{"id":13118,"date":"2020-02-12T18:12:26","date_gmt":"2020-02-12T17:12:26","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=13118"},"modified":"2024-10-05T18:41:10","modified_gmt":"2024-10-05T16:41:10","slug":"patchday-updates-for-windows-7-8-1-server-feb-11-2020","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/02\/12\/patchday-updates-for-windows-7-8-1-server-feb-11-2020\/","title":{"rendered":"Patchday: Updates for Windows 7\/8.1\/Server (Feb. 11, 2020)"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline; border-width: 0px;\" title=\"Update\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/02\/Update.jpg\" alt=\"Windows Update\" width=\"54\" height=\"54\" align=\"left\" border=\"0\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/02\/12\/patchday-updates-fr-windows-7-8-1-server-11-februar-2020\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]On February 11, 220, Microsoft released various (security) updates for Windows 7 SP1 (ESU) and other updates for Windows 8.1 and the corresponding server versions. Here is an overview of these updates. Addition: Various information about Windows 7 added.<\/p>\n<p><!--more--><\/p>\n<h2>Updates for Windows 7\/Windows Server 2008 R2<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg01.met.vgwort.de\/na\/f2e434ae9c154cf586e0d07cd5b29171\" alt=\"\" width=\"1\" height=\"1\" \/>A rollup and a security-only update have been released for Windows 7 SP1 and Windows Server 2008 R2 SP1. However, these updates are now only available for systems with an ESU license. The update history for Windows 7 can be found on <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4009469\" target=\"_blank\" rel=\"noopener noreferrer\">this Microsoft site<\/a>. Installation requires installed SHA2 support for successful installation of the security updates.<\/p>\n<blockquote><p>Beginning January 15, 2020, Windows 7 will display a full-screen end-of-support notification in Starter, Home Basic, Home Premium, Professional (without ESU license), and Ultimate. This must then be closed by the user.<\/p>\n<p>As of January 14, 2020, Windows 7 SP1 and Windows Server 2008 R2 SP1 have reached the end of support and will only receive paid security updates under the ESU program. ESU license holders should visit the <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/release-information\/windows-message-center#388\" target=\"_blank\" rel=\"noopener noreferrer\">Windows Message Center<\/a> for details.<\/p>\n<p>In addition, Microsoft has updated the <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/obtaining-extended-security-updates-for-eligible-windows-devices\/ba-p\/1167091\" target=\"_blank\" rel=\"noopener noreferrer\">Techcommunity article on the ESU program<\/a> on February 11, 2020. Please refer to the notes on the requirements (SSU, SHA-2). Additionally, for ESU systems, you must manually install update <a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=KB4538483\" target=\"_blank\" rel=\"noopener noreferrer\">KB4538483<\/a> from the Update Catalog.<\/p>\n<p>Because the updates are provided in the Microsoft Update Catalog, do not attempt to install them on non-ESU systems. According to <a href=\"https:\/\/www.borncity.com\/blog\/2020\/02\/11\/microsoft-security-update-summary-11-februar-2020\/#comment-84968\" target=\"_blank\" rel=\"noopener noreferrer\">feedback<\/a> I have received, the installation fails and a rollback occurs.<\/p><\/blockquote>\n<h3>KB4537820 (Monthly Rollup) for Windows 7\/Windows Server 2008 R2<\/h3>\n<p>Update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4537820\" target=\"_blank\" rel=\"noopener noreferrer\">KB44537820<\/a> (Monthly Quality Rollup for Windows 7 SP1 and Windows Server 2008 R2 SP1) contains (besides the security fixes from last month) improvements and bug fixes and addresses:<\/p>\n<blockquote><p>Security updates to Internet Explorer, Microsoft Graphics Component, Windows Input and Composition, Windows Media, Windows Shell, Windows Fundamentals, Windows Cryptography, Windows Hyper-V, Windows Core Networking, Windows Peripherals, Windows Network Security and Containers, Windows Storage and Filesystems, the Microsoft Scripting Engine, and Windows Server.<\/p><\/blockquote>\n<p>There are some security fixes &#8211; Microsoft does not disclose any details. However, a remote code execution vulnerability <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\/vulnerability\/CVE-2020-0662\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-0662<\/a> in memory object handling has been closed for Windows 7. Compared to the previous months, nothing has changed for ESU systems. This update is automatically downloaded and installed by Windows Update. It is also available from the <a href=\"https:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=KB4537820\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a> and is distributed via WSUS. Details about the requirements and known issues can be found in the <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4537820\" target=\"_blank\" rel=\"noopener noreferrer\">KB article<\/a> &#8211; first installation experiences can be found in <a href=\"https:\/\/www.borncity.com\/blog\/2020\/02\/11\/microsoft-security-update-summary-11-februar-2020\/#comment-84974\" target=\"_blank\" rel=\"noopener noreferrer\">my German blog<\/a>.<\/p>\n<p>The installation requires that the SSU(<a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4490628\" target=\"_blank\" rel=\"noopener noreferrer\">KB4490628<\/a> rom March 2019 and the SHA-2 update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4474419\" target=\"_blank\" rel=\"noopener noreferrer\">KB4474419<\/a> from September 10, 2019, but if in doubt, go through the notes <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/obtaining-extended-security-updates-for-eligible-windows-devices\/ba-p\/1167091\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>, currently the MS documentation seems inconsistent) is already installed. When installing via Windows Update, this will be installed automatically. After the update installation Microsoft recommends to install SSU <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4536952\">KB4536952<\/a> (if not already installed).<\/p>\n<blockquote>\n<blockquote><p>If you do not have an ESU license and want to continue running Windows 7 SP1 online, you should take a look at the 0patch solution. There is no micro-patch available yet, but I will report as soon as I know details.<\/p>\n<p>In addition to the RCE vulnerability mentioned above, there is <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\/vulnerability\/\/CVE-2020-0683\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-0683<\/a>\u00a0 in the MSI installer that has <a href=\"https:\/\/padovah4ck.github.io\/CVE-2020-0683\/\" target=\"_blank\" rel=\"noopener noreferrer\">already been exploited<\/a>.<\/p><\/blockquote>\n<\/blockquote>\n<h3>KB4537813(Security Only) for Windows 7\/Windows Server 2008 R2<\/h3>\n<p>Update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4537813\" target=\"_blank\" rel=\"noopener noreferrer\">KB4537813<\/a> (Security-only update) is available for Windows 7 SP1 and Windows Server 2008 R2 SP1 with ESU license. The update addresses the following issues.<\/p>\n<blockquote><p>Security updates to Microsoft Graphics Component, Windows Input and Composition, Windows Media, Windows Shell, Windows Fundamentals, Windows Cryptography, Windows Hyper-V, Windows Core Networking, Windows Peripherals, Windows Network Security and Containers, Windows Storage and Filesystems, and Windows Server.<\/p><\/blockquote>\n<p>The update is available via WSUS or in the <a href=\"http:\/\/catalog.update.microsoft.com\/v7\/site\/Search.aspx?q= KB4537813\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a>. In order to install the update, the preconditions listed in the KB article and above for the rollup update must be met (but if in doubt, go through <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/obtaining-extended-security-updates-for-eligible-windows-devices\/ba-p\/1167091\" target=\"_blank\" rel=\"noopener noreferrer\">the notes here<\/a>, currently the MS documentation does not seem consistent). In addition, the security update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4537767\/\" target=\"_blank\" rel=\"noopener noreferrer\">KB4537767<\/a> for IE should also be installed.<\/p>\n<p><strong>Note: <\/strong>Currently I can't quite place it, but I'd like to refer you to the tweet from Woody Leonhard:<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">And that quote&#8230; \"We investigated and determined that some users encountered issues after attempting to deploy SHA-2 signed updates without fully deploying the latest SHA-2 enablement packages.\" Sure doesn't sound right to me. How could they install without SHA-2 support?<\/p>\n<p>\u2014 Woody Leonhard (@AskWoody) <a href=\"https:\/\/twitter.com\/AskWoody\/status\/1227344843283759109?ref_src=twsrc%5Etfw\">February 11, 2020<\/a><\/p><\/blockquote>\n<p><span id=\"preserveb4c2b0f8fe4842779f720fc5c00ad616\" class=\"wlWriterPreserve\"><script src=\"https:\/\/platform.twitter.com\/widgets.js\" async=\"\" charset=\"utf-8\"><\/script><\/span><\/p>\n<p>Would explain the issues discussed within the blog post <a href=\"https:\/\/borncity.com\/win\/2020\/02\/11\/win-7-server-2008-r2-boot-issues-with-update-kb4539602\/\">Win 7\/Server 2008 R2: Boot issues with Update KB4539602<\/a> irgendwie erkl\u00e4ren.<\/p>\n<h2>Updates for Windows 8.1\/Windows Server 2012 R2<\/h2>\n<p>For Windows 8.1 and Windows Server 2012 R2 a rollup and a security-only update have been released. The update history for Windows 8.1 can be found on <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4009470\/windows-8-1-windows-server-2012-r2-update-history\" target=\"_blank\" rel=\"noopener noreferrer\">this Microsoft page<\/a>.<\/p>\n<h3>KB4537821 (Monthly Rollup) for Windows 8.1\/Server 2012 R2<\/h3>\n<p>Update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4537821\" target=\"_blank\" rel=\"noopener noreferrer\">KB4537821<\/a> (Monthly Rollup for Windows 8.1 and Windows Server 2012 R2) contains improvements and fixes, and addresses the following.<\/p>\n<ul>\n<li>Disables Microsoft Visual Basic Script (VBScript) by default in the Internet and Restricted sites zones in Internet Explorer and the WebBrowser control.<\/li>\n<li>Security updates to Internet Explorer, Microsoft Graphics Component, Windows Input and Composition, Windows Media, Windows Shell, Windows Fundamentals, Windows Cryptography, Windows Hyper-V, Windows Core Networking, Windows Peripherals, Windows Network Security and Containers, Windows Storage and Filesystems, the Microsoft Scripting Engine, and Windows Server.<\/li>\n<\/ul>\n<p>This update is automatically downloaded and installed by Windows Update, but is also available in the <a href=\"https:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=KB4537821\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a> and via WSUS. In case of a manual installation, the latest Servicing Stack Update (SSU <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4524445\" target=\"_blank\" rel=\"noopener noreferrer\">KB4524445<\/a>) must be installed before.<\/p>\n<p>The update has a known issue: Certain actions, such as renaming, that you perform on files or folders that are located on a cluster shared volume (CSV) may fail with the error \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\". This occurs when you perform the action on a CSV owner node from a process that does not have administrator privileges. See the KB article for details.<\/p>\n<h3>KB4537803 (Security-only update) for Windows 8.1\/Server 2012 R2<\/h3>\n<p>Update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4537803\" target=\"_blank\" rel=\"noopener noreferrer\">KB4537803<\/a> (Security Only Quality Update for Windows 8.1 and Windows Server 2012 R2) addresses the following items.<\/p>\n<blockquote><p>Security updates to Microsoft Graphics Component, Windows Input and Composition, Windows Media, Windows Shell, Windows Fundamentals, Windows Cryptography, Windows Hyper-V, Windows Core Networking, Windows Peripherals, Windows Network Security and Containers, Windows Storage and Filesystems, and Windows Server.<\/p><\/blockquote>\n<p>The update is available via WSUS or in the <a href=\"http:\/\/catalog.update.microsoft.com\/v7\/site\/Search.aspx?q=KB4537803\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a>.\u00a0 The update has the same known issues as the rollup update, these are described in the KB article. In case of a manual installation the latest Servicing Stack Update (SSU) must be installed before. You should also install the security update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4537767\/\" target=\"_blank\" rel=\"noopener noreferrer\">KB4537767<\/a> for IE. For this update, Microsoft lists the same known issues as for rollup update.<\/p>\n<h2>Update KB4502496 for Windows 8.1-10\/Server<\/h2>\n<p>Microsoft has released also the update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4502496\/security-update-for-windows-10-version-1507-windows-8-1-rt-8-1-server\" target=\"_blank\" rel=\"noopener noreferrer\">KB4502496<\/a> for Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012 R2 and Windows Server 2012.<\/p>\n<blockquote><p>Addresses an issue in which a third-party Unified Extensible Firmware Interface (UEFI) boot manager might expose UEFI-enabled computers to a security vulnerability.<\/p><\/blockquote>\n<p>The update comes via Windows Update and WSUS and can be found in the <a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=KB4502496\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a>.<\/p>\n<p><strong>Similar articles:<br \/>\n<\/strong>Adobe Flash Player 32.0.0.330 released<br \/>\nMicrosoft Office Patchday (February 4, 2020)<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2020\/02\/12\/microsoft-security-update-summary-february-11-2020\/\">Microsoft Security Update Summary (February 11, 2020)<\/a><br \/>\nPatchday Windows 10-Updates (February 11, 2020)<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2020\/02\/12\/patchday-updates-for-windows-7-8-1-server-feb-11-2020\/\">Patchday: Updates for Windows 7\/8.1\/Server (Feb. 11, 2020)<\/a><br \/>\nPatchday Microsoft Office Updates (February 11, 2020)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]On February 11, 220, Microsoft released various (security) updates for Windows 7 SP1 (ESU) and other updates for Windows 8.1 and the corresponding server versions. Here is an overview of these updates. Addition: Various information about Windows 7 added.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,22,2],"tags":[2269,2270,2271,2272,69,195,17,23],"class_list":["post-13118","post","type-post","status-publish","format-standard","hentry","category-security","category-update","category-windows","tag-kb4537803","tag-kb4537813","tag-kb4537820","tag-kb4537821","tag-security","tag-update","tag-windows-7","tag-windows-8-1"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/13118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=13118"}],"version-history":[{"count":4,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/13118\/revisions"}],"predecessor-version":[{"id":35559,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/13118\/revisions\/35559"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=13118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=13118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=13118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}