This from commenter Paul: Did the security only update (KB3205394) break anyone elseโs applications? In an enterprise environment, it broke AD Admin C
[See the full post at: December Security-Only patch breaks Active Directory Admin Center console when editing object’s properties]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
December Security-Only patch breaks Active Directory Admin Center console when editing object’s properties
Home » Forums » Newsletter and Homepage topics » December Security-Only patch breaks Active Directory Admin Center console when editing object’s properties
- This topic has 44 replies, 2 voices, and was last updated 8 years, 3 months ago by
Paul.
Tags: Active Directory KB 3205394 SCCM
AuthorTopicwoody
ManagerDecember 27, 2016 at 2:32 pm #15866Viewing 43 reply threadsAuthorReplies-
jmwoods
Guest -
Layne Marshal
GuestDecember 27, 2016 at 3:00 pm #15868 -
ch100
GuestDecember 27, 2016 at 3:20 pm #15869I know of obscure problems starting with November updates, Monthly or Security-only, not fixed in December. I believe that they are related to Internet Explorer 11 JavaScript behaviour when running in Document Mode 8 or 9. This functionality was broken by patches in the past and fixed after few months. JS in Document Mode 10 or Edge Mode (nothing to do with the Edge browser) is fine and I think it is one of the QA issues with Windows Update, too frequently happening in recent times.
The issue is so obscure that I cannot find any references to it on the Internet and it certainly does not affect most of the users here who either don’t use any of the IE11 Enterprise Compatibility Mode and more likely rarely use IE11 at all. -
abbodi86
Guest -
jmwoods
GuestDecember 27, 2016 at 3:47 pm #15871Hyper-V might work for you…
https://docs.microsoft.com/en-us/virtualization/hyper-v-on-windows/
-
ch100
Guest -
Rene Bahena
Guest -
woody
Manager -
Terry Pickleson
GuestDecember 27, 2016 at 5:52 pm #15875Not sure if you saw Woody, but there are a couple new Intel Drivers again. https://i.imgur.com/edyyluQ.png
-
ch100
Guest -
ch100
GuestDecember 27, 2016 at 6:36 pm #15877I suppose some of the minor Enterprise related issues, unless major and widely reported, remain under-reported for few reasons:
– Many enterprises do not patch regularly, unless there are compliance requirements and even then many managers sign off waivers invoking operational reasons (waste of time for little or no benefit, disruptions like the current one). There are mitigation methods in place in most of this cases provided by the ISP, antivirus provider or internal active monitoring, so things are not as bad as they would otherwise appear.
– Some administrators do not wish to provide details in public about their own environment for business related reasons and in particular because in such situations it may imply that their own enterprise systems are not secure until the issue is resolved, making them easy targets (like saying on Facebook that you are away from home for 2 weeks and provide the address too).In the second situation, many of those issues, if detected, are reported to Microsoft Support.
Or in the modern times, Microsoft get the data themselves – this is the declared purpose of telemetry. -
jmwoods
GuestDecember 27, 2016 at 6:49 pm #15878It would b interesting to re-apply that update, and then use WUSA (assuming we’re not talking about Windwows 10) to uninstall the individual KB’s inside each MS that was included…
https://support.microsoft.com/en-us/kb/3205394
WUSA individual KB uninstall…
wusa /uninstall /kb:nnnnnnn /quiet /norestart
Powershell and DISM individual KB uninstall (Windows 10)…
$SearchUpdates = dism /online /get-packages | findstr “Package_for”
$updates = $SearchUpdates.replace(“Package Identity : “, “”) | findstr “KBXXXXXXX”
#$updates
DISM.exe /Online /Remove-Package /PackageName:$updates /quiet /norestart
-
ch100
Guest -
woody
ManagerDecember 27, 2016 at 9:22 pm #15880They just keep comin’…
Yep, we’ve had several additional reports. I sure wish I knew what was up with those. ch100 has already asked if anybody knows whether they solve the earlier Bluetooth problems with the KB 3172605 patch – the key July speed-up patch.
-
ch100
Guest -
jmwoods
GuestDecember 28, 2016 at 12:52 am #15882It will work…as long as the KB numbers in each Security Bulletin for version and bitness are different.
Otherwise, if the KB numbers are the same, it will not work… the entire rollup will be removed.
The new Security Guide gives a pretty good view of the KB numbering by version and bitness, as well as other info…
-
AJ North
GuestDecember 28, 2016 at 2:06 am #15883Hello Woody,
For my Win 7 Pro x64 laptop with an Intel Centrino Wireless-N 2230 adapter, the protocol outlined on this Intel support page restored my Bluetooth to operational: https://www-ssl.intel.com/content/www/us/en/support/network-and-i-o/wireless-networking/000022410.html (dated 2016.12.09); it pertains to the Intelยฎ Wireless 8260/7265/3165/7260/3160 and Intelยฎ Centrinoยฎ 6235/2230 families.
With warmest regards and every best wish for the New Year,
AJ
-
jmwoods
GuestDecember 28, 2016 at 2:41 am #15884Set up a test environment, installed the 2 new Intel driver updates, and ran DISM to get the list of all drivers for the online OS…
dism /online /get-drivers /all /format:table > “%userprofile%Desktopdrivers.txt”
The output will be created in the file “drivers.txt” on your desktop.
The Intel driver INF files affected…by date –
3/13/16 –
iccwdt.inf – version 11.0.0.1010
8/19/2016 –
haswellsystem.inf – version 10.1.2.80
lynxpointsystem.inf – version 10.1.2.8010/3/2016 –
haswellsystem.inf – version 10.1.1.38
lynxpointsystem.inf – version 10.1.1.38(appears to be a rollback)
-
jmwoods
GuestDecember 28, 2016 at 2:59 am #15885Could have something to do with this big list of bugs for 4th Gen Haswell chipsets…
See the Errata section.
-
ch100
Guest -
LoneWolf
GuestDecember 28, 2016 at 8:21 am #15887@jmwoods: Don’t assume that just because someone’s asking the question means they haven’t tested.
Even when we test, if I see behavior, one of my steps is to ask if others are seeing the same behavior outside of my organization. I want to know if it’s something related to my environment, find commonalities if others are experiencing it, etc.
One of the things I constantly strive to avoid in IT is the beatdown IT folks often give their sisteren/bretheren when a question gets asked, as if we “didn’t do something”. Questions, asked intelligently, are productive, and if we don’t treat them as such, pretty soon, people stop asking questions that might give answers beneficial to all of us.
-
woody
Manager -
abbodi86
Guest -
abbodi86
Guest -
jmwoods
Guest -
jmwoods
GuestDecember 28, 2016 at 2:51 pm #15892I don’t see any evidence of a “beatdown”…
The OP omitted the fact that it was found during testing, less than a month after the updates were released.
The phrase “In an enterprise environment, it broke AD Admin Center console when trying to edit any objectโs properties, and it also broke SCCM consoles.” seemed to (me) indicate it was rolled out.
I think he’ll get over it.
-
Hopeful Cynic
GuestDecember 28, 2016 at 3:10 pm #15893Three Vista patches gave me trouble this month (KB3196348, 3205638, and – I think – 3204724.) They patch Uniscribe and the Graphics Component. No idea if 7/8.1 are affected. The first symptom is the sound driver fails to load. From past experience this means only logging into admin. account is possible. Upon doing so I get the “classic taskbar” and the error message “failed to connect to System Event Notification Service service.” I found a simple reboot fixed my problem, though it took about 5 minutes for the machine to do so after I clicked restart.
-
messager7777777
GuestDecember 28, 2016 at 8:12 pm #15894@ jmwood ……. The link u provided …
https://support.microsoft.com/en-us/kb/3205394
…. for the December 2016 Security Only Patch Rollup only links to M$ Security Bulletin info for the various security updates found inside the Rollup. Eg the security update for IE, KB3204059, cannot be found at M$ Update Catalog = cannot be manually installed by itself.
……. I doubt very much u could uninstall KB3204059. Did u test yr solution or fix.? -
jmwoods
GuestDecember 28, 2016 at 10:39 pm #15895 -
AJ North
GuestDecember 29, 2016 at 12:35 pm #15896Woody,
In her Patch Watch column for Windows Secrets last night, Susan Bradley issued the recommendation to install the December security roll-ups for Windows 7 & 8.1:
“Decemberโs rollup updates for Win7 and Win8.1 appear to be problem free. Itโs time to ensure our Windows setups are as secure as possible. Use the links below to get rollup details.
– What to do: Install rollups KB 3205401 for Win8.1 and KB 3207752 for Win7 as soon as possible.”
(Although she was specifically referring to “Group A,” can one infer that she is also including “Group B”?)
For .NET, she concludes,
“I know of no other issues with the December .NET rollups. Install KB 3210137 or KB 3210138 โ or any of the other .NET updates in MS16-155; then check installed apps that rely on SQL Server, ensuring that they function properly.” (The “other issues” she refers to concern SQL Server installations, for which she cites a MS work-around contained in KB3214106, namely to disable the Shared Memory setting under Protocols for SQLEXPRESS.)
Do you feel that she’s jumping the gun?
-
woody
Manager -
AJ North
Guest -
woody
Manager -
ch100
Guest -
Brian
Guest -
Anony>mouse
GuestDecember 31, 2016 at 11:00 am #15902Hi ch100, just wondering if you (or other experienced VM-ers reading this) have any thoughts you’d care to share on use of VirtualBox? (…for users on “non-corporate PCs” looking for a possible alternative to Hyper-V(requires Pro or higher) or VMware($$))
Thanks and Happy New Year to all!!
-
ch100
GuestDecember 31, 2016 at 4:11 pm #15903@Anony>mouse
Happy New Year!I think VirtualBox is a useful and free alternative to VMWare which is the gold standard by far but also Hyper-V.
However I don’t have much experience with it so I cannot give you or anyone else much information about how to use if effectively.
Check Oracle’s site and read through the documentation and try to use it.
https://www.virtualbox.org/
One thing to note though. Pro is not for Corporate users and it is a mistake to use Pro in larger businesses which qualify for the Enterprise version. Pro is suitable for Small Businesses and for most home users in fact.
I also believe that most Home Edition users do not have enough RAM to run virtual machines in addition to the main physical computer. -
Paul
GuestJanuary 5, 2017 at 11:43 pm #15904Hey all,
Sorry I’ve been absent from this thread-
To clarify a few things:
We immediately test updates on a small handful of IT users in our environment to see if anything stands out like a sore thumb. Our patching schedule after that slowly rolls out to a slightly larger group of 500, then a few different groups consisting of a thousand or PCs each.
This is why we found the issue so soon after patch Tuesday. Now that that’s cleared up, some can rest easy knowing we’re testing ๐
I’ve posted this in the email distribution which is why I haven’t revisited here until now, but I’ve seen a few people replying with similar issues. Yes, it breaks the ADAC console and yes, it prevents you from connecting to your sccm mgmt console. Removing the update resolves it (after a reboot, if I recall)
Re-applying the update will once again break these applications. Our windows 10 machines are fully patched, so I’m not certain it’s due to a missing dependency or anything like that. Our windows 7 machines that I was able to check were also patched and up to date.
I have not heard of any other affected applications in our environment, which is healthcare (which means only roughly 7 billion different applications…) but our users tend to not report the things we care about such as this. But you better believe they’ll speak up if they can’t check up on the Chicago cubs website ๐
I’m debating opening a ticket with our premiere MS rep to see if they can assist, but haven’t had a spare minute lately to do so. If anything big changes I’ll make my way back here to update.
-
woody
Manager -
Bob Miller
Guest -
Paul
Guest -
Paul
GuestJanuary 17, 2017 at 2:36 pm #15908Update: MS has some workarounds for Windows 7, not so much for W10 yet (that they’ve shared with me):
1. Change the desktop color depth to 16 bit
2. Maximize the management console window
3. Disable the โenable desktop compositionโ performance option
4. Apply the Windows Basic themeI was able to verify #1 works for Windows 7, but not the other so far. These options don’t apply to Windows 10.
-
ch100
GuestJanuary 17, 2017 at 3:23 pm #15909Desktop color depth to 16-bit instead of 32-bit is usable, but has limitations.
All the other recommendations are common sense and should be done by default regardless of the current workarounds.
However Microsoft engineers should fix the patch, as those features like Aero/Desktop Composition are built-in and they have to work regardless of what I and others consider common sense settings. -
Paul
Guest
Viewing 43 reply threads - This topic has 44 replies, 2 voices, and was last updated 8 years, 3 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
A CVE-MITRE-CISA-CNA Extravaganza
by
Nibbled To Death By Ducks
2 hours, 38 minutes ago -
Sometimes I wonder about these bots
by
Susan Bradley
9 hours, 31 minutes ago -
Does windows update component store “self heal”?
by
Mike Cross
15 hours, 35 minutes ago -
Windows 11 Insider Preview build 27858 released to Canary
by
joep517
16 hours, 35 minutes ago -
Pwn2Own Berlin 2025: Day One Results
by
Alex5723
16 hours, 1 minute ago -
Windows 10 might repeatedly display the BitLocker recovery screen at startup
by
Susan Bradley
12 hours, 30 minutes ago -
Windows 11 Insider Preview Build 22631.5409 (23H2) released to Release Preview
by
joep517
19 hours, 17 minutes ago -
Windows 10 Build 19045.5912 (22H2) to Release Preview Channel
by
joep517
19 hours, 19 minutes ago -
Kevin Beaumont on Microsoft Recall
by
Susan Bradley
7 hours, 53 minutes ago -
The Surface Laptop Studio 2 is no longer being manufactured
by
Alex5723
1 day, 3 hours ago -
0Patch, where to begin
by
cassel23
21 hours, 28 minutes ago -
CFPB Quietly Kills Rule to Shield Americans From Data Brokers
by
Alex5723
1 day, 17 hours ago -
89 million Steam account details just got leaked,
by
Alex5723
1 day, 4 hours ago -
KB5058405: Linux – Windows dual boot SBAT bug, resolved with May 2025 update
by
Alex5723
2 days, 1 hour ago -
A Validation (were one needed) of Prudent Patching
by
Nibbled To Death By Ducks
1 day, 16 hours ago -
Master Patch Listing for May 13, 2025
by
Susan Bradley
1 day, 3 hours ago -
Installer program can’t read my registry
by
Peobody
41 minutes ago -
How to keep Outlook (new) in off position for Windows 11
by
EspressoWillie
1 day, 14 hours ago -
Intel : CVE-2024-45332, CVE-2024-43420, CVE-2025-20623
by
Alex5723
1 day, 21 hours ago -
False error message from eMClient
by
WSSebastian42
2 days, 12 hours ago -
Awoke to a rebooted Mac (crashed?)
by
rebop2020
2 days, 21 hours ago -
Office 2021 Perpetual for Mac
by
rebop2020
2 days, 23 hours ago -
AutoSave is for Microsoft, not for you
by
Will Fastie
1 hour, 36 minutes ago -
Difface : Reconstruction of 3D Human Facial Images from DNA Sequence
by
Alex5723
3 days, 2 hours ago -
Seven things we learned from WhatsApp vs. NSO Group spyware lawsuit
by
Alex5723
9 hours, 59 minutes ago -
Outdated Laptop
by
jdamkeene
3 days, 7 hours ago -
Updating Keepass2Android
by
CBFPD-Chief115
3 days, 13 hours ago -
Another big Microsoft layoff
by
Charlie
3 days, 13 hours ago -
PowerShell to detect NPU – Testers Needed
by
RetiredGeek
15 hours, 12 minutes ago -
May 2025 updates are out
by
Susan Bradley
16 hours, 54 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.