Jump to content

Recommended Posts

Posted

Hello

 

As like probably most other people here, when we found out about the wannacry situation we all panicked and wondered if we where protected from the smb vulnerability.

 

So, at my place we had no wsus so we quickly installed it, approved wannacry related updates and started a deployment as quick as we could reboot our machines.

 

However, when you add updates to wsus for approval. Somehow I've ended up with multiple different ones, all for the same kb number. So I'll have a 32bit and 64bit etc.

 

Also we have a very wide range of OS here. Windows xp, 7,8,8.1,10 and windows pos ready/embedded.

 

Also, the media seemed to publicise one particular security update, but I've since discovered that one released in may(later than the publicised one) actually contained the patch too.

 

So I've approved this too. And now I'm properly confused in wsus and finding out if I'm protected.

 

So I suppose my question is, is there a definitive list somewhere of what updates I can approve to ensure we are protected. And does this said list protect each version of windows I have?

 

I'm properly confused with this whole superseding thing etc too. I basically just want to know simply if I'm protected. And to be able to produce a report.

 

Finally, most of my machines in wsus show 99% even though I knew they've installed the updates I've approved. Not sure why this is.

 

Thanks

Posted

Well you have 2 ways of looking at this...

1. The way you are now which is kind of tunnel vision as you are aiming to protect yourself against Wannacry but ignoring every other exploit/patch out there.

2. Patch your machines completely so you are up-to-date and protected from both Wannacry and any other threat out there that Microsoft has patched.

 

Also if you truely want to cover off protecting against Wannacry you need to disable SMBv1 across all your machines.

 

I would create groups in WSUS for your OS types and then approve updates that are needed accordingly.

 

Every month Microsoft releases updates that are cumulative meaning they are wrapped up together (think mini service packs).

Example - May week 1 has 2 updates, week 2 has 1, week 3 has 5 and week 4 is the cumulative which is all of those wrapped up into 1.

 

Superseded is of a similar nature where Microsoft release a patch but then the next weeks patch has the previous patch/code in it also hence week 1 being replaced/superseded by week 2.

 

Personal suggestion is to patch all needed to cover your a**, especially in today's mess of viruses and exploits.

Posted

Hi,

 

I do understand what your saying and ideally I would approve all updates, however for speed, I just want to patch for this outbreak.

 

So these monthly updates then, is there some how a way to get a list of these, for each Windows version, so I can JUST approve those?

 

Thanks

Posted

You will need to google "windows X cumulative update may 2017", replace X with whatever version and then get the KB numbers that way making sure you get the x86 or x64 version where appropriate, will take 10 mins tops.

 

You will also need to google toe windows xp patch separately (easy search as it's the only Windows xp patch since retirement).

 

Finally you will want to find the nice SMBv1 disable script which is on the technet user made tools section that you can deploy via GPO.

Posted

Have a look at EduGeek.net - WannaCry Ransomware – Info, Patches & tips to disable SMBv1--Windows Patches if you haven't seen it already. That nicely pulls together lots of information that is in various different threads on here about which updates are needed for each OS version.

 

Secondly, I may be wrong, but I don't think the May updates address the specific SMB vulnerability that WannaCry used. It was the April updates that did that, which I think are the ones listed on that page.

Posted

Secondly, I may be wrong, but I don't think the May updates address the specific SMB vulnerability that WannaCry used. It was the April updates that did that, which I think are the ones listed on that page.

This is interesting and MS don't help with their wording. Some places I read that the monthly patches are fully cumulative i.e. the May patch contains everything from the last major baseline (the "Convenience" update) and in other places I read you need each monthly patch one after the other.

 

@Arthur what's your take on it? The update sizes seem to suggest the May update does cover everything back and on the reference image I'm building at present I've done this...

 

Windows 7 x64 SP1

Servicing Stack Update

Convenience Update

May 2017 Monthly Security Quality Rollup

 

When I run a check for updates afterwards I don't get offered anything pre-May but I still wouldn't bet money on it :confused:

Posted
You're right, Cumulative is just that. It should contain all previous patches.

 

I stand corrected. I was about to post this link and suggest that monthly rollups only bundled together the updates for that particular month, but then I found this later article which specifically states that yes, monthly rollups do now include previous rollups, so you just need the most recent one (along with the convenience update) to be up to date.

  • Thanks 1
Posted (edited)
I stand corrected. I was about to post this link and suggest that monthly rollups only bundled together the updates for that particular month, but then I found this later article which specifically states that yes, monthly rollups do now include previous rollups, so you just need the most recent one (along with the convenience update) to be up to date.

 

Yup! Hence why I just patch once a month to save time and hassle.

 

Patches not covered under the cumulative are Adobe and Malware so if your are patching properly each month you should have 3 patches, the cumulative, Adobe and Malware.

Edited by Tefters
Posted
thanks guys, so is there a URL someone can share with me that lists all of the may updates for each windows version?
Posted

ok, so I've managed to find

May Rollup: KB4019264

Windows 7 32, Windows 7 64, Windows Embedded 7 32, Windows Embedded 7 64

 

and

May Rollup: KB4019215

Windows 8.1 32, Windows 8.1 64

 

 

but I cant find the Windows 8, or 10 versions :/ please help!

Posted (edited)
thanks guys, so is there a URL someone can share with me that lists all of the may updates for each windows version?

 

https://www.catalog.update.microsoft.com/Search.aspx?q=2017-05%20update%20windows%207

 

Seems MS have changed the labelling so instead of the month name it now just shows a number. You want these...

 

2017-05 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4019264)

2017-05 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4019264)

Edited by gshaw
Posted

Ok, so im struggling with Windows 8, and Windows XP now.

 

Windows 8 and XP are both supposed to be KB4012598. But when I search for this in WSUS, I don't get any XP or 8 updats, just server 2008 and vista. Anyone know why this could be?

 

Thanks

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...