-
MS-DEFCON 2: Unexpected .NET patch KB3005628 means you should get Windows locked down
I didn’t see this one coming.
Microsoft just released KB 3005628, which uninstalls two earlier patches in Win 8/8.1 and Server 2012. According to the KB article
Update 3005628 removes security update 2966827 or 2966828 from any system that does not have the .NET Framework 3.5 feature content installed on Windows Server 2012 R2, Windows Server 2012, Windows 8.1, or Windows 8. After the release of update 3005628, security updates 2966827 and 2966828 will be offered only to applicable systems that have the .NET Framework 3.5 feature enabled.
If you can make sense out of that alphanumeric gobbledygook, yer a better man than me, Gunga Din.
Anyway, it’s time to move up to MS-DEFCON 2 anyway: Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don’t do it.
Let’s give this First-Tuesday patch a chance to fester a bit.