Re: Surprise! Windows Updates

From: Matthew Mucker (mattmu_at_MICROSOFT.COM)
Date: 05/18/05

  • Next message: Jeremy Brooks: "Re: Bug in server 2003 DNS policy setting"
    Date:         Wed, 18 May 2005 13:01:55 -0700
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    This is a common misunderstanding.

    The use of the word "critical" on Windows Update is *not* the same thing
    as the use of the word "critical" in the context of a security update.

    So, Windows Update can have "critical" non-security updates. (I don't
    know the rating system for non-security updates so I can't comment on
    what makes one "critical.")

    This has caused no end of confusion and is, I believe, going to be
    remedied when Microsoft goes to the next version of Windows Update that
    supports WSUS/MBSA 2/MU.

    -Matt

    -----Original Message-----
    From: Windows NTBugtraq Mailing List
    [mailto:NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM] On Behalf Of Angus
    Scott-Fleming
    Sent: Wednesday, May 18, 2005 1:40 PM
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    Subject: Surprise! Windows Updates

    Early this morning I was logged on remotely to a Windows 2000
    Server that I manage and a Windows XP box on the same network
    checking their Windows Update status, and when I did a manual
    WU scan, both of them needed a "critical" update to Windows
    Installer 3.1 http://support.microsoft.com/kb/893803 (Last
    Review: May 13, 2005). My own XP box needed that AND an
    update to Microsoft .NET Framework 1.1 Service Pack 1,
    http://support.microsoft.com/?kbid=867460 (Last Review: May
    12, 2005). Both of these post-date the May Windows Update
    release (last Tuesday, May 10), which all machines had already
    had installed.

    Neither of these shows up on the MS Security Bulletin page or
    on the Security Advisories page.

    Anyone else come across these? I have my systems set to
    download updates automatically but not to install them, and
    just as I was typing this message the Windows Installer 3.1
    update appeared in the automatic-updates-are-ready- to-install
    icon on my XP box. However, the update to .NET did NOT appear
    in the automatic update while it DID appear when I did a
    manual WU run.

    Anyone else seen this or have more info?

    Angus

    --
    NTBugtraq Editor's Note:
    Most viruses these days use spoofed email addresses. As such, using an
    Anti-Virus product which automatically notifies the perceived sender of
    a message it believes is infected may well cause more harm than good.
    Someone who did not actually send you a virus may receive the
    notification and scramble their support staff to find an infection which
    never existed in the first place. Suggest such notifications be disabled
    by whomever is responsible for your AV, or at least that the idea is
    considered.
    --
    --
    NTBugtraq Editor's Note:
    Most viruses these days use spoofed email addresses. As such, using an Anti-Virus product which automatically notifies the perceived sender of a message it believes is infected may well cause more harm than good. Someone who did not actually send you a virus may receive the notification and scramble their support staff to find an infection which never existed in the first place. Suggest such notifications be disabled by whomever is responsible for your AV, or at least that the idea is considered.
    --
    

  • Next message: Jeremy Brooks: "Re: Bug in server 2003 DNS policy setting"

    Relevant Pages

    • Re: IE patches killed internet connection
      ... IE to download/install from Windows Update manually, so don't even try using Firefox. ... Later, Auto Update reoffered the security update, but I was ... Microsoft.com to try to download manually, but I have to use Firefox to ... install all patches offered except for SP2. ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Time out error on Windows Update
      ... In the security tab, make sure you aren't blocking AcitveX. ... You may need to add Windows Update to the Trusted Sites Zone: ... Clearing Temporary Internet files, cookies and history in Internet Explorer ... It is possible that the contents of the SoftwareDistribution folder have become corrupted, ...
      (microsoft.public.windowsupdate)
    • Re: Cant update. Scan never finishes
      ... In the security tab, make sure you aren't blocking AcitveX. ... You may need to add Windows Update to the Trusted Sites Zone: ... Clearing Temporary Internet files, cookies and history in Internet Explorer ... It is possible that the contents of the SoftwareDistribution folder have become corrupted, ...
      (microsoft.public.windowsupdate)
    • Re: Problem with Windows Update for XP x64 (no error message).
      ... Start a free Windows Update support incident request: ... Support for Windows Update: ... There is no-charge for support calls that are associated with security updates. ... Content Install Reboot completed. ...
      (microsoft.public.windowsupdate)
    • [Error number: 0x800A0046]
      ... Please change your Internet Explorer security settings ... To save changes to your settings for this website, ... Click the Security tab, click the Internet security zone icon, and then ... Open the account used to access Windows Update. ...
      (microsoft.public.windowsxp.security_admin)