{"id":15563,"date":"2019-06-13T04:30:03","date_gmt":"2019-06-13T12:30:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/06\/13\/news-9312\/"},"modified":"2019-06-13T04:30:03","modified_gmt":"2019-06-13T12:30:03","slug":"news-9312","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/06\/13\/news-9312\/","title":{"rendered":"Microsoft is better at documenting patch problems, but issues abound"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2018\/08\/3_patch-training_update-software_band-aid_laptop-with-virus_binary-100768644-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Thu, 13 Jun 2019 03:55:00 -0700<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">I don\u2019t know about you, but I\u2019ve given up on Microsoft\u2019s ability to deliver reliable patches. Month after month, we\u2019ve seen big bugs and little bugs pushed and pulled and squished and re-squished. You can see a chronology from the past two years in my patching whack-a-mole columns starting <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3216425\/microsoft-patch-alert-patching-whack-a-mole-continues.html\"><span style=\"font-weight: 400;\">here<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For the past few months, though, we\u2019ve seen some improvement. Microsoft has started identifying and publicly acknowledging big bugs, shortly after they\u2019re pushed. Consider:<\/span><\/p>\n<p><strong>Event Viewer may close or you may receive an error when using Custom Views<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">When trying to expand, view or create <\/span><strong>Custom Views <\/strong><span style=\"font-weight: 400;\">in Event Viewer, you may receive the error, &#8220;MMC has detected an error in a snap-in and will unload it.&#8221; and the app may stop responding or close. You may also receive the error using <\/span><strong>Filter Current Log<\/strong><span style=\"font-weight: 400;\"> in the <\/span><strong>Action <\/strong><span style=\"font-weight: 400;\">menu with built-in views or logs. Built-in views and other features of Event Viewer should work as expected.<\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400;\">Microsoft posted a <\/span><a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/release-information\/status-windows-10-1809-and-windows-server-2019\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">description of the problem<\/span><\/a><span style=\"font-weight: 400;\">, and a complex manual workaround, on June 12. The bug\u2019s marked as \u201cmitigated,\u201d which apparently means the company has <\/span><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4508640\/event-viewer-may-close-or-you-may-receive-an-error-when-using-custom-v\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">published a PowerShell script<\/span><\/a><span style=\"font-weight: 400;\"> that can fix the bug in an ad-hoc kind of way. (\u201cYou will need to re-enter the function each time you open a new PowerShell window.&#8221;)<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Both of those bugs touched <\/span><strong><i>every <\/i><\/strong><span style=\"font-weight: 400;\">Windows machine, from Windows 7 to the latest version of Windows 10, and everything in between. They\u2019re not the product of isolated fringe circumstances. If you needed IE or Edge to access those <em>gov.uk<\/em> sites, or if you have custom views in Event Viewer, you got hit.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Neither of those bugs is particularly remarkable \u2013 just more of the same-old, same-old lousy patch quality we\u2019ve come to expect. What\u2019s different this time is Microsoft\u2019s public (and timely) confession. Instead of keeping users in the dark for days or weeks, Microsoft posted a description of the problem in very short order. The new <\/span><a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/release-information\/status-windows-10-1809-and-windows-server-2019\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Release Information page<\/span><\/a><span style=\"font-weight: 400;\"> is actually working, although there are <\/span><a href=\"https:\/\/www.askwoody.com\/2019\/may-patches-may-block-ie-11-if-you-dont-have-default-search-provider-specifiedh\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">some teething pains<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To be sure, there are problems that aren\u2019t reflected in the Patch Information page. But it\u2019s a big step in the right direction.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Here are some of the other problems we\u2019re tracking:<\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400;\">We don\u2019t know for sure if (a) this behavior\u2019s a bug, not a feature, (b) what settings remain in effect after the disappearing trick and (c) how it\u2019s supposed to work. I think it\u2019s a bug, but some are casting aspersions on Microsoft\u2019s integrity. I have no idea how Microsoft will fix it. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Addresses a security vulnerability by intentionally preventing connections between Windows and Bluetooth devices that are not secure and use well-known keys to encrypt connections, including security fobs. If BTHUSB Event 22 in the Event Viewer states, \u201cYour Bluetooth device attempted to establish a debug connection\u2026,&#8221; then your system is affected. Contact your Bluetooth device manufacturer to determine if a device update exists. For more information, see<\/span><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-2102\" rel=\"nofollow noopener\" target=\"_blank\"> <span style=\"font-weight: 400;\">CVE-2019-2102<\/span><\/a><span style=\"font-weight: 400;\"> and<\/span><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4507623\" rel=\"nofollow noopener\" target=\"_blank\"> <span style=\"font-weight: 400;\">KB4507623<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400;\"> .NET 4.8 itself is not pushed or published through Windows Update. But you do have it \u201cin the box\u201d if you\u2019re running Win10 version 1903. <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400;\">If you have .NET 4.8, you will get a separate security update for it through Windows Update.<\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400;\">Windows 8.1, Monthly Rollup KB 4503276\u2026 when I opened IE11 after restart, <\/span><a href=\"https:\/\/ie11welcome.microsoft.com\/en-us\/index.html\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">this page automatically opened <\/span><\/a><span style=\"font-weight: 400;\">asking me to set the \u201crecommended\u201d settings. I clicked the X mark inside the page, the tab closed and I retained my current settings<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We\u2019re also seeing an SSU problem with folks using update servers. Apparently, it takes two passes for some update servers to \u201csee\u201d this month\u2019s patches: The first pass discovers and installs the Servicing Stack Update, and a second pass is necessary to find and install this month\u2019s cumulative update. Old problem, frustrating nonetheless.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Then there are the <\/span><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4346085\/kb4346085-intel-microcode-updates\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">old Intel microcode patches<\/span><\/a><span style=\"font-weight: 400;\"> (2019-01, 2019-02) that suddenly appear after installing this month\u2019s cumulative updates. Lots of people are scratching their heads because the updates show up on machines that aren\u2019t covered by the patches.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There\u2019s also a very poorly documented Exchange \u201c<\/span><span style=\"font-weight: 400;\">defense in depth\u201d patch, described in <\/span><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV190018#ID0EN\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Advisory 190018<\/span><\/a><span style=\"font-weight: 400;\">. <\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">Problems? Observations? Abject feelings of despair? Hit us on the <\/span><\/i><a href=\"https:\/\/www.askwoody.com\/2019\/microsofts-getting-better-at-documenting-the-most-egregious-bugs-in-windows-patches\/\" rel=\"nofollow noopener\" target=\"_blank\"><i><span style=\"font-weight: 400;\">AskWoody Lounge<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3402337\/microsoft-is-better-at-documenting-patch-problems-but-issues-abound.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2018\/08\/3_patch-training_update-software_band-aid_laptop-with-virus_binary-100768644-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Thu, 13 Jun 2019 03:55:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p><span style=\"font-weight: 400;\">I don\u2019t know about you, but I\u2019ve given up on Microsoft\u2019s ability to deliver reliable patches. Month after month, we\u2019ve seen big bugs and little bugs pushed and pulled and squished and re-squished. You can see a chronology from the past two years in my patching whack-a-mole columns starting <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3216425\/microsoft-patch-alert-patching-whack-a-mole-continues.html\"><span style=\"font-weight: 400;\">here<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<aside class=\"fakesidebar\"><strong>[ Related: <a href=\"https:\/\/www.computerworld.com\/article\/3210805\/windows-10-may-2019-update-key-enterprise-features.html\">Windows 10 May 2019 Update: Key enterprise features<\/a> ]<\/strong><\/aside>\n<p><span style=\"font-weight: 400;\">For the past few months, though, we\u2019ve seen some improvement. Microsoft has started identifying and publicly acknowledging big bugs, shortly after they\u2019re pushed. Consider:<\/span><\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3402337\/microsoft-is-better-at-documenting-patch-problems-but-issues-abound.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[13764,714,10525],"class_list":["post-15563","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-pcs","tag-security","tag-windows"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15563","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15563"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15563\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15563"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}