch:tst:117061"/>
                  <criterion comment="clrjit.dll version is less than 4.0.30319.336" test_ref="oval:gov.nist.fdcc.patch:tst:117062"/>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11708" version="2" class="patch">
         <metadata>
            <title>MS10-081: Vulnerability in Windows Common Control Library Could Allow Remote Code Execution (2296011)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-081" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-081.mspx"/>
            <reference source="Microsoft" ref_id="KB2296011" ref_url="http://support.microsoft.com/kb/2296011"/>
            <reference source="CVE" ref_id="CVE-2010-2746" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2746"/>
            <description>Microsoft has released MS10-081 to address security issues in Windows Shell in Microsoft Windows XP SP3, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 as documented by CVE-2010-2746</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Comctl32.dll version is less than 5.82.2900.6028" test_ref="oval:gov.nist.fdcc.patch:tst:1170800"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Comctl32.dll version is less than 5.82.3790.4770" test_ref="oval:gov.nist.fdcc.patch:tst:1170801"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP1, Server 2008 x86/x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Comctl32.dll version is less than 5.82.6001.18523" test_ref="oval:gov.nist.fdcc.patch:tst:1170802"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Comctl32.dll version is greater than or equal to 5.82.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1170803"/>
                     <criterion comment="Comctl32.dll version is less than 5.82.6001.22755" test_ref="oval:gov.nist.fdcc.patch:tst:1170804"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP2, Server 2008 x86/x64/ia64 SP2">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Comctl32.dll version is less than 5.82.6002.18305" test_ref="oval:gov.nist.fdcc.patch:tst:1170805"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Comctl32.dll version is greater than or equal to 5.82.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1170806"/>
                     <criterion comment="Comctl32.dll version is less than 5.82.6002.22480" test_ref="oval:gov.nist.fdcc.patch:tst:1170807"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP1, Server 2008 x86/x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="AND" comment="GDR Service branch">
                  <criterion comment="Comctl32.dll version is greater than or equal to 6.10.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1170808"/>
                  <criterion comment="Comctl32.dll version is less than 6.10.6001.18523" test_ref="oval:gov.nist.fdcc.patch:tst:1170809"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP1, Server 2008 x86/x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="AND" comment="LDR">
                  <criterion comment="Comctl32.dll version is greater than or equal to 6.10.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1170810"/>
                  <criterion comment="Comctl32.dll version is less than 6.10.6001.22755" test_ref="oval:gov.nist.fdcc.patch:tst:1170811"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP2, Server 2008 x86/x64/ia64 SP2">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="AND" comment="GDR">
                  <criterion comment="Comctl32.dll version is greater than or equal to 6.10.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1170812"/>
                  <criterion comment="Comctl32.dll version is less than 6.10.6002.18305" test_ref="oval:gov.nist.fdcc.patch:tst:1170813"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP2, Server 2008 x86/x64/ia64 SP2">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="AND" comment="LDR">
                  <criterion comment="Comctl32.dll version is greater than or equal to 6.10.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1170814"/>
                  <criterion comment="Comctl32.dll version is less than 6.10.6002.22480" test_ref="oval:gov.nist.fdcc.patch:tst:1170815"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Comctl32.dll version is less than 5.82.7600.16661" test_ref="oval:gov.nist.fdcc.patch:tst:1170816"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Comctl32.dll version is greater than or equal to 5.82.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1170817"/>
                     <criterion comment="Comctl32.dll version is less than 5.82.7600.20787" test_ref="oval:gov.nist.fdcc.patch:tst:1170818"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="AND" comment="GDR">
                  <criterion comment="Comctl32.dll version is greater than or equal to 6.10.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1170819"/>
                  <criterion comment="Comctl32.dll version is less than 6.10.7600.16661" test_ref="oval:gov.nist.fdcc.patch:tst:1170820"/>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="AND" comment="LDR">
                  <criterion comment="Comctl32.dll version is greater than or equal to 6.10.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1170821"/>
                  <criterion comment="Comctl32.dll version is less than 6.10.7600.20787" test_ref="oval:gov.nist.fdcc.patch:tst:1170822"/>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11709" version="3" class="patch">
         <metadata>
            <title>MS10-082: Vulnerability in Windows Media Player Could Allow Remote Code Execution (2378111)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-082" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-082.mspx"/>
            <reference source="Microsoft" ref_id="KB2378111" ref_url="http://support.microsoft.com/kb/2378111"/>
            <reference source="CVE" ref_id="CVE-2010-2745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2745"/>
            <description>Microsoft has released MS10-082 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2010-2745</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Windows Media Player 9 on Windows XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
               <criterion comment="Wmp.dll version is less than 9.0.0.4510" test_ref="oval:gov.nist.fdcc.patch:tst:1170900"/>
            </criteria>
            <criteria operator="AND" comment="Windows Media Player 10 on Windows XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wmp.dll version is less than 10.0.0.4081" test_ref="oval:gov.nist.fdcc.patch:tst:1170901"/>
            </criteria>
            <criteria operator="AND" comment="Windows Media Player 10 on Windows XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Windows Media Player v10.0 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
               <criterion comment="Wwmp.dll version is less than 10.0.0.4008" test_ref="oval:gov.nist.fdcc.patch:tst:1170902"/>
            </criteria>
            <criteria operator="AND" comment="Windows Media Player 11 on Windows XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
               <criterion comment="Wwmp.dll version is less than 11.0.5721.5280" test_ref="oval:gov.nist.fdcc.patch:tst:1170903"/>
            </criteria>
            <criteria operator="AND" comment="Windows Media Player 11 on Windows XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
               <criterion comment="Wmp.dll version is less than 11.0.5721.5280" test_ref="oval:gov.nist.fdcc.patch:tst:1170904"/>
            </criteria>
            <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista SP1/Server 2008 (32-bit)/(64-bit)/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Wmp.dll version is less than 11.0.6001.7010" test_ref="oval:gov.nist.fdcc.patch:tst:1170905"/>
            </criteria>
            <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista SP1/Server 2008 (32-bit)/(64-bit)/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criterion comment="Wmp.dll version is greater than or equal to 11.0.6001.7100" test_ref="oval:gov.nist.fdcc.patch:tst:1170906"/>
               <criterion comment="Wmp.dll version is less than 11.0.6001.7118" test_ref="oval:gov.nist.fdcc.patch:tst:1170907"/>
            </criteria>
            <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista SP2/Server 2008 SP2  (32-bit)/(64-bit)/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Wmp.dll version is greater than or equal 11.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1170908"/>
               <criterion comment="Wmp.dll version is less than 11.0.6002.18311" test_ref="oval:gov.nist.fdcc.patch:tst:1170909"/>
            </criteria>
            <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista SP2/Server 2008 SP2  (32-bit)/(64-bit)/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Wmp.dll version is greater than or equal 11.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1170910"/>
               <criterion comment="Wmp.dll version is less than 11.0.6002.22486" test_ref="oval:gov.nist.fdcc.patch:tst:1170911"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Wmp.dll version is less than 12.0.7600.16667" test_ref="oval:gov.nist.fdcc.patch:tst:1170912"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Wmp.dll version is greater than or equal to 12.0.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1170913"/>
                     <criterion comment="Wmp.dll version is less than 12.0.7600.20792" test_ref="oval:gov.nist.fdcc.patch:tst:1170914"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11710" version="1" class="patch">
         <metadata>
            <title>MS10-083: Vulnerability in COM Validation in Windows Shell and WordPad Could Allow Remote Code Execution (2405882)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-083" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS10-083.mspx"/>
            <reference source="Microsoft" ref_id="KB2405882" ref_url="http://support.microsoft.com/default.aspx/kb/2405882"/>
            <reference source="CVE" ref_id="CVE-2010-1263" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1263"/>
            <description>Microsoft has released MS10-083 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-1263</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="WinXP,SP3 (32-bit)">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Ole32.dll version is less than 5.1.2600.6010" test_ref="oval:gov.nist.fdcc.patch:tst:1171000"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Ole32.dll version is less than 5.2.3790.4750" test_ref="oval:gov.nist.fdcc.patch:tst:1171001"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR or LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Ole32.dll version is less than 6.0.6001.18498" test_ref="oval:gov.nist.fdcc.patch:tst:1171002"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Ole32.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1171003"/>
                     <criterion comment="Ole32.dll version is less than 6.0.6001.22720" test_ref="oval:gov.nist.fdcc.patch:tst:1171004"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Ole32.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1171005"/>
               <criterion comment="Ole32.dll version is less than 6.0.6002.18277" test_ref="oval:gov.nist.fdcc.patch:tst:1171006"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Ole32.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1171007"/>
               <criterion comment="Ole32.dll version is less than 6.0.6002.22433" test_ref="oval:gov.nist.fdcc.patch:tst:1171008"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Ole32.dll version is less than 6.1.7600.16624" test_ref="oval:gov.nist.fdcc.patch:tst:1171009"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Ole32.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1171010"/>
                     <criterion comment="Ole32.dll version is less than 6.1.7600.20744" test_ref="oval:gov.nist.fdcc.patch:tst:1171011"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR or LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Msshsq.dll version is less than 6.0.6001.18470" test_ref="oval:gov.nist.fdcc.patch:tst:1171012"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Msshsq.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1171013"/>
                     <criterion comment="Msshsq.dll version is less than 6.0.6001.22685" test_ref="oval:gov.nist.fdcc.patch:tst:1171014"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Msshsq.dll version is greater than or equal to 7.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1171015"/>
               <criterion comment="Msshsq.dll version is less than 7.0.6002.18255" test_ref="oval:gov.nist.fdcc.patch:tst:1171016"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Msshsq.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1171017"/>
               <criterion comment="Msshsq.dll version is less than 7.0.6002.22398" test_ref="oval:gov.nist.fdcc.patch:tst:1171018"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Structuredquery.dll version is less than 7.0.7600.16587" test_ref="oval:gov.nist.fdcc.patch:tst:1171019"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Structuredquery.dll version is greater than or equal to 7.0.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1171020"/>
                     <criterion comment="Structuredquery.dll version is less than 7.0.7600.20707" test_ref="oval:gov.nist.fdcc.patch:tst:1171021"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11711" version="1" class="patch">
         <metadata>
            <title>MS10-084: Vulnerability in Windows Local Procedure Call Could Cause Elevation of Privilege (2360937)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-084" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-084.mspx"/>
            <reference source="Microsoft" ref_id="KB2360937" ref_url="http://support.microsoft.com/kb/2360937"/>
            <reference source="CVE" ref_id="CVE-2010-3222" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3222"/>
            <description>Microsoft has released MS10-084 to address security issues in Windows XP as documented by CVE-2010-3222</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP x86 SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Rpcrt4.dll version is less than 5.1.2600.6022" test_ref="oval:gov.nist.fdcc.patch:tst:117110"/>
            </criteria>
            <criteria operator="AND" comment="XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Rpcrt4.dll version is less than 5.2.3790.4759" test_ref="oval:gov.nist.fdcc.patch:tst:117111"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11718" version="1" class="patch">
         <metadata>
            <title>MS10-094: Vulnerability in Windows Media Encoder Could Allow Remote Code Execution (2447961)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
               <product>Microsoft Media Encoder</product>
            </affected>
            <reference source="Microsoft" ref_id="MS10-094" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-094.mspx"/>
            <reference source="Microsoft" ref_id="KB2447961" ref_url="http://support.microsoft.com/kb/2447961"/>
            <reference source="CVE" ref_id="CVE-2010-3965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3965"/>
            <description>Microsoft has released MS10-094 to address security issues as documented by CVE-2010-3965.</description>
         </metadata>
         <criteria operator="AND">
            <criteria operator="OR">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
               <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
               <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
               <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
               <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
               <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
               <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            </criteria>
            <criteria operator="OR" comment="32-bit Windows Media Encoder">
               <criterion comment="Wmenceng.dll version is less than 9.0.0.3374" test_ref="oval:gov.nist.fdcc.patch:tst:117180"/>
               <criteria operator="AND" comment="64-bit Windows Media Encoder">
                  <criterion comment="Wmenceng.dll version is greater than or equal to 10.0.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:117181"/>
                  <criterion comment="Wmenceng.dll version is less than 10.0.0.3822" test_ref="oval:gov.nist.fdcc.patch:tst:117182"/>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11720" version="1" class="patch">
         <metadata>
            <title>MS10-096: Vulnerability in Windows Address Book Could Allow Remote Code Execution (2423089)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-096" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-096.mspx"/>
            <reference source="Microsoft" ref_id="KB2423089" ref_url="http://support.microsoft.com/kb/2423089"/>
            <reference source="CVE" ref_id="CVE-2010-3147" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3147"/>
            <description>Microsoft has released MS10-096 to address security issues as documented by CVE-2010-3147</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
               <criterion comment="Wab.exe version is less than 6.0.2900.6040" test_ref="oval:gov.nist.fdcc.patch:tst:1172000"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
               <criterion comment="Wab.exe version is less than 6.0.3790.4785" test_ref="oval:gov.nist.fdcc.patch:tst:1172001"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP1, Server 2008 x86/x64/ia64">
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Wab.exe version is less than 6.0.6001.18535" test_ref="oval:gov.nist.fdcc.patch:tst:1172002"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Wab.exe version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1172003"/>
                     <criterion comment="Wab.exe version is less than 6.0.6001.22774" test_ref="oval:gov.nist.fdcc.patch:tst:1172004"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP2, Server 2008 x86/x64/ia64 SP2">
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Wab.exe version is less than 6.0.6002.18324" test_ref="oval:gov.nist.fdcc.patch:tst:1172005"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Wab.exe version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1172006"/>
                     <criterion comment="Wab.exe version is less than 6.0.6002.22503" test_ref="oval:gov.nist.fdcc.patch:tst:1172007"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
               <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Wab.exe version is less than 6.1.7600.16684" test_ref="oval:gov.nist.fdcc.patch:tst:1172008"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Wab.exe version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1172009"/>
                     <criterion comment="Wab.exe version is less than 6.1.7600.20814" test_ref="oval:gov.nist.fdcc.patch:tst:1172010"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11721" version="1" class="patch">
         <metadata>
            <title>MS10-097: Insecure Library Loading in Internet Connection Signup Wizard Could Allow Remote Code Execution (2443105)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-097" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-097.mspx"/>
            <reference source="Microsoft" ref_id="KB2443105" ref_url="http://support.microsoft.com/kb/2443105"/>
            <reference source="CVE" ref_id="CVE-2010-3144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3144"/>
            <description>Microsoft has released MS10-097 to address security issues in Microsoft Windows XP as documented by CVE-2010-3144</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP x86 SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Isign32.dll version is less than 6.0.2900.6052" test_ref="oval:gov.nist.fdcc.patch:tst:117210"/>
            </criteria>
            <criteria operator="AND" comment="XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Isign32.dll version is less than 6.0.3790.4799" test_ref="oval:gov.nist.fdcc.patch:tst:117211"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11723" version="1" class="patch">
         <metadata>
            <title>MS10-099: Vulnerability in Routing and Remote Access Could Allow Elevation of Privilege (2440591)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS10-099" ref_url="http://www.microsoft.com/technet/security/bulletin/MS10-099.mspx"/>
            <reference source="Microsoft" ref_id="KB2440591" ref_url="http://support.microsoft.com/kb/2440591"/>
            <reference source="CVE" ref_id="CVE-2010-3963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3963"/>
            <description>Microsoft has released MS10-099 to address security issues in Microsoft Windows XP as documented by CVE-2010-3963</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP x86 SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Ndproxy.sys version is less than 5.1.2600.6048" test_ref="oval:gov.nist.fdcc.patch:tst:117230"/>
            </criteria>
            <criteria operator="AND" comment="XP x64 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Ndproxy.sys version is less than 5.2.3790.4795" test_ref="oval:gov.nist.fdcc.patch:tst:117231"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11728" version="2" class="patch">
         <metadata>
            <title>MS11-002: Vulnerabilities in Microsoft Data Access Components Could Allow Remote Code Execution (2451910)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
               <product>MDAC</product>
               <product>Windows DAC</product>
            </affected>
            <reference source="Microsoft" ref_id="MS11-002" ref_url="http://www.microsoft.com/technet/security/Bulletin/MS11-002.mspx"/>
            <reference source="Microsoft" ref_id="KB2451910" ref_url="http://support.microsoft.com/kb/2451910"/>
            <reference source="CVE" ref_id="CVE-2011-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0026"/>
            <reference source="CVE" ref_id="CVE-2011-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0027"/>
            <description>Microsoft has released MS11-002 to address security issues in MDAC and Windows DAC as documented by CVE-2011-0026 and CVE-2011-0027.</description>
         </metadata>
         <criteria operator="OR">
            <criteria comment="Windows XP SP3 with MDAC 2.8 SP1" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Microsoft Data Access Components 2.8 (SP1) is installed" test_ref="oval:org.mitre.oval:tst:725"/>
               <criterion comment="Msado15.dll version is less than 2.81.3012.0" test_ref="oval:gov.nist.fdcc.patch:tst:1172800"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2 with MDAC 2.8 SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Microsoft Data Access Components 2.8 (SP2) is installed" test_ref="oval:gov.nist.fdcc.patch:tst:1172813"/>
               <criterion comment="Msado15.dll version is less than 2.82.4795.0" test_ref="oval:gov.nist.fdcc.patch:tst:1172801"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) with Windows DAC 6.0">
               <criterion comment="Microsoft Data Access Components 6.0 is installed" test_ref="oval:gov.nist.fdcc.patch:tst:1172814"/>
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Msado15.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1172802"/>
                     <criterion comment="Msado15.dll version is less than  6.0.6001.18570" test_ref="oval:gov.nist.fdcc.patch:tst:1172803"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Msado15.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1172804"/>
                     <criterion comment="Msado15.dll version is less than  6.0.6001.22821" test_ref="oval:gov.nist.fdcc.patch:tst:1172805"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) with Windows DAC 6.0">
               <criterion comment="Microsoft Data Access Components 6.0 is installed" test_ref="oval:gov.nist.fdcc.patch:tst:1172814"/>
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Msado15.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1172806"/>
                     <criterion comment="Msado15.dll version is less than  6.0.6002.18362" test_ref="oval:gov.nist.fdcc.patch:tst:1172807"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Msado15.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1172808"/>
                     <criterion comment="Msado15.dll version is less than  6.0.6002.22555" test_ref="oval:gov.nist.fdcc.patch:tst:1172809"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) with Windows DAC 6.0">
               <criterion comment="Microsoft Data Access Components 6.0 is installed" test_ref="oval:gov.nist.fdcc.patch:tst:1172814"/>
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR">
                  <criterion comment="Msado15.dll version is less than 6.1.7600.16688" test_ref="oval:gov.nist.fdcc.patch:tst:1172810"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Msado15.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1172811"/>
                     <criterion comment="Msado15.dll version is less than 6.1.7600.20818" test_ref="oval:gov.nist.fdcc.patch:tst:1172812"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11731" version="1" class="patch">
         <metadata>
            <title>MS11-006: Vulnerability in Windows Shell Graphics Processing Could Allow Remote Code Execution (2483185)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-006" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-006.mspx"/>
            <reference source="Microsoft" ref_id="KB2483185" ref_url="http://support.microsoft.com/kb/2483185"/>
            <reference source="CVE" ref_id="CVE-2010-3970" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3970"/>
            <description>Microsoft has released MS11-006 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by CVE-2010-3970.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Shell32.dll version is less than 6.0.2900.6072" test_ref="oval:gov.nist.fdcc.patch:tst:117310"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Shell32.dll version is less than 6.0.3790.4822" test_ref="oval:gov.nist.fdcc.patch:tst:117311"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Shell32.dll version is less than 6.0.6001.18588" test_ref="oval:gov.nist.fdcc.patch:tst:117312"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Shell32.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1167903"/>
                     <criterion comment="Shell32.dll version is less than 6.0.6001.22839" test_ref="oval:gov.nist.fdcc.patch:tst:117314"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Shell32.dll version is less than 6.0.6002.18393" test_ref="oval:gov.nist.fdcc.patch:tst:117315"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Shell32.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1167906"/>
                     <criterion comment="Shell32.dll version is less than 6.0.6002.22574" test_ref="oval:gov.nist.fdcc.patch:tst:117317"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11735" version="1" class="patch">
         <metadata>
            <title>MS11-011: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-011" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-011.mspx"/>
            <reference source="Microsoft" ref_id="KB2393802" ref_url="http://support.microsoft.com/kb/2393802"/>
            <reference source="CVE" ref_id="CVE-2010-4398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4398"/>
            <reference source="CVE" ref_id="CVE-2011-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0045"/>
            <description>Microsoft has released MS11-011 to address security issues in Microsoft Windows as documented by CVE-2010-4398 and CVE-2011-0045.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Ntoskrnl.exe version is less than 5.1.2600.6055" test_ref="oval:gov.nist.fdcc.patch:tst:1173500"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Ntoskrnl.exe version is less than 5.2.3790.4789" test_ref="oval:gov.nist.fdcc.patch:tst:1173501"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Ntoskrnl.exe version is less than 6.0.6001.18538" test_ref="oval:gov.nist.fdcc.patch:tst:1173502"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Ntoskrnl.exe version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1159204"/>
                     <criterion comment="Ntoskrnl.exe version is less than 6.0.6001.22777" test_ref="oval:gov.nist.fdcc.patch:tst:1173504"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Ntoskrnl.exe version is less than 6.0.6002.18327" test_ref="oval:gov.nist.fdcc.patch:tst:1173505"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Ntoskrnl.exe version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1159206"/>
                     <criterion comment="Ntoskrnl.exe version is less than 6.0.6002.22505" test_ref="oval:gov.nist.fdcc.patch:tst:1173507"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.16695" test_ref="oval:gov.nist.fdcc.patch:tst:1173508"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="the version of Ntoskrnl.exe is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1173509"/>
                     <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.20826" test_ref="oval:gov.nist.fdcc.patch:tst:1173510"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64 SP1 RC">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12295"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12435"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:11590"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12159"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7601.17695" test_ref="oval:gov.nist.fdcc.patch:tst:1173511"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1173512"/>
                     <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7601.21826" test_ref="oval:gov.nist.fdcc.patch:tst:1173513"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11736" version="1" class="patch">
         <metadata>
            <title>MS11-012: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2479628)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-012" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-012.mspx"/>
            <reference source="Microsoft" ref_id="KB2479628" ref_url="http://support.microsoft.com/kb/2479628"/>
            <reference source="CVE" ref_id="CVE-2011-0086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0086"/>
            <reference source="CVE" ref_id="CVE-2011-0087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0087"/>
            <reference source="CVE" ref_id="CVE-2011-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0088"/>
            <reference source="CVE" ref_id="CVE-2011-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0089"/>
            <reference source="CVE" ref_id="CVE-2011-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0090"/>
            <description>Microsoft has released MS11-012 to address security issues in Microsoft Windows as documented by CVE-2011-0086, CVE-2011-0087, CVE-2011-0088, CVE-2011-0089, and CVE-2011-0090.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Win32k.sys version is less than 5.1.2600.6064" test_ref="oval:gov.nist.fdcc.patch:tst:1173600"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Win32k.sys version is less than 5.2.3790.4813" test_ref="oval:gov.nist.fdcc.patch:tst:1173601"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Win32k.sys version is less than 6.0.6001.18573" test_ref="oval:gov.nist.fdcc.patch:tst:1173602"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Win32k.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115477"/>
                     <criterion comment="Win32k.sys version is less than 6.0.6001.22824" test_ref="oval:gov.nist.fdcc.patch:tst:1173604"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Win32k.sys version is less than 6.0.6002.18365" test_ref="oval:gov.nist.fdcc.patch:tst:1173605"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Win32k.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116219"/>
                     <criterion comment="Win32k.sys version is less than 6.0.6002.22560" test_ref="oval:gov.nist.fdcc.patch:tst:1173607"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Win32k.sys version is less than 6.1.7600.16732" test_ref="oval:gov.nist.fdcc.patch:tst:1173608"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Win32k.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1167094"/>
                     <criterion comment="Win32k.sys version is less than 6.1.7600.20873" test_ref="oval:gov.nist.fdcc.patch:tst:1173610"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) SP1 RC - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12295"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12435"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:11590"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12159"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Win32k.sys version is less than 6.1.7601.17535" test_ref="oval:gov.nist.fdcc.patch:tst:1173611"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Win32k.sys version is greater than or equal to 6.1.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1173612"/>
                     <criterion comment="Win32k.sys version is less than 6.1.7601.21634" test_ref="oval:gov.nist.fdcc.patch:tst:1173613"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11737" version="1" class="patch">
         <metadata>
            <title>MS11-013: Vulnerabilities in Kerberos Could Allow Elevation of Privilege (2496930)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-013" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-013.mspx"/>
            <reference source="Microsoft" ref_id="KB2496930" ref_url="http://support.microsoft.com/kb/2496930"/>
            <reference source="CVE" ref_id="CVE-2011-0043" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0043"/>
            <reference source="CVE" ref_id="CVE-2011-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0091"/>
            <description>Microsoft has released MS11-013 to address security issues in Windows XP, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-0043 and CVE-2011-0091.</description>
         </metadata>
         <criteria operator="OR">
            <criteria comment="XP (32-bit) SP3" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Kerberos.dll version is less than 5.1.2600.6059" test_ref="oval:gov.nist.fdcc.patch:tst:117370"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Kerberos.dll version is less than 5.2.3790.4806" test_ref="oval:gov.nist.fdcc.patch:tst:117371"/>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Kerberos.dll version is less than 6.1.7600.16722" test_ref="oval:gov.nist.fdcc.patch:tst:117372"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Kerberos.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:117373"/>
                     <criterion comment="Kerberos.dll version is less than 6.1.7600.20861" test_ref="oval:gov.nist.fdcc.patch:tst:117374"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) SP1 RC - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12295"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12435"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:11590"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12159"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Kerberos.dll version is less than 6.1.7601.17527" test_ref="oval:gov.nist.fdcc.patch:tst:117375"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Kerberos.dll version is greater than or equal to 6.1.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:117376"/>
                     <criterion comment="Kerberos.dll version is less than 6.1.7601.21624" test_ref="oval:gov.nist.fdcc.patch:tst:117377"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11738" version="1" class="patch">
         <metadata>
            <title>MS11-014: Vulnerability in Local Security Authority Subsystem Service Could Allow Local Elevation of Privilege (2478960)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-014" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-014.mspx"/>
            <reference source="Microsoft" ref_id="KB2478960" ref_url="http://support.microsoft.com/kb/2478960"/>
            <reference source="CVE" ref_id="CVE-2011-0039" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0039"/>
            <description>Microsoft has released MS11-014 to address security issues in the Local Security Authority Subsystem Service (LSASS) in Windows XP as documented by CVE-2011-0039.</description>
         </metadata>
         <criteria operator="OR">
            <criteria comment="XP (32-bit) SP3" operator="AND">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Lsasrv.dll version is less than 5.1.2600.6058" test_ref="oval:gov.nist.fdcc.patch:tst:117380"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Lsasrv.dll version is less than 5.2.3790.4806" test_ref="oval:gov.nist.fdcc.patch:tst:117381"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11739" version="3" class="patch">
         <metadata>
            <title>MS11-015: Vulnerabilities in Windows Media Could Allow Remote Code Execution (2510030)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-015" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-015.mspx"/>
            <reference source="Microsoft" ref_id="KB2510030" ref_url="http://support.microsoft.com/kb/2510030"/>
            <reference source="CVE" ref_id="CVE-2011-0032" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0032"/>
            <reference source="CVE" ref_id="CVE-2011-0042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0042"/>
            <description>Microsoft has released MS11-015 to address security issues in Windows XP, Windows Vista, Windows 7 and Windows Server 2008 R2 as documented by CVE-2011-0032 and CVE-2011-0042.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Encdec.dll version is less than 6.5.2600.6076" test_ref="oval:gov.nist.fdcc.patch:tst:1173900"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Encdec.dll version is less than 6.5.3790.4826" test_ref="oval:gov.nist.fdcc.patch:tst:1173901"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Encdec.dll version is less than 6.6.6001.18571" test_ref="oval:gov.nist.fdcc.patch:tst:1173902"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Encdec.dll version is greater than or equal to 6.6.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1173903"/>
                     <criterion comment="Encdec.dll version is less than 6.6.6001.22822" test_ref="oval:gov.nist.fdcc.patch:tst:1173904"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Encdec.dll version is less than 6.6.6002.18363" test_ref="oval:gov.nist.fdcc.patch:tst:1173905"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Encdec.dll version is greater than or equal to 6.6.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1173906"/>
                     <criterion comment="Encdec.dll version is less than 6.6.6002.22558" test_ref="oval:gov.nist.fdcc.patch:tst:1173907"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Encdec.sys version is less than 6.6.7600.16724" test_ref="oval:gov.nist.fdcc.patch:tst:1173908"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Encdec.dll version is greater than or equal to 6.6.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1173909"/>
                     <criterion comment="Encdec.dll version is less than 6.6.7600.20865" test_ref="oval:gov.nist.fdcc.patch:tst:1173910"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) SP1 - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Encdec.dll version is less than 6.6.7601.17528" test_ref="oval:gov.nist.fdcc.patch:tst:1173911"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Encdec.dll version is greater than or equal to 6.6.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1173912"/>
                     <criterion comment="Encdec.dll version is less than 6.6.7601.21626" test_ref="oval:gov.nist.fdcc.patch:tst:1173913"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11740" version="3" class="patch">
         <metadata>
            <title>MS11-017: Vulnerability in Remote Desktop Client Could Allow Remote Code Execution (2508062)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-017" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-017.mspx"/>
            <reference source="Microsoft" ref_id="KB2508062" ref_url="http://support.microsoft.com/kb/2508062"/>
            <reference source="CVE" ref_id="CVE-2011-0029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0029"/>
            <description>Microsoft has released MS11-017 to address security issues in Windows Remote Desktop Client as documented by CVE-2011-0029.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP SP3 w/ Remote Desktop Client 5.2">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="2k3mstscax.dll version is less than 5.2.3790.4807" test_ref="oval:gov.nist.fdcc.patch:tst:1174000"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2 or Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) w/ Remote Desktop Client 6.0">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Mstscax.dll version is less than 6.0.6001.18564" test_ref="oval:gov.nist.fdcc.patch:tst:1174014"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174005"/>
                     <criterion comment="Mstscax.dll version is less than 6.0.6001.22815" test_ref="oval:gov.nist.fdcc.patch:tst:1174006"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="XP SP3 w/ Remote Desktop Client 6.1">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mstscax.dll version is greater than 6.0.6001.18564" test_ref="oval:gov.nist.fdcc.patch:tst:1174004"/>
                     <criterion comment="Mstscax.dll version is less than 6.0.6001.18589" test_ref="oval:gov.nist.fdcc.patch:tst:1174001"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mstscax.dll version is greater than to 6.0.6001.22815" test_ref="oval:gov.nist.fdcc.patch:tst:1174002"/>
                     <criterion comment="Mstscax.dll version is less than 6.0.6001.22840" test_ref="oval:gov.nist.fdcc.patch:tst:1174003"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) w/ Remote Desktop Client 6.x">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Mstscax.dll version is less than 6.0.6002.18356" test_ref="oval:gov.nist.fdcc.patch:tst:1174007"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mstscax.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174008"/>
                     <criterion comment="Mstscax.dll version is less than 6.0.6002.22550" test_ref="oval:gov.nist.fdcc.patch:tst:1174009"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="XP SP3, XP (64-bit) SP2, Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64), 7, Server 2008 R2 RTM/SP1 (32-bit, 64-bit, ia-64) w/ Remote Desktop Client 7.0">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Mstscax.dll version is greater than or equal to 6.1.7600.16000" test_ref="oval:gov.nist.fdcc.patch:tst:1174010"/>
                     <criterion comment="Mstscax.dll version is less than 6.1.7600.16722" test_ref="oval:gov.nist.fdcc.patch:tst:1174011"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mstscax.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1174012"/>
                     <criterion comment="Mstscax.dll version is less than 6.1.7600.20861" test_ref="oval:gov.nist.fdcc.patch:tst:1174013"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11743" version="4" class="patch">
         <metadata>
            <title>MS11-020: Vulnerabilities in SMB Server Could Allow Remote Code Execution (2508429)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <!--<platform>Microsoft Windows 7</platform>
                    <platform>Microsoft Windows Server 2008 R2</platform>-->
            </affected>
            <reference source="Microsoft" ref_id="MS11-020" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-020.mspx"/>
            <reference source="Microsoft" ref_id="KB2508429" ref_url="http://support.microsoft.com/kb/2508429"/>
            <reference source="CVE" ref_id="CVE-2011-0661" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0661"/>
            <description>Microsoft has released MS11-020 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-0661</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Srv.sys version is less than 5.1.2600.6082" test_ref="oval:gov.nist.fdcc.patch:tst:1174301"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Srv.sys version is less than 5.2.3790.4832" test_ref="oval:gov.nist.fdcc.patch:tst:1174302"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Srv.sys version is less than 6.0.6001.18602" test_ref="oval:gov.nist.fdcc.patch:tst:1174303"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174304"/>
                     <criterion comment="Srv.sys version is less than 6.0.6001.22857" test_ref="oval:gov.nist.fdcc.patch:tst:1174305"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Srv.sys version is less than 6.0.6002.18407" test_ref="oval:gov.nist.fdcc.patch:tst:1174306"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1164910"/>
                     <criterion comment="Srv.sys version is less than 6.0.6002.22592" test_ref="oval:gov.nist.fdcc.patch:tst:1174308"/>
                  </criteria>
               </criteria>
            </criteria>
            <!--<criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR/LDR">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                    </criteria>
                    <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Srv.sys version is less than 6.1.7600.16765" test_ref="oval:gov.nist.fdcc.patch:tst:1174309"/>
                        <criteria operator="AND" comment="LDR">
                            <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1164914"/>
                            <criterion comment="Srv.sys version is less than 6.1.7600.20907" test_ref="oval:gov.nist.fdcc.patch:tst:1174311"/>
                        </criteria>
                    </criteria>
                </criteria>
                <criteria operator="AND" comment="7, Server 2008 R2 SP1-RC (32-bit, 64-bit, ia-64)">
                    <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12295"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12435"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:11590"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 Release Candidate is installed" definition_ref="oval:org.mitre.oval:def:12159"/>
                    </criteria>
                    <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Srv.sys version is less than 6.1.7601.17565" test_ref="oval:gov.nist.fdcc.patch:tst:1174312"/>
                        <criteria operator="AND" comment="LDR">
                            <criterion comment="Srv.sys version is greater than or equal to 6.1.7601.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1174313"/>
                            <criterion comment="Srv.sys version is less than 6.1.7601.21666" test_ref="oval:gov.nist.fdcc.patch:tst:1174314"/>
                        </criteria>
                    </criteria>
                </criteria>-->
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11744" version="2" class="patch">
         <metadata>
            <title>MS11-024: Vulnerability in Windows Fax Cover Page Editor Could Allow Remote Code Execution (2527308)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-024" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-024.mspx"/>
            <reference source="Microsoft" ref_id="KB2527308" ref_url="http://support.microsoft.com/kb/2527308"/>
            <reference source="CVE" ref_id="CVE-2010-3974" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3974"/>
            <description>Microsoft has released MS11-024 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2010-3974</description>
         </metadata>
         <criteria operator="AND">
            <criteria operator="OR">
               <criteria operator="AND" comment="XP (32-bit) SP3">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <criteria operator="OR">
                     <criterion comment="Fxscover.exe version is less than 5.2.2600.6078" test_ref="oval:gov.nist.fdcc.patch:tst:1174401"/>
                     <criterion comment="Mfc42.dll version is less than 6.2.8081.0" test_ref="oval:gov.nist.fdcc.patch:tst:1174415"/>
                  </criteria>
               </criteria>
               <criteria operator="AND" comment="XP (64-bit) SP2">
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <criteria operator="OR">
                     <criterion comment="Fxscover.exe version is less than 5.2.3790.4829" test_ref="oval:gov.nist.fdcc.patch:tst:1174402"/>
                     <criterion comment="Mfc42.dll version is less than 6.5.9151.0" test_ref="oval:gov.nist.fdcc.patch:tst:1174416"/>
                  </criteria>
               </criteria>
               <criteria operator="AND" comment="Vista, Server 2008 SP1 or SP 2 or 7, Server 2008 R2 RTM or SP1(32-bit, 64-bit, ia-64)">
                  <criteria operator="OR">
                     <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                     <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                     <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                     <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                     <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                     <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                     <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                     <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                     <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                     <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                     <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                     <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                     <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                     <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                     <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                     <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                     <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                     <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
                  </criteria>
                  <criterion comment="Mfc42.dll version is less than 6.6.8064.0" test_ref="oval:gov.nist.fdcc.patch:tst:1174417"/>
               </criteria>
               <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit) - GDR">
                  <criteria operator="OR">
                     <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                     <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                     <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                     <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  </criteria>
                  <criteria operator="OR" comment="GDR or LDR Service branch">
                     <criterion comment="Fxscover.exe version is less than 6.0.6001.18597" test_ref="oval:gov.nist.fdcc.patch:tst:1174403"/>
                     <criteria operator="AND" comment="LDR">
                        <criterion comment="Fxscover.exe version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174404"/>
                        <criterion comment="Fxscover.exe version is less than 6.0.6001.22852" test_ref="oval:gov.nist.fdcc.patch:tst:1174405"/>
                     </criteria>
                  </criteria>
               </criteria>
               <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit) - GDR">
                  <criteria operator="OR">
                     <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                     <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                     <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                     <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  </criteria>
                  <criteria operator="OR" comment="GDR or LDR Service branch">
                     <criterion comment="Fxscover.exe version is less than 6.0.6002.18403" test_ref="oval:gov.nist.fdcc.patch:tst:1174406"/>
                     <criteria operator="AND" comment="LDR">
                        <criterion comment="Fxscover.exe version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174407"/>
                        <criterion comment="Fxscover.exe version is less than 6.0.6002.22586" test_ref="oval:gov.nist.fdcc.patch:tst:1174408"/>
                     </criteria>
                  </criteria>
               </criteria>
               <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit) - GDR/LDR">
                  <criteria operator="OR">
                     <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                     <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                     <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  </criteria>
                  <criteria operator="OR" comment="GDR or LDR Service branch">
                     <criterion comment="Fxscover.exe version is less than 6.1.7600.16759" test_ref="oval:gov.nist.fdcc.patch:tst:1174409"/>
                     <criteria operator="AND" comment="LDR">
                        <criterion comment="Fxscover.exe version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1174410"/>
                        <criterion comment="Fxscover.exe version is less than 6.1.7600.20900" test_ref="oval:gov.nist.fdcc.patch:tst:1174411"/>
                     </criteria>
                  </criteria>
               </criteria>
               <criteria operator="AND" comment="7, Server 2008 R2 SP1 (32-bit, 64-bit) - GDR/LDR">
                  <criteria operator="OR">
                     <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                     <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                     <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  </criteria>
                  <criteria operator="OR" comment="GDR or LDR Service branch">
                     <criterion comment="Fxscover.exe version is less than 6.1.7601.17559" test_ref="oval:gov.nist.fdcc.patch:tst:1174412"/>
                     <criteria operator="AND" comment="LDR">
                        <criterion comment="Fxscover.exe version is greater than or equal to 6.1.7601.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1174413"/>
                        <criterion comment="Fxscover.exe version is less than 6.1.7601.21659" test_ref="oval:gov.nist.fdcc.patch:tst:1174414"/>
                     </criteria>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11746" version="1" class="patch">
         <metadata>
            <title>MS11-027: Cumulative Security Update of ActiveX Kill Bits (2508272)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-027" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-027.mspx"/>
            <reference source="Microsoft" ref_id="KB2508272" ref_url="http://support.microsoft.com/kb/2508272"/>
            <reference source="CVE" ref_id="CVE-2010-0811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0811"/>
            <reference source="CVE" ref_id="CVE-2010-3973" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3973"/>
            <reference source="CVE" ref_id="CVE-2011-1243" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1243"/>
            <description>Microsoft has released MS11-027 to address security issues as documented by CVE-2010-0811, CVE-2010-3973, and CVE-2011-1243</description>
         </metadata>
         <criteria operator="AND">
            <criteria operator="OR">
               <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
               <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
               <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
               <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
               <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
               <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            </criteria>
            <criteria operator="OR">
               <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1}!Compatibility Flags does not exist" test_ref="oval:gov.nist.fdcc.patch:tst:117460"/>
               <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:gov.nist.fdcc.patch:tst:117461"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11748" version="1" class="patch">
         <metadata>
            <title>MS11-029: Vulnerability in GDI+ Could Allow Remote Code Execution (2489979)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-029" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-029.mspx"/>
            <reference source="Microsoft" ref_id="KB2489979" ref_url="http://support.microsoft.com/kb/2489979"/>
            <reference source="CVE" ref_id="CVE-2011-0041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0041"/>
            <description>Microsoft has released MS11-029 to address security issues in Windows XP, Windows Vista, and Windows Server 2008 as documented by 2011-0041.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Gdiplus.dll version is less than 5.2.6002.22509" test_ref="oval:gov.nist.fdcc.patch:tst:1174800"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Gdiplus.dll version is less than 5.2.6002.22507" test_ref="oval:gov.nist.fdcc.patch:tst:1174801"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Gdiplus.dll version is less than 5.2.6001.18551" test_ref="oval:gov.nist.fdcc.patch:tst:1174802"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Gdiplus.dll version is greater than or equal to 5.2.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174803"/>
                     <criterion comment="Gdiplus.dll version is less than 5.2.6001.22791" test_ref="oval:gov.nist.fdcc.patch:tst:1174804"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Gdiplus.dll version is less than 5.2.6002.18342" test_ref="oval:gov.nist.fdcc.patch:tst:1174805"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Gdiplus.dll version is greater than or equal to 5.2.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174806"/>
                     <criterion comment="Gdiplus.dll version is less than 5.2.6002.22519" test_ref="oval:gov.nist.fdcc.patch:tst:1174807"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Gdiplus.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1174808"/>
                     <criterion comment="Gdiplus.dll version is less than 6.0.6001.18551" test_ref="oval:gov.nist.fdcc.patch:tst:1174809"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Gdiplus.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174810"/>
                     <criterion comment="Gdiplus.dll version is less than 6.0.6001.22791" test_ref="oval:gov.nist.fdcc.patch:tst:1174811"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Gdiplus.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1174812"/>
                     <criterion comment="Gdiplus.dll version is less than 6.0.6002.18342" test_ref="oval:gov.nist.fdcc.patch:tst:1174813"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Gdiplus.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174814"/>
                     <criterion comment="Gdiplus.dll version is less than 6.0.6002.22519" test_ref="oval:gov.nist.fdcc.patch:tst:1174815"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11749" version="2" class="patch">
         <metadata>
            <title>MS11-030: Vulnerability in DNS Resolution Could Allow Remote Code Execution (2509553)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-030" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-030.mspx"/>
            <reference source="Microsoft" ref_id="KB2509553" ref_url="http://support.microsoft.com/kb/2509553"/>
            <reference source="CVE" ref_id="CVE-2011-0657" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0657"/>
            <description>Microsoft has released MS11-030 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-0657</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Dnsapi.dll version is less than 5.1.2600.6089" test_ref="oval:gov.nist.fdcc.patch:tst:1174900"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Dnsapi.dll version is less than 5.2.3790.4840" test_ref="oval:gov.nist.fdcc.patch:tst:1174901"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Dnsapi.dll version is less than 6.0.6001.18611" test_ref="oval:gov.nist.fdcc.patch:tst:1174902"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Dnsapi.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174903"/>
                     <criterion comment="Dnsapi.dll version is less than 6.0.6001.22866" test_ref="oval:gov.nist.fdcc.patch:tst:1174904"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Dnsapi.dll version is less than 6.0.6002.18416" test_ref="oval:gov.nist.fdcc.patch:tst:1174905"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Dnsapi.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174906"/>
                     <criterion comment="Dnsapi.dll version is less than 6.0.6002.22600" test_ref="oval:gov.nist.fdcc.patch:tst:1174907"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Dnsapi.dll version is less than 6.1.7600.16772" test_ref="oval:gov.nist.fdcc.patch:tst:1174908"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Dnsapi.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1174909"/>
                     <criterion comment="Dnsapi.dll version is less than 6.1.7600.20914" test_ref="oval:gov.nist.fdcc.patch:tst:1174910"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) SP1 - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Dnsapi.dll version is less than 6.1.7601.17570" test_ref="oval:gov.nist.fdcc.patch:tst:1174911"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Dnsapi.dll version is greater than or equal to 6.1.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1174912"/>
                     <criterion comment="Dnsapi.dll version is less than 6.1.7601.21673" test_ref="oval:gov.nist.fdcc.patch:tst:1174913"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11750" version="5" class="patch">
         <metadata>
            <title>MS11-031: Vulnerability in JScript and VBScript Scripting Engines Could Allow Remote Code Execution (2514666)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-031" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-031.mspx"/>
            <reference source="Microsoft" ref_id="KB2514666" ref_url="http://support.microsoft.com/kb/2514666"/>
            <reference source="CVE" ref_id="CVE-2011-0663" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0663"/>
            <description>Microsoft has released MS11-031 to address security issues in JScript and VBScript scripting engines as documented by 2011-0663</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="JScript 5.6 and VBScript 5.6 on XP (32-bit SP2 or SP3, 64-bit SP2)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <criterion comment="Jscript.dll version is greater than or equal to 5.6.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:115851"/>
               <criterion comment="Jscript.dll version is less than 5.6.0.8850" test_ref="oval:gov.nist.fdcc.patch:tst:1175001"/>
               <criterion comment="Vbscript.dll version is greater than or equal to 5.1.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:1175002"/>
               <criterion comment="Vbscript.dll version is less than 5.6.0.8850" test_ref="oval:gov.nist.fdcc.patch:tst:1175003"/>
            </criteria>
            <criteria operator="AND" comment="JScript 5.7 and VBScript 5.7 on XP (32-bit SP2 or SP3, 64-bit SP2)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <criterion comment="Jscript.dll version is greater than or equal to 5.7.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:115853"/>
               <criterion comment="Jscript.dll version is less than 5.7.6002.22589" test_ref="oval:gov.nist.fdcc.patch:tst:1175005"/>
               <criterion comment="Vbscript.dll version is greater than or equal to 5.7.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:1165802"/>
               <criterion comment="Vbscript.dll version is less than 5.7.6002.22589" test_ref="oval:gov.nist.fdcc.patch:tst:1175007"/>
            </criteria>
            <criteria operator="AND" comment="JScript 5.7 and VBScript 5.7 on Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Jscript.dll version is greater than or equal to 5.7.0.18000" test_ref="oval:gov.nist.fdcc.patch:tst:115857"/>
                     <criterion comment="Jscript.dll version is less than 5.7.0.18599" test_ref="oval:gov.nist.fdcc.patch:tst:1175009"/>
                     <criterion comment="Vbscript.dll version is greater than or equal to 5.7.0.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1165806"/>
                     <criterion comment="Vbscript.dll version is less than 5.7.0.18599" test_ref="oval:gov.nist.fdcc.patch:tst:1175011"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Jscript.dll version is greater than or equal to 5.7.0.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115859"/>
                     <criterion comment="Jscript.dll version is less than 5.7.0.22854" test_ref="oval:gov.nist.fdcc.patch:tst:1175013"/>
                     <criterion comment="Vbscript.dll version is greater than or equal to 5.7.0.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165810"/>
                     <criterion comment="Vbscript.dll version is less than 5.7.0.22854" test_ref="oval:gov.nist.fdcc.patch:tst:1175015"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="JScript 5.7 and VBScript 5.7 on Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Jscript.dll version is greater than or equal to 5.7.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1158592"/>
                     <criterion comment="Jscript.dll version is less than 5.7.6002.18405" test_ref="oval:gov.nist.fdcc.patch:tst:1175017"/>
                     <criterion comment="Vbscript.dll version is greater than or equal to 5.7.6002.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1165813"/>
                     <criterion comment="Vbscript.dll version is less than 5.7.6002.18405" test_ref="oval:gov.nist.fdcc.patch:tst:1175019"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Jscript.dll version is greater than or equal to 5.7.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1158531"/>
                     <criterion comment="Jscript.dll version is less than 5.7.6002.22589" test_ref="oval:gov.nist.fdcc.patch:tst:1175005"/>
                     <criterion comment="Vbscript.dll version is greater than or equal to 5.7.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1165815"/>
                     <criterion comment="Vbscript.dll version is less than 5.7.6002.22589" test_ref="oval:gov.nist.fdcc.patch:tst:1175007"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="JScript 5.8 and VBScript 5.8 on XP (32-bit SP2 or SP3, 64-bit SP2)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <criterion comment="Jscript.dll version is greater than or equal to 5.8.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:115855"/>
               <criterion comment="Jscript.dll version is less than 5.8.6001.23141" test_ref="oval:gov.nist.fdcc.patch:tst:1175025"/>
               <criterion comment="Vbscript.dll version is greater than or equal to 5.8.0.0" test_ref="oval:gov.nist.fdcc.patch:tst:1165804"/>
               <criterion comment="Vbscript.dll version is less than 5.8.6001.23141" test_ref="oval:gov.nist.fdcc.patch:tst:1175027"/>
            </criteria>
            <criteria operator="AND" comment="JScript 5.8 and VBScript 5.8 on Vista, Server 2008 SP1 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985" negate="true"/>
               <criteria operator="OR" comment="GDR or LDR">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Jscript.dll version is greater than or equal to 5.8.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1158595"/>
                     <criterion comment="Jscript.dll version is less than 5.8.6001.19046" test_ref="oval:gov.nist.fdcc.patch:tst:1175029"/>
                     <criterion comment="Vbscript.dll version is greater than or equal to 5.8.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1175030"/>
                     <criterion comment="Vbscript.dll version is less than 5.8.6001.19046" test_ref="oval:gov.nist.fdcc.patch:tst:1175031"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Jscript.dll version is greater than or equal to 5.8.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1175032"/>
                     <criterion comment="Jscript.dll version is less than 5.8.6001.23141" test_ref="oval:gov.nist.fdcc.patch:tst:1175025"/>
                     <criterion comment="Vbscript.dll version is greater than or equal to 5.8.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1175034"/>
                     <criterion comment="Vbscript.dll version is less than 5.8.6001.23141" test_ref="oval:gov.nist.fdcc.patch:tst:1175027"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="JScript 5.8 and VBScript 5.8 on Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985" negate="true"/>
               <criteria operator="OR" comment="GDR or LDR">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Jscript.dll version is greater than or equal to 5.8.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1158595"/>
                     <criterion comment="Jscript.dll version is less than 5.8.6001.19046" test_ref="oval:gov.nist.fdcc.patch:tst:1175029"/>
                     <criterion comment="Vbscript.dll version is greater than or equal to 5.8.6001.18000" test_ref="oval:gov.nist.fdcc.patch:tst:1175030"/>
                     <criterion comment="Vbscript.dll version is less than 5.8.6001.19046" test_ref="oval:gov.nist.fdcc.patch:tst:1175031"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Jscript.dll version is greater than or equal to 5.8.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1175032"/>
                     <criterion comment="Jscript.dll version is less than 5.8.6001.23141" test_ref="oval:gov.nist.fdcc.patch:tst:1175025"/>
                     <criterion comment="Vbscript.dll version is greater than or equal to 5.8.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1175034"/>
                     <criterion comment="Vbscript.dll version is less than 5.8.6001.23141" test_ref="oval:gov.nist.fdcc.patch:tst:1175027"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="JScript 5.8 and VBScript 5.8 on Windows 7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985" negate="true"/>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Jscript.dll version is less than 5.8.7600.16762" test_ref="oval:gov.nist.fdcc.patch:tst:1175036"/>
                     <criterion comment="Vbscript.dll version is less than 5.8.7600.16762" test_ref="oval:gov.nist.fdcc.patch:tst:1175037"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Jscript.dll version is greater than or equal to 5.8.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1173302"/>
                     <criterion comment="Jscript.dll version is less than 5.8.7600.20904" test_ref="oval:gov.nist.fdcc.patch:tst:1175039"/>
                     <criterion comment="Vbscript.dll version is greater than or equal to 5.8.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1165818"/>
                     <criterion comment="Vbscript.dll version is less than 5.8.7600.20904" test_ref="oval:gov.nist.fdcc.patch:tst:1175041"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="JScript 5.8 and VBScript 5.8 on Windows 7, Server 2008 R2 SP1 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985" negate="true"/>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Jscript.dll version is less than 5.8.7601.17562" test_ref="oval:gov.nist.fdcc.patch:tst:1175042"/>
                     <criterion comment="Vbscript.dll version is less than 5.8.7601.17562" test_ref="oval:gov.nist.fdcc.patch:tst:1175043"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Jscript.dll version is greater than or equal to 5.8.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1173308"/>
                     <criterion comment="Jscript.dll version is less than 5.8.7601.21663" test_ref="oval:gov.nist.fdcc.patch:tst:1175045"/>
                     <criterion comment="Vbscript.dll version is greater than or equal to 5.8.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1173310"/>
                     <criterion comment="Vbscript.dll version is less than 5.8.7601.21663" test_ref="oval:gov.nist.fdcc.patch:tst:1175047"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11751" version="3" class="patch">
         <metadata>
            <title>MS11-032: Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2507618)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-032" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-032.mspx"/>
            <reference source="Microsoft" ref_id="KB2507618" ref_url="http://support.microsoft.com/kb/2507618"/>
            <reference source="CVE" ref_id="CVE-2011-0034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0034"/>
            <description>Microsoft has released MS11-032 to address security issues in the OpenType Compact Font Format (CFF) driver as documented by CVE-2011-0034.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="(vista sp1/2 (32/64) OR 2008 RTM/sp2 (32/64) OR xp sp2/3)">
               <criteria operator="OR" comment="vista sp1/2 (32/64) OR 2008 RTM/sp2 (32/64) OR xp sp2/3 OR xp x64 sp2 OR 7 OR 2008 R2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criterion comment="Atmfd.dll version is less than 5.1.2.232" test_ref="oval:gov.nist.fdcc.patch:tst:117510"/>
            </criteria>
            <criteria operator="AND" comment="xp x64 sp2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Atmfd.dll version is less than 5.2.2.232" test_ref="oval:gov.nist.fdcc.patch:tst:117511"/>
            </criteria>
            <criteria operator="AND" comment="Windows 7, Server 2008 R2 RTM/SP1 (32-bit, 64-bit, ia-64)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <criterion comment="Atmfd.dll version is less than 5.1.2.234" test_ref="oval:gov.nist.fdcc.patch:tst:117512"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11752" version="1" class="patch">
         <metadata>
            <title>MS11-033: Vulnerability in WordPad Text Converters Could Allow Remote Code Execution (2485663)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-033" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-033.mspx"/>
            <reference source="Microsoft" ref_id="KB2485663" ref_url="http://support.microsoft.com/kb/2485663"/>
            <reference source="CVE" ref_id="CVE-2011-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0028"/>
            <description>Microsoft has released MS11-033 to address security issues in Windows XP as documented by CVE-2011-0028.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3 or (64-bit) SP2">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <criterion comment="Mswrd8.wpc version is less than 2011.1.31.10" test_ref="oval:gov.nist.fdcc.patch:tst:117520"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11755" version="2" class="patch">
         <metadata>
            <title>MS11-037: Vulnerability in MHTML Could Allow Information Disclosure (2544893)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-037" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-037.mspx"/>
            <reference source="Microsoft" ref_id="KB2544893" ref_url="http://support.microsoft.com/kb/2544893"/>
            <reference source="CVE" ref_id="CVE-2011-1894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1894"/>
            <description>Microsoft has released MS11-037 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1894.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.2900.6109" test_ref="oval:gov.nist.fdcc.patch:tst:1175500"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Inetcomm.dll version is less than 6.0.3790.4862" test_ref="oval:gov.nist.fdcc.patch:tst:1175501"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Inetcomm.dll version is less than 6.0.6001.18645" test_ref="oval:gov.nist.fdcc.patch:tst:1175502"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Inetcomm.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174504"/>
                     <criterion comment="Inetcomm.dll version is less than 6.0.6001.22911" test_ref="oval:gov.nist.fdcc.patch:tst:1175504"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Inetcomm.dll version is less than 6.0.6002.18463" test_ref="oval:gov.nist.fdcc.patch:tst:1175505"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Inetcomm.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1174507"/>
                     <criterion comment="Inetcomm.dll version is less than 6.0.6002.22634" test_ref="oval:gov.nist.fdcc.patch:tst:1175507"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Inetcomm.dll version is less than 6.1.7600.16807" test_ref="oval:gov.nist.fdcc.patch:tst:1175508"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Inetcomm.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1174510"/>
                     <criterion comment="Inetcomm.dll version is less than 6.1.7600.20958" test_ref="oval:gov.nist.fdcc.patch:tst:1175510"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 SP1 (32-bit, 64-bit)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Inetcomm.dll version is less than 6.1.7601.17609" test_ref="oval:gov.nist.fdcc.patch:tst:1175511"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Inetcomm.dll version is greater than or equal to 6.1.7601.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1174513"/>
                     <criterion comment="Inetcomm.dll version is less than 6.1.7601.21719" test_ref="oval:gov.nist.fdcc.patch:tst:1175513"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11756" version="1" class="patch">
         <metadata>
            <title>MS11-038: Vulnerability in OLE Automation Could Allow Remote Code Execution (2476490)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-038" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-038.mspx"/>
            <reference source="Microsoft" ref_id="KB2476490" ref_url="http://support.microsoft.com/kb/2476490"/>
            <reference source="CVE" ref_id="CVE-2011-0658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0658"/>
            <description>Microsoft has released MS11-038 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-0658.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Oleaut32.dll version is less than 5.1.2600.6058" test_ref="oval:gov.nist.fdcc.patch:tst:1175600"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Oleaut32.dll version is less than 5.2.3790.4807" test_ref="oval:gov.nist.fdcc.patch:tst:1175601"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Oleaut32.dll version is less than 6.0.6001.18565" test_ref="oval:gov.nist.fdcc.patch:tst:1175602"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Oleaut32.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1175603"/>
                     <criterion comment="Oleaut32.dll version is less than 6.0.6001.22816" test_ref="oval:gov.nist.fdcc.patch:tst:1175604"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Oleaut32.dll version is less than 6.0.6002.18357" test_ref="oval:gov.nist.fdcc.patch:tst:1175605"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Oleaut32.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1175606"/>
                     <criterion comment="Oleaut32.dll version is less than 6.0.6002.22551" test_ref="oval:gov.nist.fdcc.patch:tst:1175607"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Oleaut32.dll version is less than 6.1.7600.16722" test_ref="oval:gov.nist.fdcc.patch:tst:1175608"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Oleaut32.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1175609"/>
                     <criterion comment="Oleaut32.dll version is less than 6.1.7600.20861" test_ref="oval:gov.nist.fdcc.patch:tst:1175610"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 SP1 (32-bit, 64-bit)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Oleaut32.dll version is less than 6.1.7601.16722" test_ref="oval:gov.nist.fdcc.patch:tst:1175611"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Oleaut32.dll version is greater than or equal to 6.1.7601.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1175612"/>
                     <criterion comment="Oleaut32.dll version is less than 6.1.7601.21669" test_ref="oval:gov.nist.fdcc.patch:tst:1175613"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11759" version="1" class="patch">
         <metadata>
            <title>MS11-042: Vulnerabilities in Distributed File System Could Allow Remote Code Execution (2535512)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-042" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-042.mspx"/>
            <reference source="Microsoft" ref_id="KB2535512" ref_url="http://support.microsoft.com/kb/2535512"/>
            <reference source="CVE" ref_id="CVE-2011-1868" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1868"/>
            <reference source="CVE" ref_id="CVE-2011-1869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1869"/>
            <description>Microsoft has released MS11-042 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1868 and CVE-2011-1869.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Mup.sys version is less than 5.1.2600.6103" test_ref="oval:gov.nist.fdcc.patch:tst:1175900"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mup.sys version is less than 5.2.3790.4851" test_ref="oval:gov.nist.fdcc.patch:tst:1175901"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Dfsc.sys version is less than 6.0.6001.18633" test_ref="oval:gov.nist.fdcc.patch:tst:1175902"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Dfsc.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1175903"/>
                     <criterion comment="Dfsc.sys version is less than 6.0.6001.22899" test_ref="oval:gov.nist.fdcc.patch:tst:1175904"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Dfsc.sys version is less than 6.0.6002.18451" test_ref="oval:gov.nist.fdcc.patch:tst:1175905"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Dfsc.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1175906"/>
                     <criterion comment="Dfsc.sys version is less than 6.0.6002.22625" test_ref="oval:gov.nist.fdcc.patch:tst:1175907"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Dfsc.sys version is less than 6.1.7600.16804" test_ref="oval:gov.nist.fdcc.patch:tst:1175908"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Dfsc.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1175909"/>
                     <criterion comment="Dfsc.sys version is less than 6.1.7600.20953" test_ref="oval:gov.nist.fdcc.patch:tst:1175910"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11760" version="2" class="patch">
         <metadata>
            <title>MS11-043: Vulnerability in SMB Client Could Allow Remote Code Execution (2536276)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-043" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-043.mspx"/>
            <reference source="Microsoft" ref_id="KB2536276" ref_url="http://support.microsoft.com/kb/2536276"/>
            <reference source="CVE" ref_id="CVE-2011-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1268"/>
            <description>Microsoft has released MS11-043 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1268.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Mrxsmb.sys version is less than 5.1.2600.6133" test_ref="oval:gov.nist.fdcc.patch:tst:1176000"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Mrxsmb.sys version is less than 5.2.3790.4883" test_ref="oval:gov.nist.fdcc.patch:tst:1176001"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.18644" test_ref="oval:gov.nist.fdcc.patch:tst:1176002"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mrxsmb10.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9535"/>
                     <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.22939" test_ref="oval:gov.nist.fdcc.patch:tst:1176004"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.18490" test_ref="oval:gov.nist.fdcc.patch:tst:1176005"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1176006"/>
                     <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.22672" test_ref="oval:gov.nist.fdcc.patch:tst:1176007"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16847" test_ref="oval:gov.nist.fdcc.patch:tst:1176008"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1176009"/>
                     <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.21005" test_ref="oval:gov.nist.fdcc.patch:tst:1176010"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 SP1 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Mrxsmb10.sys version is less than 6.1.7601.17647" test_ref="oval:gov.nist.fdcc.patch:tst:1176011"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1176012"/>
                     <criterion comment="Mrxsmb10.sys version is less than 6.1.7601.21767" test_ref="oval:gov.nist.fdcc.patch:tst:1176013"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11761" version="2" class="patch">
         <metadata>
            <title>MS11-044: Vulnerability in .NET Framework Could Allow Remote Code Execution (2538814)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-044" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-044.mspx"/>
            <reference source="Microsoft" ref_id="KB2538814" ref_url="http://support.microsoft.com/kb/2538814"/>
            <reference source="CVE" ref_id="CVE-2011-1271" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1271"/>
            <description>Microsoft has released MS11-044 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1271.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="(xp sp3 OR xp x64 sp2) AND 2.0 sp2">
               <criteria operator="OR" comment="xp sp3 OR xp x64 sp2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <criteria operator="OR" comment=".net 2.0 sp2 or 3.5 sp1">
                  <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2, or later, is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
                  <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11583"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR update has been applied">
                  <criterion comment="Mscorlib.dll version is less than 2.0.50727.3623" test_ref="oval:gov.nist.fdcc.patch:tst:1176100"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mscorlib.dll version is greater than or equal to 2.0.50727.5000" test_ref="oval:gov.nist.fdcc.patch:tst:1169106"/>
                     <criterion comment="Mscorlib.dll version is less than 2.0.50727.5662" test_ref="oval:gov.nist.fdcc.patch:tst:1176102"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="(xp sp3 OR xp x64 sp2) AND 3.5 (gold) or 4.0">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <criteria operator="OR">
                  <extend_definition comment="Microsoft .NET Framework 4.0 is Installed" definition_ref="oval:gov.nist.fdcc.patch:def:115295"/>
                  <extend_definition comment="Microsoft .NET Framework 3.5 (Gold) is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11582"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR update has been applied">
                  <criterion comment="Mscorlib.dll version is less than 4.0.30319.235" test_ref="oval:gov.nist.fdcc.patch:tst:1176103"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mscorlib.dll version is greater than or equal to 4.0.30319.300" test_ref="oval:gov.nist.fdcc.patch:tst:1174710"/>
                     <criterion comment="Mscorlib.dll version is less than 4.0.30319.454" test_ref="oval:gov.nist.fdcc.patch:tst:1176105"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="(vista sp1 (32/64) OR 2008 RTM (32/64)) AND .net 2.0 sp1 AND 3.5 (Gold)">
               <criteria operator="OR" comment="vista sp1 (32/64) OR 2008 RTM (32/64)">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6428"/>
               <extend_definition comment="Microsoft .NET Framework 3.5 (Gold) is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11582"/>
               <criterion comment="Mscorlib.dll version is less than 2.0.50727.1891" test_ref="oval:gov.nist.fdcc.patch:tst:1176106"/>
            </criteria>
            <criteria operator="AND" comment="(vista sp1 (32/64) OR 2008 RTM (32/64)) AND .net 2.0 sp2 AND 3.5 sp1">
               <criteria operator="OR" comment="vista sp1 (32/64) OR 2008 RTM (32/64)">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2, or later, is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
               <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11583"/>
               <criteria operator="OR" comment="GDR or LDR update has been applied">
                  <criterion comment="Mscorlib.dll version is less than 2.0.50727.3623" test_ref="oval:gov.nist.fdcc.patch:tst:1176100"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mscorlib.dll version is greater than or equal to 2.0.50727.4000" test_ref="oval:gov.nist.fdcc.patch:tst:1159403"/>
                     <criterion comment="Mscorlib.dll version is less than 2.0.50727.5662" test_ref="oval:gov.nist.fdcc.patch:tst:1176102"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="(vista sp2 (32/64) OR 2008 SP2 (32/64)) AND .net 2.0 sp2 OR 3.5 sp1">
               <criteria operator="OR" comment="vista sp2 (32/64) OR 2008 SP2 (32/64)">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment=".net 2.0 sp2 OR 3.5 sp1">
                  <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2, or later, is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
                  <extend_definition comment="Microsoft .NET Framework 3.5 Service Pack 1, or later, is installed" definition_ref="oval:gov.nist.fdcc.patch:def:11583"/>
               </criteria>
               <criteria operator="OR">
                  <criterion comment="Mscorlib.dll version is less than 2.0.50727.4214" test_ref="oval:gov.nist.fdcc.patch:tst:1176110"/>
                  <criteria operator="AND">
                     <criterion comment="Mscorlib.dll version is greater than or equal to 2.0.50727.5000" test_ref="oval:gov.nist.fdcc.patch:tst:1176111"/>
                     <criterion comment="Mscorlib.dll version is less than 2.0.50727.5662" test_ref="oval:gov.nist.fdcc.patch:tst:1176112"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64 AND .net 3.5.1">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:gov.nist.oval:def:115301"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:gov.nist.oval:def:115302"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:gov.nist.oval:def:115303"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:gov.nist.oval:def:115302"/>
               </criteria>
               <criteria operator="OR">
                  <criterion comment="Mscorlib.dll version is less than 2.0.50727.4961" test_ref="oval:gov.nist.fdcc.patch:tst:1176113"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mscorlib.dll version is greater than or equal to 2.0.50727.5000" test_ref="oval:gov.nist.fdcc.patch:tst:1176111"/>
                     <criterion comment="Mscorlib.dll version is less than 2.0.50727.5662" test_ref="oval:gov.nist.fdcc.patch:tst:1176112"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Windows 7 SP1 x86/x64, Windows Server 2008 R2 SP1 x64/ia64 AND .net 3.5.1">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <criteria operator="OR">
                  <criterion comment="Mscorlib.dll version is less than 2.0.50727.5446" test_ref="oval:gov.nist.fdcc.patch:tst:1176116"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Mscorlib.dll version is greater than or equal to 2.0.50727.5600" test_ref="oval:gov.nist.fdcc.patch:tst:1176117"/>
                     <criterion comment="Mscorlib.dll version is less than 2.0.50727.5662" test_ref="oval:gov.nist.fdcc.patch:tst:1176112"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11762" version="1" class="patch">
         <metadata>
            <title>MS11-046: Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2503665)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-046" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-046.mspx"/>
            <reference source="Microsoft" ref_id="KB2503665" ref_url="http://support.microsoft.com/kb/2503665"/>
            <reference source="CVE" ref_id="CVE-2011-1249" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1249"/>
            <description>Microsoft has released MS11-046 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1249.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Afd.sys version is less than 5.1.2600.6081" test_ref="oval:gov.nist.fdcc.patch:tst:1176200"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Afd.sys version is less than 5.2.3790.4828" test_ref="oval:gov.nist.fdcc.patch:tst:1176201"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Afd.sys version is less than 6.0.6001.18639" test_ref="oval:gov.nist.fdcc.patch:tst:1176202"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Afd.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1176203"/>
                     <criterion comment="Afd.sys version is less than 6.0.6001.22905" test_ref="oval:gov.nist.fdcc.patch:tst:1176204"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Afd.sys version is less than 6.0.6002.18457" test_ref="oval:gov.nist.fdcc.patch:tst:1176205"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Afd.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1176206"/>
                     <criterion comment="Afd.sys version is less than 6.0.6002.22629" test_ref="oval:gov.nist.fdcc.patch:tst:1176207"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Afd.sys version is less than 6.1.7600.16802" test_ref="oval:gov.nist.fdcc.patch:tst:1176208"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Afd.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1176209"/>
                     <criterion comment="Afd.sys version is less than 6.1.7600.20951" test_ref="oval:gov.nist.fdcc.patch:tst:1176210"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) SP1 - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Afd.sys version is less than 6.1.7601.17603" test_ref="oval:gov.nist.fdcc.patch:tst:1176211"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Afd.sys version is greater than or equal to 6.1.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1176212"/>
                     <criterion comment="Afd.sys version is less than 6.1.7601.21712" test_ref="oval:gov.nist.fdcc.patch:tst:1176213"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11767" version="1" class="patch">
         <metadata>
            <title>MS11-052: Vulnerability in Vector Markup Language Could Allow Remote Code Execution (2544521)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-052" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-052.mspx"/>
            <reference source="Microsoft" ref_id="KB2544521" ref_url="http://support.microsoft.com/kb/2544521"/>
            <reference source="CVE" ref_id="CVE-2011-1266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1266"/>
            <description>Microsoft has released MS11-052 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1266.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Internet Explorer 6">
               <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
               <criteria operator="OR">
                  <criteria operator="AND" comment="XP x64 SP2">
                     <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                     <criterion comment="Vgx.dll version is less than 6.0.3790.4861" test_ref="oval:gov.nist.fdcc.patch:tst:1176700"/>
                  </criteria>
                  <criteria operator="AND" comment="XP x86 SP3">
                     <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                     <criterion comment="Vgx.dll version is less than 6.0.2900.6108" test_ref="oval:gov.nist.fdcc.patch:tst:1176701"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Internet Explorer 7">
               <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
               <criteria operator="OR">
                  <criteria operator="AND" comment="XP SP3 (x86), SP2 (x64) - GDR/QFE">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                        <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                     </criteria>
                     <criterion comment="Vgx.dll version is less than 7.0.6000.21301" test_ref="oval:gov.nist.fdcc.patch:tst:1176702"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP1 (32/64-bit, ia-64) - GDR/LDR">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Vgx.dll version is less than 7.0.6001.18645" test_ref="oval:gov.nist.fdcc.patch:tst:1176703"/>
                        <criteria operator="AND" comment="LDR">
                           <criterion comment="Vgx.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1176704"/>
                           <criterion comment="Vgx.dll version is less than 7.0.6001.22911" test_ref="oval:gov.nist.fdcc.patch:tst:1176705"/>
                        </criteria>
                     </criteria>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP2 (32/64-bit, ia-64) - GDR/LDR">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Vgx.dll version is less than 7.0.6002.18463" test_ref="oval:gov.nist.fdcc.patch:tst:1176706"/>
                        <criteria operator="AND" comment="LDR">
                           <criterion comment="Vgx.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1176707"/>
                           <criterion comment="Vgx.dll version is less than 7.0.6002.22634" test_ref="oval:gov.nist.fdcc.patch:tst:1176708"/>
                        </criteria>
                     </criteria>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Internet Explorer 8">
               <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
               <criteria operator="OR">
                  <criteria operator="AND" comment="XP SP3 (x86), SP2 (x64) - GDR/QFE">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                        <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                     </criteria>
                     <criterion comment="Vgx.dll version is less than 8.0.6001.23167" test_ref="oval:gov.nist.fdcc.patch:tst:1176709"/>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 (32/64-bit, ia-64) - GDR/LDR">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Vgx.dll version is less than 8.0.6001.19076" test_ref="oval:gov.nist.fdcc.patch:tst:1176710"/>
                        <criteria operator="AND" comment="LDR">
                           <criterion comment="Vgx.dll version is greater than or equal to 8.0.6001.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1176711"/>
                           <criterion comment="Vgx.dll version is less than 8.0.6001.23169" test_ref="oval:gov.nist.fdcc.patch:tst:1176712"/>
                        </criteria>
                     </criteria>
                  </criteria>
                  <criteria operator="AND" comment="7, Server 2008 R2 (32-bit) - GDR/LDR">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Vgx.dll version is less than 8.0.7600.16806" test_ref="oval:gov.nist.fdcc.patch:tst:1176713"/>
                        <criteria operator="AND" comment="LDR">
                           <criterion comment="Vgx.dll version is greater than or equal to 8.0.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1176714"/>
                           <criterion comment="Vgx.dll version is less than 8.0.7600.20975" test_ref="oval:gov.nist.fdcc.patch:tst:1176715"/>
                        </criteria>
                     </criteria>
                  </criteria>
                  <criteria operator="AND" comment="7, Server 2008 R2 SP1 (32-bit) - GDR/LDR">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Vgx.dll version is less than 8.0.7600.17608" test_ref="oval:gov.nist.fdcc.patch:tst:1176716"/>
                        <criteria operator="AND" comment="LDR">
                           <criterion comment="Vgx.dll version is greater than or equal to 8.0.7600.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1176717"/>
                           <criterion comment="Vgx.dll version is less than 8.0.7600.21718" test_ref="oval:gov.nist.fdcc.patch:tst:1176718"/>
                        </criteria>
                     </criteria>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11769" version="1" class="patch">
         <metadata>
            <title>MS11-054: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2555917)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-054" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-054.mspx"/>
            <reference source="Microsoft" ref_id="KB2555917" ref_url="http://support.microsoft.com/kb/2555917"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1874"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1874"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1875"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1876"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1877"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1878"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1879"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1880"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1881"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1882"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1883"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1884"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1885"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1886"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1887"/>
            <reference source="CVE" ref_id="CVE-2011-1874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1888"/>
            <description>Microsoft has released MS11-054 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1874, CVE-2011-1875, CVE-2011-1876, CVE-2011-1877, CVE-2011-1878, CVE-2011-1879, CVE-2011-1880, CVE-2011-1881, CVE-2011-1882, CVE-2011-1883, CVE-2011-1884, CVE-2011-1885, CVE-2011-1886, CVE-2011-1887, and CVE-2011-1888.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Win32k.sys version is less than 5.1.2600.6119" test_ref="oval:gov.nist.fdcc.patch:tst:1176900"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Win32k.sys version is less than 5.2.3790.4872" test_ref="oval:gov.nist.fdcc.patch:tst:1176901"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit,64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Win32k.sys version is less than 6.0.6001.18653" test_ref="oval:gov.nist.fdcc.patch:tst:1176902"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Win32k.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115477"/>
                     <criterion comment="Win32k.sys version is less than 6.0.6001.22927" test_ref="oval:gov.nist.fdcc.patch:tst:1176904"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Win32k.sys version is less than 6.0.6002.18475" test_ref="oval:gov.nist.fdcc.patch:tst:1176905"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Win32k.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:116219"/>
                     <criterion comment="Win32k.sys version is less than 6.0.6002.22653" test_ref="oval:gov.nist.fdcc.patch:tst:1176907"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Win32k.sys version is less than 6.1.7600.16830" test_ref="oval:gov.nist.fdcc.patch:tst:1176908"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Win32k.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1167094"/>
                     <criterion comment="Win32k.sys version is less than 6.1.7600.20983" test_ref="oval:gov.nist.fdcc.patch:tst:1176910"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 SP1 (32-bit, 64-bit, ia-64) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Win32k.sys version is less than 6.1.7601.17630" test_ref="oval:gov.nist.fdcc.patch:tst:1176911"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Win32k.sys version is greater than or equal to 6.1.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1173612"/>
                     <criterion comment="Win32k.sys version is less than 6.1.7601.21744" test_ref="oval:gov.nist.fdcc.patch:tst:1176913"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11770" version="2" class="patch">
         <metadata>
            <title>MS11-056: Vulnerabilities in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2507938)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <!--<platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>-->
            </affected>
            <reference source="Microsoft" ref_id="MS11-056" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-056.mspx"/>
            <reference source="Microsoft" ref_id="KB2507938" ref_url="http://support.microsoft.com/kb/2507938"/>
            <reference source="CVE" ref_id="CVE-2011-1281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1281"/>
            <reference source="CVE" ref_id="CVE-2011-1281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1282"/>
            <reference source="CVE" ref_id="CVE-2011-1281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1283"/>
            <reference source="CVE" ref_id="CVE-2011-1281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1284"/>
            <reference source="CVE" ref_id="CVE-2011-1281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1870"/>
            <description>Microsoft has released MS11-056 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1281, CVE-2011-1282, CVE-2011-1283, CVE-2011-1284, and CVE-2011-1870.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Vulnerable Windows XP (x86) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Winsrv.dll version is less than 5.1.2600.6104" test_ref="oval:gov.nist.fdcc.patch:tst:1177000"/>
               <criterion comment="Csrsrv.dll version is less than 5.1.2600.6104" test_ref="oval:gov.nist.fdcc.patch:tst:1177001"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows XP (x64) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Winsrv.dll version is less than 5.2.3790.4860" test_ref="oval:gov.nist.fdcc.patch:tst:1177002"/>
               <criterion comment="Csrsrv.dll version is less than 5.2.3790.4860" test_ref="oval:gov.nist.fdcc.patch:tst:1177003"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP1 (32-bit, 64-bit) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Csrsrv.dll version is less than 6.0.6001.18638" test_ref="oval:gov.nist.fdcc.patch:tst:1177004"/>
                     <criterion comment="Winsrv.dll version is less than 6.0.6001.18638" test_ref="oval:gov.nist.fdcc.patch:tst:1177005"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Csrsrv.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1177006"/>
                     <criterion comment="Csrsrv.dll version is less than 6.0.6001.22904" test_ref="oval:gov.nist.fdcc.patch:tst:1177007"/>
                     <criterion comment="Winsrv.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1177008"/>
                     <criterion comment="Winsrv.dll version is less than 6.0.6001.22904" test_ref="oval:gov.nist.fdcc.patch:tst:1177009"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Csrsrv.dll version is less than 6.0.6002.18456" test_ref="oval:gov.nist.fdcc.patch:tst:1177010"/>
                     <criterion comment="Winsrv.dll version is less than 6.0.6002.18456" test_ref="oval:gov.nist.fdcc.patch:tst:1177011"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Csrsrv.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1177012"/>
                     <criterion comment="Csrsrv.dll version is less than 6.0.6002.22628" test_ref="oval:gov.nist.fdcc.patch:tst:1177013"/>
                     <criterion comment="Winsrv.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1177014"/>
                     <criterion comment="Winsrv.dll version is less than 6.0.6002.22628" test_ref="oval:gov.nist.fdcc.patch:tst:1177015"/>
                  </criteria>
               </criteria>
            </criteria>
            <!--<criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Kernel32.dll version is less than 6.1.7600.16816" test_ref="oval:gov.nist.fdcc.patch:tst:1177016"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Kernel32.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1177017"/>
                     <criterion comment="Kernel32.dll version is less than 6.1.7600.20978" test_ref="oval:gov.nist.fdcc.patch:tst:1177018"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 SP1 (32-bit, 64-bit)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="Kernel32.dll version is less than 6.1.7601.17617" test_ref="oval:gov.nist.fdcc.patch:tst:1177019"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Kernel32.dll version is greater than or equal to 6.1.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1177020"/>
                     <criterion comment="Kernel32.dll version is less than 6.1.7601.21728" test_ref="oval:gov.nist.fdcc.patch:tst:1177021"/>
                  </criteria>
               </criteria>
            </criteria>-->
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11771" version="1" class="patch">
         <metadata>
            <title>MS11-057: Cumulative Security Update for Internet Explorer (2559049)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
               <platform>Microsoft Internet Explorer 6</platform>
               <platform>Microsoft Internet Explorer 7</platform>
               <platform>Microsoft Internet Explorer 8</platform>
               <platform>Microsoft Internet Explorer 9</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-057" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-057.mspx"/>
            <reference source="Microsoft" ref_id="KB2559049" ref_url="http://support.microsoft.com/kb/2559049"/>
            <reference source="CVE" ref_id="CVE-2011-1257" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1257"/>
            <reference source="CVE" ref_id="CVE-2011-1960" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1960"/>
            <reference source="CVE" ref_id="CVE-2011-1961" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1961"/>
            <reference source="CVE" ref_id="CVE-2011-1962" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1962"/>
            <reference source="CVE" ref_id="CVE-2011-1963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1963"/>
            <reference source="CVE" ref_id="CVE-2011-1964" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1964"/>
            <reference source="CVE" ref_id="CVE-2011-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2383"/>
            <description>Microsoft has released MS11-057 to address security issues in Microsoft Internet Explorer 6, 7, 8, and 9 on Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1257, CVE-2011-1960, CVE-2011-1961, CVE-2011-1962, CVE-2011-1963, CVE-2011-1964, and CVE-2011-2383.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Internet Explorer 6">
               <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
               <criteria operator="OR">
                  <criteria operator="AND" comment="XP x64 SP2">
                     <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                     <criterion comment="Mshtml.dll version is less than 6.0.3790.4879" test_ref="oval:gov.nist.fdcc.patch:tst:1177100"/>
                  </criteria>
                  <criteria operator="AND" comment="XP x86 SP3">
                     <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                     <criterion comment="Mshtml.dll version is less than 6.0.2900.6129" test_ref="oval:gov.nist.fdcc.patch:tst:1177101"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Internet Explorer 7">
               <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
               <criteria operator="OR">
                  <criteria operator="AND" comment="XP SP3 (x86), SP2 (x64) - GDR/QFE">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                        <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or QFE Service branch">
                        <criterion comment="Mshtml.dll version is less than 7.0.6000.17102" test_ref="oval:gov.nist.fdcc.patch:tst:1177102"/>
                        <criteria operator="AND" comment="QFE">
                           <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6000.20000" test_ref="oval:gov.nist.fdcc.patch:tst:115304"/>
                           <criterion comment="Mshtml.dll version is less than 7.0.6000.21305" test_ref="oval:gov.nist.fdcc.patch:tst:1177104"/>
                        </criteria>
                     </criteria>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 SP2 (32/64-bit, ia-64) - GDR/LDR">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Mshtml.dll version is less than 7.0.6002.18494" test_ref="oval:gov.nist.fdcc.patch:tst:1177105"/>
                        <criteria operator="AND" comment="LDR">
                           <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:115658"/>
                           <criterion comment="Mshtml.dll version is less than 7.0.6002.22683" test_ref="oval:gov.nist.fdcc.patch:tst:1177107"/>
                        </criteria>
                     </criteria>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Internet Explorer 8">
               <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
               <criteria operator="OR">
                  <criteria operator="AND" comment="XP SP3 (x86), SP2 (x64) - GDR/QFE">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                        <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or QFE Service branch">
                        <criterion comment="Mshtml.dll version is less than 8.0.6001.19120" test_ref="oval:gov.nist.fdcc.patch:tst:1177108"/>
                        <criteria operator="AND" comment="QFE">
                           <criterion comment="Mshtml.dll version is greater than or equal to 8.0.6001.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1171414"/>
                           <criterion comment="Mshtml.dll version is less than 8.0.6001.23216" test_ref="oval:gov.nist.fdcc.patch:tst:1177110"/>
                        </criteria>
                     </criteria>
                  </criteria>
                  <criteria operator="AND" comment="Vista, Server 2008 (32/64-bit, ia-64) - GDR/LDR">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Mshtml.dll version is less than 8.0.6001.19120" test_ref="oval:gov.nist.fdcc.patch:tst:1177108"/>
                        <criteria operator="AND" comment="LDR">
                           <criterion comment="Mshtml.dll version is greater than or equal to 8.0.6001.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1171414"/>
                           <criterion comment="Mshtml.dll version is less than 8.0.6001.23216" test_ref="oval:gov.nist.fdcc.patch:tst:1177110"/>
                        </criteria>
                     </criteria>
                  </criteria>
                  <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia64) - GDR/LDR">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Mshtml.dll version is less than 8.0.7600.16853" test_ref="oval:gov.nist.fdcc.patch:tst:1177114"/>
                        <criteria operator="AND" comment="LDR">
                           <criterion comment="Mshtml.dll version is greater than or equal to 8.0.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1171418"/>
                           <criterion comment="Mshtml.dll version is less than 8.0.7600.21013" test_ref="oval:gov.nist.fdcc.patch:tst:1177116"/>
                        </criteria>
                     </criteria>
                  </criteria>
                  <criteria operator="AND" comment="7, Server 2008 R2 SP1 (32-bit, 64-bit, ia64) - GDR/LDR">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Mshtml.dll version is less than 8.0.7601.17655" test_ref="oval:gov.nist.fdcc.patch:tst:1177117"/>
                        <criteria operator="AND" comment="LDR">
                           <criterion comment="Mshtml.dll version is greater than or equal to 8.0.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1172918"/>
                           <criterion comment="Mshtml.dll version is less than 8.0.7601.21776" test_ref="oval:gov.nist.fdcc.patch:tst:1177119"/>
                        </criteria>
                     </criteria>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Internet Explorer 9">
               <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
               <criteria operator="OR">
                  <criteria operator="AND" comment="Vista, Server 2008, 7, 2008 r2 (32/64-bit, ia-64) - GDR/LDR">
                     <criteria operator="OR">
                        <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                        <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                        <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                        <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                        <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                        <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                        <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                        <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                        <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
                     </criteria>
                     <criteria operator="OR" comment="GDR or LDR Service branch">
                        <criterion comment="Mshtml.dll version is less than 9.0.8112.16434" test_ref="oval:gov.nist.fdcc.patch:tst:1177120"/>
                        <criteria operator="AND" comment="LDR">
                           <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1176521"/>
                           <criterion comment="Mshtml.dll version is less than 9.0.8112.20534" test_ref="oval:gov.nist.fdcc.patch:tst:1177122"/>
                        </criteria>
                     </criteria>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11775" version="1" class="patch">
         <metadata>
            <title>MS11-062: Vulnerability in Remote Access Service NDISTAPI Driver Could Allow Elevation of Privilege (2566454)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-062" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-062.mspx"/>
            <reference source="Microsoft" ref_id="KB2566454" ref_url="http://support.microsoft.com/kb/2566454"/>
            <reference source="CVE" ref_id="CVE-2011-1974" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1974"/>
            <description>Microsoft has released MS11-062 to address security issues in Windows XP as documented by CVE-2011-1974.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Ndistapi.sys version is less than 5.1.2600.6132" test_ref="oval:gov.nist.fdcc.patch:tst:117750"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Ndistapi.sys version is less than 5.2.3790.4885" test_ref="oval:gov.nist.fdcc.patch:tst:117751"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11776" version="2" class="patch">
         <metadata>
            <title>MS11-063: Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2567680)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-063" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-063.mspx"/>
            <reference source="Microsoft" ref_id="KB2567680" ref_url="http://support.microsoft.com/kb/2567680"/>
            <reference source="CVE" ref_id="CVE-2011-1967" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1967"/>
            <description>Microsoft has released MS11-063 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1967.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="Vulnerable Windows XP (x86) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Winsrv.dll version is less than 5.1.2600.6125" test_ref="oval:gov.nist.fdcc.patch:tst:1177600"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows XP (x64) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Winsrv.dll version is less than 5.2.3790.4877" test_ref="oval:gov.nist.fdcc.patch:tst:1177601"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit) - GDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Winsrv.dll version is less than 6.0.6002.18484" test_ref="oval:gov.nist.fdcc.patch:tst:1177602"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Winsrv.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:1177014"/>
                     <criterion comment="Winsrv.dll version is less than 6.0.6002.22662" test_ref="oval:gov.nist.fdcc.patch:tst:1177604"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit) - GDR/LDR">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Winsrv.dll version is less than 6.1.7600.16850" test_ref="oval:gov.nist.fdcc.patch:tst:1177605"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Winsrv.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:1177606"/>
                     <criterion comment="Winsrv.dll version is less than 6.1.7600.20995" test_ref="oval:gov.nist.fdcc.patch:tst:1177607"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 SP1 (32-bit, 64-bit)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Winsrv.dll version is less than 6.1.7601.17641" test_ref="oval:gov.nist.fdcc.patch:tst:1177608"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Winsrv.dll version is greater than or equal to 6.1.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:1177609"/>
                     <criterion comment="Winsrv.dll version is less than 6.1.7601.21756" test_ref="oval:gov.nist.fdcc.patch:tst:1177610"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11778" version="1" class="patch">
         <metadata>
            <title>MS11-065: Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (2570222)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-065" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-065.mspx"/>
            <reference source="Microsoft" ref_id="KB2570222" ref_url="http://support.microsoft.com/kb/2570222"/>
            <reference source="CVE" ref_id="CVE-2011-1968" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1968"/>
            <description>Microsoft has released MS11-065 to address security issues in Windows XP as documented by CVE-2011-1968.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <criterion comment="Rdpwd.sys version is less than 5.1.2600.6128" test_ref="oval:gov.nist.fdcc.patch:tst:117780"/>
            </criteria>
            <criteria operator="AND" comment="XP (64-bit) SP2">
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <criterion comment="Rdpwd.sys version is less than 5.2.3790.4881" test_ref="oval:gov.nist.fdcc.patch:tst:117781"/>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11779" version="1" class="patch">
         <metadata>
            <title>MS11-066: Vulnerability in Microsoft Chart Control Could Allow Information Disclosure (2567943)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-066" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-066.mspx"/>
            <reference source="Microsoft" ref_id="KB2567943" ref_url="http://support.microsoft.com/kb/2567943"/>
            <reference source="CVE" ref_id="CVE-2011-1977" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1977"/>
            <description>Microsoft has released MS11-066 to address security issues in .NET Framework 4.0 on Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1977.</description>
         </metadata>
         <criteria operator="AND" comment="(XP SP2 OR Vista SP1/SP2 OR Server 2008 RTM/SP2 OR 7 OR 2008 R2)(32-bit/64-bit/ia-64) AND .Net 4.0">
            <criteria operator="OR">
               <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
               <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
               <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
               <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
               <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
               <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
               <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
               <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
               <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
               <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            </criteria>
            <extend_definition comment="Microsoft .NET Framework 4.0 is Installed" definition_ref="oval:gov.nist.fdcc.patch:def:115295"/>
            <criteria operator="OR">
               <criteria operator="AND" comment="GDR">
                  <criterion comment="System.Web.DataVisualization.dll version is less than 4.0.30319.236" test_ref="oval:gov.nist.fdcc.patch:tst:117790"/>
               </criteria>
               <criteria operator="AND" comment="LDR">
                  <criterion comment="System.Web.DataVisualization.dll version is greater than or equal to 4.0.30319.300" test_ref="oval:gov.nist.fdcc.patch:tst:117791"/>
                  <criterion comment="System.Web.DataVisualization.dll version is less than 4.0.30319.461" test_ref="oval:gov.nist.fdcc.patch:tst:117792"/>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11781" version="1" class="patch">
         <metadata>
            <title>MS11-069: Vulnerability in .NET Framework Could Allow Information Disclosure (2567951)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
               <product>Microsoft .NET Framework</product>
            </affected>
            <reference source="Microsoft" ref_id="MS11-069" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-069.mspx"/>
            <reference source="Microsoft" ref_id="KB2567951" ref_url="http://support.microsoft.com/kb/2567951"/>
            <reference source="CVE" ref_id="CVE-2011-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1978"/>
            <description>Microsoft has released MS11-069 to address security issues in .NET Framework on Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1978.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="(xp sp3 OR xp x64 sp2) AND 2.0 SP2">
               <criteria operator="OR" comment="xp sp3 OR xp x64 sp2">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2, or later, is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
               <criteria operator="OR">
                  <criterion comment="System.dll version is less than 2.0.50727.3624" test_ref="oval:gov.nist.fdcc.patch:tst:1178100"/>
                  <criteria operator="AND">
                     <criterion comment="System.dll version is greater than or equal 2.0.50727.5600" test_ref="oval:gov.nist.fdcc.patch:tst:1175712"/>
                     <criterion comment="System.dll version is less than 2.0.50727.5668" test_ref="oval:gov.nist.fdcc.patch:tst:1178102"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="(vista sp2 (32/64) OR 2008 SP2 (32/64)) AND .net 2.0 sp2">
               <criteria operator="OR" comment="vista sp2 (32/64) OR 2008 SP2 (32/64)">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2, or later, is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
               <criteria operator="OR">
                  <criterion comment="System.dll version is less than 2.0.50727.4215" test_ref="oval:gov.nist.fdcc.patch:tst:1178103"/>
                  <criteria operator="AND">
                     <criterion comment="System.dll version is greater than or equal to 2.0.50727.5600" test_ref="oval:gov.nist.fdcc.patch:tst:1175712"/>
                     <criterion comment="System.dll version is less than 2.0.50727.5668" test_ref="oval:gov.nist.fdcc.patch:tst:1178102"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64 AND .net 3.5.1">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:gov.nist.oval:def:115301"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:gov.nist.oval:def:115302"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:gov.nist.oval:def:115303"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:gov.nist.oval:def:115302"/>
               </criteria>
               <criteria operator="OR">
                  <criterion comment="System.dll version is less than 2.0.50727.4962" test_ref="oval:gov.nist.fdcc.patch:tst:1178106"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="System.dll version is greater than or equal to 2.0.50727.5600" test_ref="oval:gov.nist.fdcc.patch:tst:1175712"/>
                     <criterion comment="System.dll version is less than 2.0.50727.5668" test_ref="oval:gov.nist.fdcc.patch:tst:1178102"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="Windows 7 SP1 x86/x64, Windows Server 2008 R2 SP1 x64/ia64 AND .net 3.5.1">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <criteria operator="OR">
                  <criterion comment="System.dll version is less than 2.0.50727.5447" test_ref="oval:gov.nist.fdcc.patch:tst:1178109"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="System.dll version is greater than or equal to 2.0.50727.5600" test_ref="oval:gov.nist.fdcc.patch:tst:1175712"/>
                     <criterion comment="System.dll version is less than 2.0.50727.5668" test_ref="oval:gov.nist.fdcc.patch:tst:1178102"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="(XP SP2 OR Vista SP1/SP2 OR Server 2008 RTM/SP2 OR 7 OR 2008 R2)(32-bit/64-bit/ia-64) AND .Net 4.0">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
               </criteria>
               <extend_definition comment="Microsoft .NET Framework 4.0 is Installed" definition_ref="oval:gov.nist.fdcc.patch:def:115295"/>
               <criteria operator="OR">
                  <criteria operator="AND" comment="GDR">
                     <criterion comment="System.dll version is less than 4.0.30319.236" test_ref="oval:gov.nist.fdcc.patch:tst:1178112"/>
                  </criteria>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="System.dll version is greater than or equal to 4.0.30319.300" test_ref="oval:gov.nist.fdcc.patch:tst:1175715"/>
                     <criterion comment="System.dll version is less than 4.0.30319.463" test_ref="oval:gov.nist.fdcc.patch:tst:1178114"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <definition id="oval:gov.nist.fdcc.patch:def:11783" version="1" class="patch">
         <metadata>
            <title>MS11-071: Vulnerability in Windows Components Could Allow Remote Code Execution (2570947)</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008 R2</platform>
            </affected>
            <reference source="Microsoft" ref_id="MS11-071" ref_url="http://www.microsoft.com/technet/security/bulletin/MS11-071.mspx"/>
            <reference source="Microsoft" ref_id="KB2570947" ref_url="http://support.microsoft.com/kb/2570947"/>
            <reference source="CVE" ref_id="CVE-2011-1991" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1991"/>
            <description>Microsoft has released MS11-071 to address security issues in Windows XP, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 as documented by CVE-2011-1991.</description>
         </metadata>
         <criteria operator="OR">
            <criteria operator="AND" comment="XP (32-bit) SP3 or (64-bit) SP2">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
                  <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
               </criteria>
               <criterion comment="AllowProtectedRenames exists and equals 1" test_ref="oval:gov.nist.fdcc.patch:tst:117839"/>
            </criteria>
            <criteria operator="AND" comment="Vista, Server 2008 SP2 (32-bit, 64-bit, ia64)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
                  <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
                  <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
                  <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
                  <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Imjpapi.dll version is less than 10.0.6002.18495" test_ref="oval:gov.nist.fdcc.patch:tst:117830"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Imjpapi.dll version is greater than or equal to 10.0.6002.22000" test_ref="oval:gov.nist.fdcc.patch:tst:117831"/>
                     <criterion comment="Imjpapi.dll version is less than 10.0.6002.22684" test_ref="oval:gov.nist.fdcc.patch:tst:117832"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 (32-bit, 64-bit, ia64)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Imjpapi.dll version is less than 10.1.7600.16856" test_ref="oval:gov.nist.fdcc.patch:tst:117833"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Imjpapi.dll version is greater than or equal to 10.1.7600.20000" test_ref="oval:gov.nist.fdcc.patch:tst:117834"/>
                     <criterion comment="Imjpapi.dll version is less than 10.1.7600.21016" test_ref="oval:gov.nist.fdcc.patch:tst:117835"/>
                  </criteria>
               </criteria>
            </criteria>
            <criteria operator="AND" comment="7, Server 2008 R2 SP1 (32-bit, 64-bit, ia64)">
               <criteria operator="OR">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
                  <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 Edition is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
                  <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
               </criteria>
               <criteria operator="OR" comment="GDR or LDR Service branch">
                  <criterion comment="Imjpapi.dll version is less than 10.1.7601.17658" test_ref="oval:gov.nist.fdcc.patch:tst:117836"/>
                  <criteria operator="AND" comment="LDR">
                     <criterion comment="Imjpapi.dll version is greater than or equal to 10.1.7601.21000" test_ref="oval:gov.nist.fdcc.patch:tst:117837"/>
                     <criterion comment="Imjpapi.dll version is less than 10.1.7601.21779" test_ref="oval:gov.nist.fdcc.patch:tst:117838"/>
                  </criteria>
               </criteria>
            </criteria>
         </criteria>
      </definition>
      <!-- ==================================================================================================== -->
      <!-- ======================================= EXTENDED DEFINITIONS ======================================= -->
      <!-- ==================================================================================================== -->
      <definition id="oval:org.mitre.oval:def:105" version="5" class="inventory">
         <metadata>
            <title>Microsoft Windows XP is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp"/>
            <description>The operating system installed on the system is Microsoft Windows XP.</description>
            <oval_repository>
               <dates>
                  <submitted date="2006-06-26T12:55:00.000-04:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </submitted>
                  <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
                  <modified comment="Added CPE reference." date="2007-04-30T07:48:00.244-04:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2007-04-30T08:01:55.267-04:00">INTERIM</status_change>
                  <status_change date="2007-05-23T15:05:25.969-04:00">ACCEPTED</status_change>
                  <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.073-04:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </modified>
                  <status_change date="2008-04-04T11:27:52.098-04:00">INTERIM</status_change>
                  <status_change date="2008-04-21T04:00:10.499-04:00">ACCEPTED</status_change>
                  <modified comment="Changed the test for windows to be case insensitive and replaced the test for Windows 5.1 with a new test for Windows XP" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:15.920-05:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:208" version="3" class="inventory">
         <metadata>
            <title>Microsoft Outlook Express 6 for Windows XP/2003 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:outlook_express:6.0"/>
            <description>Microsoft Outlook Express 6 for Windows XP/2003 is installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-07-03T12:32:22">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2007-07-03T14:04:49.139-04:00">DRAFT</status_change>
                  <status_change date="2007-07-18T15:57:53.037-04:00">INTERIM</status_change>
                  <status_change date="2007-08-02T14:47:15.591-04:00">ACCEPTED</status_change>
                  <modified date="2009-06-15T04:44:54" comment="Added CPE">
                     <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
                  </modified>
                  <status_change date="2009-06-22T04:00:51.618-04:00">INTERIM</status_change>
                  <status_change date="2009-07-13T04:00:31.131-04:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:ste:1485 - Correction to pattern match in ste:1485." date="2010-12-27T19:49:00.448-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-12-27T19:58:09.275-05:00">INTERIM</status_change>
               </dates>
               <status>INTERIM</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" test_ref="oval:org.mitre.oval:tst:1633"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:227" version="2" class="inventory">
         <metadata>
            <title>Microsoft IIS 6.0 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:iis:6.0"/>
            <description>The application Microsoft IIS 6.0 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2006-07-25T12:05:33">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2006-09-27T12:29:16.652-04:00">INTERIM</status_change>
                  <status_change date="2006-10-16T15:58:35.614-04:00">ACCEPTED</status_change>
                  <modified comment="Added CPE reference." date="2007-04-30T07:48:00.336-04:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2007-04-30T08:13:22.361-04:00">INTERIM</status_change>
                  <status_change date="2007-05-23T15:05:39.977-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="IIS Major Version equals 6" test_ref="oval:org.mitre.oval:tst:170"/>
            <criterion comment="IIS Minor Version equals 0" test_ref="oval:org.mitre.oval:tst:164"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:228" version="5" class="inventory">
         <metadata>
            <title>Microsoft Windows Vista is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Vista</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista"/>
            <description>The operating system installed on the system is Microsoft Windows Vista</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-02-13T12:46:06">
                     <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <status_change date="2007-02-13T14:53:06-04:00">DRAFT</status_change>
                  <status_change date="2007-03-21T16:17:12.775-04:00">INTERIM</status_change>
                  <status_change date="2007-04-13T15:13:39.760-04:00">ACCEPTED</status_change>
                  <modified comment="Added CPE reference." date="2007-04-30T07:48:00.893-04:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2007-04-30T07:56:25.929-04:00">INTERIM</status_change>
                  <status_change date="2007-05-23T15:05:40.286-04:00">ACCEPTED</status_change>
                  <modified comment="Vista test updated because of the conflictions with Server 2008" date="2008-03-26T10:51:02.210-04:00">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </modified>
                  <status_change date="2008-03-31T04:00:22.690-04:00">INTERIM</status_change>
                  <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.315-04:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </modified>
                  <status_change date="2008-04-21T04:00:18.129-04:00">ACCEPTED</status_change>
                  <modified comment="Changed the tests for Vista and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-28T04:00:11.598-05:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:460" version="2" class="inventory">
         <metadata>
            <title>Microsoft IIS 5.1 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:iis:5.1"/>
            <description>The application Microsoft IIS 5.1 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2006-07-25T12:05:33">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2006-09-27T12:29:27.089-04:00">INTERIM</status_change>
                  <status_change date="2006-10-16T15:58:41.067-04:00">ACCEPTED</status_change>
                  <modified comment="Added CPE reference." date="2007-04-30T07:48:00.815-04:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2007-04-30T08:14:32.837-04:00">INTERIM</status_change>
                  <status_change date="2007-05-23T15:05:46.398-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="IIS major version equals 5" test_ref="oval:org.mitre.oval:tst:3081"/>
            <criterion comment="IIS 5.1 Minor Version" test_ref="oval:org.mitre.oval:tst:1357"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:563" version="4" class="inventory">
         <metadata>
            <title>Microsoft Internet Explorer 6 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <product>Microsoft Internet Explorer 6</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:ie:6"/>
            <description>The application Microsoft Internet Explorer 6 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2006-08-11T12:53:40">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
                  <status_change date="2006-09-27T12:29:31.086-04:00">INTERIM</status_change>
                  <status_change date="2006-10-16T15:58:44.500-04:00">ACCEPTED</status_change>
                  <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
                     <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
                  </modified>
                  <status_change date="2007-01-11T20:49:17.329-05:00">INTERIM</status_change>
                  <status_change date="2007-02-20T13:40:46.580-05:00">ACCEPTED</status_change>
                  <modified comment="Added CPE reference." date="2007-04-30T07:48:00.756-04:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2007-04-30T07:54:07.779-04:00">INTERIM</status_change>
                  <status_change date="2007-05-23T15:05:48.577-04:00">ACCEPTED</status_change>
                  <modified comment="Added Microsoft Internet Explorer 6 to products. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
                     <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
                  </modified>
                  <status_change date="2009-06-08T04:00:43.851-04:00">INTERIM</status_change>
                  <status_change date="2009-06-29T04:00:29.720-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="Internet Explorer 6 (any patch level) is installed" test_ref="oval:org.mitre.oval:tst:2333"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:627" version="2" class="inventory">
         <metadata>
            <title>Microsoft Internet Explorer 7 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>Microsoft Internet Explorer 7</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:ie:7"/>
            <description>A version of Microsoft Internet Explorer 7 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-01-09T06:00:00">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2007-01-11T15:30:00-04:00">DRAFT</status_change>
                  <status_change date="2007-02-20T13:40:49.320-05:00">INTERIM</status_change>
                  <modified comment="Added Microsoft Windows Vista to the list of affected platforms." date="2007-03-05T09:10:00.104-05:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </modified>
                  <status_change date="2007-03-21T16:17:23.092-04:00">ACCEPTED</status_change>
                  <modified comment="Added Microsoft Internet Explorer 7 product. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
                     <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
                  </modified>
                  <status_change date="2009-06-08T04:01:04.886-04:00">INTERIM</status_change>
                  <status_change date="2009-06-29T04:01:07.843-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="Internet Explorer 7 is installed" test_ref="oval:org.mitre.oval:tst:178"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:754" version="6" class="inventory">
         <metadata>
            <title>Microsoft Windows XP (x86) SP2 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::sp2:x86"/>
            <description>A version of Microsoft Windows XP (x86) Service Pack 2 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-03-05T09:00:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </submitted>
                  <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
                  <status_change date="2007-03-21T16:17:26.869-04:00">INTERIM</status_change>
                  <status_change date="2007-04-10T13:44:28.583-04:00">ACCEPTED</status_change>
                  <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.434-04:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </modified>
                  <status_change date="2008-04-04T11:29:22.458-04:00">INTERIM</status_change>
                  <status_change date="2008-04-21T04:00:24.359-04:00">ACCEPTED</status_change>
                  <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </modified>
                  <status_change date="2009-05-07T10:34:02.214-04:00">INTERIM</status_change>
                  <status_change date="2009-06-22T04:00:33.535-04:00">ACCEPTED</status_change>
                  <modified comment="Changed the tests for x86, SP2, and windows to be case insensitive and replaced the test for Windows 5.1 with a new test for Windows XP" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-28T04:00:42.528-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
                     <contributor organization="Telos">Sudhir Gandhe</contributor>
                  </modified>
                  <status_change date="2011-04-25T14:44:45.277-04:00">INTERIM</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
                     <contributor organization="G2, Inc.">Shane Shaffer</contributor>
                  </modified>
               </dates>
               <status>INTERIM</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
            <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
            <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:1834" version="2" class="inventory">
         <metadata>
            <title>Microsoft .NET Framework 1.1 Service Pack 1 is Installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>.NET Framework</product>
            </affected>
            <description>Microsoft .NET Framework 1.1 Service Pack 1 is Installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-07-11T18:34:24">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2007-07-16T09:52:04.902-04:00">DRAFT</status_change>
                  <status_change date="2007-08-01T22:26:14.747-04:00">INTERIM</status_change>
                  <status_change date="2007-08-20T08:04:39.021-04:00">ACCEPTED</status_change>
                  <status_change date="2007-09-13T11:07:56.030-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="Mscorlib.dll version is greater than or equal to 1.1.4322.2032" test_ref="oval:org.mitre.oval:tst:4041"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:1934" version="2" class="inventory">
         <metadata>
            <title>Microsoft .NET Framework 2.0 (Original RTM or later) is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>.NET Framework</product>
            </affected>
            <description>Microsoft .NET Framework 2.0 (Original RTM or later) is installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-07-11T18:34:24">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2007-07-16T09:52:05.115-04:00">DRAFT</status_change>
                  <status_change date="2007-08-01T22:26:15.137-04:00">INTERIM</status_change>
                  <status_change date="2007-08-20T08:04:39.577-04:00">ACCEPTED</status_change>
                  <status_change date="2007-09-13T11:07:56.103-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="Mscorlib.dll version is greater than or equal to 2.0.50727.42" test_ref="oval:org.mitre.oval:tst:3761"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:2047" version="1" class="inventory">
         <metadata>
            <title>MSN Messenger 7.0 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>MSN Messenger</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger_service:7.0"/>
            <description>MSN Messenger 7.0 is installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-09-25T05:47:58">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2007-09-27T08:47:03.858-04:00">DRAFT</status_change>
                  <status_change date="2007-10-12T07:56:13.457-04:00">INTERIM</status_change>
                  <status_change date="2007-10-28T20:27:11.135-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="MSN Messenger 7.0 is installed" test_ref="oval:org.mitre.oval:tst:4098"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:2058" version="3" class="inventory">
         <metadata>
            <title>Microsoft Windows Mail is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows 7</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <product>Windows Mail</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:windows_mail"/>
            <description>Microsoft Windows Mail is installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-06-13T12:32:06.000-04:00">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
                  <modified comment="Corrected regex in ste:3814 to account for both commas and dots, also anchored the boundaries." date="2007-06-15T13:10:00.106-04:00">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </modified>
                  <status_change date="2007-07-03T14:05:59.294-04:00">INTERIM</status_change>
                  <status_change date="2007-07-18T15:57:52.876-04:00">ACCEPTED</status_change>
                  <modified comment="Corrected comment for oval:org.mitre.oval:tst:3506 and updated ste:3814 to match with newer versions of Windows Mail 6.0." date="2010-05-12T11:21:00.138-04:00">
                     <contributor organization="Symantec, Inc.">Dragos Prisaca</contributor>
                  </modified>
                  <status_change date="2010-05-12T11:23:48.997-04:00">INTERIM</status_change>
                  <modified comment="Added new test to check for Windows Mail 6.1" date="2010-05-12T11:57:00.591-04:00">
                     <contributor organization="Symantec, Inc.">Dragos Prisaca</contributor>
                  </modified>
                  <status_change date="2010-05-31T04:00:05.436-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria operator="OR">
            <criterion comment="Windows Mail version 6.0" test_ref="oval:org.mitre.oval:tst:3506"/>
            <criterion comment="Windows Mail version 6.1" test_ref="oval:org.mitre.oval:tst:11318"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:2087" version="1" class="inventory">
         <metadata>
            <title>MSN Messenger 7.5 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>MSN Messenger</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger_service:7.5"/>
            <description>MSN Messenger 7.5 is installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-09-25T05:47:58">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2007-09-27T08:47:04.432-04:00">DRAFT</status_change>
                  <status_change date="2007-10-12T07:56:14.129-04:00">INTERIM</status_change>
                  <status_change date="2007-10-28T20:27:11.697-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="MSN Messenger 7.5 is installed" test_ref="oval:org.mitre.oval:tst:4242"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:2126" version="1" class="inventory">
         <metadata>
            <title>Windows Media Player v11.0 is installed.</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>Media Player</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:media_player:11"/>
            <description>Windows Media Player v11.0 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-08-15T09:28:35">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2007-08-15T15:55:11.057-04:00">DRAFT</status_change>
                  <status_change date="2007-09-06T09:13:31.049-04:00">INTERIM</status_change>
                  <status_change date="2007-09-27T08:57:44.929-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="PlayerVersion is greater than 11.0.0.0" test_ref="oval:org.mitre.oval:tst:3203"/>
            <criterion comment="PlayerVersion is less than 12.0.0.0" test_ref="oval:org.mitre.oval:tst:4192"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:2136" version="2" class="inventory">
         <metadata>
            <title>Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>.NET Framework</product>
            </affected>
            <description>Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-07-11T18:34:24">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2007-07-16T09:52:04.577-04:00">DRAFT</status_change>
                  <status_change date="2007-08-01T22:26:16.025-04:00">INTERIM</status_change>
                  <status_change date="2007-08-20T08:04:40.665-04:00">ACCEPTED</status_change>
                  <status_change date="2007-09-13T11:07:56.167-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="Mscorlib.dll version is greater than or equal to 1.0.3705.6018" test_ref="oval:org.mitre.oval:tst:3168"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:2147" version="1" class="inventory">
         <metadata>
            <title>Windows Media Player v9.0 is installed.</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <product>Media Player</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:media_player:9"/>
            <description>Windows Media Player v9.0 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-08-15T09:28:35">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2007-08-15T15:55:11.096-04:00">DRAFT</status_change>
                  <status_change date="2007-09-06T09:13:31.363-04:00">INTERIM</status_change>
                  <status_change date="2007-09-27T08:57:45.263-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="Windows Media Player 9 is installed" test_ref="oval:org.mitre.oval:tst:786"/>
            <criterion negate="true" comment="Windows Media Player 10 is installed" test_ref="oval:org.mitre.oval:tst:833"/>
            <extend_definition negate="true" comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:2172" version="1" class="inventory">
         <metadata>
            <title>Windows Media Player v10.0 is installed.</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <product>Media Player</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:media_player:10"/>
            <description>Windows Media Player v10.0 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-08-15T09:28:35">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2007-08-15T15:55:11.378-04:00">DRAFT</status_change>
                  <status_change date="2007-09-06T09:13:31.729-04:00">INTERIM</status_change>
                  <status_change date="2007-09-27T08:57:45.569-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="Windows Media Player 10 is installed" test_ref="oval:org.mitre.oval:tst:833"/>
            <extend_definition negate="true" comment="Windows Media Player v11.0 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:2187" version="1" class="inventory">
         <metadata>
            <title>MSN Messenger 6.2 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>MSN Messenger</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger_service:6.2"/>
            <description>MSN Messenger 6.2 is installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-09-25T05:47:58">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2007-09-27T08:47:03.757-04:00">DRAFT</status_change>
                  <status_change date="2007-10-12T07:56:14.421-04:00">INTERIM</status_change>
                  <status_change date="2007-10-28T20:27:11.996-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="MSN Messenger 6.2 is installed" test_ref="oval:org.mitre.oval:tst:4055"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:2209" version="1" class="inventory">
         <metadata>
            <title>MSN Messenger 8.0 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>MSN Messenger</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger_service:8.0"/>
            <description>MSN Messenger 8.0 is installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-09-25T05:47:58">
                     <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
                  </submitted>
                  <status_change date="2007-09-27T08:47:04.491-04:00">DRAFT</status_change>
                  <status_change date="2007-10-12T07:56:14.490-04:00">INTERIM</status_change>
                  <status_change date="2007-10-28T20:27:12.150-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="MSN Messenger 8.0 is installed" test_ref="oval:org.mitre.oval:tst:4188"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:4193" version="6" class="inventory">
         <metadata>
            <title>Microsoft Windows XP x64 Edition SP2 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::sp2:x64"/>
            <description>A version of Microsoft Windows XP Professional x64 Edition Service Pack 2 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2007-11-15T15:56:12">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2007-11-16T08:53:11.596-05:00">DRAFT</status_change>
                  <status_change date="2007-12-03T04:06:19.275-05:00">INTERIM</status_change>
                  <status_change date="2007-12-24T04:06:02.885-05:00">ACCEPTED</status_change>
                  <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.080-04:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </modified>
                  <status_change date="2008-04-04T11:21:54.103-04:00">INTERIM</status_change>
                  <status_change date="2008-04-21T04:00:19.231-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-11-19T18:35:09.716-05:00">INTERIM</status_change>
                  <modified comment="Replaced the test for 'SP2 or later' with a test for strictly 'SP2' and the test for Windows 5.1 with a new test for Windows XP and changed the tests for SP2 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:31.215-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
                     <contributor organization="Telos">Sudhir Gandhe</contributor>
                  </modified>
                  <status_change date="2011-04-25T14:45:59.384-04:00">INTERIM</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
                     <contributor organization="G2, Inc.">Shane Shaffer</contributor>
                  </modified>
               </dates>
               <status>INTERIM</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
            <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
            <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:4870" version="6" class="inventory">
         <metadata>
            <title>Microsoft Windows Server 2008 (32-bit) is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:::x86"/>
            <description>The operating system installed on the system is Microsoft Windows Server 2008 (32-bit)</description>
            <oval_repository>
               <dates>
                  <submitted date="2008-03-26T10:44:02">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2008-03-26T16:27:25.280-04:00">DRAFT</status_change>
                  <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.555-04:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </modified>
                  <status_change date="2008-04-21T04:00:20.181-04:00">INTERIM</status_change>
                  <status_change date="2008-05-12T04:00:10.618-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-09-07T04:00:25.188-04:00">INTERIM</status_change>
                  <status_change date="2009-09-28T04:00:03.365-04:00">ACCEPTED</status_change>
                  <modified comment="Replaced negation of test for x64 with a case insensitive test for x86, added a negated test for 2008 R2, and changed the test for windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:33.629-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:def:4870 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2010-12-21T11:00:20.655-05:00">INTERIM</status_change>
                  <status_change date="2011-02-07T04:00:11.791-05:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
            <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
            <criterion negate="true" comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:4873" version="5" class="inventory">
         <metadata>
            <title>Microsoft Windows Vista (32-bit) Service Pack 1 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Vista</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista::sp1:x86"/>
            <description>The operating system installed on the system is Microsoft Windows Vista (32-bit) Service Pack 1</description>
            <oval_repository>
               <dates>
                  <submitted date="2008-03-26T10:44:02">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2008-03-26T16:27:29.495-04:00">DRAFT</status_change>
                  <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.108-04:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </modified>
                  <status_change date="2008-04-21T04:00:20.428-04:00">INTERIM</status_change>
                  <status_change date="2008-05-12T04:00:14.497-04:00">ACCEPTED</status_change>
                  <modified comment="Replaced negation of test for x64 with a case insensitive test for x86 and changed the tests for SP1, Vista, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:34.223-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
                     <contributor organization="Telos">Sudhir Gandhe</contributor>
                  </modified>
                  <status_change date="2011-04-25T14:45:45.918-04:00">INTERIM</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
                     <contributor organization="G2, Inc.">Shane Shaffer</contributor>
                  </modified>
               </dates>
               <status>INTERIM</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
            <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
            <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:5254" version="6" class="inventory">
         <metadata>
            <title>Microsoft Windows Vista x64 Edition Service Pack 1 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Vista</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista::sp1:x64"/>
            <description>The operating system installed on the system is Microsoft Windows Vista x64 Edition Service Pack 1</description>
            <oval_repository>
               <dates>
                  <submitted date="2008-03-26T10:44:02">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2008-03-26T16:27:29.700-04:00">DRAFT</status_change>
                  <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.236-04:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </modified>
                  <status_change date="2008-04-21T04:00:21.267-04:00">INTERIM</status_change>
                  <status_change date="2008-05-12T04:00:14.836-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-09-07T04:00:25.662-04:00">INTERIM</status_change>
                  <status_change date="2009-09-28T04:00:03.631-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-11-19T18:35:10.408-05:00">INTERIM</status_change>
                  <modified comment="Changed the tests for SP1, Vista, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:34.743-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
                     <contributor organization="Telos">Sudhir Gandhe</contributor>
                  </modified>
                  <status_change date="2011-04-25T14:44:07.861-04:00">INTERIM</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
                     <contributor organization="G2, Inc.">Shane Shaffer</contributor>
                  </modified>
               </dates>
               <status>INTERIM</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
            <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
            <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:5356" version="6" class="inventory">
         <metadata>
            <title>Microsoft Windows Server 2008 (64-bit) is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:::x64"/>
            <description>The operating system installed on the system is Microsoft Windows Server 2008 (64-bit)</description>
            <oval_repository>
               <dates>
                  <submitted date="2008-03-26T10:44:02">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2008-03-26T16:27:25.493-04:00">DRAFT</status_change>
                  <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.340-04:00">
                     <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
                  </modified>
                  <status_change date="2008-04-21T04:00:21.761-04:00">INTERIM</status_change>
                  <status_change date="2008-05-12T04:00:15.160-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-11-19T18:35:09.355-05:00">INTERIM</status_change>
                  <modified comment="Added a negated test for 2008 R2 and changed the test for windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:35.383-05:00">ACCEPTED</status_change>
                  <modified comment="Removed the SP1 component in the CPE reference" date="2010-01-08T15:44:00.632-05:00">
                     <contributor organization="DTCC">J. Daniel Brown</contributor>
                  </modified>
                  <status_change date="2010-01-08T15:44:32.646-05:00">INTERIM</status_change>
                  <status_change date="2010-01-25T04:00:02.861-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:def:5356 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2010-12-21T11:00:20.063-05:00">INTERIM</status_change>
                  <status_change date="2011-02-07T04:00:12.352-05:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
            <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
            <criterion negate="true" comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:5377" version="1" class="inventory">
         <metadata>
            <title>Microsoft IIS 7.0 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Vista</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:iis:7.0"/>
            <description>The application Microsoft IIS 7.0 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2008-02-14T10:00:19">
                     <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
                  </submitted>
                  <status_change date="2008-02-14T14:55:51.694-05:00">DRAFT</status_change>
                  <status_change date="2008-03-03T04:00:13.826-05:00">INTERIM</status_change>
                  <status_change date="2008-03-24T04:00:43.767-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="IIS Major Version equals 7" test_ref="oval:org.mitre.oval:tst:7848"/>
            <criterion comment="IIS Minor Version equals 0" test_ref="oval:org.mitre.oval:tst:164"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:5594" version="6" class="inventory">
         <metadata>
            <title>Microsoft Windows Vista x64 Edition Service Pack 2 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Vista</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista::sp2:x64"/>
            <description>The operating system installed on the system is Microsoft Windows Vista x64 Edition Service Pack 2</description>
            <oval_repository>
               <dates>
                  <submitted date="2009-05-04T16:00:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </modified>
                  <status_change date="2009-05-07T11:17:43.459-04:00">DRAFT</status_change>
                  <status_change date="2009-05-25T04:01:41.151-04:00">INTERIM</status_change>
                  <status_change date="2009-06-22T04:00:22.934-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-09-07T04:00:26.214-04:00">INTERIM</status_change>
                  <status_change date="2009-09-28T04:00:05.829-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-11-19T18:35:08.959-05:00">INTERIM</status_change>
                  <modified comment=" Changed the tests for SP2, Vista, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:35.796-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
                     <contributor organization="Telos">Sudhir Gandhe</contributor>
                  </modified>
                  <status_change date="2011-04-25T14:44:50.876-04:00">INTERIM</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
                     <contributor organization="G2, Inc.">Shane Shaffer</contributor>
                  </modified>
               </dates>
               <status>INTERIM</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
            <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
            <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:5631" version="5" class="inventory">
         <metadata>
            <title>Microsoft Windows XP (x86) SP3 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::sp3:x86"/>
            <description>A version of Microsoft Windows XP (x86) Service Pack 3 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2008-06-10T14:50:00">
                     <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
                  </submitted>
                  <status_change date="2008-06-12T13:58:47.155-04:00">DRAFT</status_change>
                  <status_change date="2008-06-30T04:00:18.370-04:00">INTERIM</status_change>
                  <status_change date="2008-07-21T04:00:18.901-04:00">ACCEPTED</status_change>
                  <modified comment="Changed the tests for x86, SP3, and windows to be case insensitive and replaced the test for Windows 5.1 with a new test for Windows XP" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:36.319-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
                     <contributor organization="Telos">Sudhir Gandhe</contributor>
                  </modified>
                  <status_change date="2011-04-25T14:44:36.981-04:00">INTERIM</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
                     <contributor organization="G2, Inc.">Shane Shaffer</contributor>
                  </modified>
               </dates>
               <status>INTERIM</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
            <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
            <criterion comment="Win2K/XP/2003 service pack 3 is installed" test_ref="oval:org.mitre.oval:tst:7814"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:5653" version="8" class="inventory">
         <metadata>
            <title>Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
            <description>The operating system installed on the system is Microsoft Windows Server 2008 (32-bit) Service Pack 2</description>
            <oval_repository>
               <dates>
                  <submitted date="2009-05-04T16:00:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <status_change date="2009-05-07T11:17:37.121-04:00">DRAFT</status_change>
                  <status_change date="2009-05-25T04:01:42.700-04:00">INTERIM</status_change>
                  <status_change date="2009-06-22T04:00:24.249-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-09-07T04:00:26.467-04:00">INTERIM</status_change>
                  <status_change date="2009-09-28T04:00:07.133-04:00">ACCEPTED</status_change>
                  <modified comment="Replaced negation of test for x64 with a case insensitive test for x86, added a negated test for 2008 R2 and changed the tests for SP2 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:38.208-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:def:5653 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2010-12-21T11:00:21.376-05:00">INTERIM</status_change>
                  <status_change date="2011-02-07T04:00:12.818-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
                     <contributor organization="Telos">Sudhir Gandhe</contributor>
                  </modified>
                  <status_change date="2011-04-25T14:45:40.947-04:00">INTERIM</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
                     <contributor organization="G2, Inc.">Shane Shaffer</contributor>
                  </modified>
               </dates>
               <status>INTERIM</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
            <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
            <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criterion negate="true" comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:5667" version="6" class="inventory">
         <metadata>
            <title>Microsoft Windows Server 2008 (ia-64) is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:::itanium"/>
            <description>The operating system installed on the system is Microsoft Windows Server 2008 Itanium Edition</description>
            <oval_repository>
               <dates>
                  <submitted date="2008-07-08T14:18:00">
                     <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
                  </submitted>
                  <status_change date="2008-07-11T10:55:58.360-04:00">DRAFT</status_change>
                  <status_change date="2008-07-28T04:00:20.824-04:00">INTERIM</status_change>
                  <status_change date="2008-08-18T04:00:47.533-04:00">ACCEPTED</status_change>
                  <modified comment="Added a negated test for 2008 R2 and changed the tests for ia-64 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:38.631-05:00">ACCEPTED</status_change>
                  <modified comment="Removed the SP1 component in the CPE reference" date="2010-01-08T15:43:00.851-05:00">
                     <contributor organization="DTCC">J. Daniel Brown</contributor>
                  </modified>
                  <status_change date="2010-01-08T15:44:06.864-05:00">INTERIM</status_change>
                  <status_change date="2010-01-25T04:00:06.763-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:def:5667 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2010-12-21T11:00:21.141-05:00">INTERIM</status_change>
                  <status_change date="2011-02-07T04:00:13.308-05:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
            <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion negate="true" comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:5691" version="2" class="inventory">
         <metadata>
            <title>Windows Messenger 5.1 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:windows_messenger:5.1"/>
            <description>The application Windows Messenger 5.1 is installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2008-08-13T09:28:00">
                     <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <status_change date="2008-08-14T15:02:34.047-04:00">DRAFT</status_change>
                  <status_change date="2008-09-01T04:01:03.898-04:00">INTERIM</status_change>
                  <status_change date="2008-09-22T04:00:28.414-04:00">ACCEPTED</status_change>
                  <modified comment="Updated registry state" date="2009-05-25T10:32:00.713-04:00">
                     <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
                  </modified>
                  <status_change date="2009-05-25T10:32:00.713-04:00">INTERIM</status_change>
                  <status_change date="2009-06-15T04:00:46.373-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="Windows Messenger 5.1 or later is installed" test_ref="oval:org.mitre.oval:tst:9121"/>
            <criterion comment="Windows Messenger is less than 5.2 is installed" test_ref="oval:org.mitre.oval:tst:9618"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:5950" version="3" class="inventory">
         <metadata>
            <title>Microsoft Windows 7 x64 Edition is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 7</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_7:::x64"/>
            <description>The operating system installed on the system is Microsoft Windows 7 x64 Edition</description>
            <oval_repository>
               <dates>
                  <submitted date="2009-09-08T11:27:37.975-04:00">
                     <contributor organization="Hewlett-Packard">Pai Peng</contributor>
                  </submitted>
                  <status_change date="2009-09-08T20:49:38.713-04:00">DRAFT</status_change>
                  <status_change date="2009-09-28T04:00:13.304-04:00">INTERIM</status_change>
                  <status_change date="2009-10-26T04:00:04.351-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-11-19T18:35:09.654-05:00">INTERIM</status_change>
                  <modified comment="Changed the tests for Windows 7 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.171-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.647-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:41.003-05:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows 7 is installed" test_ref="oval:org.mitre.oval:tst:10792"/>
            <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:5954" version="4" class="inventory">
         <metadata>
            <title>Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
            <description>The operating system installed on the system is Microsoft Windows Server 2008 R2 Itanium Edition</description>
            <oval_repository>
               <dates>
                  <submitted date="2009-10-13T13:00:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <status_change date="2009-10-22T17:36:49.462-04:00">DRAFT</status_change>
                  <status_change date="2009-11-09T04:00:29.206-05:00">INTERIM</status_change>
                  <status_change date="2009-11-30T04:00:15.509-05:00">ACCEPTED</status_change>
                  <modified comment="Changed the tests for 2008 R2, ia64, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:41.428-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:def:5954 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2010-12-21T11:00:20.491-05:00">INTERIM</status_change>
                  <status_change date="2011-02-07T04:00:13.727-05:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
            <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:6101" version="2" class="inventory">
         <metadata>
            <title>Windows Messenger 4.7 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:windows_messenger:4.7"/>
            <description>The application Windows Messenger 4.7 is installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2008-08-13T09:28:00">
                     <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <status_change date="2008-08-14T15:02:33.603-04:00">DRAFT</status_change>
                  <status_change date="2008-09-01T04:01:25.460-04:00">INTERIM</status_change>
                  <status_change date="2008-09-22T04:00:41.476-04:00">ACCEPTED</status_change>
                  <modified comment="Corrected CPE reference" date="2009-09-25T09:28:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </modified>
                  <status_change date="2009-09-28T04:00:32.074-04:00">INTERIM</status_change>
                  <status_change date="2009-10-19T04:00:09.298-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="Windows Messenger 4.7 is installed" test_ref="oval:org.mitre.oval:tst:8484"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:6124" version="6" class="inventory">
         <metadata>
            <title>Microsoft Windows Vista (32-bit) Service Pack 2 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Vista</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista::sp2:x86"/>
            <description>The operating system installed on the system is Microsoft Windows Vista (32-bit) Service Pack 2</description>
            <oval_repository>
               <dates>
                  <submitted date="2009-05-04T16:00:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </modified>
                  <status_change date="2009-05-07T11:17:28.873-04:00">DRAFT</status_change>
                  <status_change date="2009-05-25T04:02:00.040-04:00">INTERIM</status_change>
                  <status_change date="2009-06-22T04:00:28.642-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-09-07T04:00:27.692-04:00">INTERIM</status_change>
                  <status_change date="2009-09-28T04:00:15.275-04:00">ACCEPTED</status_change>
                  <modified comment="Replaced negation of test for x64 with a case insensitive test for x86 and changed the tests for SP2, Vista, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:42.790-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
                     <contributor organization="Telos">Sudhir Gandhe</contributor>
                  </modified>
                  <status_change date="2011-04-25T14:44:31.595-04:00">INTERIM</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
                     <contributor organization="G2, Inc.">Shane Shaffer</contributor>
                  </modified>
               </dates>
               <status>INTERIM</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
            <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
            <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:6150" version="7" class="inventory">
         <metadata>
            <title>Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
            <description>The operating system installed on the system is Microsoft Windows Server 2008 Itanium Edition Service Pack 2</description>
            <oval_repository>
               <dates>
                  <submitted date="2009-05-04T16:00:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </modified>
                  <status_change date="2009-05-07T11:17:27.535-04:00">DRAFT</status_change>
                  <status_change date="2009-05-25T04:02:02.357-04:00">INTERIM</status_change>
                  <status_change date="2009-06-22T04:00:30.433-04:00">ACCEPTED</status_change>
                  <modified comment="Changed the tests for ia64, SP2, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-21T04:00:47.950-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:def:6150 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
                     <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
                  </modified>
                  <status_change date="2010-12-21T11:00:20.359-05:00">INTERIM</status_change>
                  <status_change date="2011-02-07T04:00:14.142-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
                     <contributor organization="Telos">Sudhir Gandhe</contributor>
                  </modified>
                  <status_change date="2011-04-25T14:43:51.991-04:00">INTERIM</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
                     <contributor organization="G2, Inc.">Shane Shaffer</contributor>
                  </modified>
               </dates>
               <status>INTERIM</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
            <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:6158" version="5" class="inventory">
         <metadata>
            <title>Microsoft .NET Framework 2.0 Service Pack 2 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 2000</platform>
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Vista</platform>
               <product>Microsoft .NET Framework</product>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
            <description>Microsoft .NET Framework 2.0 Service Pack 2 is installed</description>
            <oval_repository>
               <dates>
                  <submitted date="2009-10-13T13:00:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <status_change date="2009-10-22T17:36:54.998-04:00">DRAFT</status_change>
                  <status_change date="2009-11-09T04:00:38.208-05:00">INTERIM</status_change>
                  <status_change date="2009-11-30T04:00:23.181-05:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:tst:10028 - Created OVAL vulnerability definition for MS10-070" date="2011-02-28T09:25:00.601-05:00">
                     <contributor organization="Symantec Corporation">Josh Turpin</contributor>
                  </modified>
                  <status_change date="2011-02-28T09:32:44.470-05:00">INTERIM</status_change>
                  <status_change date="2011-03-21T04:00:14.972-04:00">ACCEPTED</status_change>
                  <modified comment="EDITED oval:org.mitre.oval:tst:10028 - New Definitions for April 2011 Patch Tuesday" date="2011-04-18T00:17:00.032-04:00">
                     <contributor organization="Symantec Corporation">Josh Turpin</contributor>
                  </modified>
                  <status_change date="2011-04-18T00:18:31.230-04:00">INTERIM</status_change>
                  <status_change date="2011-05-09T04:01:38.435-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria operator="AND">
            <criterion comment="The version of Mscorlib.dll is greater than or equal to 2.0.50727.3053" test_ref="oval:org.mitre.oval:tst:10028"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:6165" version="3" class="inventory">
         <metadata>
            <title>Microsoft Windows 7 (32-bit) is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows 7</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_7:::x86"/>
            <description>The operating system installed on the system is Microsoft Windows 7 (32-bit)</description>
            <oval_repository>
               <dates>
                  <submitted date="2009-09-08T11:27:37.975-04:00">
                     <contributor organization="Hewlett-Packard">Pai Peng</contributor>
                  </submitted>
                  <status_change date="2009-09-08T20:49:38.394-04:00">DRAFT</status_change>
                  <status_change date="2009-09-28T04:00:16.403-04:00">INTERIM</status_change>
                  <status_change date="2009-10-19T04:00:10.283-04:00">ACCEPTED</status_change>
                  <modified comment="Replaced negation of test for x64 with a case insensitive test for x86 and changed the tests for Windows 7 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
                  <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.171-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.647-05:00">
                     <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
                  </modified>
                  <status_change date="2010-01-04T04:01:43.679-05:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
            <criterion comment="Windows 7 is installed" test_ref="oval:org.mitre.oval:tst:10792"/>
            <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:6210" version="2" class="inventory">
         <metadata>
            <title>Microsoft Internet Explorer 8 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows XP</platform>
               <platform>Microsoft Windows Vista</platform>
               <platform>Microsoft Windows Server 2003</platform>
               <platform>Microsoft Windows Server 2008</platform>
               <platform>Microsoft Windows 7</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/a:microsoft:ie:8"/>
            <description>A version of Microsoft Internet Explorer 8 is installed.</description>
            <oval_repository>
               <dates>
                  <submitted date="2009-03-23T10:00:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <status_change date="2009-03-23T10:43:47.804-04:00">DRAFT</status_change>
                  <status_change date="2009-04-13T04:00:28.239-04:00">INTERIM</status_change>
                  <status_change date="2009-05-04T04:00:36.679-04:00">ACCEPTED</status_change>
                  <modified comment="Added additional affected platfroms" date="2009-09-24T11:17:00.434-04:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </modified>
                  <status_change date="2009-09-28T04:00:32.351-04:00">INTERIM</status_change>
                  <status_change date="2009-10-26T04:00:04.951-04:00">ACCEPTED</status_change>
               </dates>
               <status>ACCEPTED</status>
            </oval_repository>
         </metadata>
         <criteria>
            <criterion comment="Internet Explorer 8 is installed" test_ref="oval:org.mitre.oval:tst:9082"/>
         </criteria>
      </definition>
      <definition id="oval:org.mitre.oval:def:6216" version="8" class="inventory">
         <metadata>
            <title>Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed</title>
            <affected family="windows">
               <platform>Microsoft Windows Server 2008</platform>
            </affected>
            <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
            <description>The operating system installed on the system is Microsoft Windows Server 2008 x64 Edition Service Pack 2</description>
            <oval_repository>
               <dates>
                  <submitted date="2009-05-04T16:00:00">
                     <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
                  </submitted>
                  <status_change date="2009-05-07T11:17:37.293-04:00">DRAFT</status_change>
                  <status_change date="2009-05-25T04:02:07.677-04:00">INTERIM</status_change>
                  <status_change date="2009-06-22T04:00:31.225-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
                     <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
                  </modified>
                  <status_change date="2009-09-07T04:00:28.404-04:00">INTERIM</status_change>
                  <status_change date="2009-09-28T04:00:16.986-04:00">ACCEPTED</status_change>
                  <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.59