Looks like they were all pulled, then re-issued, to minimize the impact on Lenovo servers. If you got yours installed, no need to do anything. InfoWor
[See the full post at: The full story on the Nov 23 re-issue of KB 3197873, 3197874, 3197876, 3197877, 3193479, 3200970]
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
The full story on the Nov 23 re-issue of KB 3197873, 3197874, 3197876, 3197877, 3193479, 3200970
Home » Forums » Newsletter and Homepage topics » The full story on the Nov 23 re-issue of KB 3197873, 3197874, 3197876, 3197877, 3193479, 3200970
- This topic has 18 replies, 3 voices, and was last updated 8 years, 4 months ago.
AuthorTopicwoody
ManagerNovember 28, 2016 at 9:10 am #20605Viewing 17 reply threadsAuthorReplies-
Seff
Guest -
woody
Manager -
Seff
Guest -
AlexEiffel
GuestNovember 28, 2016 at 4:24 pm #20609Woody, sorry for my ignorance, but I am not sure I understand what happens if a patch gets pulled then reissued. If I installed a patch like 3197867 then it got pulled then reissued, do I need to reinstall it again because it changed?
And how can you know if that happened at all? It is not like you go to the Microsoft Update Catalog and find there is a new version of the patch announced to you like you do on your site? So what, are we forced to read your blog forever, then? Not that I don’t like it, but it is a bit scary to run an OS for which you can’t easily know what is patched properly and what is missing. Fragmentation seems much more easy to happen for group B than in the era before this new way of patching.
-
woody
ManagerNovember 28, 2016 at 6:12 pm #20610In this case, no, the re-issued patch is identical to the original patch. All that changed (we subsequently found out) is the installation detection logic.
Yep, this site keeps on top of the details. If you don’t want to deal with the details, just watch for the MS-DEFCON rating and follow the instructions.
You’re right. All sorts of things were easier before the patchocalypse.
-
poohsticks
GuestNovember 28, 2016 at 9:53 pm #20611Re: “what happens if a patch gets pulled then reissued. …do I need to reinstall it again because it changed?”
It is my understanding that yes, sometimes you will want to uninstall a patch that has been pulled after you had initially installed it, and then install the reissued version of the patch.
In this particular case, the old patch is not different to new patch, so the old patch can stay on the system and you don’t have to take any action. I am not an expert, but I am guessing that this will not always be the way it works, unfortunately.
I think that I am correct in saying that even with the former Windows 7/8 updating system, sometimes, rarely, there was a patch or a hotfix that required some manual intervention on the part of the computer owner to get *exactly right*, despite all the automatic patching that the computer owner was allowing MS to do on his/her computer.
And Microsoft’s announcements of this kind of thing were not widespread and often would not be known about by most ordinary computer owners. There were times I stumbled across such advice when I was looking up an unrelated computer question online. (This was before I was forced to become a regular visitor to sites such as Wilders Security Forum, SevenForums, GHacks, Susan Bradley’s, Woody’s, others.)
—
Re: “And how can you know if that happened at all? …are we forced to read your blog forever, then? […] Fragmentation seems much more easy to happen for group B….”I don’t think that ordinary computer owners are going to know that this sort of thing has happened, unless they keep abreast of Windows news in general, or regularly follow at least one good, focused website, like AskWoody.com is.
The Group B path is quite risky in some ways. It’s only “meant” for IT professionals to follow on behalf of their firms.
And even for those seasoned people, they probably are pretty nervous about it because it’s an unknown, untested path and Microsoft is sometimes so slap-dash about things, especially things that they wish didn’t exist in the first place.Path A is pushed so, so strongly by AskWoody.com contributor CH100 in part because he is understandably really worried about people getting locked into a continuous (checking in every few weeks, at a minimum) reliance on Woody’s voluntary help in guiding them precisely in how to navigate path B.
If, for any reason, the Group B people who are ordinary home computer owners reached a point where they were no longer able to get careful, constant, high-quality help from Woody (or someone similar – and there isn’t anyone similar!), they are going to have to know what to do on their own, and they might wish at that time to move to Group A or C rather than deal with the complications.
This is such a tough decision to make, because every conceivable path forward has some big downsides and risks.
The fact that some IT-industry people (current and retired) are choosing Path C
(= to accept no Windows updates at all, despite the many security dangers there are out in the world… just read a week’s worth of a site like krebsonsecurity.com and it will be clear what sort of dangers that good people are up against, and it’s getting worse all the time)
for themselves and the people they care about indicates how bad some aspects of Path A and B must be.The fact that some individuals, including IT experts, who are seriously privacy-conscious and anti-Microsoft’s-heavyhandedness are choosing Path A because everything else is so darn complicated and risky indicates how bad Path B and C could get.
Path A is no walk in the park — it is going to have problems itself, just like regular Windows patching did in the past, and probably moreso, because of the unwieldy nature of the cumulative Rollup concept.
And just due to the MS slap-dash approach to some of these things.If you go with Path A, you won’t have to follow Woody’s posts as closely as you will have to if you choose Path B, but you will still need to follow Windows news and at least one good blogger/journalist such as Woody.
If you go with Path C, you will be more independent (and more vulnerable), but if you are going to operate a computer that is connected to the internet, you’ll still need to be aware of the major happenings in the Windows world as relates to security threats, and you’ll need to be extra careful about your internet activities, your ad and tracker blocking, your computer defense systems, etc.
Every path is probably going to be a time-consuming, somewhat-risky proposition. And that is really annoying, because this is not how it should be for ordinary home computer owners.
-
bravokilo
GuestNovember 29, 2016 at 2:52 am #20612I did my usual System Image, then ran Windows Update. Next reboot, and every second or third boot, I got a bsod.
Every time, a different driver caused the crash. I had gotten to the point that it HAD to be hardware…bad news for a laptop…when I saw the news here about the updated patch.
I put the last image back on, re- Windows Updated, and everything has been flawless since.This wasn’t just a Lenovo problem.
-
woody
Manager -
AlexEiffel
GuestNovember 29, 2016 at 9:17 am #20614Thanks poohsticks.
So for now, if I am in group B, I just need to have applied the October and November security updates?
Office and .Net updates are still pushed through Windows update?
Someone should write a little software to verify your patching status when you run group B.
I think I went group C for a month to decide if I would be B or A, but then I applied the November security only patch thinking I already applied the October one. I am glad those seems to be independent and you don’t need one before the other. That could not always be the case.
-
poohsticks
GuestNovember 29, 2016 at 8:15 pm #20615Yes, to be in Group B,
1. install the Oct and Nov security-only updates from the Update Catalog
2. install the .NET and Office updates that show up in your Windows UpdateWoody’s steps for Group B: http://www.infoworld.com/article/3136173/microsoft-windows/how-to-cautiously-update-windows-7-and-81-machines.html
The security-only updates are said to be independent of each other, and while everyone here has said that it would be better to install them in date order, I would expect that it would be fine for you to add your October after your November, if November is already on your computer.
-
bravokilo
Guest -
ch100
AskWoody_MVPNovember 30, 2016 at 1:44 am #20617Hmm, yesterday I have just encountered a problem with KB3197868 breaking certain Microsoft business applications over which I have little control. It is only an obscure functionality in those systems which is broken and this is why it took so long to be reported in the first place. The access to those systems is done in IE11 configured in IE8 Document Mode compatibility and I give Microsoft the benefit of doubt as they cannot test against every combination available in the wild and more than likely their answer would be that updated products which are not affected are available.
I had to uninstall KB3197868 and rollback to the October 2016 monthly update for the affected systems. I suspect the NTLM change of behaviour to be the more likely culprit rather than the IE security component, but this is only of academic interest while they come as a bundle and can normally be installed or uninstalled only as whole. Our good friend abbodi86 may contradict me, but we are talking about supported enterprise configurations here.
Home users or the smallest businesses have nothing to worry about, as those products are certainly not in use by those users. -
woody
Manager -
woody
Manager -
Bob?(Maybe?err…ok)
Guest -
ch100
AskWoody_MVP -
RODNEY COPELAND
GuestDecember 7, 2016 at 9:21 pm #20622“Only the detection mechanism — the “metadata’ — was changed”
as in an “if Lenovo, do not install” rule?
Yes = MS issues a security-only patch that clobbers Lenovo laptops (for example)… I read about it and refrain from installing the patch. MS re-issues the patch with a rule that prevents it from installing on a Lenovo laptop.
Now I am missing a security patch, unless they later re-issue the patch in a form that works for Lenovo laptops. Right?
-
woody
Manager
Viewing 17 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Update your Apple Devices Wormable Zero-Click Remote Code Execution in AirPlay..
by
Alex5723
7 minutes ago -
Amazon denies it had plans to be clear about consumer tariff costs
by
Alex5723
19 minutes ago -
Return of the brain dead FF sidebar
by
EricB
38 minutes ago -
windows settings managed by your organization
by
WSDavidO61
3 seconds ago -
Securing Laptop for Trustee Administrattor
by
PeachesP
4 hours, 23 minutes ago -
The local account tax
by
Susan Bradley
3 hours, 34 minutes ago -
Recall is back with KB5055627(OS Build 26100.3915) Preview
by
Alex5723
6 hours, 55 minutes ago -
Digital TV Antenna Recommendation
by
Win7and10
6 hours, 31 minutes ago -
Server 2019 Domain Controllers broken by updates
by
MP Support
18 hours, 48 minutes ago -
Google won’t remove 3rd party cookies in Chrome as promised
by
Alex5723
20 hours, 26 minutes ago -
Microsoft Manager Says macOS Is Better Than Windows 11
by
Alex5723
23 hours, 39 minutes ago -
Outlook (NEW) Getting really Pushy
by
RetiredGeek
2 hours, 4 minutes ago -
Steps to take before updating to 24H2
by
Susan Bradley
17 minutes ago -
Which Web browser is the most secure for 2025?
by
B. Livingston
6 hours, 31 minutes ago -
Replacing Skype
by
Peter Deegan
14 hours, 1 minute ago -
FileOptimizer — Over 90 tools working together to squish your files
by
Deanna McElveen
17 hours, 30 minutes ago -
Excel Macro — ask for filename to be saved
by
nhsj
1 day, 1 hour ago -
Trying to backup Win 10 computer to iCloud
by
SheltieMom
4 hours, 55 minutes ago -
Windows 11 Insider Preview build 26200.5570 released to DEV
by
joep517
2 days, 23 hours ago -
Windows 11 Insider Preview build 26120.3941 (24H2) released to BETA
by
joep517
3 days, 1 hour ago -
Windows 11 Insider Preview Build 22635.5305 (23H2) released to BETA
by
joep517
3 days, 1 hour ago -
No April cumulative update for Win 11 23H2?
by
Peobody
1 day, 13 hours ago -
AugLoop.All (TEST Augmentation Loop MSIT)
by
LarryK
3 days, 1 hour ago -
Boot Sequence for Dell Optiplex 7070 Tower
by
Serge Carniol
3 days, 16 hours ago -
OTT Upgrade Windows 11 to 24H2 on Unsupported Hardware
by
bbearren
3 days, 20 hours ago -
Inetpub can be tricked
by
Susan Bradley
2 days, 4 hours ago -
How merge Outlook 2016 .pst file w/into newly created Outlook 2024 install .pst?
by
Tex265
2 days, 14 hours ago -
FBI 2024 Internet Crime Report
by
Alex5723
4 days ago -
Perplexity CEO says its browser will track everything users do online
by
Alex5723
1 day, 9 hours ago -
Login issues with Windows Hello
by
CWBillow
4 days, 11 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.