• Closing a long year of Windows patching

    Home » Forums » Newsletter and Homepage topics » Closing a long year of Windows patching

    • This topic has 43 replies, 21 voices, and was last updated 11 years ago.
    Author
    Topic
    #492387


    PATCH WATCH

    Closing a long year of Windows patching

    By Susan Bradley

    Congratulations! We’ve come to the end of 2013 with 103 security bulletins, numerous nonsecurity updates, several security advisories, and a few zero-days. Facing the end of official support, XP users end the year battling a resurgence of the SVCHost bug.


    The full text of this column is posted at windowssecrets.com/patch-watch/closing-a-long-year-of-windows-patching/ (opens in a new window/tab).

    Columnists typically cannot reply to comments here, but do incorporate the best tips into future columns.[/td]

    [/tr][/tbl]

    Viewing 20 reply threads
    Author
    Replies
    • #1428297

      What about the KB 2862330 kernel update from MS13-081, left over from October?

      It seems to have disappeared from all the charts!

      Also, please, please, please add the YEAR to the “RELEASED” column of the charts; the dates are quickly becoming very confusing when trying to find an entry from a particular month, say KB 2862330 as mentioned above.

      • #1428603

        I wrote about it giving it a pass. check the past Patch Watch and you’ll see my write up.

        • #1428890

          I wrote about it giving it a pass. check the past Patch Watch and you’ll see my write up.

          Sorry Susan, JC said you’d OKed it and that was good enough for me 🙂

      • #1428646

        What about the KB 2862330 kernel update from MS13-081, left over from October?

        It seems to have disappeared from all the charts!

        Also, please, please, please add the YEAR to the “RELEASED” column of the charts; the dates are quickly becoming very confusing when trying to find an entry from a particular month, say KB 2862330 as mentioned above.

        KB2862330 refers to the description of the security bulletin. There are many individual patches for the various OSes to which it applies. See Microsoft Security Bulletin MS13-081 for a list of the various fixes.

        Joe

        --Joe

        • #1428941

          Is kb2847311 still on hold?

          • #1428946

            Is kb2847311 still on hold?

            In the newsletter of 28 November Susan gave the OK to install 2847311

        • #1430879

          KB2862330 refers to the description of the security bulletin. There are many individual patches for the various OSes to which it applies. See Microsoft Security Bulletin MS13-081 for a list of the various fixes.

          Joe

          Joe, I think we’re waiting for Susan to move 2862330 from “wait” to “install”.

          • #1431343

            Joe, I think we’re waiting for Susan to move 2862330 from “wait” to “install”.

            I’m still not comfy with saying okay on that one.

    • #1428318

      I got hit hard with the svchost taking 100% cpu issue which, of course, was caused by wuauserve. I used Process explorer to disable, temporarily, this service and all’s well. Then, I found the cool utility below from betanews to get all my XP updates (over 830MBytes of updates unfortunately since I didn’t see any way to focus my updates to just what I needed; make sure you click on the legacy tab since that’s where 32-bit XP is located). Don’t bother, though, to use the utility’s update.bat file since the cpu issue (had to activate wuauserve of course) kicked back in. I looked at the directory where the updates were stored and fortunately, the program saves the updates by their release date (how cool is that) so I manually installed all the updates (yes, one at a time; don’t think there were more then 6 that I actually installed). I had missed one since, after reboot, I went to the Windows update site and one was left (well two; Malicious removal tool as well; lol) so proceeded to update and now my XP is humming smoothly. Not sure what patch fixed the SVCHost issue, but one of these did (at least for me). I run XP in a virtual machine (VirtualBox) by the way for sandbox purposes to protect my Win7. My VirtualPC XPMode updates is a lost cause though even using this utility. Haven’t tried to go to a recovery point yet with it but I only have one utility that I use that I never tried again to get VirtualBox XP to work when I couldn’t those many years ago. Sad what Microsoft did to XP; the paranoid in me thinks it was on purpose. lol

      🙂

      http://fileforum.betanews.com/detail/WSUS-Offline-Update/1293039523/1

      • #1428418

        I was also hit by the Windows Update high CPU (50%) bug when I tried to check the latest updates. The update window was just spinning for over 10 minutes. It worked fine on Dec 4 and failed Dec 12.

        I took a clue from Susan Bradley and downloaded the December 2013 Internet Explorer fix [MS13-097 KB2898785] directly from Microsoft and installed it manually, rebooted, and after that, Windows Update worked normally.

        I hope this is helpful for other loungers.

        • #1428448

          I was also hit by the Windows Update high CPU (50%) bug when I tried to check the latest updates. The update window was just spinning for over 10 minutes. It worked fine on Dec 4 and failed Dec 12.

          I took a clue from Susan Bradley and downloaded the December 2013 Internet Explorer fix [MS13-097 KB2898785] directly from Microsoft and installed it manually, rebooted, and after that, Windows Update worked normally.

          I hope this is helpful for other loungers.

          Yup – works for me too, though in my case I got it as part of Update Tuesday (it took about an hour lol)

          Happy days! 🙂

    • #1428573

      Yeah; at the time, I couldn’t find the solution, so the shotgun approach for me. lolol

      Still, now I have every update since SP3 and may put these on a thumbdrive for future XP rebuilds should I need them (had an issue with Virtualbox and lost my XP VM and had to build it from scratch once already). 🙂

    • #1428635

      Microsoft offered me KB2850079 for Office 2010 and KB2837593 for Word 2010. However, the write-up says you must have Office 2010 SP2 install, and I do not (just have not got round to it). I am not sure why WU offered these two patches in that case, but I held off in case it creates problems installing on a SP1 system. The writeups give no indication as to what the patches comprise.

      Just a heads up for other Loungers.

      Chris B

      Chris
      Win 10 Pro x64 Group A

      • #1430502

        Like Chris B I have not yet installed Office 2010 SP2 since I don’t recall seeing an “all clear” from Susan + my web search shows a mix of user results. And since O-2010 is working fine and I do not have any updates waiting that are dependent on SP2 I have not been motivated. But with year end approaching and trying to get this off my update list, did I miss an ok from Susan to install SP2? Or any suggestions or links re installing SP2 on a Win7 Pro machine? Thanks .. TGH

        • #1430880

          Susan wrote: “Please join me for our special end-of-the year Patch Watch cleanup column in the Windows Secrets Lounge. Look in the Windows Secrets Columns section. If there are other security updates I’ve failed to mention, list them in the Lounge and I’ll give my thumbs-up or thumbs-down.”

          I have searched all the patch watch charts and not found direction on the following security updates (all #s are preceded with KB):

          2861855
          2862966
          2892074
          2917500
          2862330 (hidden at Susan’s suggestion until she gives it the all clear).

          I have a longer list of “important” nonsecurity updates for Office 2010, XP and Windows 7×64 (an administrator or another lounger one time told me to go ahead with these if they’d been around a while — e.g., several months — is this generally good advice?).

          Thanks.

    • #1428814

      RE: Svchost running amok on Windows XP PCs

      Got hit and then got lucky.

      Was able to restore working windows update by uninstalling IE8 and reinstalling a fresh copy of IE8 downloaded from MSFT website.

    • #1429457

      OK; posted at the XP forum as to why XP has issues. Will post the link I found at Slashdot here too. Sad. In Microsoft’s eyes, it’s probably a good think XP updates ends in April (if they can milk WSUS for that long that is; lol). 🙂

      http://tech.slashdot.org/story/13/12/16/1959259/exponential-algorithm-in-windows-update-slowing-xp-machines

    • #1431325

      First off a holiday cookie recipe:
      http://www.marthastewart.com/343445/gingerbread-cookies Okay so it’s Martha’s not mine, but I made cookies that look like thisout of them.
      Now on to patching comments.

      No new patches were out this week of the 24th so we can serve up leftover patches and report on them:

      First up Office 2010 sp2:

      Office 2010 sp2 is finally okay to install. After installing sp2 you will find that you receive errors in application event log after Office sp2 and recent security updates:
      Event ID 27, “Calendar Folder property is missing,” after you apply Office 2010 SP2:
      http://support.microsoft.com/kb/2883156
      If you are suffering from that error filling your event logs
      Install the hotfix below and it will fix the issue
      Description of the Outlook 2010 hotfix package (Outlook-x-none.msp): December 10, 2013
      http://support.microsoft.com/kb/2849973

      • #1438981

        First off a holiday cookie recipe:
        http://www.marthastewart.com/343445/gingerbread-cookies Okay so it’s Martha’s not mine, but I made cookies that look like thisout of them.
        Now on to patching comments.

        No new patches were out this week of the 24th so we can serve up leftover patches and report on them:

        First up Office 2010 sp2:

        Office 2010 sp2 is finally okay to install. After installing sp2 you will find that you receive errors in application event log after Office sp2 and recent security updates:
        Event ID 27, “Calendar Folder property is missing,” after you apply Office 2010 SP2:
        http://support.microsoft.com/kb/2883156
        If you are suffering from that error filling your event logs
        Install the hotfix below and it will fix the issue
        Description of the Outlook 2010 hotfix package (Outlook-x-none.msp): December 10, 2013
        http://support.microsoft.com/kb/2849973

        Office 2010 SP 2 is now listed on the regularly updated PW chart to “install”. On our W7 pro, it’s listed under important updates, but the box next to it is unchecked (as is IE 11). Why would it remain unchecked? Is this an indication to not install at this time?

    • #1431326

      SVCHost @ 100% on Windows XP and Server 2003
      http://blogs.technet.com/b/asiasupp/archive/2007/05/29/automatic-update-causes-svchost-exe-high-cpu.aspx?PageIndex=2#comments
      We have numerous XP and 2003 servers which are having this problem. SVCHOST.EXE uses up 100% of CPU and causes all critical applications to fail. We’ve tried everything mentioned in this article – no success.
      So if you are still running Server 2003 and Windows XP and you see SVCHOST.exe chewing up the CPU, yes, it’s a known issue right now and yes Microsoft it working on fixing it. It’s on their end not yours.
      As a workaround, manually download the December IE update (https://technet.microsoft.com/en-us/security/bulletin/ms13-097 ) and manually install it. Then install the rest of the updates as normal.

    • #1431327

      Problem:
      IMAP downloads inbox don’t work after November patches.
      If you install a fresh OS and O2K13 unpatched ,the IMAP works fine.
      Fully patched O2K10 works fine too.

      I’d highly recommend reading this blog post on the topic:
      Two Microsoft Updates Cause Problems With Outlook 2013 | Help Desk: http://helpdesk.missouristate.edu/news/two-microsoft-updates-cause-problems-with-outlook-2013

      You need to apply all 3 hotfix. The crash issue and IMAP issue would get resolved immediately while the issue related to Free / Busy and OOF not getting set would take 24-36 hours to start working once the patch is applied.
      Below are the KB articles:

      Description of the Outlook 2013 hotfix package (Outlook-x-none.msp): December 10, 2013: http://support.microsoft.com/kb/2825652

      Description of the Word 2013 hotfix package (Word-x-none.msp): December 10, 2013: http://support.microsoft.com/kb/2837674

      Description of the Office 2013 hotfix package (Mso-x-none.msp): December 10, 2013: http://support.microsoft.com/kb/2849994

    • #1431329

      Microsoft Security Advisory: Updates to improve Remote Desktop Protocol network-level authentication: August 13, 2013:
      http://support.microsoft.com/default.aspx?scid=kb;en-us;2861855

      No side effects seen on this one, okay to install.

    • #1431330

      MS13-081: Description of the security update for USB drivers: October 8, 2013:
      http://support.microsoft.com/default.aspx?scid=kb;en-us;2862330

      I still can’t guarantee no issues with installing this update. If you’ve installed it, FANTASTIC! Leave it on. If you are one of the unlucky ones that have unusual usb devices and it won’t install, the best advise is to unplug all usb devices and attempt to install it. If you STILL can’t install it, skip it. If you have having this much trouble patching it, attackers will have just as much trouble attacking you with this vulnerability.

    • #1431331

      Microsoft security advisory: Improperly issued digital certificates could allow spoofing:
      http://support.microsoft.com/default.aspx?scid=kb;en-us;2917500

      This should be only see on Windows XP machines. For those systems go ahead and install it. For Vista and higher this update that removes an improperly issued digital certificate will be done for you automatically.

    • #1431332

      MS13-099: Description of the security update for Windows Script 5.8: December 10, 2013:
      http://support.microsoft.com/default.aspx?scid=kb;en-us;2892074

      I think I missed a kb number on this one, as I did go ahead and give the go ahead for this update.

      http://technet.microsoft.com/en-us/security/bulletin/ms13-099
      Depending on your operating system you may get different versions of this security bulletin offered up.
      You may see 2892075 or 2892076 or 2892074. All are okay to install.

    • #1431341

      An update is available that improves management of weak certificate cryptographic algorithms in Windows:
      http://support.microsoft.com/default.aspx?scid=kb;en-us;2862966

      I haven’t seen any issues with this update, okay to install.

    • #1431342

      I have not seen issues with the December non security updates (listed below). But I recommend that you wait until the end of the month to ensure there are no issues.

      The following updates are okay to install for December:

      NON-SECURITY UPDATES
      To improve visuals for SharePoint 2013
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2826037)
      To improve stability and performance for SharePoint 2013
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2850071)
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2827232)
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2760521)
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2826038)
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2827214)
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2827217)
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2827220)
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2827229)
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2827231)
      • Update for Microsoft SharePoint Enterprise Server 2013 (KB2850068)
      To improve stability and performance for Office 2013
      • Update for Microsoft Office 2013 (KB2826004)
      • Update for Microsoft Office 2013 (KB2837637)
      • Update for Microsoft Office 2013 (KB2837638)
      • Update for Microsoft Office 2013 (KB2850066)
      To improve visuals for Office 2013
      • Update for Microsoft Office 2013 (KB2827227)
      • Update for Microsoft Office 2013 (KB2837626)
      • Update for Microsoft Office 2013 (KB2837655)
      • Update for Microsoft Access 2013 (KB2827233)
      • Update for Microsoft InfoPath 2013 (KB2837648)
      • Update for Microsoft OneNote 2013 (KB2850063)
      • Update for Microsoft Project 2013 (KB2727085)
      • Update for Microsoft Publisher 2013 (KB2837635)
      • Update for Microsoft Visio 2013 (KB2817306)
      • Update for Microsoft Word 2013 (KB2850060)
      • Update for Microsoft Word 2013 (KB2837647)
      To improve video playback for PowerPoint 2013
      • Update for Microsoft PowerPoint 2013 (KB2767850)
      To improve stability and performance for Project Server 2013
      • Update for Microsoft Project Server 2013 (KB2827221)
      To improve localized remote controls for SharePoint Designer 2013
      • Update for Microsoft SharePoint Designer 2013 (KB2837633)
      • Update for Microsoft SharePoint Designer 2013 (KB2760212)
      To improve stability and performance for SharePoint Foundation 2013
      • Update for Microsoft SharePoint Foundation 2013 (KB2827216)
      To improve stability and performance for SkyDrive Pro
      • Update for Microsoft SkyDrive Pro (KB2817495)
      To improve stability and performance for SharePoint Server Client Components SDK 2013
      • Update for Microsoft SharePoint Server 2013 Client Components SDK (KB2817619)
      To improve stability and performance for Office 2010
      • Update for Microsoft Office 2010 (KB2837593)
      • Update for Microsoft Office 2010 (KB2837590)
      To improve visuals for Office 2010
      • Update for Microsoft Office 2010 (KB2850079)
      To improve stability and performance for Project Server 2010
      • Update for Microsoft Project Server 2010 (KB2553430)
      To improve visuals for Business Productivity Servers 2010
      • Update for 2010 Microsoft Business Productivity Servers (KB2553156)
      To improve visuals for Web Apps Server 2010
      • Update for Microsoft Web Applications (KB2553400)
      And the junk e-mail filters
      • Definition Update for Microsoft 2013 (KB2760587)
      • Definition Update for Microsoft Office 2010 (KB982726)
      • Update for Outlook 2007 Junk E-mail Filter (KB2850085)
      • Update for Outlook 2003 Junk E-mail Filter (KB2863822)

      • #1431344

        MS13-101: Vulnerabilities in Windows kernel-mode drivers could allow elevation of privilege: December 10, 2013:
        http://support.microsoft.com/default.aspx?scid=kb;en-us;2880430
        Seen issues with this update especially with AVG antivirus and KB2887069. Ensure you
        a. Disable AVG
        b. Clean out temp file
        Still being investigated at this time
        http://answers.microsoft.com/en-us/windows/forum/windows_7-windows_update/kb2887069-hangs-at-12/b1ae1909-cf28-442f-a44f-f3824f6c1af3

        Keep this on hold still for now.

      • #1431533

        Similar to phoonman, I still have the following KB’s waiting to be installed on my Win7 Pro machine:

        Security updates – KB2887069 + KB2893984

        Non-Security KB2847077

        And one lingering Net.5.1 update KB2858725

        Did I/we miss getting the all clear to install? Thanks for your help, Susan and others here …

        • #1431537

          And one lingering Net.5.1 update KB2858725

          Did I/we miss getting the all clear to install?

          Susan wrote about the .NET 4.5.1 KB2858725 in the 28 November issue of the newsletter:

          … it’s highly unlikely that you’ll need .NET 4.5.1 anytime soon …

          She advised to skip the update.

          I, too, am waiting for her recommendation on what to do with the other updates mentioned.

          • #1431642

            2858725 .net 4.5.1 is in fact causing issues with SBS 2011 servers. Def a not install.

            • #1431982

              Hi Susan or anyone,
              Susan wrote on 10/24 regarding upgrading Windows 8.0 to 8.1, “Stick with your original Windows 8 for a while longer…”

              (Specifically, this is for my father’s laptop, and one which I would have to talk him through or do remotely….)

              Is Susan still holding to this advice, or has it been revised, and where? Thanks and Happy New Year.

            • #1432853

              Hi Susan or anyone,
              Susan wrote on 10/24 regarding upgrading Windows 8.0 to 8.1, “Stick with your original Windows 8 for a while longer…”

              (Specifically, this is for my father’s laptop, and one which I would have to talk him through or do remotely….)

              Is Susan still holding to this advice, or has it been revised, and where? Thanks and Happy New Year.

              I’ll revisit this in this month’s PW. We have some known issues and resolutions that have been fleshed out.

    • #1431345

      The good news is that Microsoft pulled a faulty firmware:
      Microsoft pulls faulty Surface Pro 2 firmware update | ZDNet:
      http://www.zdnet.com/microsoft-pulls-faulty-surface-pro-2-firmware-update-7000024477/

    • #1431374

      I still have these sitting in my Windows Update screen.
      Can you comment on them?

      Security
      KB2887069 was a wait
      KB2893984 was a wait

      Non-Security
      KB2834140
      KB2836502
      KB2847077
      KB2891804
      KB2904266
      KB2913152

    • #1432208

      THANK YOU Patch Watch STAFF for adding the NOTE to the TOP of the latest Patch Watch article!

      Note: Because Windows Secrets will be taking a break at the end of December, there will be no second Patch Watch column this month. But around Christmas time, I’ll be posting Patch Watch updates in the Windows Secrets Lounge/Windows Secrets Columns. So join me there for a bit of holiday fun!

      I remember in previous years, scratching my head as a noob, trying to figure out where the missing info was for all my remaining updates.

      I had NO idea that during the ‘holidays’ there was a forum based wrap up that covered the remaining items from the Patch Watch articles. This had never been mentioned in the actual articles, and in later years it was not always clear that the follow ups where in the forums.

      To a new ‘member’ this appears as if you left unfinished business, and gives the appearance that Windows Secrets / Patch Watch may not be a very reliable and/or consistent source for updates. Most ‘noobs’ will never take the effort to look for an answer and will simply stop coming to the site.

      I am personally a rather stubborn and persistent type, so I found the correct info after finding the forums, creating a separate account here, and THEN posting here in the forums.

      Most ‘noobs’ won’t make it this far.

      This was very frustrating to me, especially as a paid subscriber. It also frustrated me that I had to create, and now keep track of, a separate account to access these forums.

      You would think a ‘techie’ group of folks, like those at Windows Secrets, would have figured out how to use a single login to access both of these sites. Just saying…

      I also like that this year there was an included hyper-link to these forums!

      http://windowssecrets.com/forums/forumdisplay//53-Windows-Secrets-Columns

      The link in the note at least brings a new member to the “Lounge: Windows Secrets Columns” section of the forums.

      So now I just need to figure out which topic is the one that contains the info from that Patch Watch article…hmmm

      This is of course assuming I have ever seen a forum and understand how they work…

      I’d like to suggest sharing a link directly to the forum post that you will write the follow up in…AKA that means THIS thread

      http://windowssecrets.com/forums/showthread//158381

      It is still a hyper-link, just a more specific one. Not any harder really.

      So that is my 2 cents worth on that matter.

    • #1432210

      While we’re on a roll of cleaning up Kbs that have been hanging fire for awhile, I’ve seen nothing since August 15 about KB2767849 (Office digital signatures). I search Windows Secrets site-wide, and that’s the only hit I get. Any update?

      • #1432852

        While we’re on a roll of cleaning up Kbs that have been hanging fire for awhile, I’ve seen nothing since August 15 about KB2767849 (Office digital signatures). I search Windows Secrets site-wide, and that’s the only hit I get. Any update?

        http://support.microsoft.com/default.aspx?scid=kb;en-us;2767849 Do you ever sign and use digital signatures on Office 2007? If you do then you need it, otherwise, it’s optional.

    • #1433383

      I’ve noticed I have some rather old .NET 4 patches that I had put on hold away back when … are they okay to install now?

      KB2487367
      KB2729449
      KB2737019

      More generally, .NET 4 was pre-installed on my computer. Is there a way to check whether any of my applications are actually using it? I’d be happy to uninstall it otherwise.

      Many thanks to Susan for her excellent column – always a must-read for me!

      • #1436768

        Hi,

        OK, been dealing w/ update issues for years… I could KISS all of you! Didn’t realize this was here.

        Time to share with a ‘few’ others. I value what little I have left of my hair…:)

    • #1437197

      I am upgrading my four office computers to new ones with Win 7 – 64. The first one is up and running and when I went to Windows update, I received 52 updates that stretched back into 2011. Most were .net updates. Is there a quick way to go through them and find which ones are OK, or maybe it would be easier to identify the ones that are not?

    Viewing 20 reply threads
    Reply To: Reply #1428603 in Closing a long year of Windows patching

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information:




    Cancel