{"id":15042,"date":"2020-07-15T17:10:20","date_gmt":"2020-07-15T15:10:20","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=15042"},"modified":"2022-03-24T00:40:48","modified_gmt":"2022-03-23T23:40:48","slug":"patchday-windows-7-server-2008-r2-updates-07-14-2020","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/07\/15\/patchday-windows-7-server-2008-r2-updates-07-14-2020\/","title":{"rendered":"Patchday: Windows 7\/Server 2008 R2 Updates (07\/14\/2020)"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline; border-width: 0px;\" title=\"Update\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/02\/Update.jpg\" alt=\"Windows Update\" width=\"54\" height=\"54\" align=\"left\" border=\"0\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/07\/15\/patchday-updates-fr-windows-7-server-2008-r2-14-7-2020\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]On July 14, 2020, Microsoft released various (security) updates for Windows 7 SP1 (ESU) and Windows Server 2008 R2. Here is an overview of these updates.<\/p>\n<p><!--more--><\/p>\n<h2>Updates for Windows 7\/Windows Server 2008 R2<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg04.met.vgwort.de\/na\/0f93426c084948208626b49ee2cc2ec5\" alt=\"\" width=\"1\" height=\"1\" \/>A rollup and a security-only update have been released for Windows 7 SP1 and Windows Server 2008 R2 SP1. However, these updates are now only available for systems with ESU licenses. The update history for Windows 7 can be found on <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4009469\" target=\"_blank\" rel=\"noopener noreferrer\">this Microsoft page<\/a>. Installation requires installed SHA2 support for successful installation of the security updates.<\/p>\n<blockquote><p>Starting January 15, 2020, Windows 7 will display a full-screen notification of the end of support in Starter, Home Basic, Home Premium, Professional (without ESU license) and Ultimate. This must then be closed by the user.<\/p>\n<p>As of January 14, 2020, Windows 7 SP1 and Windows Server 2008 R2 SP1 have reached the end of support and will only receive paid security updates under the ESU program. ESU license holders should visit the <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/release-information\/windows-message-center\" target=\"_blank\" rel=\"noopener noreferrer\">Windows Message Center<\/a>\u00a0 for details.<\/p>\n<p>Microsoft last updated the <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/obtaining-extended-security-updates-for-eligible-windows-devices\/ba-p\/1167091\" target=\"_blank\" rel=\"noopener noreferrer\">Techcommunity article on the ESU program<\/a> on February 11, 2020. Please refer to the notes on requirements (SSU, SHA-2). Additionally, for ESU systems, you must manually install the <a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=KB4538483\" target=\"_blank\" rel=\"noopener noreferrer\">KB4538483<\/a> update from the Update Catalog. Furthermore, the update <a href=\"https:\/\/support.microsoft.com\/help\/4538483\/\" target=\"_blank\" rel=\"noopener noreferrer\">KB4538483<\/a> was released in May 2020 (see <a href=\"https:\/\/borncity.com\/win\/2020\/05\/09\/windows-7-esu-update-kb4538483-may-2020\/\">Windows 7 ESU-Update KB4538483 (May 2020)<\/a>).<\/p>\n<p>Because the updates are provided in the Microsoft Update Catalog, do not attempt to install them on systems that do not have an ESU license. The installation fails and a rollback occurs. But what works: Use the BypassESU method described in the links at the end of this article (see <a href=\"https:\/\/borncity.com\/win\/2020\/03\/05\/windows-7-forcing-february-2020-security-updates-part-1\/\">Windows 7: Forcing February 2020 Security Updates \u2013 Part 1<\/a>). <a href=\"https:\/\/www.borncity.com\/blog\/2020\/07\/15\/microsoft-security-update-summary-14-juli-2020\/#comment-92016\" target=\"_blank\" rel=\"noopener noreferrer\">This German comment<\/a> confirms that the July updates could be installed with it. Also note the discussion <a title=\"https:\/\/www.borncity.com\/blog\/2020\/05\/12\/windows-7-wink-mit-dem-zaunpfahl-bei-gkd-el\/#comment-89052\" href=\"https:\/\/www.borncity.com\/blog\/2020\/05\/12\/windows-7-wink-mit-dem-zaunpfahl-bei-gkd-el\/#comment-89052\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/p><\/blockquote>\n<blockquote><p>Important: Starting in July 2020 all Windows updates disable the <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-server\/virtualization\/hyper-v\/deploy\/deploy-graphics-devices-using-remotefx-vgpu\" target=\"_blank\" rel=\"noopener noreferrer\">RemoteFX vGPU feature<\/a> due to the <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\/vulnerability\/CVE-2020-1036\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-1036<\/a> vulnerability (see also <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4570006\" target=\"_blank\" rel=\"noopener noreferrer\">KB4570006<\/a>). After installing this update, attempts to start virtual machines (VM) with RemoteFX vGPU enabled will fail. More information can be found in the <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4565541\" target=\"_blank\" rel=\"noopener noreferrer\">KB article<\/a> and <a href=\"https:\/\/go.microsoft.com\/fwlink\/?linkid=2131976)\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/p><\/blockquote>\n<h3>KB4565524 (Monthly Rollup) for Windows 7\/Windows Server 2008 R2<\/h3>\n<p>Update <a href=\"https:\/\/support.microsoft.com\/help\/4565524\" target=\"_blank\" rel=\"noopener noreferrer\">KB4565524<\/a> (Monthly Quality Rollup for Windows 7 SP1 and Windows Server 2008 R2 SP1) contains (besides the security fixes from last month) improvements and bug fixes and addresses the following issues:<\/p>\n<blockquote><p>Security updates to Windows App Platform and Frameworks, Windows Apps, Windows Graphics, Windows Input and Composition, Windows Fundamentals, Windows Kernel, Windows Remote Desktop, Internet Explorer, the Microsoft Scripting Engine, and Windows SQL components.<\/p><\/blockquote>\n<p>Compared to the previous months, nothing has changed for ESU systems. This update is automatically downloaded and installed by Windows Update. The package is also available through the <a href=\"https:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=KB4565524\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a> and is distributed via WSUS. For details about requirements and known issues (without ESU, installation fails and there is a \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\" error), see the <a href=\"https:\/\/support.microsoft.com\/help\/4565524\" target=\"_blank\" rel=\"noopener noreferrer\">KB article<\/a>. There you will also find information that the SSU <a href=\"https:\/\/support.microsoft.com\/help\/4565354\/\" target=\"_blank\" rel=\"noopener noreferrer\">KB4565354<\/a> has to be installed afterwards.<\/p>\n<h3>KB4565539 (Security Only) for Windows 7\/Windows Server 2008 R2<\/h3>\n<p>Update <a href=\"https:\/\/support.microsoft.com\/help\/4565539\" target=\"_blank\" rel=\"noopener noreferrer\">KB4565539<\/a> (Security-only update) is available for Windows 7 SP1 and Windows Server 2008 R2 SP1 with ESU license. The update addresses the following issues.<\/p>\n<blockquote><p>Security updates to Windows App Platform and Frameworks, Windows Apps, Windows Graphics, Windows Input and Composition, Windows Fundamentals, Windows Kernel, Windows Remote Desktop, and Windows SQL components.<\/p><\/blockquote>\n<p>The update is available via WSUS or in the <a href=\"http:\/\/catalog.update.microsoft.com\/v7\/site\/Search.aspx?q=KB44565539\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a>. To install the update, you must meet the prerequisites listed in the KB article and in the Rollup Update above. In addition, the security update <a href=\"https:\/\/support.microsoft.com\/help\/4565479\/\">KB4565479<\/a> for IE should also be installed.<\/p>\n<h3>Servicing Stack Update KB4565354<\/h3>\n<p>The Servicing Stack Update <a href=\"https:\/\/support.microsoft.com\/help\/4565354\/\" target=\"_blank\" rel=\"noopener noreferrer\">KB4565354<\/a> for Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 was released on July 14, 2020. This update makes quality improvements to the service stack and ensures that Windows has a robust and reliable service stack to receive and install Microsoft updates.<\/p>\n<p>This update also fixes an increased privilege escalation vulnerability that occurs when the Windows Modules Installer does not process file operations correctly. An attacker who successfully exploited this vulnerability could be granted elevated privileges. This security update resolves the vulnerability by ensuring that Windows Modules Installer correctly handles file operations. For more information, see <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-1346\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-1346<\/a> (Windows Modules Installer Elevation of Privilege Vulnerability).<\/p>\n<p><strong>Similar articles:<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2020\/07\/08\/microsoft-office-patchday-july-72020\/\">Microsoft Office Patchday (July 7, 2020)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2020\/07\/15\/microsoft-security-update-summary-july-14-2020\/\">Microsoft Security Update Summary (14. Juli 2020)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2020\/07\/15\/patchday-windows-10-updates-july-14-2020\/\">Patchday: Windows 10-Updates (14. Juli 2020)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2020\/07\/15\/patchday-windows-8-1-server-2012-updates-july-14-2020\/\">Patchday: Windows 8.1\/Server 2012-Updates (July 14, 2020)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2020\/07\/15\/patchday-windows-7-server-2008-r2-updates-07-14-2020\/\">Patchday: Windows 7\/Server 2008 R2 Updates (07\/14\/2020)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]On July 14, 2020, Microsoft released various (security) updates for Windows 7 SP1 (ESU) and Windows Server 2008 R2. Here is an overview of these updates.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,22,2],"tags":[2195,2522,2519,2520,2521,2507,69,195,17,18],"class_list":["post-15042","post","type-post","status-publish","format-standard","hentry","category-security","category-update","category-windows","tag-esu","tag-kb4565354","tag-kb4565479","tag-kb4565524","tag-kb4565539","tag-patchday-07-2020","tag-security","tag-update","tag-windows-7","tag-windows-server-2008-r2"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/15042","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=15042"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/15042\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=15042"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=15042"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=15042"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}