{"id":10421,"date":"2019-07-11T11:11:55","date_gmt":"2019-07-11T09:11:55","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=10421"},"modified":"2019-07-11T11:12:49","modified_gmt":"2019-07-11T09:12:49","slug":"windows-7-update-kb4507456-security-only-with-telemetry","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2019\/07\/11\/windows-7-update-kb4507456-security-only-with-telemetry\/","title":{"rendered":"Windows 7 Update KB4507456 (security only) with Telemetry"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" title=\"win7\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; float: left; margin: 0px 10px 0px 0px; display: inline; border-top-width: 0px\" border=\"0\" alt=\"win7\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2012\/03\/win7_thumb1.jpg\" width=\"44\" align=\"left\" height=\"42\">[<a href=\"https:\/\/www.borncity.com\/blog\/2019\/07\/11\/windows-7-update-kb4507456-mit-telemetrie-im-beipack\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]It's an unpleasant surprise administrators of Windows 7 systems. July 9, 2019 patchday from Microsoft comes also with security-only Update KB4507456, but this package has telemetry on board.&nbsp; <\/p>\n<p><!--more--><\/p>\n<h2>Rollup and security-only updates <\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg01.met.vgwort.de\/na\/8276801f77774c2db2771af2b4015941\" width=\"1\" height=\"1\">A brief review of the nomenclature. For Windows 7 SP1 and Windows Server 2008\/R2 there was a monthly rollup update as well as a security-only update. The monthly rollup update contained all security fixes, but also bug fixes. And this rollup update included telemetry features. <\/p>\n<p>Exactly these telemetry functions were missing in the security-only updates that Microsoft offers in the Microsoft Update Catalog and via WSUS. Many administrators have therefore installed the security-only updates.<\/p>\n<h2>Security-only update with Telemetry<\/h2>\n<p>German blog reader Bolko had already posted <a href=\"https:\/\/www.borncity.com\/blog\/2019\/07\/10\/patchday-updates-fr-windows-7-8-1-server-9-juli-2019-2\/#comment-74568\" target=\"_blank\" rel=\"noopener noreferrer\">this comment<\/a> on the blog a few hours ago (thanks for that). <\/p>\n<blockquote>\n<p>The security-only KB4507456 contains telemetry (KB2952664, diagtrack, appraiser). Telemetry was previously only included in the rollups, but not in security-only. Secretly quiet and quietly Microsoft wants to extend the monitoring.<\/p>\n<\/blockquote>\n<p>I only noticed that, but haven't time to dig in. Later, while visiting <em>askwoody.com<\/em> I came across the article <a href=\"https:\/\/www.askwoody.com\/2019\/microsoft-surreptitiously-adds-telemetry-functionality-to-july-2019-win7-security-only-patch\/\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft surreptitiously adds telemetry functionality to July 2019 Win7 Security-only patch<\/a> linked by Bolko. Microsoft has added silently telemetry functionality to the July 2019 Security-only update for Windows 7 KB4507456. An anonymous poster had contacted <em>askwoody.com<\/em> with the following hint:  <\/p>\n<blockquote>\n<p>Warning for group B Windows 7 users!  <\/p>\n<p>The \"July 9, 2019\u2014KB4507456 (Security-only update)\" is NOT \"security-only\" update.  <\/p>\n<p>It replaces infamous KB2952664 and contains telemetry. Some details can be found in&nbsp; <a href=\"http:\/\/download.microsoft.com\/download\/5\/9\/1\/591534C3-E10D-427B-8889-69D20F36FBB5\/4507456.csv\" target=\"_blank\" rel=\"noopener noreferrer\">file information for update 4507456<\/a> (keywords: \"telemetry\", \"diagtrack\" and \"appraiser\") and under <a href=\"http:\/\/www.catalog.update.microsoft.com\/ScopedViewInline.aspx?updateid=7cdee6a8-6f30-423e-b02c-3453e14e3a6e\" target=\"_blank\" rel=\"noopener noreferrer\">http:\/\/www.catalog.update.microsoft.com\/ScopedViewInline.aspx?updateid=7cdee6a8-6f30-423e-b02c-3453e14e3a6e<\/a> (in \"Package details\"-&gt;\"This update replaces the following updates\" and there is KB2952664 listed).  <\/p>\n<p>It doesn't apply for IA-64-based systems, but applies both x64 and x86-based systems.<\/p>\n<\/blockquote>\n<p>The poster had inspected the file list (<a href=\"http:\/\/download.microsoft.com\/download\/5\/9\/1\/591534C3-E10D-427B-8889-69D20F36FBB5\/4507456.csv\" target=\"_blank\" rel=\"noopener noreferrer\">link<\/a> is available the KB article). There are entries for files with names like \"telemetry\", \"diagtrack\" and \"appraiser\". In 2016, I had already written something about the Diagnostics Tracking service (DiagTrack) in the article <a href=\"https:\/\/www.borncity.com\/blog\/2016\/11\/06\/plant-microsoft-die-ausweitung-der-telemetriedatenerfassung-in-windows-78-1\/\" target=\"_blank\" rel=\"noopener noreferrer\">Plant Microsoft die Ausweitung der Telemetriedatenerfassung in Windows 7\/8.1?<\/a> At askwoody.com <a href=\"https:\/\/www.askwoody.com\/forums\/topic\/microsoft-surreptitiously-adds-telemetry-functionality-to-july-2019-win7-security-only-patch\/#post-1873658\" target=\"_blank\" rel=\"noopener noreferrer\">abbodi86 writes<\/a> that DiagTrack is part of the Compatel Runner. And about appraiser I had written something documented in the article <a href=\"https:\/\/borncity.com\/win\/2017\/08\/31\/windows-10-v1607-update-kb4033637-finally-documented\/\">Windows 10 V1607: Update KB4033637 finally documented<\/a>.&nbsp; <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i.imgur.com\/YQvBLsq.jpg\">  <\/p>\n<p>The anonymous poster at <em>askwoody.com<\/em> made another interesting statement. In the <a href=\"https:\/\/www.catalog.update.microsoft.com\/ScopedViewInline.aspx?updateid=7cdee6a8-6f30-423e-b02c-3453e14e3a6e\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog for update KB4507456<\/a> you will find on the tab <em>Package Details<\/em> the information that the update KB4507456 replaces three other updates. Among others the update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/2952664\/compatibility-update-for-keeping-windows-up-to-date-in-windows-7\" target=\"_blank\" rel=\"noopener noreferrer\">KB2952664<\/a> will be replaced, a compatibility update to keep Windows 7 up to date. The KB article says:  <\/p>\n<blockquote>\n<p>This update performs diagnostics on the Windows systems that participate in the Windows Customer Experience Improvement Program. The diagnostics evaluate the compatibility status of the Windows ecosystem, and help Microsoft to ensure application and device compatibility for all updates to Windows. There is no GWX or upgrade functionality contained in this update.<\/p>\n<\/blockquote>\n<p>This is interpreted on askwoody.com in such a way that telemetry functions now find their way into security-only updates. It is still unclear whether the telemetry is now included in every security-only update or whether it is a one-time thing. At askwoody.com there is <a href=\"https:\/\/www.askwoody.com\/forums\/topic\/2000012-neutralize-telemetry-sustain-win-7-8-1-monthly-rollup-model\/\" target=\"_blank\" rel=\"noopener noreferrer\">this thread<\/a> which describes how to disable the telemetry. <\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"de\">\n<p lang=\"en\" dir=\"ltr\">I have officially stopped updating my Win7 machine. I no longer trust Microsoft's updating process. I'll protect it from any existing and future vulnerabilities with my other defenses, as well as I can. Fuck you, <a href=\"https:\/\/twitter.com\/Microsoft?ref_src=twsrc%5Etfw\">@microsoft<\/a>.<a href=\"https:\/\/t.co\/x3CYassKMO\">https:\/\/t.co\/x3CYassKMO<\/a><\/p>\n<p>\u2014 Vess (@VessOnSecurity) <a href=\"https:\/\/twitter.com\/VessOnSecurity\/status\/1149003884284846085?ref_src=twsrc%5Etfw\">10. Juli 2019<\/a><\/p><\/blockquote>\n<p><span id=\"preserveefaa2aab6fd547318ae19f9d1366d26e\" class=\"wlWriterPreserve\"><SCRIPT charset=\"utf-8\" src=\"https:\/\/platform.twitter.com\/widgets.js\" async><\/SCRIPT><\/span> <\/p>\n<p>VessOnSecurity,&nbsp; a security researcher has drawn consequences and announced them on Twitter (see above). He won't update his Windows 7 anymore, because he doesn't trust Microsoft anymore.<\/p>\n<p><strong>Similar articles:<br \/><\/strong><a href=\"https:\/\/borncity.com\/win\/2019\/07\/10\/patchday-updates-fr-windows-7-8-1-server-9-juli-2019-2\/\">Patchday: Updates for Windows 7\/8.1\/Server (July 9, 2019)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2019\/07\/10\/patchday-windows-10-updates-july-9-2019\/\">Patchday Windows 10 Updates (July 9, 2019)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2019\/07\/11\/windows-july-9-2019-updates-breaks-sfc\/\">Windows: July 9, 2019 Updates breaks sfc<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]It's an unpleasant surprise administrators of Windows 7 systems. July 9, 2019 patchday from Microsoft comes also with security-only Update KB4507456, but this package has telemetry on board.&nbsp;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,22,2],"tags":[2036,2025,660,195],"class_list":["post-10421","post","type-post","status-publish","format-standard","hentry","category-security","category-update","category-windows","tag-indows-7","tag-kb4507456","tag-telemetry","tag-update"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/10421","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=10421"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/10421\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=10421"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=10421"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=10421"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}