{"id":10641,"date":"2017-11-28T14:30:02","date_gmt":"2017-11-28T22:30:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/11\/28\/news-4413\/"},"modified":"2017-11-28T14:30:02","modified_gmt":"2017-11-28T22:30:02","slug":"news-4413","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/11\/28\/news-4413\/","title":{"rendered":"Microsoft Patch Alert: November\u2019s forced upgrades, broken printers and more"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.techhive.com\/images\/article\/2016\/11\/windows-bug-100692311-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Tue, 28 Nov 2017 13:08:00 -0800<\/strong><\/p>\n<p>There are so many issues with this month\u2019s security patches that it\u2019s hard to decide where to begin. Let\u2019s start with the problems that have been acknowledged, then move into the realm of what\u2019s not yet fully defined.<\/p>\n<p>Many users <a href=\"https:\/\/www.askwoody.com\/forums\/topic\/microsoft-confirms-that-win10-1703-users-are-being-upgraded-without-warning-to-1709\/#post-146981\" rel=\"nofollow\">have remarked<\/a> about how much the forced 1703-to-1709 Windows 10 upgrades feel like Microsoft\u2019s detested forced upgrades from Win 7 and 8.1 to 10 \u2013 the \u201cGet Windows X\u201d campaign. Although the situation\u2019s different on the surface, the net result is the same. Many people who were happily using Windows 10 Fall Update \u2013 version 1703 \u2013 were forcibly upgraded this month to the Fall Creators Update \u2013 version 1709 \u2013 even on systems that were not supposed to be upgraded.<\/p>\n<p>At first, Microsoft <a href=\"https:\/\/www.computerworld.com\/article\/3237172\/microsoft-windows\/microsoft-forces-win10-1703-customers-onto-1709-and-other-patch-tuesday-shenanigans.html\">ignored the uproar<\/a>. But last week it quietly <a href=\"https:\/\/www.askwoody.com\/2017\/microsoft-confirms-that-win10-1703-users-are-being-upgraded-without-warning-to-1709\/\" rel=\"nofollow\">owned up<\/a> to the move by putting this notification in the description for November\u2019s Win 10 1703 <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4048954\" rel=\"nofollow\">Patch Tuesday cumulative update<\/a>:<\/p>\n<p style=\"padding-left: 30px;\">Known issues in this update:<\/p>\n<p style=\"padding-left: 30px;\">Windows Pro devices on the Current Branch for Business (CBB) will upgrade unexpectedly.<\/p>\n<p style=\"padding-left: 30px;\">Microsoft is working on a resolution and will provide an update in an upcoming release.<\/p>\n<p>On the same day, Nov. 22, Microsoft released another cumulative update for 1703, <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4055254\" rel=\"nofollow\">KB 4055254<\/a>, which doesn\u2019t mention the problem. I\u2019m going to guess it was fixed.<\/p>\n<p>Those who were forcibly upgraded from 1703 to 1709 are now in limbo; if you allowed Win10 to automatically update itself, and the 1709 installer decided to take over, you\u2019re stuck on 1709. Users had 10 days to roll back to the older version, and <a href=\"https:\/\/www.askwoody.com\/2017\/microsoft-confirms-that-win10-1703-users-are-being-upgraded-without-warning-to-1709\/\" rel=\"nofollow\">those days are gone<\/a>.<\/p>\n<p>That\u2019s not good news if you hit problems with 1709, like the <a href=\"https:\/\/www.askwoody.com\/2017\/problem-reported-with-folder-permissions-on-win10-1709-office-2016\/\" rel=\"nofollow\">folder permissions problem<\/a> or the <a href=\"https:\/\/answers.microsoft.com\/en-us\/insider\/forum\/insider_wintp-insider_perf-insiderplat_pc\/programs-autostart-after-boot-in-windows-10-fall\/09dd8d3e-7b36-45d1-9181-6587dd5d53ab\" rel=\"nofollow\">autostart after boot<\/a> problem. Those who got hit were upgraded without warning.<\/p>\n<p>There are lots and lots of Epson dot matrix (and POS terminal) printers alive and well, thank you very much.<\/p>\n<p>To recap, this month\u2019s Patch Tuesday patches broke the Epson dot matrix driver for every supported version of Windows: Win10 1709, Win10 1703, Win10 1607\/Server 2016, Win10 1511 Enterprise, Win10 1507 LTSC, Win 8.1\/Server 2012 R2, Server 2012, and Win7\/Server 2008 R2. (It\u2019s quite remarkable: Microsoft is now actively supporting 11 versions of Windows \u2013 14 if you count the Server versions separately.)<\/p>\n<p>As <a href=\"https:\/\/www.computerworld.com\/article\/3238470\/microsoft-windows\/microsoft-thanksgiving-turkeys-one-patch-disappears-another-yanked.html\">noted yesterday<\/a>, there are now fixes for six of those versions: Win 8.1\/Server 2012 R2, Server 2012, and Win7\/Server 2008 R2 and Win10 1703. There was a fleeting fix for Win10 1709, but <a href=\"https:\/\/www.computerworld.com\/article\/3238470\/microsoft-windows\/microsoft-thanksgiving-turkeys-one-patch-disappears-another-yanked.html\">it disappeared<\/a>. As of <a href=\"https:\/\/www.askwoody.com\/2017\/microsoft-releases-epson-dot-matrix-fix-for-win10-1703-kb-4051033-and-teases-at-a-fix-for-1709-kb-4051963\/\" rel=\"nofollow\">this morning<\/a>, there&#8217;s a spot reserved for a Win10 1709 cumulative update, <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4051963\" rel=\"nofollow\">KB 4051963 for build 16299.96<\/a>, but there&#8217;s no KB article as yet and no reports of it rolling out. Presumeably, it&#8217;ll include a fix for the Epson printing bug.<\/p>\n<p>But there\u2019s still no word on Epson printer fixes for Win10 1511 Enterprise or for Win10 1507 LTSC.<\/p>\n<p>Microsoft released four .NET Framework patches on Patch Tuesday:<\/p>\n<p>The company then pulled all of them down before Thanksgiving. There was no official notice, just a <a href=\"https:\/\/www.computerworld.com\/article\/3238470\/microsoft-windows\/microsoft-thanksgiving-turkeys-one-patch-disappears-another-yanked.html\">string of comments<\/a> on the MSDN TechNet blog that said, in effect, Microsoft hadn\u2019t handled the supercedence chain on the patches properly and would fix the problem sometime after the U.S. holiday.<\/p>\n<p>Sure enough, they were <a href=\"https:\/\/www.askwoody.com\/forums\/topic\/microsoft-yanks-buggy-november-rollup-kb-4049016for-net-framework-on-win7-and-server-2008-r2\/#post-147797\" rel=\"nofollow\">re-released yesterday<\/a>.<\/p>\n<p>This bug, introduced in the Win10 1607 October cumulative update and both of the November 1607 cumulative updates, was finally acknowledged a little over a week ago. The three cumulative updates now contain this notice:<\/p>\n<p style=\"padding-left: 30px;\">After installing KB4041688, KB4052231, or KB4048953, the error &#8220;CDPUserSvc_XXXX has stopped working&#8221; appears. Additionally, Event ID 1000 is logged in the Application event log. It notes that svchost.exe_CDPUserSvc_XXXX has stopped working and the faulting module name is &#8220;cdp.dll&#8221;.<\/p>\n<p style=\"padding-left: 30px;\">Microsoft is working on a resolution and will provide an update in an upcoming release.<\/p>\n<p style=\"padding-left: 30px;\">Until then, follow the steps in the <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/application-management\/per-user-services-in-windows\" rel=\"nofollow\">Per-user services in Windows 10 and Windows Server<\/a> article.<\/p>\n<p>To be clear, the bug has not been fixed, although it\u2019s been well documented for six weeks. It even appears in the Win10 1703 Cumulative Update, KB 4051033, which was <a href=\"https:\/\/www.askwoody.com\/2017\/win10-1703-has-a-new-cumulative-update-kb-4051033-bringing-the-build-up-to-14393-1914\/\" rel=\"nofollow\">released on Nov. 27<\/a>. Expect a real fix in the December Patch Tuesday crop.<\/p>\n<p>In Win10 1709 Fall Creators Update, adjusting the setting \u201cAfter a Preview Build or Feature Update is released, defer receiving it for this many days\u201d may, in fact, defer cumulative updates (which Microsoft insists on calling \u201cquality updates\u201d).<\/p>\n<p>Poster Klaasklever who first <a href=\"https:\/\/social.technet.microsoft.com\/Forums\/en-US\/16172050-6cec-4e5d-b0fb-884b79571de0\/win-10-v1709-preview-buildsfeature-updates-deferral-group-policy-incorrectly-blocks-cumulative?forum=win10itprosecurity\" rel=\"nofollow\">described the bug<\/a> on the TechNet, pointed to \u201creports that this issue is also caused by setting to defer Feature Updates in the Windows Update Settings within the normal Windows Settings App.\u201d<\/p>\n<p>It\u2019s clearly a bug in Win10 1709, though it\u2019s not clear which versions are afflicted \u2013 and there\u2019s a possibility that the not-yet-released Win10 1709 cumulative update, <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4051963\" rel=\"nofollow\">KB 4051963 for build 16299.96<\/a>, may fix it. As noted, there&#8217;s no KB article as yet, and no reports of it rolling out.<\/p>\n<p>This bug, introduced in Microsoft\u2019s October security patch release, led to Microsoft pushing out five patches in early November:<\/p>\n<p>Users who installed those patches (they had to be manually downloaded and installed) <a href=\"https:\/\/www.computerworld.com\/article\/3236029\/microsoft-windows\/ms-fixes-external-database-bug-with-patches-that-have-even-more-bugs.html\">soon discovered<\/a> that they all brought back old Windows security patches which themselves had bugs. Those buggy patches <a href=\"https:\/\/www.computerworld.com\/article\/3235911\/microsoft-windows\/microsoft-yanks-buggy-windows-patches-kb-4052233-4052234-4052235.html\">were yanked<\/a> a few days later, and all mention of them was scrubbed as if they never existed.<\/p>\n<p>In their stead, the Patch Tuesday Win7 and 8.1 Monthly Rollups and Security-only Updates and the Patch Tuesday patches for Win10 1709, 1703, 1607, 1511 and 1507 all claim to solve the problem.<\/p>\n<p>Two weeks ago, I <a href=\"https:\/\/www.computerworld.com\/article\/3237172\/microsoft-windows\/microsoft-forces-win10-1703-customers-onto-1709-and-other-patch-tuesday-shenanigans.html\">talked about<\/a> the Equation Editor bug, CVE-2017-11882. There are a few exploits out in the wild at this point. If you\u2019re concerned about them, you can bypass Equation Editor and eliminate the security hole by changing two Registry entries described in the <a href=\"https:\/\/embedi.com\/blog\/skeleton-closet-ms-office-vulnerability-you-didnt-know-about\" rel=\"nofollow\">Embedi article<\/a> on the subject.<\/p>\n<p>Good news? The <a href=\"https:\/\/www.askwoody.com\/2017\/hp-is-installing-new-spyware-hp-touchpoint-analytics-client-but-the-infection-vector-remains-unclear\/\" rel=\"nofollow\">HP Spyware update<\/a> doesn\u2019t appear to be a Windows problem. It\u2019s all on HP.<\/p>\n<p>Special thanks to @MrBrian, @abbodi86 and @PKCano<\/p>\n<p><em>Did I miss a bug? Need a scorecard? I sympathize! Drop by the <\/em><a href=\"https:\/\/www.askwoody.com\/2017\/patch-alert-where-we-stand-with-this-months-mess\/\" rel=\"nofollow\"><em>AskWoody Lounge<\/em><\/a><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3216425\/microsoft-windows\/microsoft-patch-alert-novembers-forced-upgrades-broken-printers-and-more.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.techhive.com\/images\/article\/2016\/11\/windows-bug-100692311-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Tue, 28 Nov 2017 13:08:00 -0800<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>There are so many issues with this month\u2019s security patches that it\u2019s hard to decide where to begin. Let\u2019s start with the problems that have been acknowledged, then move into the realm of what\u2019s not yet fully defined.<\/p>\n<aside class=\"fakesidebar\">\n<aside class=\"fakesidebar\"><strong>[ Further reading: <a href=\"https:\/\/www.computerworld.com\/article\/3237586\/microsoft-windows\/patch-alert-microsoft-acknowledges-printer-bug-forced-1709-upgrades-continue.html\">Patch alert: Microsoft acknowledges printer bug; forced 1709 upgrades continue<\/a> ]<\/strong><\/aside>\n<\/aside>\n<h2><strong>Forced upgrades<\/strong><\/h2>\n<p>Many users <a href=\"https:\/\/www.askwoody.com\/forums\/topic\/microsoft-confirms-that-win10-1703-users-are-being-upgraded-without-warning-to-1709\/#post-146981\" rel=\"nofollow\">have remarked<\/a> about how much the forced 1703-to-1709 Windows 10 upgrades feel like Microsoft\u2019s detested forced upgrades from Win 7 and 8.1 to 10 \u2013 the \u201cGet Windows X\u201d campaign. Although the situation\u2019s different on the surface, the net result is the same. Many people who were happily using Windows 10 Fall Update \u2013 version 1703 \u2013 were forcibly upgraded this month to the Fall Creators Update \u2013 version 1709 \u2013 even on systems that were not supposed to be upgraded.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3216425\/microsoft-windows\/microsoft-patch-alert-novembers-forced-upgrades-broken-printers-and-more.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[714,10761],"class_list":["post-10641","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-security","tag-windows-10"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10641","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=10641"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10641\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=10641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=10641"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=10641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}