Jump to content

Microsoft delays its usual Patch Tuesday updates


Recommended Posts

Posted

Source: Microsoft (Via ZDNet)

 

Microsoft officials posted a terse note on the company's site about the unusual circumstance:

 

"Our top priority is to provide the best possible experience for customers in maintaining and protecting their systems. This month, we discovered a last minute issue that could impact some customers and was not resolved in time for our planned updates today.

 

"After considering all options, we made the decision to delay this month's updates. We apologize for any inconvenience caused by this change to the existing plan."

 

I've asked Microsoft if there's any more information about the reasons for the delay and how long this delay is likely to last. No word back so far.

 

This may be the first time ever since it began releasing security patches on the second Tuesday of each month that Microsoft didn't actually deliver any on the specified day.

 

As my ZDNet colleague Zack Whittaker tweeted, today's delay means there's no patch so far for the Windows SMB bug which has public exploit code.

 

Microsoft modified its patching schedule last year. But The second Tuesday of the month remains the regularly scheduled Patch Tuesday. Any security-specific fixes for Office are slated to show up on that day, along with the bulk of the rest of Microsoft's security and non-security patches and fixes across its product line.

  • Thanks 3
  • 4 weeks later...
Posted

Here's the changelog for this months Patch Tuesday update. It's huge! :eek:

 

https://support.microsoft.com/en-us/help/4013429/windows-10-update-kb4013429

 

This update includes quality improvements. No new operating system features are being introduced in this update. Key changes include:

 

  • Addressed known issue called out in KB3213986. Users may experience delays while running 3D rendering apps with multiple monitors.
  • Addressed issue in KB3213986 where the Cluster Service may not start automatically on the first reboot after applying the update.
  • Addressed issue where the Active Directory Administrative Center (ADAC) crashes when attempting to modify any attribute of any user account in Active Directory.
  • Addressed issue where the Japanese Input Method Editor is leaking graphics device interface resources, which causes windows to disappear or only partially render after typing approximately 100 sentences.
  • Addressed an issue which improves the reliability of Enable-ClusterS2D PowerShell cmdlet.
  • Addressed an issue where the Virtual Machine Management Service (Vmms.exe) may crash during a live migration of virtual machines.
  • Improved the bandwidth of SSD/NVMe drives available to application workloads during S2D rebuild operations.
  • Addressed issue where Work Folders clients get duplicate files (sync conflict files) when Work Folders is configured using Group Policy.
  • Addressed an issue where Remote Desktop Servers crash with a Stop 0x27 in RxSelectAndSwitchPagingFileObject when RDP clients connect and utilize redirected drives, printers, or removable USB drives.
  • Addressed issue where adjusting the Windows Server Update Services settings using the Group Policy feature causes downloads to fail.
  • Addressed issue to hard code Microsoft's first-party provider registry key values.
  • Addressed issue that causes the System Preparation (Sysprep) tool to fail.
  • Addressed issue that causes Office 2016 profile corruption when used with User Experience Virtualization (UE-V) roaming.
  • Addressed issue that causes the Local Security Authority Subsystem Service to become unresponsive after upgrading the OS.
  • Addressed issue that causes the Local Security Authority Subsystem Service to fail when a SAP® application uses Transport Layer Security authentication.
  • Addressed issue where sequencing large registries using the Application Virtualization 5.1 Sequencer results in missing registry keys in the final package.
  • Addressed issue that fails to retain the sort order of names in a contact list after a device restarts when using the Japanese language.
  • Addressed issue that causes transactions to fail because of a memory shortage.
  • Addressed issue that allows files that are forbidden by the security zone setting to be opened in Internet Explorer.
  • Addressed issue that causes Internet Explorer 11 to fail after installing KB3175443.
  • Addressed issue that causes applications that use the VBScript engine to fail after applying KB3185319.
  • Addressed issue that occurs in Internet Explorer when the CSS float style is set to "center" in a webpage.
  • Addressed issue that occurs whenever the multipath IO attempts to log I/O statistics with no paths present.
  • Addressed issue that causes a 32-bit static route added by a VPN solution to fail, which prevents users from establishing a connection through the VPN.
  • Addressed issue that may decrease performance by up to 50% when Ethernet adapters that support receive side scaling (RSS) fail to re-enable RSS after a fault or system upgrade.
  • Addressed issue to allow wildcards in the Allowed list field for the Point and Print Restrictions Group Policy.
  • Addressed issue with multipath I/O failure that can lead to data corruption or application failures.
  • Addressed issue that can lead to system failure when removing a multipath IO ID_ENTRY.
  • Addressed issue that occurs when a Network Driver Interface Specification function NdisMFreeSharedMemory() is not called at the correct Interrupt Request Level.
  • Addressed issue to utilize the proper service vault for Azure Backup integration.
  • Addressed issue where SQL server takes 30 minutes to shut down on machines with a lot of RAM (>2TB).
  • Addressed additional issues with updated time zone information, Internet Explorer, file server and clustering, wireless networking, Map apps, mobile upgrades for IoT, display rendering, USB 2.0 safe removal, multimedia, Direct3D, Microsoft Edge, enterprise security, Windows Server Update Services, storage networking, Remote Desktop, clustering, Windows Hyper-V, and Credential Guard.
  • Security updates to Microsoft Edge, Internet Explorer, Microsoft Graphics Component, Internet Information Services, Windows SMB Server, Microsoft Windows PDF Library, Windows kernel-mode drivers, Microsoft Uniscribe, the Windows kernel, DirectShow, the Windows OS, and Windows Hyper-V.

If you installed earlier updates, only the new fixes contained in this package will be downloaded and installed on your device.

Posted (edited)

^ On Win10 Enterprise 1607 I haven't seen any problems so far with ~12 or so computers installed. Test hosts also came back cleanly.

 

I have just spotted this in /r/sysadmin though:

 

 

Been chasing this issue down today. Apparently both of the recent Security Roll-ups (KB4012213 - March 2017 Security Only Quality Update for Windows 8.1 and Windows Server 2012 R2 KB4012216 - March 2017 Security Monthly Quality Rollup for Windows 8.1 and Windows Server 2012 R2) contain a patch that modifies logging behavior.

 

We noticed that as of the most recent patching cycle we lost Authentication Success/Fail notifications (ID 4768). After removing both roll-ups logging events starting appearing again for 4768.

 

This may also affect KB4012212 and KB4012215 (Windows 7 SP1 and Windows Server 2008 R2 SP1), but have not validated that.

 

Which is something of a showstopper.

Edited by pete
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...