{"id":12147,"date":"2018-04-27T08:30:03","date_gmt":"2018-04-27T16:30:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/04\/27\/news-5916\/"},"modified":"2018-04-27T08:30:03","modified_gmt":"2018-04-27T16:30:03","slug":"news-5916","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/04\/27\/news-5916\/","title":{"rendered":"Time to install the April Windows and Office patches, but there\u2019s a big problem with Win7"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2017\/09\/windows_patch_security2-100734733-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Fri, 27 Apr 2018 09:22:00 -0700<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Good things come to those who wait. If you resisted the drill sergeant scream of \u201cGET THOSE PATCHES INSTALLED AS SOON AS THEY\u2019RE OUT, MAGGOT!\u201d you\u2019re about to reap your just reward. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">As is so often the case, the Patch Tuesday screams are something you should consider, but they\u2019re hardly the final word. At this point, there\u2019s a credible threat forming for Win7 and Server 2008 R2 machines \u2014 Total Meltdown <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3269003\/microsoft-windows\/heads-up-total-meltdown-exploit-code-now-available-on-github.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">is definitely coming<\/span><\/a><span style=\"font-weight: 400;\">\u00a0\u2014 but the sky hasn\u2019t fallen. There are no known Meltdown or Spectre exploits in the wild, and all of the <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3216425\/microsoft-windows\/microsoft-patch-alert-april-patches-infested-with-bugs-but-most-are-finally-contained.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">hell unleashed<\/span><\/a><span style=\"font-weight: 400;\"> by this month\u2019s series of patches and re-patches and pre-appended re-re-patches primarily served as demonic theater to those of us who chose to wait.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I don\u2019t know of any major exploits in the wild, as yet, that are blocked by the April patches. But you do need to patch sooner or later \u2014 and right now is as good a time as any.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you waited, the way forward is clear. If you installed some (or all) of this month\u2019s patches as they came out, and you\u2019re using Win7 or Server 2008 R2, you may be stuck in a very difficult spot.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft\u2019s Keystone Kops act returned with a vengeance this month, kicked off by a bug in <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3268010\/microsoft-windows\/microsoft-jiggles-but-doesnt-fix-buggy-win7-patches-kb-4088875-kb-4088878.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">last month\u2019s 64-bit Win7 Monthly Rollup<\/span><\/a><span style=\"font-weight: 400;\"> that knocked some Network Interface Cards and some machines with manually set IP addresses off their networks. Microsoft fixed, then re-fixed, then pulled apart and re-fixed the bug, but the re-fix still has problems, even if you uninstall the original fix. Got that? Naw, me neither.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Here\u2019s the short version for 64-bit Win7 and Server 2008 R2 machines, for those who install the Monthly Rollups (\u201cGroup A\u201d). Thx to <\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/a-protocol-question-about-kb-4099950\/#post-187379\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">@abbodi86<\/span><\/a><span style=\"font-weight: 400;\">, @MrBrian and @PKCano, all of whom contributed to this simplified solution:<\/span><\/p>\n<p><strong>Step 1.<\/strong><span style=\"font-weight: 400;\"> Check your update history to see if you have already installed this month\u2019s Win7\/Server 2008 R2 Monthly Rollup, KB 4093118. If you <\/span><strong><i>haven\u2019t <\/i><\/strong><span style=\"font-weight: 400;\">installed KB 4093118, you\u2019re fine; proceed with the next section to install the April Monthly Rollup, KB 4093118.<\/span><\/p>\n<p><strong>Step 2.<\/strong><span style=\"font-weight: 400;\"> You have (a possibly old version of) this month\u2019s Monthly Rollup, KB 4093118. Uninstall KB 4093118. Then &#8230;<\/span><\/p>\n<p><strong>Step 2a.<\/strong><span style=\"font-weight: 400;\"> If you have the March Monthly Rollup, KB 4088875, uninstall it.<\/span><\/p>\n<p><strong>Step 2b.<\/strong><span style=\"font-weight: 400;\"> If you have the <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3268750\/microsoft-windows\/surprise-theres-a-new-version-of-this-months-buggy-win7-monthly-rollup-kb-4093118.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Carnak patch<\/span><\/a><span style=\"font-weight: 400;\">, KB 4099950, uninstall it.<\/span><\/p>\n<p><strong>Step 3.<\/strong><span style=\"font-weight: 400;\"> Just for good luck, reboot.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That\u2019s the simplest sequence I know to make sure you ultimately get the latest version of a file called pci.sys, after you install this month&#8217;s Monthly Rollup. You can <\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/a-protocol-question-about-kb-4099950\/#post-187514\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">follow along with the discussion<\/span><\/a><span style=\"font-weight: 400;\">, but the simple fact is that Microsoft\u2019s mucking with KB 4099950 metadata and re-re-releasing KB 4093118 can put you in a position where you have an outdated version of that key file.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For those of you who are spitting in the patching god\u2019s face and manually installing Security Only patches (the \u201cGroup B\u201d approach), I wish you well and point you to <\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/a-protocol-question-about-kb-4099950\/#post-187509\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">@abbodi86\u2019s instructions<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">See how you\u2019re way ahead of the game if you didn\u2019t install any of this month\u2019s patches?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Go ahead and install all outstanding Win10 patches. The first set of April cumulative updates <a href=\"https:\/\/www.computerworld.com\/article\/3216425\/microsoft-windows\/microsoft-patch-alert-april-patches-infested-with-bugs-but-most-are-finally-contained.html\" rel=\"noopener\" target=\"_blank\">had some bad bugs<\/a>, but those were fixed in the versions released later in the month.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We\u2019re seeing a late-surfacing bug in KB 4018319 (Office 2016) and KB 4018288 (Office 2013) that cause <\/span><a href=\"https:\/\/www.askwoody.com\/2018\/patch-lady-office-issues-with-april-updates\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">problems when opening files with embedded charts<\/span><\/a><span style=\"font-weight: 400;\">. Microsoft has not yet <\/span><a href=\"https:\/\/support.office.com\/en-us\/article\/fixes-or-workarounds-for-recent-issues-in-excel-for-windows-49d932ce-0240-49cf-94df-1587d9d97093?ui=en-US&amp;rs=en-US&amp;ad=US\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">officially acknowledged the bug<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Other than that, Susan Bradley\u2019s<\/span><a href=\"https:\/\/www.askwoody.com\/patch-list-master\/\" rel=\"nofollow noopener\" target=\"_blank\"> <span style=\"font-weight: 400;\">Master Patch List<\/span><\/a><span style=\"font-weight: 400;\"> says the April Office patches are OK.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Before you install this month\u2019s Win7\/Server 2008 R2 patches, make sure you use the above steps to figure out if you have to uninstall anything before you proceed.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The patching pattern should be familiar to many of you.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There\u2019s a non-zero chance that the patches \u2014 even the latest, greatest patches of patches of patches \u2014 will hose your machine. Best to have a backup that you can reinstall even if your machine refuses to boot. This, in addition to the usual need for System Restore points.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There are plenty of full-image backup products, including at least two good free ones:<\/span><a href=\"https:\/\/www.macrium.com\/reflectfree\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> Macrium Reflect Free<\/span><\/a><span style=\"font-weight: 400;\"> and<\/span><a href=\"https:\/\/www.computerworld.com\/article\/3199125\/microsoft-windows\/top-30-free-apps-for-windows-10.html#slide9\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> EaseUS Todo Backup<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft is blocking updates to Windows 7 and 8.1 on recent computers. If you are running Windows 7 or 8.1 on a PC that\u2019s a year old or less, follow the instructions in<\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/2000006-see-if-microsoft-is-blocking-windows-update-on-your-new-computer\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> AKB 2000006<\/span><\/a><span style=\"font-weight: 400;\"> or<\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/installing-win-updates-on-win-7-or-8-1-computers-with-kaby-lake-or-ryzen-cpus\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> @MrBrian\u2019s summary of @radosuaf\u2019s method<\/span><\/a><span style=\"font-weight: 400;\"> to make sure you can use Windows Update to get updates applied.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you\u2019re very concerned about Microsoft\u2019s snooping on you and want to install just security patches, realize that the privacy path\u2019s getting more difficult. The old \u201cGroup B\u201d \u2014 security patches only \u2014 isn\u2019t dead, but it\u2019s no longer within the grasp of typical Windows customers. If you insist on manually installing security patches only, follow the instructions in @PKCano\u2019s<\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/2000003-ongoing-list-of-group-b-monthly-updates-for-win7-and-8-1\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> AKB 2000003<\/span><\/a><span style=\"font-weight: 400;\"> and be aware of<\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/new-directions-for-win-7-and-8-1-patching\/#post-138998\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> @MrBrian\u2019s recommendations<\/span><\/a><span style=\"font-weight: 400;\"> for hiding any unwanted patches.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For most Windows 7 and 8.1 users, I recommend following<\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/2000004-how-to-apply-the-win7-and-8-1-monthly-rollups\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> AKB 2000004: How to apply the Win7 and 8.1 Monthly Rollups<\/span><\/a><span style=\"font-weight: 400;\">. Realize that some or all of the expected patches for April may not show up or, if they do show up, may not be checked. DON&#8217;T CHECK any unchecked patches. Unless you&#8217;re very sure of yourself, DON&#8217;T GO LOOKING for additional patches. That way thar be tygers. If you&#8217;re going to install the April patches, accept your lot in life, and don&#8217;t mess with Mother Microsoft.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you want to minimize Microsoft\u2019s snooping but still install all of the offered patches, turn off the Customer Experience Improvement Program (Step 1 of<\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/2000007-turning-off-the-worst-windows-7-and-8-1-snooping\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> AKB 2000007: Turning off the worst Windows 7 and 8.1 snooping<\/span><\/a><span style=\"font-weight: 400;\">) before you install any patches. (Thx, @MrBrian.) If you see KB 2952664 (for Win7) or \u00a0its Win8.1 cohort, KB 2976978 \u2014 the patches that so helpfully make it easier to upgrade to Win10 \u2014 uncheck them and spread your machine with garlic. Watch out for driver updates \u2014 you\u2019re far better off getting them from a manufacturer\u2019s website.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After you\u2019ve installed the latest Monthly Rollup, if you\u2019re intent on minimizing Microsoft\u2019s snooping, run through the steps in<\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/2000007-turning-off-the-worst-windows-7-and-8-1-snooping\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> AKB 2000007: Turning off the worst Win7 and 8.1 snooping<\/span><\/a><span style=\"font-weight: 400;\">. Realize that <\/span><strong><i>we don\u2019t know <\/i><\/strong><span style=\"font-weight: 400;\">what information Microsoft collects on Window 7 and 8.1 machines. But I\u2019m starting to believe that information pushed to Microsoft\u2019s servers for Win7 owners is nearing that pushed in Win10.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you\u2019re running Win10 Creators Update, <\/span><strong>version 1703<\/strong><span style=\"font-weight: 400;\"> (my current preference), or <\/span><strong>version 1607<\/strong><span style=\"font-weight: 400;\">, the Anniversary Update, and you want to stay on 1607 or 1703 while those on 1709 get to eat Microsoft\u2019s dog food, follow the<\/span><a href=\"https:\/\/www.computerworld.com\/article\/3232632\/microsoft-windows\/how-to-block-windows-10-fall-creators-update-from-installing.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> instructions here<\/span><\/a><span style=\"font-weight: 400;\"> to ward off the upgrade. As you go through the steps, keep in mind that Microsoft, uh,<\/span><a href=\"https:\/\/www.askwoody.com\/2017\/microsoft-confirms-that-win10-1703-users-are-being-upgraded-without-warning-to-1709\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> forgot to honor<\/span><\/a><span style=\"font-weight: 400;\"> the \u201cCurrent Branch for Business\u201d setting \u2014 so you need to run the \u201cfeature update\u201d (read: version change) deferral setting, if you have one, all the way up to 365. And hope that Microsoft doesn\u2019t forget how to count to 365.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you\u2019re running an earlier version of Win10, you\u2019re basically on your own. Microsoft doesn&#8217;t support you anymore.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you have trouble getting the latest cumulative update installed, make sure you\u2019ve checked your antivirus settings (see ProTip #2 above) and, if all is well, run the<\/span><a href=\"https:\/\/www.askwoody.com\/2018\/new-version-of-the-windows-update-troubleshooter\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> newly refurbished<\/span><\/a><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/10164\/fix-windows-update-errors\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\"> Windows Update Troubleshooter<\/span><\/a><span style=\"font-weight: 400;\"> before inventing new epithets.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To get Windows 10 patched, go through the steps in &#8220;<\/span><a href=\"https:\/\/www.computerworld.com\/article\/3215668\/windows-pcs\/8-steps-to-install-windows-10-patches-like-a-pro.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">8 steps to install Windows 10 patches like a pro<\/span><\/a><span style=\"font-weight: 400;\">.&#8221;<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">Thanks to the dozens of volunteers on AskWoody who contribute mightily.<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">We\u2019ve moved to MS-DEFCON 3 on the<\/span><\/i><a href=\"https:\/\/www.askwoody.com\/2018\/ms-defcon-3-apply-april-patches-but-if-you-have-64-bit-win7-or-server-2008-r2-read-the-fine-print\/\" rel=\"nofollow noopener\" target=\"_blank\"> <i><span style=\"font-weight: 400;\">AskWoody Lounge<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3269469\/microsoft-windows\/time-to-install-the-april-windows-and-office-patches-but-there-s-a-big-problem-with-win7.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2017\/09\/windows_patch_security2-100734733-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Fri, 27 Apr 2018 09:22:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p><span style=\"font-weight: 400;\">Good things come to those who wait. If you resisted the drill sergeant scream of \u201cGET THOSE PATCHES INSTALLED AS SOON AS THEY\u2019RE OUT, MAGGOT!\u201d you\u2019re about to reap your just reward. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">As is so often the case, the Patch Tuesday screams are something you should consider, but they\u2019re hardly the final word. At this point, there\u2019s a credible threat forming for Win7 and Server 2008 R2 machines \u2014 Total Meltdown <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3269003\/microsoft-windows\/heads-up-total-meltdown-exploit-code-now-available-on-github.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">is definitely coming<\/span><\/a><span style=\"font-weight: 400;\">\u00a0\u2014 but the sky hasn\u2019t fallen. There are no known Meltdown or Spectre exploits in the wild, and all of the <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3216425\/microsoft-windows\/microsoft-patch-alert-april-patches-infested-with-bugs-but-most-are-finally-contained.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">hell unleashed<\/span><\/a><span style=\"font-weight: 400;\"> by this month\u2019s series of patches and re-patches and pre-appended re-re-patches primarily served as demonic theater to those of us who chose to wait.<\/span><\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3269469\/microsoft-windows\/time-to-install-the-april-windows-and-office-patches-but-there-s-a-big-problem-with-win7.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[714,10525],"class_list":["post-12147","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-security","tag-windows"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12147"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12147\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12147"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}