Microsoft just posted CVE-2018-8653: Scripting Engine Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that the
[See the full post at: Heads up — Bug fix for IE coming out through Win10 cumulative updates, Win7 and 8.1]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Heads up — Bug fix for IE coming out through Win10 cumulative updates, Win7 and 8.1
Home » Forums » Newsletter and Homepage topics » Heads up — Bug fix for IE coming out through Win10 cumulative updates, Win7 and 8.1
- This topic has 88 replies, 27 voices, and was last updated 6 years, 3 months ago by
anonymous.
Tags: CVE-2018-8653
AuthorTopicwoody
ManagerDecember 19, 2018 at 12:27 pm #241184Viewing 43 reply threadsAuthorReplies-
anonymous
Guest -
anonymous
Guest -
woody
Manager -
anonymous
Guest -
anonymous
Guest -
anonymous
GuestDecember 19, 2018 at 6:26 pm #241325I’d just like to point out that .. in some cases, IE is activated by Windows. Case being mine. I don’t even consider using Chrome. Who would? Google has more data than the NSA and the CIA combined, just from users inputs in their search engine lol .. imagine what Chrome is allowing/preventing. Anyways. Is it possible that, just maybe, this update is critical to some people, or was. Before they were hacked. Every device on the network except the Xbox One. And I’ve not once opened IE. True enough, that just means I already had something in there from one of these other exploits we’re hearing about (Intel vulnerability, ASUS router exploit)ย which are fixed after the damage is done to some people. I’m all for the update but Microsoft needs to tighten up. I needed it a month ago. I needed the ASUS fw patch back before I got infected.
Edit to remove HTML
-
-
-
-
radosuaf
AskWoody LoungerDecember 20, 2018 at 4:02 am #241401Firefox is cool. I use it :).
Fractal Design Pop Air * Thermaltake Toughpower GF3 750W * ASUS TUF GAMING B560M-PLUSย * Intel Core i9-11900Kย * 4ย x 8 GB G.Skill Aegis DDR4 3600 MHz CL16ย * ASRock RX 6800 XT Phantom Gaming 16GB OCย *ย XPG GAMMIX S70 BLADE 1TBย *ย SanDisk Ultra 3D 1TBย *ย Samsung EVO 840 250GB * DVD RW Lite-ONย iHAS 124 *ย Windows 10 Pro 22H2 64-bit Insider * Windows 11 Pro Beta Insider
OscarCP
MemberDecember 19, 2018 at 1:00 pm #241200Thanks. Now, this is probably a very naive question, as I do not use Windows 10, but can one run IE on Windows 10? I’ve understood (for no particular reason) that it was Edge the only MS browser that can be run there. And if one can, is it the same IE11 version as for Windows 8.1?
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV-
PKCano
Manager -
OscarCP
MemberDecember 19, 2018 at 1:08 pm #241205Thanks, but not really the whole answer: is it the same version as for Windows 8.1, or a different one?
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV
-
Mr. Natural
AskWoody LoungerDecember 19, 2018 at 1:35 pm #241214IE is in Windows Accessories on the start menu in Windows 10.
I only use IE at work for a few legacy apps. Unfortunately we do have users in the office still using IE. Chrome is on all installs and I tell folks to use it when they call me with IE issues.
Not disclosed yet so Iโll wait and see what happens with this one.
Red Ruffnsore
-
mn–
AskWoody LoungerDecember 20, 2018 at 3:25 am #241397Legacy apps unfortunately including such as, some Sharepoint Online integration features … and local-only tools like RAID, NAS and even network device management for certain hardware (honestly, couldn’t they just write either a browser-agnostic tool or a proper application?)…
Really, with the odds being that IE is the only browser left on most systems that can run integrated Java applets and Java applets also being the only way to configure some of those…ย even on this year’s hardware models occasionally.
Or I suppose you could rig the Hyper-V host server to multiboot Linux on the bare hardware and use the custom drivers and unofficial opensource command line tool every time you need to rearrange RAID volumes for a guest VM… because even the cold-boot firmware RAID setup UI doesn’t have access to some of the settings.
(Why yes, I do have a copy of the last ESR 52.x Firefox stashed away too…)
anonymous
Guest-
bhen
AskWoody Lounger -
anonymous
GuestDecember 19, 2018 at 3:06 pm #241285It’s a security update so it should come down either way.
One can also download it from the catalog site and manually install it but, as always, those using this method must make sure to first install the latest Servicing Stack Update (SSU). There is no new SSU with this Latest Cumulative Update (LCU) but if this is the first time you’re updating this month and you choose the manual method, be sure to first apply the associated SSU released earlier in the month. The KB article for each version of the Win10 LCU has the details.
anonymous
GuestDecember 19, 2018 at 2:29 pm #241250I never use IE but some programs use it even if you have set another browser as default.
I wish there was a way to block IE being accidentally accessed through those programs. Sometimes it is as simple as clicking on “about” or “help” in the program interface and IE starts up and must be closed.
This is annoying.
firemindbhen
AskWoody LoungerDecember 19, 2018 at 2:36 pm #241262If you’re at risk of being tricked into using IE, you should probably let this download and install.
As someone on 1803, when I saw a folder with files show up in SoftwareDistribution on a Wednesday, I was expecting “automatic 1809 update”, not “security update for 1803”. (Yeah yeah, the 1809 update files probably land somewhere else when they arrive, right?)
abbodi86
AskWoody_MVPDrBonzo
AskWoody PlusDecember 19, 2018 at 2:44 pm #241274I wonder if this effectively makes the WIN 7 December Rollup a new patch? I was just at the support page for the Rollup and it was last updated Dec 11. That would imply that even Group A folks would need the new IE Patch. But at some point every Win 7 (and maybe Win 8.1 and 10 as well) user will need the IE 11 patch whether they browse with IE 11 or not since IE 11 is part of the OS.
-
StoopidMonkey
AskWoody Plus
anonymous
GuestDecember 19, 2018 at 3:14 pm #241286I am seeing the patches show up on our WSUS servers, but NOT seeing the patches offered when running a WindowsUpdate client check connecting to Microsoft.
And FWIW the patches are listed as available in the Update Catalog.
I’m not sure why they are not showing up via WindowsUpdate client 3+ hours after they showed up on the WSUS servers.ย That is not the usual behavior.
However it does make me wonder if they have already been pulled from Windows/Microsoft Update web site.
Jim
anonymous
GuestDecember 19, 2018 at 3:32 pm #241293Does theis new IE cumulative SEC Patch(KB4483187) negate having to install KB4470199 the regular Dcember IE cumulative SEC Patch I have one of my 4 laptops already updated for the Dec 2018 patches and the other 3 are still waiting to be patched for Dec 2018. I’d like to have to install as little as possible from Microsoft if possible.
1 user thanked author for this post.
-
AJNorth
AskWoody PlusDecember 20, 2018 at 3:20 pm #241624Does the new IE cumulative SEC Patch (KB4483187) negate having to install KB4470199 the regular December IE cumulative SEC Patch
Hello,
The answer is yes; KB4471328 supersedes KB4470199 (please seeย https://support.microsoft.com/en-us/help/20181219/security-update-deployment-information ).
ashfan212
AskWoody LoungerPKCano
ManagerDecember 19, 2018 at 3:57 pm #241301AKB2000003 has been updated on 12/19/2018 to include the out-of-band KB 4483187 IE11 Cumulative Update for Group B and anyone else who needs to download it.
This update replaces KB4470199 2018-12 Cumulative Security Update for IE11.
(For those of you still running XP, you will need this patch as well. Thanks to @? says)
anonymous
GuestDecember 19, 2018 at 4:00 pm #241297Per the MSRC blog post this has been seen by Google in targeted attacks.ย Malware can pull a specific instance of a browser and thus even if you aren’t using IE, malware could target it.ย So don’t blow this off if you (or your firm) think you might be in one of these targeted attacks.ย I am seeing the IE patch on my 7 so they haven’t pulled them.
PKCano
Managerwarrenrumak
AskWoody LoungerDecember 19, 2018 at 4:52 pm #241308Attacks like this are demonstrative of why it’s important to leave UAC turned on.ย I know lots of smartypants-types turn UAC off because they don’t like being nagged to elevate privileges….. but the point is to ensure that processes like Internet Explorer that don’t need to be an Administrator, ever, are not running with the Administrator token by default.
1 user thanked author for this post.
-
GoneToPlaid
AskWoody Lounger
anonymous
GuestDecember 19, 2018 at 5:42 pm #241315Updated IE11 on a Windows 7 machine and it required a reboot and seemed to install fine via Windows Update.
Attempted to update a Windows 8.1 machine and it seemed to install, but strangely didn’t require a reboot.ย Checked Windows history and it indicates being installed but when I open IE11 to check the most recent IE security update it’s still showing Dec 11 KB4470199 as being installed.ย Uninstalled and tried again using Windows Update and still the same result.ย Tried a manual installation via the catalog download and it still showing the same.
Is there anyway of showing whether this update installed correctly?
-
PKCano
ManagerDecember 19, 2018 at 5:47 pm #241320The MS pages on KB4483187 Cumulative Update for IE11 say this:
After you install this security update on a computer that is running Windows Server 2012 R2 or Windows 8.1, the About Internet Explorer 11 dialog box will show KB4470199 (the December 11, 2018 security update for Internet Explorer) instead of KB4483187. Users can confirm they are protected by verifying that the version of jscript.dll is 5.8.9600.19230.
6 users thanked author for this post.
-
anonymous
Guest
-
woody
ManagerDecember 19, 2018 at 6:05 pm #241322There’s a workaround published in the CVE article:
Workarounds
Restrict access to JScript.dllย For 32-bit systems, enter the following command at an administrative command prompt:
cacls %windir%\system32\jscript.dll /E /P everyone:N
For 64-bit systems, enter the following command at an administrative command prompt:
cacls %windir%\syswow64\jscript.dll /E /P everyone:N
Impact of Workaround. By default, IE11, IE10, and IE9 uses Jscript9.dll which is not impacted by this vulnerability. This vulnerability only affects certain websites that utilizes jscript as the scripting engine.
How to undo the workaround. For 32-bit systems, enter the following command at an administrative command prompt:
cacls %windir%\system32\jscript.dll /E /R everyone
For 64-bit systems, enter the following command at an administrative command prompt:
cacls %windir%\syswow64\jscript.dll /E /R everyone
2 users thanked author for this post.
-
deuce120
AskWoody PlusDecember 19, 2018 at 7:46 pm #241341Woody,
You posted workarounds that were listed in a CVE article posted on a Mircosoft website. I get alerts from Microsoft when new articles, updates, etc are posted. The crazy thing is if I click on link on the to the CVE article, CVE-2018-8653, it takes me to different article than the one your link does. The second one does not list any workarounds – stated as no known worlarounds. That link is https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8653.
Goes to show that Microsoft has some serious issues and we are suppose to “trust” them.
Thanks for all the great information that you and others provide.
-
PKCano
Manager -
anonymous
GuestDecember 22, 2018 at 10:28 am #242028Yeah, Microsoft realized that you can’t change or edit the access control list of certain files without being the owner of them in the first place, so they added the command to take ownership of the jscript.dll file. The file’s original owner is the TrustedInstaller.exe program, which runs a good portion of Windows Update.
-
anonymous
Guestfernlady
AskWoody LoungerGeo
AskWoody Plusanonymous
GuestDecember 19, 2018 at 8:39 pm #241344So is this an extreme urgent one? Donโt use IE at all, always wondered why I canโt uninstall it. Hope I can pospone it for a week or so since weโre packing up for the holidays and prepare for a long trip. Just shut down, backed up and imaged laptops we take. I am not very keen to start them again with all kinds of risks involved… :-/ Sorry for the question, but donโt know if I should be nervous about this one.
-
GoneToPlaid
AskWoody Lounger -
anonymous
GuestDecember 19, 2018 at 9:58 pm #241358Tnx, I was afraid of that already ๐ I have so extremely enough of Windows 10 you canโt imagine that. Ok, so the first time we fire up those laptops at our destination, they will start updating. Absolutely wonderful thought. Why on earth canโt we install stuff we donโt need, it would save such a lot of hassle. The sad thing is that some hours ago we checked for updates, none were found, while this one was released some hours before this check. Even just before Christmas Microsoft rolls out nasty surprises, so demotivating. Weโll hope the next time we switch on those laptops, the updates will be installed smoothly.
-
anonymous
Guest
-
-
anonymous
Guest-
GoneToPlaid
AskWoody Lounger
abbodi86
AskWoody_MVPDecember 19, 2018 at 10:25 pm #241365Side notice: a flood of new KB articles about privacy in Windows 10
https://support.microsoft.com/en-us/help/4459081/general-privacy-settings-in-windows-10-microsoft-privacy
https://support.microsoft.com/en-us/help/4468236/diagnostics-feedback-and-privacy-in-windows-10-microsoft-privacy
https://support.microsoft.com/en-us/help/4468228/windows-10-app-diagnostics-and-privacy-microsoft-privacy
https://support.microsoft.com/en-us/help/4468229/windows-10-apps-and-services-activity-on-the-privacy-dashboard-microso
https://support.microsoft.com/en-us/help/4468240/windows-10-location-service-and-privacy-microsoft-privacy
https://support.microsoft.com/en-us/help/4468247/windows-10-privacy-settings-that-apps-use-microsoft-privacy
https://support.microsoft.com/en-us/help/4468227/windows-10-activity-history-and-your-privacy-microsoft-privacy
https://support.microsoft.com/en-us/help/4468232/windows-10-camera-microphone-and-privacy-microsoft-privacy
https://support.microsoft.com/en-us/help/4468230/windows-10-background-apps-and-privacy-microsoft-privacy
https://support.microsoft.com/en-us/help/4468235/windows-10-eye-tracking-and-privacy-microsoft-privacy
https://support.microsoft.com/en-us/help/4468243/windows-10-motion-data-and-privacy-microsoft-privacy
https://support.microsoft.com/en-us/help/4468234/windows-10-desktop-apps-and-privacy
https://support.microsoft.com/en-us/help/4468239/location-activity-on-the-privacy-dashboard-microsoft-privacy
https://support.microsoft.com/en-us/help/4468231/browsing-history-on-the-privacy-dashboard-microsoft-privacy1 user thanked author for this post.
Hopper15
AskWoody PlusDecember 19, 2018 at 10:57 pm #241368So is this an extreme urgent one? Donโt use IE at all, always wondered why I canโt uninstall it. Hope I can pospone it for a week or so since weโre packing up for the holidays and prepare for a long trip. Just shut down, backed up and imaged laptops we take. I am not very keen to start them again with all kinds of risks involvedโฆ :-/ Sorry for the question, but donโt know if I should be nervous about this one.
“Way-out-of-band patches like this one have a nasty history of blowing up” Like Woody said I would avoid it.
-
anonymous
Guest
anonymous
GuestDecember 19, 2018 at 11:18 pm #241369I got lost. Just to avoid a nasty surprise during Christmas, I decided to fire up my laptop in the middle of the night. It didnโt find the update. Neither did another laptop. And yes, I even dared to click this dreaded seek for updates-button, several times even. Both systems are on 1803, Semi Annual Channel, 365 days deferral of feature updates and 0 days deferral of quality updates. Could that have anything to do with it? I have a vague memory of not getting some other out of band updates in the past either, but not sure. Also I never get those extra non-security updates seperately (not that I miss them). The updates from patch Tuesday I always pick up. Same behavior on all systems which have no exotic software or drivers.
Or is this specific update/patch withdrawn already? Saw some complaints on Reddit regarding hanging black boot screens and some other weird things.
Anyway: should I as someone who defenitely never uses IE worry about this at all, actually…? I assume that I get the patch included in Januaryโs cumulative updates, so yeah… Manually installing updates I never did in my life and I donโt feel comfortable doing that now either to be honest. I am just an average user, not an IT-expert.
anonymous
GuestNibbled To Death By Ducks
AskWoody PlusDecember 20, 2018 at 1:45 am #241384According to Ars Technica,
“Windows users should ensure their computer installs the update as soon as possible, even if they don’t normally use IE to browse sites.”
Woody says not to patch.
The article seems to infer (it’s the last sentence) that MSFT has decreed this. It’s not clear if this is the opinion of the writer or MSFT.
Can anyone decipher this? I hate it when two security sources I trust seem to disagree.
Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
--
"The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scottyradosuaf
AskWoody LoungerDecember 20, 2018 at 4:05 am #241402Does not show up in WU with 7 days quality updates deferral set.
Fractal Design Pop Air * Thermaltake Toughpower GF3 750W * ASUS TUF GAMING B560M-PLUSย * Intel Core i9-11900Kย * 4ย x 8 GB G.Skill Aegis DDR4 3600 MHz CL16ย * ASRock RX 6800 XT Phantom Gaming 16GB OCย *ย XPG GAMMIX S70 BLADE 1TBย *ย SanDisk Ultra 3D 1TBย *ย Samsung EVO 840 250GB * DVD RW Lite-ONย iHAS 124 *ย Windows 10 Pro 22H2 64-bit Insider * Windows 11 Pro Beta Insideranonymous
Guestanonymous
Guestnumike
AskWoody LoungerDecember 20, 2018 at 6:42 am #241420Microsoft issues emergency update to fix critical IE flaw under active exploit
TJ
AskWoody PlusDecember 20, 2018 at 7:04 am #241424Given the fact that I personally don’t know to what extend IE is embedded in the OS and therefore endangering system wide safety, I decided to install KB 4483187 on my Group B Win7 X64 system.
All seems well.**** Happy days to all ****
MintDE is my daily driver now. Old friend Win10 keeps spinning in the backgroundgeekdom
AskWoody_MVPDecember 20, 2018 at 7:21 am #241432Beta Test
Reporting on Windows 7 x64 update– KB4483187 installed without error and the system rebooted without error.
– Firefox 65.0b5 (64-bit) in use.On permanent hiatus {with backup and coffee}
offlineโธ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offlineโธ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
onlineโธ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefenderMicrofix
AskWoody MVPDecember 20, 2018 at 7:46 am #241438Win8.1 Pro x64 (2 devices)
no restart required after patch installation (did one anyway, habit)
no errors in event viewer pre/ post restart.
Don’t use IE, although this is integral to OS and important.
No issues with patch.
Leaving it off W10 1803 and XP for now..Windows - commercial by definition and now function...Speccy
AskWoody LoungerDecember 20, 2018 at 8:11 am #241454As PKCano correctly pointed out, besides updating version numbers, the only major differences between KB4483187 (datetime stamped Dec 15, 2018) and KB4470199 (datetime stamped Nov 14, 2018) are in the specific vulnerability being patched – namely, the mshtml.dll HTML Viewer library (both 64/32 bit versions) and the jscript.dll (both 64/32 bit versions) and jscript9.dll (64-bit version) JScript engine libraries.
NOTE: Incidentally, that could also mean that the proposed workaround might not fully cover the vulnerability on 64-bit systems…
There are a few other minor differences (the 32-bit iedkcs32.dll, iexplore.exe and sqmapi.dll files have updated its embedded certificates) but these are, from a functional point of view, irrelevant: basically, KB4483187 is an updated version of (replacement for) KB4470199, patching the specific, Javascript-related vulnerability.
David Beroff
AskWoody LoungerDecember 20, 2018 at 9:12 am #241479Why did my Windows 7 Home Premium (ver 6.1, build 7601, SP1) system start crashing as soon as KB4483187 was installed?ย I had about 5 crashes in as many hours, while I was trying to work with overseas clients, before I was able to go in and uninstall it.ย I don’t ever use MSIE, and would uninstall it if I could.ย No other software was installed recently, and my system is usually as stable as a rock.ย (The last time I had crashing issues, I narrowed it down to Google’s Backup and Sync, which is now only run manually at night, rather than on startup, but today it was not running at all during any of these events.)ย Thank you.
2 users thanked author for this post.
-
PKCano
ManagerDecember 20, 2018 at 9:16 am #241486My guess is that there is some conflict between the javascript files that were changed in the KB4483187 update and some program you are using on your computer.
What browser are you using?
What program(s) are you using when the crash occurs?
What AV program do you run?3 users thanked author for this post.
-
David Beroff
AskWoody LoungerDecember 20, 2018 at 9:39 am #241500Thanks for the reply, @PKCano.ย Each time, I was only using Chrome and sometimes Notepad.ย Would Chrome even use any of MSIE’s JS?ย I was finally able to uninstall (and “hide”) the update, and have had zero crashes, although admittedly, it’s only been an hour so far.ย I’ll be more certain when I can go a week or longer.ย I was most-recently using Bitdefender, but it was sucking up way too many resources, which were directly interfering with my overseas work, so I had to turn that off, and haven’t yet had a chance to replace it.
1 user thanked author for this post.
-
anonymous
GuestDecember 20, 2018 at 9:30 am #241492Windows 7 Pro x64 – After waiting overnight to let this settle, I installed KB4483187 requiring a re-start, all OK.
While I ususally await on Woody, in this instance it doesn’t seem the extreme risk is worth a lengthy wait on one critical security IE update. The normal wait period is usually justified by there is nothing critical, or no known exploits of a pending update fix. In this case neither is correct.
Based on my and others here, as well as other sitesย reported install success – I suggest you install but it is ultimately up to each individual.Risk <-> Reward
-
woody
ManagerDecember 20, 2018 at 9:45 am #241507 -
Microfix
AskWoody MVPDecember 20, 2018 at 2:08 pm #241588The PC security industry has a long, sordid history of โSky is fallingโ warnings that fail to live up to their initial billing.
Need I mention ‘Meltdown’ and nothing in the wild a year later..
Windows - commercial by definition and now function... -
mn–
AskWoody LoungerDecember 21, 2018 at 7:59 am #241747Still haven’t seen any specific reports about this one in the wild, but the local national cybersecurity authority did have an official warning up about it being used in specifically targeted attacks…
Oh well. Guess it isn’t a high priority thing as long as you aren’t a target, then? (Note, no information on target grouping seems to be publicly available. Anyone want to throw wild guesses about likely targets?)
-
darynman@gmail.com
AskWoody PlusDecember 20, 2018 at 10:15 am #241518Nibbled To Death By Ducks
AskWoody PlusDecember 20, 2018 at 1:59 pm #241585Bit The bullet, as Ars Tech article went on to say:
โAs the flaw is being actively exploited in the wild, users are urged to update their systems as soon as possible to reduce the risk of compromise,โ Narang said.
I went for it.
So far, no issues.
YMMV.
I hate it when reports of “In The Wild” are non-specific, but thought reports of install success were important too…ย ?
Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
--
"The more kinks you put in the plumbing, the easier it is to stop up the pipes." -ScottyNibbled To Death By Ducks
AskWoody PlusDecember 20, 2018 at 2:06 pm #241587Sorry…the comments from Narang about it being in the wild were from Krebs at:
https://krebsonsecurity.com/2018/12/microsoft-issues-emergency-fix-for-ie-zero-day/
My bad. ๐
But when it’s on Krebs….<sigh>..remember when having a PC, and the Internet was fun?
Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
--
"The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty1 user thanked author for this post.
anonymous
Guest-
Microfix
AskWoody MVP
anonymous
Guest-
PKCano
ManagerDecember 21, 2018 at 9:08 am #241768 -
anonymous
GuestDecember 21, 2018 at 10:37 am #241785Now I’m really confused.ย Running Windows 10 Pro x64 ver 1803 – Group A, Group Policy 2
My Quality Update 10 day hold justย gave me KB4471324 (12/11 update) which I was going to hide pending Defcon Rating 3.ย There was also mention of an SSU KB4477137, but normally SSU’s are automatically installed with/before an update installed thru Windows Update (ie: not a manual install).
This post then shows a KB4483234 for ver 1803 and you mention a new SSU.
So, should I still hide KB4471324?
Should I set my Quality Update hold to 0 days and will KB4483234 come down? Or should I leave QU at 10 days and wait it out?ย ย Will this KB supercede KB4471324?
When KB4483234 comes down, should I install it or hide it pending Defcon Rating 3?
If I allow installation via Windows Updater, do I need to manually installย a SSU? And is it KB4477137 or is there a newer SSU?
-
anonymous
Guest -
Microfix
AskWoody MVPDecember 21, 2018 at 10:47 am #241796What PKCano is saying is, the links to the SSU patches are in Woody’s Blog:
https://www.askwoody.com/2018/december-2018-patch-tuesday-is-under-way/For those of you with Windows 10, there are new Servicing Stack updates:
Win10 1709 Build 16229.846 KB 4477136
Win10 1803 Build 17134.471 KB 4477137Windows - commercial by definition and now function...1 user thanked author for this post.
-
-
geekdom
AskWoody_MVPDecember 21, 2018 at 9:19 am #241771Further information regarding December patches is now here:
https://www.askwoody.com/forums/topic/where-we-stand-with-the-december-patches/On permanent hiatus {with backup and coffee}
offlineโธ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offlineโธ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
onlineโธ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefenderanonymous
GuestViewing 43 reply threads - This topic has 88 replies, 27 voices, and was last updated 6 years, 3 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Windows 11 Insider Preview build 26200.5518 released to DEV
by
joep517
4 hours, 35 minutes ago -
Windows 11 Insider Preview build 26120.3671 (24H2) released to BETA
by
joep517
4 hours, 36 minutes ago -
Forcing(or trying to) save Local Documents to OneDrive
by
PateWilliam
13 hours, 29 minutes ago -
Hotpatch for Windows client now available (Enterprise)
by
Alex5723
1 hour, 25 minutes ago -
MS-DEFCON 2: Seven months and counting
by
Susan Bradley
33 minutes ago -
My 3 monitors go black & then the Taskbar is moved to center monitor
by
saturn2233
22 hours, 25 minutes ago -
Apple backports fixes
by
Susan Bradley
4 hours, 59 minutes ago -
Win 11 24H2 will not install
by
Michael1950
1 day ago -
Advice to convert MBR to GPT and install Windows 11 Pro on unsupported PC
by
Andy M
59 minutes ago -
Photos from iPhone to Win 10 duplicating/reformatting to .mov
by
J9438
9 hours, 48 minutes ago -
Thunderbird in trouble. Here comes Thundermail
by
Alex5723
1 day ago -
Get back ” Open With” in context menus
by
CWBillow
1 day, 13 hours ago -
Many AMD Ryzen 9800X3D on ASRock have died
by
Alex5723
5 hours, 17 minutes ago -
simple general stupid question
by
WSaltamirano
1 day, 11 hours ago -
April 2025 Office non-Security updates
by
PKCano
2 days, 4 hours ago -
Microsoft wants to hear from you
by
Will Fastie
1 day, 4 hours ago -
Windows 11 Insider Preview Build 22635.5160 (23H2) released to BETA
by
joep517
2 days, 7 hours ago -
Europe Seeks Alternatives to U.S. Cloud Providers
by
Alex5723
2 days, 13 hours ago -
Test post
by
Susan Bradley
2 days, 15 hours ago -
Used Systems to delete Temp files Gone WRONG what does this mean?
by
Deo
2 days, 17 hours ago -
SSD shuts down on its own
by
CWBillow
2 days, 8 hours ago -
OneDrive File Sharing Changes
by
David Clark
3 days, 1 hour ago -
OneDrive File Sharing Changes
by
David Clark
3 days, 3 hours ago -
Win 10 Pro 22H2 to Win 11 Pro 23H2 Conversion Guide
by
doneager
2 days, 3 hours ago -
Today is world backup day
by
Alex5723
2 days, 18 hours ago -
Windows .exe on Mint
by
Slowpoke47
5 hours, 16 minutes ago -
Reviewing your licensing options
by
Susan Bradley
13 hours, 14 minutes ago -
Apple has been analyzing your photos since September 2024
by
B. Livingston
3 hours, 5 minutes ago -
What Windows 11 24H2 offers beyond bugs
by
Lance Whitney
1 day, 19 hours ago -
Making sense of Settings in Windows 11
by
Simon Bisson
1 day, 21 hours ago
Recent blog posts
- MS-DEFCON 2: Seven months and counting
- Apple backports fixes
- April 2025 Office non-Security updates
- Microsoft wants to hear from you
- Reviewing your licensing options
- Apple has been analyzing your photos since September 2024
- What Windows 11 24H2 offers beyond bugs
- Making sense of Settings in Windows 11
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.