![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
BlueKeep is almost here. Get your XP/Win7 systems patched!
Home » Forums » Newsletter and Homepage topics » BlueKeep is almost here. Get your XP/Win7 systems patched!
- This topic has 40 replies, 18 voices, and was last updated 5 years, 9 months ago.
Tags: BlueKeep
Viewing 10 reply threadsAuthorReplies-
bobcat5536
AskWoody LoungerJuly 25, 2019 at 11:23 am #1888494 -
anonymous
GuestJuly 25, 2019 at 11:31 am #1888543I also have Windows 7 SP1 and have been doing the monthly roll-ups. I had a moment of panic when I couldn’t find KB4499164 in Programs and Features -> View installed updates… but I found it installed in Windows Update -> View update history. I’m not sure why it appears in the latter and not the former, but I assume that means I’m protected?
-
bobcat5536
AskWoody Lounger
-
-
-
PKCano
ManagerJuly 25, 2019 at 12:03 pm #1888600The Rollups are cumulative, ie, July’s contains June, May, April…. etc. So you will see the latest one you installed in “Installed updates.”
But History is something different. If you did something, well, you did it, and you can’t take it back. So you DID install April Rollup, and you DID install May Rollup, and you DID install June Rollup. Those events will continue to show up in history, even if you only see the latest CU (which is the cumulative result = the big bag that contains all of the updates) in “Installed Updates.”
Now, the Security-only Updates are different. They are not cumulative. So they will show up as individual patches in the “Installed updates.”
3 users thanked author for this post.
-
Sparky
AskWoody LoungerJuly 25, 2019 at 12:26 pm #1888613I’m show the same, KB4499164 is showing in “View Update History” but not in “Installed Updates”. But when I do THIS I get what is in the first PHOTO. I am I still safe?
Dell, W10 Professional, 64-bit, Intel Core i7 Quad, Group A
HP, W7 Home Premium, 64-bit, AMD Phenom II, Group A
-
This reply was modified 5 years, 9 months ago by
Sparky.
1 user thanked author for this post.
-
This reply was modified 5 years, 9 months ago by
-
PKCano
ManagerJuly 25, 2019 at 12:41 pm #1888789The KBs listed are not Hotfixes, they are the Rollup and the SO for May 2019.
Rollups are cumulative.
The May Cumulative Rollup contains the fix.
The June Cumulative Rollup contains the May Cumulative Rollup.
The July Cumulative Rollup contains contains the June Cumulative Rollup and the May Cumulative Rollup.So if you have the May Rollup, or the June Rollup, or the July Rollup (all of which have the fix), you are safe,
-
Sparky
AskWoody LoungerJuly 25, 2019 at 2:35 pm #1888855PKCano,
Yes I do have those Rollups. Thanks
If your into airplanes Checkout this live airshow right now.
Thanks for the help.
Dell, W10 Professional, 64-bit, Intel Core i7 Quad, Group A
HP, W7 Home Premium, 64-bit, AMD Phenom II, Group A
-
Sparky
AskWoody LoungerJuly 26, 2019 at 9:31 pm #1892303 -
Myst
AskWoody PlusJuly 26, 2019 at 10:19 pm #1892332I’m waiting for the DEFCON to lower, before installing any July patches.
Yo Sparky, you want that DEFCON to get into higher numbers before installing July updates, and wait for that thumbs up from Woody.
MacOS iPadOS and sometimes SOS
-
Sparky
AskWoody LoungerJuly 26, 2019 at 10:51 pm #1892410That is what I meant to say, I’m waiting for the DEFCON to go higher and for Woody to give the thumbs up. Before installing the July patches.
Thanks for clarifying my clarification.Dell, W10 Professional, 64-bit, Intel Core i7 Quad, Group A
HP, W7 Home Premium, 64-bit, AMD Phenom II, Group A
1 user thanked author for this post.
-
-
-
Charlie
AskWoody PlusJuly 25, 2019 at 1:54 pm #1888814For us Group B people, that’s the May Security Only Win 7 update KB4499175.
KB4999164 is the Group A, all-in-one, rollup update.
If I’m wrong about this, please correct me, but I don’t think so.
Being 20 something in the 70's was far more fun than being 70 something in the insane 20's1 user thanked author for this post.
-
BobT
AskWoody LoungerJuly 25, 2019 at 2:09 pm #1888816Ah that’s good, I have the May manual security ones installed, and June’s.
Ain’t doing July’s though, no Telemetry in “Security ONLY” patches, no thankyou, that’s why I was in Group B in the first place.
If that doesn’t change, I’ll be in W. Bluekeep or not, don’t give a toss. Be honest with patches, or get out. My PC is my own, and I’ll take responsibility for any negatives that come.
1 user thanked author for this post.
-
anonymous
GuestJuly 25, 2019 at 9:08 pm #1889628Yes I’m also not installing July’s “Security Only” Windows 7 KB with that extra snooping thrown in, do you hear that MS! So I hope that there are no BlueKeep like issues in July 2019 as that’s a big No No for Redmond for Security – ONLY – patches.
It sure looks like Windows 7’s Support may just have ended for many folks in July 2019 instead of Jan 2020! If MS keeps that nonsense up!
-
Microfix
AskWoody MVPglnz
AskWoody PlusJuly 25, 2019 at 2:29 pm #1888829Sorry – not clear to me. WHICH patches are needed on (a) Win 7 Pro 64-bit and (b) Win XP Pro?
On my 7, I’m patched through the June patches (group A). Wasn’t going to do July’s until Defcon 3 or 4, but you tell me.
On my XP, I got all the updates with the POS hack until that stopped after the April updates (and I recall two more SO updates came through after).
So, what am I missing on each?
Thanks.
1 user thanked author for this post.
-
Seff
AskWoody PlusJuly 25, 2019 at 2:41 pm #1888864This raises an important point.
While I believe that the advice here is that we need to ensure we have the necessary update installed from May or June to protect against this threat, the headline appears to instruct XP/Win7 users to get patched – and that implies breaking the normal hold and installing the current July updates, while the DefCon rating is still against doing that.
This seriously needs clarification.
1 user thanked author for this post.
-
Alex5723
AskWoody PlusJuly 26, 2019 at 3:48 am #1890799This seriously needs clarification.
XP/Win 7 BlueKeep patch is mandatory disregarding Defcon level, which is global for Home, Pro, Enterprise…and not per Windows version.
-
Seff
AskWoody PlusJuly 26, 2019 at 8:51 am #1891029Quite so. My point is simply that while all the explanations and clarifications provided in these comments are excellent they follow the article and it would actually be good for the headline to be edited to show that it’s the historic BlueKeep fixes that need to be patched, rather than the current July updates which some may otherwise think is what is covered by the briefest of instructions “Get your XP/Win7 systems patched!”
I don’t want Woody or the team to think I’m being overly critical of articles or headlines these days, I’m just trying to remember that we have been joined by a lot of new followers who are not as familiar with things like DefCon ratings as some of us are, and followers generally cover a massive range of technical know-how, so we need to provide clarification on occasion and not assume that because we know what the article or headline means everyone else will do so.
1 user thanked author for this post.
-
PKCano
Manager
-
-
-
anonymous
GuestJuly 25, 2019 at 2:48 pm #1888862On my XP, I got all the updates with the POS hack until that stopped after the April updates (and I recall two more SO updates came through after).
Are you using the registry trick or is your business still pay MS for Windows Xp updates? If it paid support, there were three other updates released three days ago.
-
anonymous
Guest
alkhall
AskWoody Loungeranonymous
GuestJuly 25, 2019 at 5:36 pm #1889185Note I am not with this company, but I do want to let users know they have a choice beside ms if they want to patch only bluekeep. And Yes I know they charge as this is in PRO. ( who knows might go to free it outbreak is bad enough)
https://www.infosecurity-magazine.com/infosec/patching-bluekeep-big-1-1-1/
“. In addition to Microsoft’s own patch, though, BlueKeep has a ‘micropatch’ courtesy of 0Patch”
anonymous
GuestJuly 25, 2019 at 8:01 pm #1889501I thought that Bluekeep exploit was released three or four months ago. Groups now a days infect and hide inside OS with backdoor programs to create a huge bot net. This is why they released the exploit free so the script kids can play and cause a distraction from the original infection that can lay dormant for months or years before it is deployed. This is how money is generated now.
-
Paul T
AskWoody MVPJuly 26, 2019 at 12:57 am #1890485Not so. You can’t exploit the vulnerability without showing up and that just isn’t happening, according to Kevin Beaumont.
https://www.askwoody.com/2019/kevin-beaumont-still-no-sign-of-bluekeep-in-the-wild/
cheers, Paul
anonymous
Guestanonymous
Guest-
PKCano
ManagerJuly 26, 2019 at 6:15 am #1890895DEFCON 2 refers to the Current month’s patches – that’s means, in this case JULY patches. DEFCON 2 does NOT mean you can’t install ANY patch.
The fix for BlueKeep (the patching referred to in this thread) was present in the MAY Security-only Updates (Group B), the MAY Monthly Rollup and the JUNE Monthly Rollup (Group A). These patches have already passed the DEFCON rating and can be installed any time.
Only the JULY patch installation are restricted by the current DEFCON 2.
-
L95
AskWoody PlusJuly 26, 2019 at 10:03 am #1891115I agree with other commenters that the headline seemed confusing. But now that PKCano has written this clarification, it seems to me that the article only applies to people who hadn’t already updated in May or June. If I’m wrong about this, please correct me.
-
This reply was modified 5 years, 9 months ago by
L95.
-
This reply was modified 5 years, 9 months ago by
-
glnz
AskWoody Plus -
PKCano
Manager
-
-
F A Kramer
AskWoody Plus-
Microfix
AskWoody MVPJuly 26, 2019 at 9:51 am #1891108https://en.wikipedia.org/wiki/BlueKeep_(security_vulnerability)
this wiki explains it 🙂Windows - commercial by definition and now function...3 users thanked author for this post.
-
anonymous
GuestJuly 26, 2019 at 11:36 am #1891200Thank you Microfix for putting up the wiki description of Blue Keep. What is a Blue…Keep? Don’t know why such odd names are used instead of Remote Access Vulnerability which then describes what it is. Thank you for setting us straight.
Now I am curious what Canadian Tech thinks about this exploit.
-
anonymous
Guest -
Carl D
AskWoody LoungerJuly 26, 2019 at 7:02 pm #1892183I’m always amused by the ‘cute’ icons someone comes up with for these ‘big’ security issues.
The Meltdown and Spectre ones (especially the ghost holding the branch for Spectre) always give me a bit of a chuckle and now we have the nice blue castle for BlueKeep. Lovely.
Wonder how much money is getting paid to the ‘artists’ who design these things? Mind you, I’m sure it isn’t anywhere near as much as these ‘security researchers’ get for seemingly spending every hour of every day looking for the endless security issues in Windows.
Security really is a multi million (billion?) dollar industry, isn’t it? The ‘security researchers’ keep raking in the money and Microsoft are able to ‘keep a leash’ on customers’ computers with the never ending security updates.
Looks like I’ve been working in the wrong business all these years – I should have continued learning computer programming which I dabbled in for a while back in the 80’s and maybe today I could be a Windows ‘security researcher’ too – I might even have been a millionaire by now.
(Disclaimer – the above post is intended as sarcasm but I have a strong suspicion a large part or all of it is actually close to the truth).
1 user thanked author for this post.
-
-
-
rexr
AskWoody PlusJuly 26, 2019 at 10:51 am #1891186I missed the patch links in all that, old eyes. So here are the BlueKeep patch links to MS. These installed on my old machines without a hitch:
Win7/Server2008 & R2: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
WinXP/Server2003 & R2: https://support.microsoft.com/en-us/help/4500705/customer-guidance-for-cve-2019-0708
Win10 Pro 20H2,backups with Macrium Reflect home edition1 user thanked author for this post.
Alex5723
AskWoody PlusJuly 26, 2019 at 2:45 pm #1891748Kaspersky Security software (KIS, KAV..) 2020 have been just released (for now in English). One of the new features is guarding against RATs (remote access tools) :
Another type of threats we’ve dealt with in this update is RATs aka remote access tools. RATs are legitimate tools used for remote support, often misused by cybercriminals to defraud people. In the 2020 versions of Kaspersky security products, protection against RATs of all kinds is enabled by default. This to ensure a user is protected from getting a RAT without their consent. In case the user really needs to use such a tool, they can temporarily disable that protection.
https://www.kaspersky.com/blog/kaspersky-2020-security-solutions/27749/
1 user thanked author for this post.
Microfix
AskWoody MVPViewing 10 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Why It’s Time to Upgrade from Windows 7 to Windows 10 (Awaiting moderation)
by
kasfiya
41 minutes ago -
We live in a simulation
by
Alex5723
1 hour, 1 minute ago -
Netplwiz not working
by
RetiredGeek
22 minutes ago -
Windows 11 24H2 is broadly available
by
Alex5723
13 hours, 28 minutes ago -
Microsoft is killing Authenticator
by
Alex5723
12 hours, 3 minutes ago -
Downloads folder location
by
CWBillow
19 hours, 55 minutes ago -
Remove a User from Login screen
by
CWBillow
1 hour, 36 minutes ago -
TikTok fined €530 million for sending European user data to China
by
Nibbled To Death By Ducks
11 hours, 1 minute ago -
Microsoft Speech Recognition Service Error Code 1002
by
stanhutchings
11 hours, 3 minutes ago -
Is it a bug or is it expected?
by
Susan Bradley
15 hours, 41 minutes ago -
Image for Windows TBwinRE image not enough space on target location
by
bobolink
10 hours, 12 minutes ago -
Start menu jump lists for some apps might not work as expected on Windows 10
by
Susan Bradley
1 day, 10 hours ago -
Malicious Go Modules disk-wiping malware
by
Alex5723
23 hours, 50 minutes ago -
Multiple Partitions?
by
CWBillow
1 day ago -
World Passkey Day 2025
by
Alex5723
1 day, 17 hours ago -
Add serial device in Windows 11
by
Theodore Dawson
2 days, 9 hours ago -
Windows 11 users reportedly losing data due forced BitLocker encryption
by
Alex5723
9 hours, 54 minutes ago -
Cached credentials is not a new bug
by
Susan Bradley
2 days, 13 hours ago -
Win11 24H4 Slow!
by
Bob Bible
2 days, 13 hours ago -
Microsoft hiking XBox prices starting today due to Trump’s tariffs
by
Alex5723
2 days, 10 hours ago -
Asus adds “movement sensor” to their Graphics cards
by
n0ads
2 days, 15 hours ago -
‘Minority Report’ coming to NYC
by
Alex5723
2 days, 12 hours ago -
Apple notifies new victims of spyware attacks across the world
by
Alex5723
3 days ago -
Tracking content block list GONE in Firefox 138
by
Bob99
3 days ago -
How do I migrate Password Managers
by
Rush2112
2 days, 7 hours ago -
Orb : how fast is my Internet connection
by
Alex5723
2 days, 9 hours ago -
Solid color background slows Windows 7 login
by
Alex5723
3 days, 12 hours ago -
Windows 11, version 24H2 might not download via Windows Server Updates Services
by
Alex5723
3 days, 10 hours ago -
Security fixes for Firefox
by
Susan Bradley
12 hours, 3 minutes ago -
Notice on termination of services of LG Mobile Phone Software Updates
by
Alex5723
3 days, 23 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.