Microsoft (finally!) divulged some details about that CVE-2019-1367 patch (actually, three bumbling, successive patches, for all versions of Windows).
[See the full post at: MS-DEFCON 1: Don’t patch, don’t use Internet Explorer, and set up an alternate default browser]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
MS-DEFCON 1: Don’t patch, don’t use Internet Explorer, and set up an alternate default browser
Home » Forums » Newsletter and Homepage topics » MS-DEFCON 1: Don’t patch, don’t use Internet Explorer, and set up an alternate default browser
- This topic has 41 replies, 19 voices, and was last updated 5 years, 4 months ago.
AuthorTopicwoody
ManagerOctober 7, 2019 at 8:48 am #1976270Viewing 16 reply threadsAuthorReplies-
HE48AEEXX77WEN4Edbtm
AskWoody PlusOctober 7, 2019 at 9:36 am #1976324I am really confused now. I received an email from the AskWoody Plus: ” Prioritize installation of the security update for CVE-2019-1367. The update is automatically deployed as a required update through Microsoft Update and the WSUS catalog. Customers with automatic updates turned on don’t need to take additional action”.
Per the previous advice, I had already paused all automatic updates on my computer. Therefore I went to the “CVE-2019-1367” link to download the file kb452417. However, in the meantime, the AskWoody home page states “Don’t patch, don’t use Internet Explorer, and set up an alternate default browser”.
Should I install Kb452417 or not??
Thank you.
-
Chris B
AskWoody PlusOctober 7, 2019 at 9:46 am #1976329If you look at the email, the language you cite is a quote from the Microsoft Windows Defender site, perhaps a rather self serving one. Woody’s advice is quite clear at the moment – Dont patch.
Chris
Win 10 Pro x64 Group A2 users thanked author for this post.
-
woody
ManagerOctober 7, 2019 at 10:04 am #1976356Believe me, I know it’s confusing.
For folks who have to support IE, it’s both confusing and overwhelming.
Bottom line, though: Delay updates, don’t patch anything until we get to MS-DEFCON 3 or 4, don’t use IE and remove it as the default browser.
I’m really steamed that MS put its real IE zero-day warning behind a $690 paywall.
-
anonymous
GuestOctober 7, 2019 at 10:38 am #1976386Hey Woody, I missed the brief Defcon 3 window so have not installed ANY September patches. If October’s patches are a hot mess I’m guessing the green light may not be until early November, am i safe to wait it out or is there any patch from Sept/early Oct that’s o.k or really needed? Thanks for all you do it’s much appreciated.
-
-
NetDef
AskWoody_MVPCAS
AskWoody PlusOctober 7, 2019 at 10:40 am #1976391I use Quicken 2019 which downloads my financial information via Internet Explorer, only. That is the only time I use IE. My default browser is Firefox but it will not work with Quicken. MS Edge has been disabled and I do not use any of the Apps supported by Win 10.
My current OS is Win 10 1803 and my computer has been patched through September based on the master patch list. Windows update is off. When the October patches come out I intend to hide them utilizing wushowhide. I checked today and the IE patch does not appear.
My computer is running without any problems. I log into Win 10 locally and do not have a MS login account. What risk(s), if any, do I face if I continue to use Quicken?
anonymous
GuestOctober 7, 2019 at 11:01 am #1976401I use Firefox and it is set as the default browser on my computer but some programs default to IE anyway. IIRC Windows Update doesn’t use IE to retrieve updates – and I have noticed WU uses my default browser – so I was wondering if I should set my firewall to block IE from accessing the Internet. Any thoughts?
-firemind.
-
Microfix
AskWoody MVPOctober 7, 2019 at 11:12 am #1976409I have on Win8.1 with no ill effects as I use firefox ESR and WU works as intended when/if I need it. You would need to test it, easily undone when/if required anyway. I’m not saying it’s completely blocked off but, I certainly feel better about it as I don’t use it period. YMMV
If debian is good enough for NASA...
WildBill
AskWoody PlusOctober 7, 2019 at 11:17 am #1976414Minor question: When I finally apply most of the M$ patches, I’m still leaning toward following AKB 2000012 to turn off telemetry at bootup & moving back to Group A. I’ve already turned it off according to AKB 2000007. I won’t ready that until I get ready to apply October patches in November. The only patches that seem basically independent of the rest are the Servicing Stack update & the Security Update for Adobe Flash Player. Should I backup my system & apply those, or just wait until November? BTW, even if I don’t apply any patches this month, I’m going to backup today. My system with all the Defender updates & the new Windows Update pipe will be there if I have to restore between now & November.
Bought a refurbished Windows 10 64-bit, currently updated to 22H2. Have broke the AC adapter cord going to the 8.1 machine, but before that, coaxed it into charging. Need to buy new adapter if wish to continue using it.
Wild Bill Rides Again...-
WildBill
AskWoody PlusOctober 7, 2019 at 12:35 pm #1976455Well, I can backup today or tomorrow. Tomorrow if I want to backup the new Windows Updates that drop. BTW, @pkcano keeps saying “FOLLOW MS-DEFCON 1!” Guess I’ll heed his wise advice & leave the Servicing Stack & Flash updates until November too.
Bought a refurbished Windows 10 64-bit, currently updated to 22H2. Have broke the AC adapter cord going to the 8.1 machine, but before that, coaxed it into charging. Need to buy new adapter if wish to continue using it.
Wild Bill Rides Again...1 user thanked author for this post.
BobbyB
AskWoody LoungerOctober 7, 2019 at 11:19 am #1976419“Batten Down the Hatches” sounds like its going to be another rough one, as for IE11, well its been relegated, for some time now, just to a Shortcuts creator on the Desktop as the other Browsers seem to want to put you through hoops to create a simple Desktop Shortcut, whereas IE11 does the same with a single click.
Long since really abandoned IE11 in favour of FireFox Quantum and the occasional use of Edge, well there had to be at least one user out there; 😉
Hopefully “Credge” or “Edgium” may be better although no high hopes here, preferring to wait until “Credge” becomes more main stream and hopefully better integrated, although not holding my breath.1 user thanked author for this post.
JimmyJames
AskWoody LoungerOctober 7, 2019 at 11:30 am #1976427I’ve long wondered why Ask Woody doesn’t have an OS specific DEFCON, say top row with the Windows OS versions and row underneath with the DEFCON for each version.
Right now, I think that the highest DEFCON is for 1903 (buggiest updates) while 1809 seems a little better off (hard to believe it’s possible). This is important to me as I need to upgrade from 1803 to either 1903 or 1809 before I get stuck with 1903 and the hairiest updates yet. A separate DEFCON might help me. As it is I will take a chance with 1809.
I am definitely confused more and more as the time goes on about all this, despite Woody’s team’s best efforts and me being somewhat of a geek and able to wade through most problems. But I’m getting older, and simpler always seems better now. I suspect like many of you, I only hang onto Windows now because of Stockholm Syndrome.
-
PKCano
Manager -
ht
AskWoody LoungerOctober 7, 2019 at 12:54 pm #1976470DEFCON-1 loud & clear, and I’m happy to continue to wait without installing any of the Win7x64 security monthly rollups for September.
My only confusion is from today’s ComputerWorld article (Woody On Windows): If you followed my instructions about installing last month’s updates as soon as they appeared, you got the first set of September patches installed, and you defended your machine against Microsoft’s second, third and fourth volleys. That, and ensuring IE isn’t your default browser (see preceding section), is the best of all possible worlds.
I have not installed any of the Win7x64 security monthly rollups for September. After WU removed KB 4524157, I have been offered (with checks) security monthly rollup for Win7x64 KB 4516065 and security update for Win7x64 KB 4474419, both of which are dated 9/10/2019. Are these the “first set of September patches” to which Woody refers and, if so, is he recommending they be installed now if all the other conditions in the above statement are met?
-
woody
ManagerOctober 7, 2019 at 2:24 pm #1976523Right now, the MS-DEFCON 1 applies across the board.
All of my production machines use 1809. But the mess this month clobbered 1809, too.
The problem with individual MS-DEFCON ratings for each version of Windows is… man alive, do you know how many versions of Windows are out there?
2 users thanked author for this post.
-
b
AskWoody_MVP -
woody
ManagerOctober 8, 2019 at 7:47 am #1976941Let’s see….
Normal people/client only: Win7, 8.1, Win10 1803, 1809, 1903 and soon 1909 (dropping Win7 and Win10 1803 in the next three months)
Abnormal people: Those five-or-so plus 1507, 1607
Server: 2008, 2008 R2, 2012, 2012 R2, 2016, 2019
Arguably, the Security-only Win7 and 8.1 patches, various .NET versions and IE could have their own DEFCON ratings, too. Each has specific considerations.
Oh, and then there’s the Servicing Stack Updates. Did I miss anything significant?
It’s a jungle out there. 🙂
-
anonymous
GuestJo-Anne
AskWoody PlusOctober 7, 2019 at 12:42 pm #1976457Today I received the following Patch information from Susan Bradley:
Windows 7/Server 2008 R2 SP1 (Install only one of these updates.4524157 – Monthly rollup
4524135 – Internet Explorer cumulative security updateI looked at Windows Update on my computer, and I’m being offered 4524157–BUT it’s not checkmarked. Should I hold off installing it until Microsoft sees fit to checkmark it?
Thank you,
Jo-Anne
-
PKCano
ManagerOctober 7, 2019 at 12:44 pm #1976463Microsoft leaves updates unchecked for a reason – so they don’t get installed automatically.
We don’t recommend installing unchecked patches.
Wait till it’s checked.BTW, the Monthly Rollup contains the IE CU – that’s why you don’t install both
-
Jo-Anne
AskWoody PlusOctober 9, 2019 at 12:23 pm #1977787A few days ago I received KB4524157 (2019-10 Security Monthly Quality Rollup for Windows 7 for x64-based Systems), which Microsoft had not checkmarked. On the advice of PKCano and Woody, I didn’t install that update, waiting instead for Microsoft to checkmark it. Today I got the October Patch Tuesday updates from Microsoft. KB4524157 is no longer listed; in its place is KB4519976, with the same label (other than the KB number). This one is checkmarked. I usually don’t install the monthly patches until the end of the month. Should I hold off on this one too?
Thank you,
Jo-Anne
-
PKCano
Manager
-
-
DrBonzo
AskWoody Plus-
woody
Manager -
DrBonzo
AskWoody PlusOctober 7, 2019 at 3:39 pm #1976550For whatever this is worth to anybody, I described the installation of KB4522007 here:
At the time, there were no known printer issues so I didn’t comment on printing. But I can report now that printing on all 3 machines is just fine with a Canon MX860 connected with USB cable.
All three machines are working as normal (Dell Inspiron 5th gen core i3 and Dell OptiPlex 9010 3rd gen core i5, both running Win 7 Pro SP1, and my test machine, an old Gateway laptop with an Intel Atom and Win 7 Starter)
Hope this helps somebody.
Edit: well the link above doesn’t go to my post although it goes to the right thread. The post is #1971810
-
This reply was modified 5 years, 5 months ago by
DrBonzo.
1 user thanked author for this post.
-
This reply was modified 5 years, 5 months ago by
-
PKCano
Manager
-
-
anonymous
GuestOctober 7, 2019 at 1:27 pm #1976485Speaking of Chrome browser- funny – today I used the “Youtube” app in the Chrome browser. When the site loaded I received a notification on the “suspicious site reporter” flag. So I clicked it – the report was that “youtube” was a suspicious site that needed to be reported! So I obediently clicked the send report with a screen shot & URL info! Googles gotta keep us safe! 😛
anonymous
GuestAJNorth
AskWoody PlusOctober 7, 2019 at 2:59 pm #1976538IE-related Question:
One of the banks that a client uses requires the Java RTE, which only functions in IE. With an IE emulator add-on available for Chrome, IE Tab, Java functions and allows full online access with the bank.
Is this IE emulator considered safe? (Win 7 Pro x64 with KB4522007 and uBlock Origin, NoScript, Privacy Badger & HTTPS Everywhere installed.)
Thank you,
AJN
-
mn–
AskWoody LoungerOctober 7, 2019 at 4:39 pm #1976566Yeah, Java plugins really got dropped too quickly, they’re still needed in all too many places…
I understand the IE Emulator really pulls the IE rendering engine and uses it, so might have many of its problems too?
Somehow I expect something like Pale Moon – or even Midori 0.5.11 – might well be safer. Then again they probably just won’t do many of the other IE-specific things at all.
1 user thanked author for this post.
-
AJNorth
AskWoody PlusOctober 7, 2019 at 5:28 pm #1976627Thanks for the suggestion.
Pale Moon states that their browser still supports NPAPI plug-ins, specifically listing Java (https://www.palemoon.org/technical.shtml), so I shall test it on that banking site.
Regards,
AJN
-
b
AskWoody_MVPOctober 7, 2019 at 5:47 pm #1976630 -
AJNorth
AskWoody PlusOctober 7, 2019 at 6:06 pm #1976635Yes, I had spoken with their online services last year about the Java RTE being deprecated from virtually every browser except IE and suggested that perhaps they might look into changing to another platform, such as the Adobe AIR (or .NET Framework). They replied that that was something they were considering, but that there was no timeline (and that .NET was not an option, as it was Windows-specific).
1 user thanked author for this post.
-
-
-
woody
ManagerOctober 7, 2019 at 3:10 pm #1976542Just a parenthetic note…
The official Servicing Stack Update list, Software Advisory ADV990001, has been down all weekend.
1 user thanked author for this post.
EP
AskWoody_MVPOctober 7, 2019 at 5:13 pm #1976603well woody it seems Liam Tung of ZDNet has also written a recent article on the recent Windows patches causing “more pain”
the recent out-of-band patches that were also supposed to fix the printing problems seem to be doing the opposite – causing them rather than fixing them
1 user thanked author for this post.
NoLoki
AskWoody LoungerOctober 7, 2019 at 5:48 pm #1976631Just reading through all the comments – no outrage concerning the $690 paywall. I was expecting more angst. We all have a duty (to each other) to not become complacent over this attempt at a ‘new normal’ that Microsoft has embraced. The ‘new normal’ is not normal at all.
So here it is … I see the use of a paywall in this situation as blatant elitism.
1 user thanked author for this post.
-
woody
ManagerOctober 8, 2019 at 7:49 am #1976942I wouldn’t call it elitism. I’d call it a stupid, stupid mistake.
Limiting information about security holes to paying Enterprise “E5” level customers must’ve been a mistake. Must have.
Worth nothing: As of this moment, four-or-so days after the details were posted on the paywalled site, Microsoft still hasn’t said anything on the CVE-2019-1367 page.
1 user thanked author for this post.
woody
ManagerOctober 22, 2019 at 9:28 pm #1988636From GW:
I just checked my Notebook and the version is 1809 Build 17763.775. Several times in the last week when I shut it off it said it was updating. However the version is still the same. A bit weird I think. I downloaded the update to 1903 file, Windows10Upgrade9252.exe. but did not run that. Should I? My desk top says it is Version 1903 Build 18362.356. Is that up to date? This is really confusing stuff. Any help will be appreciated.
Viewing 16 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Microsoft Defender as Primary Security Question
by
blueboy714
1 hour, 14 minutes ago -
USB printers might print random text with the January 2025 preview update
by
Alex5723
26 minutes ago -
Hacktool:Win32/Winring0 (Awaiting moderation)
by
Marvel Wars
4 hours, 3 minutes ago -
Google’s 10-year-old Chromecast is busted, but a fix is coming
by
Alex5723
5 hours, 58 minutes ago -
Expand the taskbar?
by
CWBillow
5 hours, 48 minutes ago -
Gregory Forrest “Woody” Leonhard (1951-2025)
by
Susan Bradley
4 hours, 1 minute ago -
March 2025 updates are out
by
Susan Bradley
1 hour, 19 minutes ago -
Windows 11 Insider Preview build 26120.3380 released to DEV and BETA
by
joep517
23 hours, 34 minutes ago -
Update Firefox to prevent add-ons issues from root certificate expiration
by
Alex5723
1 day, 6 hours ago -
Latest Firefox requires Password on start up
by
Gordski
1 day, 1 hour ago -
Resolved : AutoCAD 2022 might not open after updating to 24H2
by
Alex5723
1 day, 19 hours ago -
Missing api-ms-win-core-libraryloader-11-2-1.dll
by
IreneLinda
18 hours, 19 minutes ago -
How Much Daylight have YOU Saved?
by
Nibbled To Death By Ducks
21 hours, 17 minutes ago -
A brief history of Windows Settings
by
Simon Bisson
14 hours, 55 minutes ago -
Thunderbolt is not just for monitors
by
Ben Myers
13 hours, 31 minutes ago -
Password Generators — Your first line of defense
by
Deanna McElveen
18 hours, 58 minutes ago -
AskWoody at the computer museum
by
Will Fastie
14 hours, 34 minutes ago -
Planning for the unexpected
by
Susan Bradley
19 hours, 58 minutes ago -
Which printer type is the better one to buy?
by
Bob99
1 day, 21 hours ago -
Upgrading the web server
by
Susan Bradley
1 day, 19 hours ago -
New Windows 11 24H2 Setup – Initial Win Update prevention settings?
by
Tex265
2 days, 14 hours ago -
Creating a Google account
by
DavidofIN
2 days, 13 hours ago -
Undocumented “backdoor” found in Bluetooth chip used by a billion devices
by
Alex5723
2 days, 19 hours ago -
Microsoft Considering AI Models to Replace OpenAI’s in Copilot
by
Alex5723
3 days, 6 hours ago -
AI *emergent misalignment*
by
Alex5723
3 days, 8 hours ago -
Windows 11 Disk Encryption/ Bitlocker/ Recovery Key
by
Tex265
1 day, 16 hours ago -
Trouble signing out and restarting
by
Tech Hiker
15 hours, 22 minutes ago -
Windows 7 MSE Manual Updating
by
Microfix
12 hours, 9 minutes ago -
Problem running LMC 22 flash drive
by
Charlie
2 days, 15 hours ago -
Outlook Email Problem
by
Lil88reb
2 days, 15 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.