Jump to content

Looks like January windows updates are causing all sorts of issues..


Recommended Posts

Posted

Is anybody using L2TP VPN connections?

 

https://www.bleepingcomputer.com/news/microsoft/new-windows-kb5009543-kb5009566-updates-break-l2tp-vpn-connections/

"The bug is not affecting all VPN devices and seems only to be affecting users using the built-in Windows VPN client to make the connection.

 

A security researcher known as Ronny on Twitter told BleepingComputer that the bug affects their Ubiquiti Client-to-Site VPN connections for those using the Windows VPN client.

 

Many Windows admins also report on Reddit that the bug also affects connections to SonicWall, Cisco Meraki, and WatchGuard Firewalls, with the latter's client also affected by the bug."

Posted
One of our DCs rebooted overnight but is showing KB5009557 as having failed. Thankfully not boot looping.

 

This may not be very helpful to those of you struggling with these updates, but to follow up on my post from yesterday, our 2019 DC that initially failed the update installed it successfully last night with no apparent issues coming into this morning.

Posted
If the updates are yanked - but have already been downloaded to a server ready for manual installation kick-off - what do you do?

 

I managed to hide mine via Control Panel, though mine had already been installed and done the damage and then uninstalled and re-downloaded.

Posted (edited)
Only just seen this thread, thankfully the updates appears to have applied without issue for us (a mixture of Server 2019 & 2016). ��

 

Yeah, some affected and some not, bit strange but I guess it is maybe a combination of roles/features or whether whatever kicks it of is triggered by something specific happening on the server...?

 

If the updates are yanked - but have already been downloaded to a server ready for manual installation kick-off - what do you do?

 

Not sure if it works with downloaded updates (I have mine set to notify, not download), but I uninstalled it yesterday and it has just popped up on the server today to be installed again. Luckily it's 2012R2 so I'm just going to use right click and hide/show updates (not sure if that works on newer flavours).... actually will that also hide an updated version with a same KB number or will the fixed one have a different number... I might just leave it.

 

Am still seeing 2016 updates available. Little worried as my HyperV's are 2016.

 

As above it is impossible to know, some seem ok, other not...

Edited by Koldov
Posted
If the updates are yanked - but have already been downloaded to a server ready for manual installation kick-off - what do you do?

 

This might/will need further investigation before applying to your live servers, but I'm thinking that if the update is downloaded but has not yet started to install, you could maybe stop the BITS and Windows Update services, clear the contents of %WINDIR%\SoftwareDistribution and then restart the services. If the update has already started to install, or is installed and awaiting a restart in order to complete, then don't do this. That's generally what you'd do if you had an update package corrupted on a system and getting stuck. It would prompt the system to download a fresh copy of any updates that it needs, and in this case, provided the update in question is no longer approved, it just wouldn't download in again.

 

The other option might be to take a good backup prior to the installation starting and be in a position to restore the server right away if it runs into problems after installing the update.

  • Thanks 1
Posted
This might/will need further investigation before applying to your live servers, but I'm thinking that if the update is downloaded but has not yet started to install, you could maybe stop the BITS and Windows Update services, clear the contents of %WINDIR%\SoftwareDistribution and then restart the services. If the update has already started to install, or is installed and awaiting a restart in order to complete, then don't do this. That's generally what you'd do if you had an update package corrupted on a system and getting stuck. It would prompt the system to download a fresh copy of any updates that it needs, and in this case, provided the update in question is no longer approved, it just wouldn't download in again.

 

The other option might be to take a good backup prior to the installation starting and be in a position to restore the server right away if it runs into problems after installing the update.

 

Can confirm cleaning up the softwaredistribution folder will sort this. Also if your servers are pending a restart then wusa /uninstall /kb:5009624 (Or the one for whichever serverOS you're on) should take care of it.

 

I havent had any servers failing to boot so far only had them rebooting every 20 minutes or so.

  • Thanks 1
Posted
It would prompt the system to download a fresh copy of any updates that it needs, and in this case, provided the update in question is no longer approved, it just wouldn't download in again.

 

Annoyingly I removed the update yesterday and it has appeared again today so I guess my server checked before it was yanked...

 

I havent had any servers failing to boot so far only had them rebooting every 20 minutes or so.

 

Was it Hyper-V (Virtual Machines) fail to boot, DCs reboot and ReFS is just downright killed?

Posted
Annoyingly I removed the update yesterday and it has appeared again today so I guess my server checked before it was yanked...

 

 

 

Was it Hyper-V (Virtual Machines) fail to boot, DCs reboot and ReFS is just downright killed?

 

All of the ones that kept rebooting were domain controllers yes.

Posted (edited)

I'm alittle confused with this one.

 

I manually authorise all updates, so when i saw issues i of course didn't authorise them.

 

From what i understand now, the updates have been pulled. However they still appear in WSUS. I have done a sync, and nothing has been removed/recalled etc.

 

Are these safe yet?

 

KB5009557

 

Capture.JPG

 

does this mean its been amended?

 

Capture1.JPG

Edited by Jaan
Posted
I'm alittle confused with this one.

 

I manually authorise all updates, so when i saw issues i of course didn't authorise them.

 

From what i understand now, the updates have been pulled. However they still appear in WSUS. I have done a sync, and nothing has been removed/recalled etc.

 

Are these safe yet?

 

KB5009557

 

[ATTACH=CONFIG]64236[/ATTACH]

 

does this mean its been amended?

 

[ATTACH=CONFIG]64237[/ATTACH]

 

The date of the revision says the 11/01/2022 which was the original release date so I would say no. If it wasnt for the vulnerabilities it patches I would be waiting for the February ones.

Posted

I'm not sure how/whether updates that are pulled from the MS catalogue also get pulled from WSUS. I'm guessing that they would become expired, rather than disappeared. If you've declined the update and checked that it's then not still being queued up by clients, you're probably okay.

 

Until February.

Posted

Think I'm gonna give this one a week or two for all the guinea pigs to test! :p

 

Strange it mentions Server 2012R2 as needing to get the updates from Microsoft Update Catalog, but says there are Windows Update versions for Windows 7 and Server 2008 SP2... :confused:

Posted
We've got a few last remaining 2012R2 DC's at one of our sites, we've removed KB5009624 but are struggling to remove KB5009595 using the Wusa command. Anyone else had this issue? Error reads: Installer encountered an error: 0x800f0831
Posted
Looks like the revised updates should be rolling out, though you may need to use the Update Catalogue for older OSes.

I don't use WSUS anymore and simply run the updates when I am ready. For my 2012r2 DC that uses the built in Windows update, would it use the update Catalogue to fetch its updates from, or do I need to manually download / install this?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...