After installing Windows 7 SP1 x64 from scratch in a VM according to PKCano’s guide and patching all the way up to the August monthly security updates in Group B, I noticed that the Windows Media Player version was only 12.0.7601.17514, compared to my (Group B) desktop OS’s version at 12.0.7601.19148.
In Group A, the WMP version is currently 12.0.7601.23517.
I discovered that I was missing the “Security Update for Windows Media to Address Remote Code Execution” from MS16-027.
After manually installing KB3138962 from that bulletin, WMP was updated to 12.0.7601.19148.
I compared all the security updates for Windows 7 in the fresh installation to my desktop installation (which was installed long ago), and found a total of 11 missing that are applicable.
KB3138962 is not applicable on an installation patched with the monthly rollup (Group A), so I’m concerned about security updates prior to the October 2016 rollups being removed and replaced in the monthly rollups but not in the security-only updates.
Here are the 10 other updates missing in the fresh installation:
(these 4 are applicable before, but not after the 2017-09 Security Monthly Quality Rollup was installed in my testing):
KB3005607
KB3149090
KB3168965
KB3170455
(these are applicable even after applying the rollup)
KB2644615
KB2676562
KB2709715
KB2813170
KB3123479
(this one gave a message that it was already installed with the rollup installed)
KB3033929