{"id":10827,"date":"2019-08-21T01:49:12","date_gmt":"2019-08-20T23:49:12","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=10827"},"modified":"2019-08-21T01:49:25","modified_gmt":"2019-08-20T23:49:25","slug":"symantec-releases-a-patch-for-the-sha-2-bug-in-windows-7","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2019\/08\/21\/symantec-releases-a-patch-for-the-sha-2-bug-in-windows-7\/","title":{"rendered":"Symantec releases a patch for the SHA-2 bug in Windows 7"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" title=\"win7\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; float: left; margin: 0px 10px 0px 0px; display: inline; border-top-width: 0px\" border=\"0\" alt=\"win7\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2012\/03\/win7_thumb1.jpg\" width=\"44\" align=\"left\" height=\"42\"> [<a href=\"https:\/\/www.borncity.com\/blog\/2019\/08\/21\/symantec-verffentlicht-patch-fr-sha-2-bug-in-windows-7\/\" target=\"_blank\" rel=\"noopener noreferrer\">English<\/a>]Antivirus vendor Symantec has released a patch to fix the update issue on Windows 7 \/ Windows Server 2008 R2. Distribution is scheduled for August 21, 2019 for various language versions, the English version is said to have already been released. Here is some information on the topic.&nbsp; <\/p>\n<p><!--more--><\/p>\n<h2>What exactly we are talking about?<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg01.met.vgwort.de\/na\/81ab6b4a77bc47e5aeeb8c3158a261a1\" width=\"1\" height=\"1\">Microsoft has changed the signing of Update for Windows 7 in August 2019 exclusively to SHA-2. I've addressed this, among other things, in the blog post <a href=\"https:\/\/borncity.com\/win\/2018\/11\/21\/windows-7-from-april-2019-sha-2-support-is-required\/\">Windows 7: From April 2019 'SHA-2-Support' is required<\/a>. This is not a problem, because Microsoft has provided the relevant updates to SHA-2 support since months. So far, Microsoft has also provided dual-signed update packages signed with SHA-1 as well as SHA-2.<\/p>\n<p>As of August 2019, however, the SHA-1 signature in the Windows 7 updates has been completely removed. These can only be installed if Windows 7 SP1, Windows Server 2008, Windows Server 2008 R2 and WSUS have been upgraded accordingly (see also <a href=\"https:\/\/borncity.com\/win\/2019\/07\/04\/wsus-endpoint-decommissioned-sha2-update-required\/\">WSUS: Endpoint decommissioned; SHA2 update required<\/a>).<\/p>\n<p>However, users of Windows systems that have Symantec Antivirus or Norton Antivirus installed have a problem since the August 2019 patchday. The antivirus solutions only detected updates signed with SHA2 (because of the missing SHA-1 signature) as malware and blocked these packages. <\/p>\n<p>Symantec has published the KB article <a href=\"https:\/\/support.symantec.com\/us\/en\/article.tech255857.html\" target=\"_blank\" rel=\"noopener noreferrer\">Windows 7\/Windows 2008 R2 updates that are only SHA-2 signed are not available with Symantec Endpoint Protection installed<\/a> . Microsoft has therefore blocked the deployment of the August 2019 updates for Windows 7 SP1 and Windows Server 2008 R2. The required August 2019 security updates were not offered. I reported in the blog post <a href=\"https:\/\/borncity.com\/win\/2019\/08\/14\/symantec-norton-blocks-windows-updates-sha-2\/\">Symantec\/Norton blocks Windows Updates (SHA-2)<\/a>.<\/p>\n<h2>Symantec startet rollout a patch<\/h2>\n<p>Through the following tweet by Woody Leonhard I became aware that Symantec has now released an update to solve this problem.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Remember that block on Win7 patches this month, on systems with Symantec or Norton antivirus? Looks like Symantec has released a fix and you can now install this month's patches. (MS's KB articles haven't been updated.) <a href=\"https:\/\/t.co\/2j8ZQp0LWi\">https:\/\/t.co\/2j8ZQp0LWi<\/a><\/p>\n<p>\u2014 Woody Leonhard (@AskWoody) <a href=\"https:\/\/twitter.com\/AskWoody\/status\/1163937843581980673?ref_src=twsrc%5Etfw\">August 20, 2019<\/a><\/p><\/blockquote>\n<p><span id=\"preserve6e9752fbb087456ca3055916a5f8c5b5\" class=\"wlWriterPreserve\"><SCRIPT charset=\"utf-8\" src=\"https:\/\/platform.twitter.com\/widgets.js\" async><\/SCRIPT><\/span> <\/p>\n<p>Leonhard received a notification from CA, which indicates the release of the patch:<\/p>\n<blockquote>\n<p>Symantec released an updated version of Norton Internet Security that<br \/>fixes the SHA-2 patch problem for Windows 7 this morning (Tues). The new version will show up through Live Update (140+ mb).  <\/p>\n<p>Once the patched version is applied (v22.18.0.222), security roll-ups<br \/>for August (Group A \u2013 Aug 13 KB4512506) will appear in Windows Update<br \/>without user intervention. A reboot may be required for this to happen.  <\/p>\n<p>MS has not updated KB4512506 or KB4512486 to reflect this:<br \/><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4512506\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/support.microsoft.com\/en-us\/help\/4512506<\/a>  <\/p>\n<p>For Symantec Endpoint Protection users, the English 14.2 version has<br \/>been updated. Localized language versions will be available on the 21st.<\/p>\n<\/blockquote>\n<p>The <a href=\"https:\/\/support.symantec.com\/us\/en\/article.tech255857.html\" target=\"_blank\" rel=\"noopener noreferrer\">Support article about Symantec Endpoint Protection<\/a> hasn't been udated yet. But I expect Symantec\/Norton users will receive the fix later today and Microsoft to release the August 2019 security updates for affected Windows systems. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[English]Antivirus vendor Symantec has released a patch to fix the update issue on Windows 7 \/ Windows Server 2008 R2. Distribution is scheduled for August 21, 2019 for various language versions, the English version is said to have already been &hellip; <a href=\"https:\/\/borncity.com\/win\/2019\/08\/21\/symantec-releases-a-patch-for-the-sha-2-bug-in-windows-7\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,580,2],"tags":[1537,2078,17],"class_list":["post-10827","post","type-post","status-publish","format-standard","hentry","category-issue","category-security","category-windows","tag-issueupdate","tag-symantec","tag-windows-7"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/10827","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=10827"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/10827\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=10827"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=10827"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=10827"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}