{"id":8223,"date":"2019-01-09T12:30:28","date_gmt":"2019-01-09T11:30:28","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=8223"},"modified":"2021-01-24T11:59:24","modified_gmt":"2021-01-24T10:59:24","slug":"netzwerk-issues-with-updates-kb4480970-and-kb4480960","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2019\/01\/09\/netzwerk-issues-with-updates-kb4480970-and-kb4480960\/","title":{"rendered":"Network issues with updates KB4480970 and KB4480960"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline; border-width: 0px;\" title=\"Update\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/02\/Update.jpg\" alt=\"Windows Update\" width=\"54\" height=\"54\" align=\"left\" border=\"0\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2019\/01\/09\/netzwerkprobleme-mit-kb4480970-monthly-rollup\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]The KB4480970 (Monthly Rollup) and KB4480960 (Security only) updates were released by Microsoft on January 8, 2018 for Windows 7 SP1 and Windows Server 2008 R2 SP1. The updates seem to cause serious network issues for some people. Network shares can no longer be achieved via SMBv2 in certain environments. Here are details and a probably a fix.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg04.met.vgwort.de\/na\/2a20190b2fec42e29ca1929bad6402fa\" alt=\"\" width=\"1\" height=\"1\" \/>I thought I'd put the subject in a separate blog post. Maybe there will be a solution. Or Microsoft improves.<\/p>\n<h2>What is Update KB4480970 doing?<\/h2>\n<p>Last night Microsoft released the update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4480970\" target=\"_blank\" rel=\"noopener\">KB4480970<\/a> (Monthly Quality Rollup for Windows 7 SP1 and Windows Server 2008 R2 SP1). his fixes several security vulnerabilities, including a remote execution vulnerability in PowerShell. Furthermore, Windows is to be hardened against various side channel attacks.<\/p>\n<p>Windows 7 SP1 and Windows Server 2008 R2 SP1 should therefore be patched quickly because of the vulnerabilities (especially PowerShell). I covered the update in <a href=\"https:\/\/borncity.com\/win\/2019\/01\/09\/patchday-updates-for-windows-7-8-1-server-jan-8-2019\/\">Patchday: Updates for Windows 7\/8.1\/Server Jan. 8, 2019<\/a>.<\/p>\n<p>Microsoft mentioned, that after installing this update, network controllers (NICs) stop working \u2013 and provided a workaround to fix this issue. See <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4480970\" target=\"_blank\" rel=\"noopener\">KB4480970<\/a> for details.<\/p>\n<blockquote><p>Also security only update KB4480960 addresses the same vulnerabilities. But for this update Microsoft writes, that there are no known issues \u2013 although this update is also causing the share-issue \u2013 see below.<\/p><\/blockquote>\n<h2>Shares not accessible<\/h2>\n<p>Afer I released my German blog post <a href=\"https:\/\/www.borncity.com\/blog\/2019\/01\/09\/patchday-updates-fr-windows-7-8-1-server-8-jan-2019\/\" target=\"_blank\" rel=\"noopener\">Patchday: Updates f\u00fcr Windows 7\/8.1\/Server 8. Jan. 2019<\/a> I received several comments from administrators, reporting, that after installing KB4480970, network shares could not be accessed anymore.<\/p>\n<blockquote><p><a href=\"https:\/\/www.borncity.com\/blog\/2019\/01\/09\/patchday-updates-fr-windows-7-8-1-server-8-jan-2019\/#comment-67128\" target=\"_blank\" rel=\"noopener\">#1<\/a>: For one of our customers who do not yet participate in patch management (\"save costs\"), the installation of the KB4480970 could not achieve network shares on other clients. Was\/is this also the case for others?<\/p>\n<p><a href=\"https:\/\/www.borncity.com\/blog\/2019\/01\/09\/patchday-updates-fr-windows-7-8-1-server-8-jan-2019\/#comment-67123\" target=\"_blank\" rel=\"noopener\">#2<\/a>: KB4480970 has caused us communication problems with SQL servers at various customers today (strangely, even the fileshare could not be reached partially, if it was on a server with SQL installation). Uninstallation fixed the problem.<\/p>\n<p><a href=\"https:\/\/www.borncity.com\/blog\/2019\/01\/09\/patchday-updates-fr-windows-7-8-1-server-8-jan-2019\/#comment-67124\" target=\"_blank\" rel=\"noopener\">#3<\/a>: We use RDP to access RemotePC from our thin clients, after installing the update KB4480970 this was no longer possible. Only the deinstallation helped. Can \/ Could somebody still reproduce this or found a way to fix the bug. We do not want to leave such a security update uninstalled.<\/p><\/blockquote>\n<p>So there seems to be an issue with KB4480970 and network shares (via SMBv2). You can uninstall the update, then the problem is gone. But a security update with remote execution vulnerability fix should be installed somehow. First I thought, that the security-only update didn't cause this issue \u2013 but I got now feedback, that there is the same behavior. So the 'workaround': Installing KB4480960 didn't help. Also reinstalling the NIC won't cure that issue.<\/p>\n<h2>Analysis: SMBv2 issue and Workaround<\/h2>\n<p>Whilst I wrote the German edition of this blog post, German blog reader Andi left a <a href=\"https:\/\/www.borncity.com\/blog\/2019\/01\/09\/patchday-updates-fr-windows-7-8-1-server-8-jan-2019\/#comment-67129\" target=\"_blank\" rel=\"noopener\">comment<\/a> (thanks for that)\u00a0 with a link to German site <a href=\"https:\/\/administrator.de\/contentid\/397581#comment-1336425\" target=\"_blank\" rel=\"noopener\">administrator.de<\/a>, where he posted some analysis. Here are the analysis for my English readers:<\/p>\n<blockquote><p>Andy wrote that the updates KB4480960 and KB4480970 are affected. After his analysis, there is no SMB2 connection to a Windows 7\/Server 2008 R2 SP2 share anymore. The reason is a STATUS_INVALID_HANDLE error when negotiating the SMBv2 connection.<\/p><\/blockquote>\n<p>Meanwhile Andi has published a workaround on <a href=\"https:\/\/administrator.de\/contentid\/397581#comment-1336425\" target=\"_blank\" rel=\"noopener\">administrator.de<\/a>. The problem: Those updates are applying some restrictions know for administrative shares to all shares. Andri wrote:<\/p>\n<blockquote><p>If the Windows 7 user accesses a share, and he is an administrator on the remote system, this should work on the W7 that hosts the share (elevated cmd):<\/p><\/blockquote>\n<blockquote>\n<pre>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\system \/v LocalAccountTokenFilterPolicy \/t REG_DWORD \/d 1 \/f<\/pre>\n<p>Afterwards you have to reboot the system<\/p><\/blockquote>\n<p>The registry entry sets above, are discussed within <a href=\"https:\/\/web.archive.org\/web\/20190119194648\/https:\/\/support.microsoft.com\/en-us\/help\/942817\/how-to-change-the-remote-uac-localaccounttokenfilterpolicy-registry-se\" target=\"_blank\" rel=\"noopener\">this article<\/a> from Microsoft. Maybe you can give feedback if that helped.<\/p>\n<blockquote><p><strong>Warning:<\/strong> The above registry 'hack' is just a quick fix. But keep in mind, that this is lowering security &#8211; your client has 'admin credentials' on shares (bad, if malware nooping your network). So keep this registry change in mind &#8211; after Microsoft has released a fix, reset the\u00a0LocalAccountTokenFilterPolicy to 0.<\/p><\/blockquote>\n<p><strong>Addendum:<\/strong> There are also SMBv1 connections are affected (used by scanners pushing scans to network shares for instance). And it seems that those updates also affecting KMS activation on Windows 7 clients, see\u00a0<a href=\"https:\/\/borncity.com\/win\/2019\/01\/10\/update-kb971033-bricks-windows-7-genuine-0xc004f200\/\" rel=\"bookmark\">Update KB971033\/KB4480960\/KB4480970 bricks Windows 7 Genuine (0xc004f200)<\/a>.<\/p>\n<p><strong>Addendum 2:<\/strong>\u00a0Microsoft has now informed us, that the KMS activation issue has nothing to do with\u00a0KB4480960<a href=\"https:\/\/borncity.com\/win\/2019\/01\/10\/update-kb971033-bricks-windows-7-genuine-0xc004f200\/\" rel=\"bookmark\">\/<\/a>KB4480970 &#8211; it was just coincidence. And Microsoft hat released a fix for the network issue (see my blog post\u00a0<a href=\"https:\/\/borncity.com\/win\/2019\/01\/12\/fix-for-the-windows-7-smb-network-bug-caused-by-update-kb4480970-kb4480960\/\" rel=\"bookmark\">Fix for the Windows 7 SMB network bug caused by Update KB4480970\/KB4480960<\/a>).<\/p>\n<p><strong>Similar articles:<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2019\/01\/04\/microsoft-office-patchday-january-2-2019\/\">Microsoft Office Patchday (January 2, 2019)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/01\/05\/office-2010-updates-for-january-2019-has-been-pulled\/\">Office 2010 Updates for January 2019 has been pulled<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/01\/09\/microsoft-security-update-summary-january-8-2019\/\">Microsoft Security Update Summary (January 8, 2019)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/01\/09\/patchday-updates-for-windows-7-8-1-server-jan-8-2019\/\">Patchday: Updates for Windows 7\/8.1\/Server Jan. 8, 2019<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/01\/09\/patchday-windows-10-updates-january-8-2019\/\">Patchday Windows 10-Updates (January 8, 2019)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]The KB4480970 (Monthly Rollup) and KB4480960 (Security only) updates were released by Microsoft on January 8, 2018 for Windows 7 SP1 and Windows Server 2008 R2 SP1. The updates seem to cause serious network issues for some people. Network shares &hellip; <a href=\"https:\/\/borncity.com\/win\/2019\/01\/09\/netzwerk-issues-with-updates-kb4480970-and-kb4480960\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,22,2],"tags":[166,1775,1771,1776,17,159],"class_list":["post-8223","post","type-post","status-publish","format-standard","hentry","category-issue","category-update","category-windows","tag-issues","tag-kb4480960","tag-kb4480970","tag-netzwork","tag-windows-7","tag-windows-server"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/8223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=8223"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/8223\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=8223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=8223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=8223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}