Looks like they were all pulled, then re-issued, to minimize the impact on Lenovo servers. If you got yours installed, no need to do anything. InfoWor
[See the full post at: The full story on the Nov 23 re-issue of KB 3197873, 3197874, 3197876, 3197877, 3193479, 3200970]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
The full story on the Nov 23 re-issue of KB 3197873, 3197874, 3197876, 3197877, 3193479, 3200970
Home » Forums » Newsletter and Homepage topics » The full story on the Nov 23 re-issue of KB 3197873, 3197874, 3197876, 3197877, 3193479, 3200970
- This topic has 18 replies, 3 voices, and was last updated 8 years, 6 months ago.
AuthorTopicwoody
ManagerNovember 28, 2016 at 9:10 am #20605Viewing 17 reply threadsAuthorReplies-
Seff
Guest -
woody
Manager -
Seff
Guest -
AlexEiffel
GuestNovember 28, 2016 at 4:24 pm #20609Woody, sorry for my ignorance, but I am not sure I understand what happens if a patch gets pulled then reissued. If I installed a patch like 3197867 then it got pulled then reissued, do I need to reinstall it again because it changed?
And how can you know if that happened at all? It is not like you go to the Microsoft Update Catalog and find there is a new version of the patch announced to you like you do on your site? So what, are we forced to read your blog forever, then? Not that I don’t like it, but it is a bit scary to run an OS for which you can’t easily know what is patched properly and what is missing. Fragmentation seems much more easy to happen for group B than in the era before this new way of patching.
-
woody
ManagerNovember 28, 2016 at 6:12 pm #20610In this case, no, the re-issued patch is identical to the original patch. All that changed (we subsequently found out) is the installation detection logic.
Yep, this site keeps on top of the details. If you don’t want to deal with the details, just watch for the MS-DEFCON rating and follow the instructions.
You’re right. All sorts of things were easier before the patchocalypse.
-
poohsticks
GuestNovember 28, 2016 at 9:53 pm #20611Re: “what happens if a patch gets pulled then reissued. …do I need to reinstall it again because it changed?”
It is my understanding that yes, sometimes you will want to uninstall a patch that has been pulled after you had initially installed it, and then install the reissued version of the patch.
In this particular case, the old patch is not different to new patch, so the old patch can stay on the system and you don’t have to take any action. I am not an expert, but I am guessing that this will not always be the way it works, unfortunately.
I think that I am correct in saying that even with the former Windows 7/8 updating system, sometimes, rarely, there was a patch or a hotfix that required some manual intervention on the part of the computer owner to get *exactly right*, despite all the automatic patching that the computer owner was allowing MS to do on his/her computer.
And Microsoft’s announcements of this kind of thing were not widespread and often would not be known about by most ordinary computer owners. There were times I stumbled across such advice when I was looking up an unrelated computer question online. (This was before I was forced to become a regular visitor to sites such as Wilders Security Forum, SevenForums, GHacks, Susan Bradley’s, Woody’s, others.)
—
Re: “And how can you know if that happened at all? …are we forced to read your blog forever, then? […] Fragmentation seems much more easy to happen for group B….”I don’t think that ordinary computer owners are going to know that this sort of thing has happened, unless they keep abreast of Windows news in general, or regularly follow at least one good, focused website, like AskWoody.com is.
The Group B path is quite risky in some ways. It’s only “meant” for IT professionals to follow on behalf of their firms.
And even for those seasoned people, they probably are pretty nervous about it because it’s an unknown, untested path and Microsoft is sometimes so slap-dash about things, especially things that they wish didn’t exist in the first place.Path A is pushed so, so strongly by AskWoody.com contributor CH100 in part because he is understandably really worried about people getting locked into a continuous (checking in every few weeks, at a minimum) reliance on Woody’s voluntary help in guiding them precisely in how to navigate path B.
If, for any reason, the Group B people who are ordinary home computer owners reached a point where they were no longer able to get careful, constant, high-quality help from Woody (or someone similar – and there isn’t anyone similar!), they are going to have to know what to do on their own, and they might wish at that time to move to Group A or C rather than deal with the complications.
This is such a tough decision to make, because every conceivable path forward has some big downsides and risks.
The fact that some IT-industry people (current and retired) are choosing Path C
(= to accept no Windows updates at all, despite the many security dangers there are out in the world… just read a week’s worth of a site like krebsonsecurity.com and it will be clear what sort of dangers that good people are up against, and it’s getting worse all the time)
for themselves and the people they care about indicates how bad some aspects of Path A and B must be.The fact that some individuals, including IT experts, who are seriously privacy-conscious and anti-Microsoft’s-heavyhandedness are choosing Path A because everything else is so darn complicated and risky indicates how bad Path B and C could get.
Path A is no walk in the park — it is going to have problems itself, just like regular Windows patching did in the past, and probably moreso, because of the unwieldy nature of the cumulative Rollup concept.
And just due to the MS slap-dash approach to some of these things.If you go with Path A, you won’t have to follow Woody’s posts as closely as you will have to if you choose Path B, but you will still need to follow Windows news and at least one good blogger/journalist such as Woody.
If you go with Path C, you will be more independent (and more vulnerable), but if you are going to operate a computer that is connected to the internet, you’ll still need to be aware of the major happenings in the Windows world as relates to security threats, and you’ll need to be extra careful about your internet activities, your ad and tracker blocking, your computer defense systems, etc.
Every path is probably going to be a time-consuming, somewhat-risky proposition. And that is really annoying, because this is not how it should be for ordinary home computer owners.
-
bravokilo
GuestNovember 29, 2016 at 2:52 am #20612I did my usual System Image, then ran Windows Update. Next reboot, and every second or third boot, I got a bsod.
Every time, a different driver caused the crash. I had gotten to the point that it HAD to be hardware…bad news for a laptop…when I saw the news here about the updated patch.
I put the last image back on, re- Windows Updated, and everything has been flawless since.This wasn’t just a Lenovo problem.
-
woody
Manager -
AlexEiffel
GuestNovember 29, 2016 at 9:17 am #20614Thanks poohsticks.
So for now, if I am in group B, I just need to have applied the October and November security updates?
Office and .Net updates are still pushed through Windows update?
Someone should write a little software to verify your patching status when you run group B.
I think I went group C for a month to decide if I would be B or A, but then I applied the November security only patch thinking I already applied the October one. I am glad those seems to be independent and you don’t need one before the other. That could not always be the case.
-
poohsticks
GuestNovember 29, 2016 at 8:15 pm #20615Yes, to be in Group B,
1. install the Oct and Nov security-only updates from the Update Catalog
2. install the .NET and Office updates that show up in your Windows UpdateWoody’s steps for Group B: http://www.infoworld.com/article/3136173/microsoft-windows/how-to-cautiously-update-windows-7-and-81-machines.html
The security-only updates are said to be independent of each other, and while everyone here has said that it would be better to install them in date order, I would expect that it would be fine for you to add your October after your November, if November is already on your computer.
-
bravokilo
Guest -
ch100
AskWoody_MVPNovember 30, 2016 at 1:44 am #20617Hmm, yesterday I have just encountered a problem with KB3197868 breaking certain Microsoft business applications over which I have little control. It is only an obscure functionality in those systems which is broken and this is why it took so long to be reported in the first place. The access to those systems is done in IE11 configured in IE8 Document Mode compatibility and I give Microsoft the benefit of doubt as they cannot test against every combination available in the wild and more than likely their answer would be that updated products which are not affected are available.
I had to uninstall KB3197868 and rollback to the October 2016 monthly update for the affected systems. I suspect the NTLM change of behaviour to be the more likely culprit rather than the IE security component, but this is only of academic interest while they come as a bundle and can normally be installed or uninstalled only as whole. Our good friend abbodi86 may contradict me, but we are talking about supported enterprise configurations here.
Home users or the smallest businesses have nothing to worry about, as those products are certainly not in use by those users. -
woody
Manager -
woody
Manager -
Bob?(Maybe?err…ok)
Guest -
ch100
AskWoody_MVP -
RODNEY COPELAND
GuestDecember 7, 2016 at 9:21 pm #20622“Only the detection mechanism — the “metadata’ — was changed”
as in an “if Lenovo, do not install” rule?
Yes = MS issues a security-only patch that clobbers Lenovo laptops (for example)… I read about it and refrain from installing the patch. MS re-issues the patch with a rule that prevents it from installing on a Lenovo laptop.
Now I am missing a security patch, unless they later re-issue the patch in a form that works for Lenovo laptops. Right?
-
woody
Manager
Viewing 17 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
National scam day
by
Susan Bradley
1 hour, 8 minutes ago -
macOS Tahoe 26 the end of the road for Intel Macs, OCLP, Hackintosh
by
Alex5723
3 hours, 20 minutes ago -
Cyberattack on some Washington Post journalists’ email accounts
by
Bob99
4 hours, 40 minutes ago -
Tools to support internet discussions
by
Kathy Stevens
11 hours, 30 minutes ago -
How get Group Policy to allow specific Driver to download?
by
Tex265
9 hours, 50 minutes ago -
AI is good sometimes
by
Susan Bradley
11 hours, 52 minutes ago -
Mozilla quietly tests Perplexity AI as a New Firefox Search Option
by
Alex5723
1 hour, 55 minutes ago -
Perplexity Pro free for 12 mos for Samsung Galaxy phones
by
Patricia Grace
1 day, 12 hours ago -
June KB5060842 update broke DHCP server service
by
Alex5723
1 day, 10 hours ago -
AMD Ryzen™ Chipset Driver Release Notes 7.06.02.123
by
Alex5723
1 day, 14 hours ago -
Excessive security alerts
by
WSSebastian42
5 hours, 31 minutes ago -
* CrystalDiskMark may shorten SSD/USB Memory life
by
Alex5723
2 days ago -
Ben’s excellent adventure with Linux
by
Ben Myers
1 hour, 29 minutes ago -
Seconds are back in Windows 10!
by
Susan Bradley
1 day, 11 hours ago -
WebBrowserPassView — Take inventory of your stored passwords
by
Deanna McElveen
4 hours, 58 minutes ago -
OS news from WWDC 2025
by
Will Fastie
15 hours, 17 minutes ago -
Need help with graphics…
by
WSBatBytes
19 hours, 31 minutes ago -
AMD : Out of Bounds (OOB) read vulnerability in TPM 2.0 CVE-2025-2884
by
Alex5723
2 days, 15 hours ago -
Totally remove or disable BitLocker
by
CWBillow
1 day, 14 hours ago -
Windows 10 gets 6 years of ESU?
by
n0ads
1 day, 18 hours ago -
Apple, Google stores still offer China-based VPNs, report says
by
Nibbled To Death By Ducks
3 days, 2 hours ago -
Search Forums only bring up my posts?
by
Deo
11 hours, 5 minutes ago -
Windows Spotlight broken on Enterprise and Pro for Workstations?
by
steeviebops
3 days, 14 hours ago -
Denmark wants to dump Microsoft for Linux + LibreOffice
by
Alex5723
3 days, 6 hours ago -
How to get Microsoft Defender to honor Group Policy Setting
by
Ralph
3 days, 14 hours ago -
Apple : Paragon’s iOS Mercenary Spyware Finds Journalists Target
by
Alex5723
4 days ago -
Music : The Rose Room – It’s Been A Long, Long Time album
by
Alex5723
4 days, 1 hour ago -
Disengage Bitlocker
by
CWBillow
3 days, 15 hours ago -
Mac Mini M2 Service Program for No Power Issue
by
Alex5723
4 days, 3 hours ago -
New Win 11 Pro Geekom Setup questions
by
Deo
10 hours, 53 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.