More of the usual. KB 4034670 – Preview of the non-security part of next month’s Win 7 Monthly Rollup KB 4034663 – Preview of the non-security part of
[See the full post at: The usual non-security update previews are out, along with three non-security patches for Server 2008]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
The usual non-security update previews are out, along with three non-security patches for Server 2008
Home » Forums » Newsletter and Homepage topics » The usual non-security update previews are out, along with three non-security patches for Server 2008
- This topic has 31 replies, 10 voices, and was last updated 7 years, 6 months ago.
Tags: KB 4034663 KB 4034670 KB 4035038
AuthorTopicwoody
ManagerAugust 15, 2017 at 4:17 pm #129564Viewing 12 reply threadsAuthorRepliesky41083
AskWoody LoungerAugust 15, 2017 at 7:21 pm #129569Well, let’s start here… they have this list of issues to fix, some of which have been on this list since .NET 4.7 was first released.
https://support.microsoft.com/en-us/help/4015088/known-issues-in-the-net-framework-4-7
Most of those issues were recently fixed on Windows 10 1703 by a 1703 rollup. As .NET 4.7 is considered part of 1703, it gets patched by Windows only rollups, outside of and in addition to (I’m assuming) the usual .NET rollups. Annoyed yet?
Now, MS is trying to bring those fixes (if not more) to all the other supported platforms. To date, this list of known issues, and lack of reasonable fixes, is the reason I have not deployed .NET 4.7 yet.
My guess, they are trying to get the .NET releases right, so people finally start deploying .NET 4.7 in the enterprise…
1 user thanked author for this post.
abbodi86
AskWoody_MVPAugust 15, 2017 at 8:30 pm #129576FYI, since July 2017 Preview, 4.6/4.6.1/4.6.2/4.7 updates had been reconciled (Microsoft wording) into one rollup update for all of them, and it’s based on 4.7 version
so even if you don’t install 4.7, you still get its updates on top of your downlevel version starting 4.6
4.5.2 is still separate
-
ky41083
AskWoody LoungerAugust 15, 2017 at 8:54 pm #129577I don’t “think?” the .NET 4.7 bits apply if you are on an older .NET, say 4.6.2 for example. I know when I run ngen.exe it still outputs the version code for 4.6.2…
Then on machines where 1703 has been installed, I am seeing the newer version code for .NET 4.7 when executing ngen.exe.
Not sure if that means the 4.7 specific changes in the 4.7 tagged rollups sit and wait until 4.7 is installed, or, if those rollups would reappear in WU after a fresh 4.7 upgrade, to be reapplied… and probably won’t find out till the end of this month.
-
abbodi86
AskWoody_MVPAugust 15, 2017 at 9:38 pm #129586Well, i’m not saying this as analysis or opinion, it’s a fact 🙂
the rollup updates part of the installed Framework, not all of it, and the changes and installed 4.7 files will become active
for Windows 8.1 (CBS), installing 4.7 later will not need to reinstall the rollup
but for Windows 7 (MSI), the rollup needs reinstallation after 4.71 user thanked author for this post.
-
ky41083
AskWoody Lounger
-
-
MrBrian
AskWoody_MVPAugust 15, 2017 at 9:28 pm #129582Revision 101 of https://support.microsoft.com/en-us/help/894199/software-update-services-and-windows-server-update-services-changes-in doesn’t mention the .NET monthly preview rollups. Revision 99 that was current earlier today did mention the .NET monthly preview rollups.
-
MrBrian
AskWoody_MVPAugust 16, 2017 at 8:26 pm #129735The August 2017 .NET monthly preview rollups have reappeared at https://support.microsoft.com/en-us/help/894199/software-update-services-and-windows-server-update-services-changes-in.
1 user thanked author for this post.
anonymous
GuestAugust 15, 2017 at 9:32 pm #129578I would say that KB4019276 to add TLS 1.1 and 1.2 on Win 2008 SP2 is interesting.
It is not categorized as security by MS, nor is it a security patch in the usual sense. More like a feature add.
But I would say that this feature add once installed (and configured!) improves security for schannel dependent communications. Arguably to a great extent depending on what the services are.
-Jim1 user thanked author for this post.
anonymous
Guestanonymous
Guest-
PKCano
ManagerAugust 16, 2017 at 2:10 pm #129685The “Previews” are the pre-release of the Rollup.
For example, the “Preview” of the August 2017 Security Monthly Quality Rollup will contain the August Rollup + the non-security patches for September. In Sept, it will be combined with the security updates to make the September Rollup.Although it supposedly contains the finished next month’s non-security updates, it is really for testing for those who need to be sure it is “going to work.” So, unless you are in the testing mode, let someone else be the Guinea Pig.
It is usually a rule not to install unchecked updates anyway.
-
anonymous
GuestAugust 16, 2017 at 2:53 pm #129698
-
Geo
AskWoody Plusradosuaf
AskWoody LoungerAugust 17, 2017 at 2:05 am #129753No sign of block for Skylake in Windows 8.1 :). According to this one:
https://blogs.windows.com/windowsexperience/2016/01/15/windows-10-embracing-silicon-innovation/
they should be already starting to get us cut off :). Is anybody following the situation with Kaby Lake? Is the block present in the latest rollups?
Fractal Design Pop Air * Thermaltake Toughpower GF3 750W * ASUS TUF GAMING B560M-PLUS * Intel Core i9-11900K * 4 x 8 GB G.Skill Aegis DDR4 3600 MHz CL16 * ASRock RX 6800 XT Phantom Gaming 16GB OC * XPG GAMMIX S70 BLADE 1TB * SanDisk Ultra 3D 1TB * Samsung EVO 840 250GB * DVD RW Lite-ON iHAS 124 * Windows 10 Pro 22H2 64-bit Insider * Windows 11 Pro Beta Insiderky41083
AskWoody LoungerAugust 17, 2017 at 4:53 am #129760-
MrBrian
AskWoody_MVPAugust 18, 2017 at 8:00 am #129850You could ask at https://github.com/zeffy/wufuc.
1 user thanked author for this post.
-
ky41083
AskWoody LoungerAugust 19, 2017 at 11:16 pm #130033Ick, hate reading decompiled code… especially hate reading assembly code, makes my head hurt.
Based on what’s there, it would appear to be a static list that needs updating for marking additional CPU’s as “unsupported”. Unless I missed it, the actual list isn’t in the posted Github code, being that the Github code is just overriding the result returned from the function that looks at the list, not the actual list itself.
Based on the way the evaluation is written, it defaults the CPU type to “supported”, and only changes it to “unsupported” if the function that references the list returns a hit from said list.
Basically, all CPU’s default to supported, until they are added to a blacklist check MS clearly went out of the way to add, as this whole “IsCpuSupported” function did not exist in the code until very recently.
Which we more or less already knew. It is nice to see the code though. And going forward, know that CPU’s will default to supported, until MS gets around to adding them to the blacklist, and updating the blacklist via Windows updates.
So, to finally answer my own question, lol… newer CPU’s MS deems “unsupported” will in fact work, until they are cut off by a future update.
My big *** here and now is, what about hypervisors that pass through the CPU ID, rather than emulate it, like VMware. This blacklist check means you HAVE to run the Github posted memory patch referenced above, especially in an enterprise environment, in order to test future updates on Win 7/8.1 VM’s, hosted on systems using any blacklisted CPU.
1 user thanked author for this post.
-
ch100
AskWoody_MVPAugust 20, 2017 at 2:20 am #130037what about hypervisors that pass through the CPU ID, rather than emulate it, like VMware.
As far as I know, none of the hypervisors emulate CPU or RAM resources. They are managed, scheduled, but not emulated.
-
ky41083
AskWoody LoungerAugust 20, 2017 at 2:33 am #130039That’s how I meant it, and it’s too late to edit above now…
I meant, that hypervisors like VMware, don’t emulate the CPU to the guest, they use passthrough instead, because it’s more efficient.
Hypervisors like QEMU, do emulate the CPU to the guest, at an increase in overhead.
Hence, old VM’s migrated to new hardware will be immediately effected by all this, on the more efficient hypervisors enterprises are using.
-
ch100
AskWoody_MVPAugust 20, 2017 at 3:45 am #130044Hypervisors like QEMU, do emulate the CPU to the guest, at an increase in overhead.
XenServer hypervisor which uses QEMU emulation for I/O (without XenServer Tools installed) does passthrough of the CPU resources and RAM.
I don’t know of any hypervisor emulating CPU.
Maybe KVM? -
ky41083
AskWoody LoungerAugust 20, 2017 at 4:03 am #130046From: https://en.wikipedia.org/wiki/QEMU
“QEMU is a hosted virtual machine monitor: it emulates CPUs through dynamic binary translation and provides a set of device models, enabling it to run a variety of unmodified guest operating systems.”
You have to mix QEMU with things like Xen or KVM to remove the CPU emulation overhead. For example, using only QEMU’s I/O emulation layer on top of Xen, as you cited. From same source:
“QEMU is involved only in the emulation of hardware; the execution of the guest is done within Xen and is totally hidden from QEMU.”
KVM definitely doesn’t do CPU emulation, and can interact similarly with QEMU like Xen does.
Basically, the CPU passthrough you are seeing on Xen, is the Xen layer, not the QEMU layer.
1 user thanked author for this post.
-
-
-
MrBrian
AskWoody_MVPAugust 20, 2017 at 6:22 am #130051
-
abbodi86
AskWoody_MVPAugust 18, 2017 at 3:06 pm #129916.NET 4.7 (involve 4.6.x) got OOB updates
https://support.microsoft.com/en-us/help/4038923/
https://support.microsoft.com/en-us/help/4038922/
https://support.microsoft.com/en-us/help/4038921/PerthMike
AskWoody PlusAugust 23, 2017 at 11:54 pm #130451I would say that KB4019276 to add TLS 1.1 and 1.2 on Win 2008 SP2 is interesting. It is not categorized as security by MS, nor is it a security patch in the usual sense. More like a feature add. But I would say that this feature add once installed (and configured!) improves security for schannel dependent communications. Arguably to a great extent depending on what the services are. -Jim
Indeed, I find this VERY interesting, since it really does qualify as a security patch if you run any sort of web server (in our case, our OWA) on a 2008 non-R2 server. Suddenly adding TLS 1.2 support to an internet-facing web server is a bit security fix for us.
Looks like there’s already been reports that installing this patch breaks FTP functionality (somehow messes up the ftp protocol packets), but I can live with that.
No matter where you go, there you are.
-
anonymous
GuestAugust 24, 2017 at 7:57 pm #130551Anyone faces any issue on the patch KB4019276 for supporting TLS 1.2 client? We installed the patch in our Windows Server 2008 SP2, and even though the TLS 1.2 server works, but the client does not, meaning we cannot connect to our client’s web API successfully because the client’s web API only supports TLS 1.2 which are not supported by sChannel in Windows Server 2008 SP2.
Anyone is aware of whether Microsoft plans to come out with the updated cipher suites for TLS 1.2 for Windows Server 2008 SP2?
abbodi86
AskWoody_MVPAugust 31, 2017 at 11:59 am #131469It seems .NET is going to get new Rollups soon (tonight?), and they are Security ones
https://support.microsoft.com/en-us/help/4035038
Notice
Previously, the .NET Framework Preview of Quality Rollup (KB 4035038) was released as an optional update. The improvements that were delivered in the Preview of Quality Rollup are now available in a Security and Quality Rollup (KB 4039114) as a recommended update. No new improvements were added since the Preview of Quality Rollup was released.
-
woody
Manager -
abbodi86
AskWoody_MVPAugust 31, 2017 at 8:19 pm #131554Well, nothing out yet (too early KB revision?)
but it’s interesting to see that KB4035038 article description itself and all sub-articles changed from “August 2017 Preview Rollups” to “Security and Quality Rollups”
this only applies to Windows 8.1 articles, Windows 7 still have the old description
https://support.microsoft.com/en-us/help/4035036 -
ch100
AskWoody_MVP
-
-
Viewing 12 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Latest Firefox requires Password on start up
by
Gordski
3 hours, 16 minutes ago -
Resolved : AutoCAD 2022 might not open after updating to 24H2
by
Alex5723
7 hours, 38 minutes ago -
Missing api-ms-win-core-libraryloader-11-2-1.dll
by
IreneLinda
3 hours, 29 minutes ago -
How Much Daylight have YOU Saved?
by
Nibbled To Death By Ducks
4 hours, 12 minutes ago -
A brief history of Windows Settings
by
Simon Bisson
3 hours, 9 minutes ago -
Thunderbolt is not just for monitors
by
Ben Myers
4 hours, 17 minutes ago -
Password Generators — Your first line of defense
by
Deanna McElveen
3 hours, 30 minutes ago -
AskWoody at the computer museum
by
Will Fastie
3 hours, 50 minutes ago -
Planning for the unexpected
by
Susan Bradley
4 hours, 48 minutes ago -
Which printer type is the better one to buy?
by
Bob99
9 hours, 23 minutes ago -
Upgrading the web server
by
Susan Bradley
7 hours, 48 minutes ago -
New Windows 11 24H2 Setup – Initial Win Update prevention settings?
by
Tex265
1 day, 2 hours ago -
Creating a Google account
by
DavidofIN
1 day, 1 hour ago -
Undocumented “backdoor” found in Bluetooth chip used by a billion devices
by
Alex5723
1 day, 8 hours ago -
Microsoft Considering AI Models to Replace OpenAI’s in Copilot
by
Alex5723
1 day, 19 hours ago -
AI *emergent misalignment*
by
Alex5723
1 day, 20 hours ago -
Windows 11 Disk Encryption/ Bitlocker/ Recovery Key
by
Tex265
4 hours, 20 minutes ago -
Trouble signing out and restarting
by
Tech Hiker
20 hours, 56 minutes ago -
Windows 7 MSE Manual Updating
by
Microfix
2 days, 4 hours ago -
Problem running LMC 22 flash drive
by
Charlie
1 day, 3 hours ago -
Outlook Email Problem
by
Lil88reb
1 day, 3 hours ago -
“Microsoft 365 Office All-in-One For Dummies, 3rd Edition FREE
by
Alex5723
1 day, 11 hours ago -
Cant use Office 2013 – Getting error message about Office 2013
by
SAAR
2 days, 4 hours ago -
Nearly 1 million Windows devices targeted in advanced “malvertising” spree
by
bbearren
2 days, 4 hours ago -
Windows 11 Insider Preview build 27808 released to Canary
by
joep517
3 days, 5 hours ago -
Windows 11 Insider Preview Build 22635.5025 (23H2) released to BETA
by
joep517
3 days, 5 hours ago -
Sysprep issue
by
Evit
3 days, 4 hours ago -
Android Security Bulletin—March 2025
by
Alex5723
3 days, 7 hours ago -
23h2: PIN TO START randomly available on right-click
by
dataman1701
3 days, 7 hours ago -
Microsoft Defender
by
agoldhammer
3 days, 13 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.