Re: Patch listing for MS products

From: Herb Martin (news_at_LearnQuick.com)
Date: 03/28/05


Date: Mon, 28 Mar 2005 15:34:23 -0600


"Desmond Lee" <mcp@donotspamplease.mars> wrote in message
news:4221A8AF-FF36-4420-ABB1-6A32A5A43E27@microsoft.com...
> A good place to start is:
>
> http://www.microsoft.com/technet/security/current.aspx
>
> Also, consider using SUS (or forthcoming WSUS) that allows you to setup an
> internal security patch management software. It works very well with Win
2000
> SP3 / Win XP SP1 and above.
>
> More info:
>
> http://www.microsoft.com/windowsserversystem/sus/default.mspx
>

Also MBSA (Microsoft Baseline Security Analyzer) has
much of this info.

And actually the included (and frequently updated)
MSSecure.XML file has this information within it.
(downloaded as MSSecure.cab).

It isn't perfect, but it is one of the most complete listings.

This file or a similar file is also included in SUS downloads.
(It may not be the same since SUS only supports a subset of
the updates, but this has been increased in each new version.)

It is of course, not particularly convenient to read, as it's
format and structure were designed for automata tools
like MBSA and not for humans but it is in text (XML) and
can be read, or processed.



Relevant Pages

  • Re: MBSA with SUS or Windows Update
    ... MBSA 1.2 detects a patches for number of categories of software ... that are not covered by the current version of Sus. ... Where MBSA is showing things not listed by Windows Update, ...
    (microsoft.public.security)
  • Re: SUS -- is it really this lacking?
    ... Good news, according to a public post at www.susserver.org, SUS 2.0 fixes ... available news reports, might be out in first quarter 2004. ... MBSA is free. ... This would ensure that machines are scanned regularly. ...
    (microsoft.public.security)
  • Re: KB823718 keeps reinstalling after CRM SFO setup
    ... This looks like an error in both MBSA and SUS. ... > Outlook installs MSDE as part of the install. ... > SQL server SP3a which reinstalls the MDAC component. ...
    (microsoft.public.windows.server.sbs)
  • Scanning remote pcs w/ MBSA & SUS...
    ... I'm trying to implement MBSA and SUS into my current environment. ... computers w/ MBSA and update them w/ approved updates through SUS. ... Normally MBSA uses ports 139 & 445, ...
    (microsoft.public.inetserver.iis)
  • Problems with MS03-043 update
    ... When I run MBSA on my Xp clients, it tells me I need the MS03-043 update. ... have approved that update on SUS, it shows in the approval log. ... The local Windows Update log files look normal. ... Why does MBSA think I need to load a version 1309? ...
    (microsoft.public.security)