[German]On July 13, Microsoft has released various updates for Windows 7 SP1 systems that are still in ESU support. Also with ESU Bypass v11 the whole thing still works. However, these security updates are also available for Windows Server 2008 R2 with ESU support. Here is some information about the Monthly Rollup and Security only Updates for this operating system.
Advertising
Updates for Windows 7/Windows Server 2008 R2
For Windows 7 SP1 and Windows Server 2008 R2 SP1 a rollup and a security-only update have been released. However, these updates are only available for systems with ESU license (2nd year). The update history for Windows 7 can be found on this Microsoft page.
As of July 2020, all Windows updates disable the RemoteFX vGPU feature due to vulnerability CVE-2020-1036 (see also KB4570006). After installing this update, attempts to start virtual machines (VM) with RemoteFX vGPU enabled will fail. KB5003209 (Monthly Rollup) for Windows 8.1/Server 2012 R2.
Update installation requires either a valid ESU license for 2021, or ESU Bypass v11 (see).
KB5004288 (Monthly Rollup) for Windows 7/Windows Server 2008 R2
Update KB5004289 (Monthly Quality Rollup for Windows 7 SP1 and Windows Server 2008 R2 SP1)contains (besides the security fixes from the previous month) improvements and bug fixes and addresses the following:
- Addresses an issue in which 16-bit applications fail with an error message that indicates a general fault in VBRUN300.DLL.
- Addresses an issue in which some EMFs built by using third-party applications that use ExtCreatePen and ExtCreateFontIndirect render incorrectly.
- Adds Advanced Encryption Standard (AES) encryption protections for CVE-2021-33757. For more information, see KB5004605.
- Removes support for the PerformTicketSignature setting and permanently enables Enforcement mode. For more information and additional steps to enable protection on domain controller servers, see Managing deployment of Kerberos S4U changes for CVE-2020-17049.
- Security updates to Windows Apps, Windows Fundamentals, Windows Authentication, Windows Graphics, Microsoft Scripting Engine, Windows HTML Platforms, and Windows MSHTML Platform.
Details about the fixed vulnerabilities can be found on this page. This update is automatically downloaded and installed via Windows Update. The package is also available via Microsoft Update Catalog and is distributed via WSUS. Details about the requirements and known issues can be found in the KB article.
KB5004307 (Security Only) for Windows 7/Windows Server 2008 R2
Update KB5004307 (Security-only update) is available for Windows 7 SP1 and Windows Server 2008 R2 SP1 with ESU license. The update addresses the following issues.
- Adds Advanced Encryption Standard (AES) encryption protections for CVE-2021-33757. For more information, see KB5004605.
- Removes support for the PerformTicketSignature setting and permanently enables Enforcement mode. For more information and additional steps to enable protection on domain controller servers, see Managing deployment of Kerberos S4U changes for CVE-2020-17049.
- Security updates to Windows Apps, Windows Fundamentals, Windows Authentication, and Windows Graphics.
The update is available via WSUS or in the Microsoft Update Catalog. To install the update, you must meet the prerequisites listed in the KB article and in the rollup update above. The update has the errors described in the KB article. In addition, Internet Explorer 11 security update KB5004233 from July 2021 should be installed. Make sure to install the latest Servicing Stack Update (SSU KB5004378) is installed.
Advertising
Similar articles:
Microsoft Office Patchday (July 6, 2021), Fix for Outlook Crashes
Out-of-Band Update closes Windows PrintNightmare Vulnerability (July 6, 2021)
PrintNightmare out-of-band update also for Windows Server 2012 and 2016 (July 7, 2021)
Microsoft Security Update Summary (July 13, 2021)
Patchday: Windows 10-Updates (July 13, 2021)
Patchday: Windows 8.1/Server 2012-Updates (July 13, 2021)
Patchday: Updates für Windows 7/Server 2008 R2 (July 13, 2021)
Patchday Microsoft Office Updates (July 13, 2021)
Advertising