It’s a long, sad list. Post coming on Computerworld.
[See the full post at: A roundup of ongoing problems with this month’s Windows and .NET patches]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
A roundup of ongoing problems with this month’s Windows and .NET patches
Home » Forums » Newsletter and Homepage topics » A roundup of ongoing problems with this month’s Windows and .NET patches
- This topic has 20 replies, 10 voices, and was last updated 7 years, 7 months ago.
Tags: KB 4038777 KB 4043564
AuthorTopicViewing 10 reply threadsAuthorReplies-
Noel Carboni
AskWoody_MVPSeptember 21, 2017 at 12:15 pm #133742Not to take away from the gravity of this headline, but after passing my own testing in VMs I’ve had my main Windows 8.1 x64 Pro/MCE workstation running continuously on the September updates (group A style) for 4+ days now. Doing my normal business management and software engineering work (including work with Office 2010) I’ve seen no downsides. Of course no one individual can possibly do all things Windows can do with a given system.
I’m still holding off updating my critical Windows 7 system as I simply haven’t had time to do update testing for that system yet.
-Noel
-
samak
AskWoody PlusSeptember 21, 2017 at 4:05 pm #133797I’m leaning towards installing the .NET patch since other people use my computer who may press the “Enable Editing” button.
Interestingly, when I went to look at the article for KB 4040960 at
and clicked on the link to the Microsoft Update Catalog, the updates offered appear to be a different number: KB 4041090. This seems unusual.
Any advice / comments? Thanks.
Windows 10 Home 22H2, Acer Aspire TC-1660 desktop + LibreOffice, non-techie
-
The Surfing Pensioner
AskWoody PlusSeptember 21, 2017 at 8:06 pm #133844 -
PKCano
ManagerSeptember 22, 2017 at 4:08 am #133896@samak
In the Update Catalog for .NET, there are several different updates for the different versions. If you click on the title of the updates (instead of “Download” button) then click on “more information” in the box that pops up, it will take you to a page that shows which patch belongs to which version. Then you can download the one(s) you need for the version(s) installed on your computer.4 users thanked author for this post.
-
The Surfing Pensioner
AskWoody PlusSeptember 22, 2017 at 5:28 am #133908Many thanks for the tip. However, having done that, the subcomponents of KB 4041090 for Windows 7 64-bit are all still described as x 86. What I’m saying is that I can’t find another version of KB 4041090 whose internal components are described as x64 anywhere. So I am wondering whether this version will fit both 32- and 64-bit Windows 7?
-
PKCano
ManagerSeptember 22, 2017 at 5:51 am #133911If you look carefully in the name, the one for 64-bit has x64 in the name (the second one down). The one without any indication is x86.
Once you identify which one(s) you need, go back to the original Update Catalog pave, click on the download button, and download the correct patch.
-
The Surfing Pensioner
AskWoody Plus
-
-
-
-
-
MrBrian
AskWoody_MVPSeptember 21, 2017 at 5:38 pm #133813Most important: If you can’t keep yourself (or your clients) from clicking “Enable Editing” in Word, you must install a broad range of .NET patches (if you’re running Windows 7 or 8.1) or cumulative updates (if you’re running Windows 10), like, NOW.
CVE-2017-8759 can also be exploited with PowerPoint or Excel. From https://github.com/nccgroup/CVE-2017-8759/: “This is interesting, as previously pointed out – CSV (and SLK files) do not trigger protected mode. This means that the number of prompts presented to a user when sent either an RTF, PPSX or CSV/SLK file from an internet location are exactly the same (due to the former triggering protected view). Furthermore, due to being plain-text and usually relatively innocuous, CSV files often sail through perimeter defenses (such as web-proxies or email spam filters).”
-
Noel Carboni
AskWoody_MVPSeptember 21, 2017 at 6:55 pm #133830If a poisoned .CSV file arrives via a method that doesn’t preserve the “mark of the web” (such as put inside a 7-Zip archive), then I would guess that the number of prompts is 0.
How is it possible to poison a .csv file? It’s just interpreted as text to be put into cells, right? Does that activity somehow carry the ability to turn that text into macros?
-Noel
-
MrBrian
AskWoody_MVP
-
-
-
woody
ManagerSeptember 21, 2017 at 8:46 pm #133853Good point that’s getting stuck in our ongoing site problems (which may be solved tomorrow):
Woody, You missed to point out that the September update not just added the search box to IE11, but the search box ignores group policy settings preventing IE11 from searching the Web. Currently, the only workaround is to null-route the domains of search providers
Overnight, there was this additional anonymous post:
Also, the search box is using ‘disabled’ search providers. Actually, the search box should be hidden when no available search provider is enabled under IE 11 settings. But Microsoft decided to ignore all that and just put the c***** search box up.
1 user thanked author for this post.
-
Kirsty
ManagerSeptember 22, 2017 at 1:37 am #133878MS have updated .NET Framework September 2017 Security and Quality Rollup
September 21, 2017:Known Issues
This release has the following known issues.
WPF Rendering in a Windows Service
.NET Framework versions: 4.6.x, 4.7
Windows versions: all
Affected KBs: KB4040956, KB4040955, KB4040957After you install this update on the .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7, you may experience rendering issues in Windows Presentation Foundation (WPF) applications that use WPF types in a Windows service. For more information, see KB 4043601.
Incorrect text in .NET Framework Setup
.NET Framework versions: 4.5.2
Windows versions: Windows 7, Windows Server 2008, Windows Server 2008 R2
Affected KBs: KB4040960, KB4040977When you apply this update on non-English locale systems, you may notice some pseudo localized characters instead of localized content in the interactive setup. This is a non-impacting, UI-only, setup issue that does not affect the deployment result or functionality of the update contents. Please apply this update to help secure your computer against vulnerabilities and the issues that are addressed by this update. For more information, see: KB 4043564.
-
walker
AskWoody LoungerSeptember 24, 2017 at 10:13 am #133992@Kirsty: The only update I see for September (an older version disappeared) is KB4041083 for the .NET Framework. Win 7, x64, (trying to get into Group A). It becomes more and more confusing with every “check for updates” results (set at NEVER). This is for the Security & Quality Rollup For .NET Framework going up to 4.7 and on.
I see that your update is more current than the one that I have which is dated 9-12-17, so that explains the reason. I must get busy and do another “check for updates” with the “NEVER CHECK” on.
I’m awaiting the Defcon3, to try to get this one DL & installed. Good luck to us all, that’s for sure. Thank you for all of the excellent information you share with us all. It is most appreciated, as always!
1 user thanked author for this post.
-
-
walker
AskWoody LoungerSeptember 24, 2017 at 10:34 am #133996@Kirsty: Well, I “checked for updates”, and they are the same as they were previously, so I only have the same one I referenced above for the .NET. The only other Important update I have is the KB4038777 (Sec. Monthly Quality Rollup for Win7 x64. I will get the MSRT and WinDef. updates installed ASAP.
Apologies for the edit, since I found nothing “new”. Thank you once again!
-
AJNorth
AskWoody PlusSeptember 25, 2017 at 1:43 am #134098Question regarding the September .NET updates: after the status changes to DEFCON 3, would those in “Group B” go ahead with KB4041083, or should the individual “Security Only Updates” be installed instead (for the machines in question, Win 7 Pro x64, these would be KB4040957 and KB4040960, both dated 2017.08.30, and KB4040966, dated 2017.08.31)?
Thanks!
-
PKCano
ManagerSeptember 25, 2017 at 4:20 am #134105Group B does not include .NET – in fact, AKB2000003 recommends in step B4, using the .NET patches provided by Windows Update (at DEFCON 3, or course).
Some people still insist on using the security-only .NET patches. I have been using the WU .NET Rollup patches, myself, without problems.
However, it is recommended for Win7 to hold off installing .NET 4.7 for the time being because of problems with Win7.
1 user thanked author for this post.
-
-
MrBrian
AskWoody_MVPSeptember 25, 2017 at 7:16 am #134116From Rendering issues after the September 12, 2017, .NET Security and Quality Rollups are installed:
“Workaround
To work around this problem, temporarily remove the September 12, 2017, Security and Quality Rollup update, and then install the corresponding September 12, 2017, Security-Only update to make sure that systems are secured against the latest vulnerabilities.”
1 user thanked author for this post.
-
AJNorth
AskWoody PlusSeptember 25, 2017 at 3:17 pm #134211Published earlier today at gHacks:
Author: Ksuvi Khor September 25, 2017 at 3:57 pm
Comment: We are experiencing a similar issue in our organization. After installing KB4038777 on our HP 6200 desktops our users are experiencing a blank screen with cursor for several minutes immediately after logging in, thus delaying their ability to log in and get to work. Removing KB4038777 and rebooting fixes this issue.
Permalink: https://www.ghacks.net/2017/09/12/microsoft-security-updates-september-2017-release/
-
anonymous
GuestOctober 3, 2017 at 11:23 am #133768 -
anonymous
Guest
Viewing 10 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Cox Communications and Charter Communications to merge
by
not so anon
58 minutes ago -
Help with WD usb driver on Windows 11
by
Tex265
6 hours, 8 minutes ago -
hibernate activation
by
e_belmont
9 hours, 54 minutes ago -
Red Hat Enterprise Linux 10 with AI assistant
by
Alex5723
13 hours, 41 minutes ago -
Windows 11 Insider Preview build 26200.5603 released to DEV
by
joep517
16 hours, 46 minutes ago -
Windows 11 Insider Preview build 26120.4151 (24H2) released to BETA
by
joep517
16 hours, 48 minutes ago -
Fixing Windows 24H2 failed KB5058411 install
by
Alex5723
19 hours, 58 minutes ago -
Out of band for Windows 10
by
Susan Bradley
21 hours, 31 minutes ago -
Giving UniGetUi a test run.
by
RetiredGeek
1 day, 4 hours ago -
Windows 11 Insider Preview Build 26100.4188 (24H2) released to Release Preview
by
joep517
1 day, 12 hours ago -
Microsoft is now putting quantum encryption in Windows builds
by
Alex5723
1 day, 10 hours ago -
Auto Time Zone Adjustment
by
wadeer
1 day, 16 hours ago -
To download Win 11 Pro 23H2 ISO.
by
Eddieloh
1 day, 14 hours ago -
Manage your browsing experience with Edge
by
Mary Branscombe
18 hours, 50 minutes ago -
Fewer vulnerabilities, larger updates
by
Susan Bradley
7 hours, 16 minutes ago -
Hobbies — There’s free software for that!
by
Deanna McElveen
13 hours, 40 minutes ago -
Apps included with macOS
by
Will Fastie
11 hours, 32 minutes ago -
Xfinity home internet
by
MrJimPhelps
8 hours, 19 minutes ago -
Convert PowerPoint presentation to Impress
by
RetiredGeek
1 day, 9 hours ago -
Debian 12.11 released
by
Alex5723
2 days, 13 hours ago -
Microsoft: Troubleshoot problems updating Windows
by
Alex5723
2 days, 17 hours ago -
Woman Files for Divorce After ChatGPT “Reads” Husband’s Coffee Cup
by
Alex5723
1 day, 20 hours ago -
Moving fwd, Win 11 Pro,, which is best? Lenovo refurb
by
Deo
30 minutes ago -
DBOS Advanced Network Analysis
by
Kathy Stevens
3 days, 10 hours ago -
Microsoft Edge Launching Automatically?
by
healeyinpa
3 days ago -
Google Chrome to block admin-level browser launches for better security
by
Alex5723
22 hours, 26 minutes ago -
iPhone SE2 Stolen Device Protection
by
Rick Corbett
3 days, 5 hours ago -
Some advice for managing my wireless internet gateway
by
LHiggins
2 days, 12 hours ago -
NO POWER IN KEYBOARD OR MOUSE
by
HE48AEEXX77WEN4Edbtm
1 day, 14 hours ago -
A CVE-MITRE-CISA-CNA Extravaganza
by
Nibbled To Death By Ducks
3 days, 22 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.