Good report from Dan Goodin at Ars Technica. Google’s Project Zero sticks to its 90-day notification policy, and a second 0day has been revealed, this
[See the full post at: February missing security patch toll: Two zero-days and counting]
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
February missing security patch toll: Two zero-days and counting
Home » Forums » Newsletter and Homepage topics » February missing security patch toll: Two zero-days and counting
- This topic has 23 replies, 9 voices, and was last updated 8 years, 1 month ago.
Tags: 0day css tokens gdi32.dll smb
AuthorTopicViewing 6 reply threadsAuthorReplies-
WildBill
AskWoody PlusFebruary 28, 2017 at 11:58 am #97752Good report from Goodin, but I strongly disagree with his last sentence:
“Additionally, people should strongly consider moving to Windows 10, which is more immune than earlier versions to software exploits, and to use the Enhanced Mitigation Experience Toolkit to extend and enhance those protections.” He does know Edge is only available on Windows 10, right? & that IE 11 is on Windows 7, 8.1 & even 10?! Overall, Windows 10 may be more immune, but with 0days attacking both its browsers & Microsoft delaying updates on All versions of Windows, I have more doubts about upgrading to Win 10.Bought a refurbished Windows 10 64-bit, currently updated to 22H2. Have broke the AC adapter cord going to the 8.1 machine, but before that, coaxed it into charging. Need to buy new adapter if wish to continue using it.
Wild Bill Rides Again... -
rc primak
AskWoody_MVPMarch 1, 2017 at 1:36 am #97893 -
woody
ManagerMarch 2, 2017 at 6:34 am #98214Of course you know that MS plans to deprecate EMET.
https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/
I should write a post in InfoWorld about that.
1 user thanked author for this post.
-
-
Microfix
AskWoody MVPabbodi86
AskWoody_MVP-
ch100
AskWoody_MVP -
abbodi86
AskWoody_MVPMarch 2, 2017 at 4:13 am #98183I have a theory 😀
as you know, all files downloaded from WU/MU/WSUS/catalog have sha1 hash appended to their names, which is used for quick verification
but now since sha1 is now totally deprecated and disclosed, they are swiching to sha256 as the default verification, which require them to recheck and rename all files at their back-end
-
Microfix
AskWoody MVP -
PhotM
AskWoody LoungerMarch 2, 2017 at 7:58 pm #98415I was wondering this too.
When the UUP to ESD converter failed, it was missing a Blob BUT it all so mention a SH 1 verification failure. I didn’t say anything because the info was so sparse.
I will check there Site for info on that… https://www.tenforums.com/tutorials/74480-uup-iso-create-bootable-iso-windows-10-build-upgrade-files.html
--------------------------------------
1. Tower Totals: 2xSSD ~512GB, 2xHHD 20 TB, Memory 32GB
SSDs: 6xOS Partitions, 2xW8.1 Main & Test, 2x10.0 Test, Pro, x64
CPU i7 2600 K, SandyBridge/CougarPoint, 4 cores, 8 Threads, 3.4 GHz
Graphics Radeon RX 580, RX 580 ONLY Over Clocked
More perishable2xMonitors Asus DVI, Sony 55" UHD TV HDMI
1. NUC 5i7 2cores, 4 Thread, Memory 8GB, 3.1 GHz, M2SSD 140GB
1xOS W8.1 Pro, NAS Dependent, Same Sony above.-----------------
-
anonymous
Guest
-
-
Noel Carboni
AskWoody_MVPMarch 1, 2017 at 11:24 pm #98138abbodi86
AskWoody_MVPMarch 3, 2017 at 3:18 am #98472I was wondering this too. When the UUP to ESD converter failed, it was missing a Blob BUT it all so mention a SH 1 verification failure. I didn’t say anything because the info was so sparse. I will check there Site for info on that… https://www.tenforums.com/tutorials/74480-uup-iso-create-bootable-iso-windows-10-build-upgrade-files.html
The tool used for converting “wimlib” is 3rd party, not related
but, wim file format uses sha1 as verification algorithm by defaultExpress UUP can’t be gathered into ISO so far, but regular Canonical UUP is good to go
p.s. i’m the creator of the original converter script 😀
1 user thanked author for this post.
-
PhotM
AskWoody LoungerMarch 3, 2017 at 11:35 am #98541Yes abbodi86,
I knew you were but Thank You for reminding us. 😀 I had one successful Delta ISO upgrade to Build 15031 BUT the next 2 have failed, the last one in the converter, as I said. Glad to know what you have just indicated!!! 😀
Are you going to update UUPtoESD for the Express UUP way?
If yes, could you post here as well?Look forward to hearing from you, until then I will forget UUP and keep it turned off. I want my Full(OKAY, if you insist “Canonical”) ISO’s, regardless! 😆
--------------------------------------
1. Tower Totals: 2xSSD ~512GB, 2xHHD 20 TB, Memory 32GB
SSDs: 6xOS Partitions, 2xW8.1 Main & Test, 2x10.0 Test, Pro, x64
CPU i7 2600 K, SandyBridge/CougarPoint, 4 cores, 8 Threads, 3.4 GHz
Graphics Radeon RX 580, RX 580 ONLY Over Clocked
More perishable2xMonitors Asus DVI, Sony 55" UHD TV HDMI
1. NUC 5i7 2cores, 4 Thread, Memory 8GB, 3.1 GHz, M2SSD 140GB
1xOS W8.1 Pro, NAS Dependent, Same Sony above.-----------------
-
abbodi86
AskWoody_MVPMarch 3, 2017 at 11:49 am #98544The latest already have Express UUP support
http://www.host-a.net/u/abbodi86/uup-converter-wimlib-4.7z
but it doesn’t work always
-
PhotM
AskWoody LoungerMarch 3, 2017 at 12:16 pm #98549Then could you lets us know when you have resolution?
Thanks,
--------------------------------------
1. Tower Totals: 2xSSD ~512GB, 2xHHD 20 TB, Memory 32GB
SSDs: 6xOS Partitions, 2xW8.1 Main & Test, 2x10.0 Test, Pro, x64
CPU i7 2600 K, SandyBridge/CougarPoint, 4 cores, 8 Threads, 3.4 GHz
Graphics Radeon RX 580, RX 580 ONLY Over Clocked
More perishable2xMonitors Asus DVI, Sony 55" UHD TV HDMI
1. NUC 5i7 2cores, 4 Thread, Memory 8GB, 3.1 GHz, M2SSD 140GB
1xOS W8.1 Pro, NAS Dependent, Same Sony above.-----------------
-
abbodi86
AskWoody_MVPMarch 3, 2017 at 7:30 pm #98670I did a test with today’s build 15048, the converter works as expected and succeeded
the problem with Express UUP is that not all files are preserved after upgrade
so the only workaround is to backup/copy the Download directory prior upgrade (before first restart), or use the script before restart and create ISO, then restart to beging upgrade -
PhotM
AskWoody LoungerMarch 3, 2017 at 7:42 pm #98671I didn’t…
When I did, I only do my conversions/file copies etc are from BEFORE Restart. That is the way I have done it for over 2 years with ESD to ISO, UUP to ISO is not any different for me.
However you said UUP to ISO was unreliable. Where I got the converter was from 10 Forums. I haven’t checked to see how similar there presentation is to the way you present???
--------------------------------------
1. Tower Totals: 2xSSD ~512GB, 2xHHD 20 TB, Memory 32GB
SSDs: 6xOS Partitions, 2xW8.1 Main & Test, 2x10.0 Test, Pro, x64
CPU i7 2600 K, SandyBridge/CougarPoint, 4 cores, 8 Threads, 3.4 GHz
Graphics Radeon RX 580, RX 580 ONLY Over Clocked
More perishable2xMonitors Asus DVI, Sony 55" UHD TV HDMI
1. NUC 5i7 2cores, 4 Thread, Memory 8GB, 3.1 GHz, M2SSD 140GB
1xOS W8.1 Pro, NAS Dependent, Same Sony above.-----------------
-
-
-
abbodi86
AskWoody_MVPMarch 4, 2017 at 7:47 am #98789I didn’t… When I did, I only do my conversions/file copies etc are from BEFORE Restart. That is the way I have done it for over 2 years with ESD to ISO, UUP to ISO is not any different for me. However you said UUP to ISO was unreliable. Where I got the converter was from 10 Forums. I haven’t checked to see how similar there presentation is to the way you present???
Canonical UUP to ISO is very reliable, the files re kept intact before and after upgrade
the tricky is Express UUPExpress UUP is basically a whole WinSxS folder, so copying is unreliable
the best is, when it prompt to restart, you start convert-UUP script and paste the path to download directory, i.e.
C:\Windows\SoftwareDistribution\Download\07172dda91861218ecc095600216d792the problem with 10 Forums is they adopted my first UUP converter release, but they didn’t cooperate with the following improved/fixed releases
-
PhotM
AskWoody LoungerMarch 4, 2017 at 3:51 pm #98929--------------------------------------
1. Tower Totals: 2xSSD ~512GB, 2xHHD 20 TB, Memory 32GB
SSDs: 6xOS Partitions, 2xW8.1 Main & Test, 2x10.0 Test, Pro, x64
CPU i7 2600 K, SandyBridge/CougarPoint, 4 cores, 8 Threads, 3.4 GHz
Graphics Radeon RX 580, RX 580 ONLY Over Clocked
More perishable2xMonitors Asus DVI, Sony 55" UHD TV HDMI
1. NUC 5i7 2cores, 4 Thread, Memory 8GB, 3.1 GHz, M2SSD 140GB
1xOS W8.1 Pro, NAS Dependent, Same Sony above.-----------------
1 user thanked author for this post.
-
abbodi86
AskWoody_MVPMarch 4, 2017 at 4:13 pm #98935Good 🙂
latest release
https://sendit.cloud/x0hbvni4v9x9
-
PhotM
AskWoody LoungerMarch 4, 2017 at 2:19 pm #98901…..
Canonical UUP to ISO is very reliable, the files re kept intact before and after upgradeFirst off, I the purge all of MS’s Upgrade files when when I am through with them with “Disk Cleanup”.
Then I Restart.
I never let MS Process upgrade my system. I only upgrade the most Reliable way I know and that is by ISO! I then purge all of their file when I have proved in the Upgrade and then take my first Image Backup.To get a Full ISO, I use a Script from the Builds 9xxx,nnnn time frame(I would guess the site still exists) called Decrypt.cmd to convert the ESD (I have made the Decrypt part variable). I only use the Decrypt part in the case of an early failure of the “‘Initial’ Install” process where Decryption of the ESD occurs before about 30%. The Panther Logs have the decryption key in the setuperr.log but whenever it happens they are the same as the original was. For me this has not happened for months.
I have now had the time to look at your Directories(but not the script or Run it) and the Readme. I am now slightly more versed in your way. I have the UUP files for 15042.0 that I can and will run it on later this weekend and let you know how it looks to me verses the 10 Forums, peoples v 1. This is the second one that run successfully for me from 10 Forums.
the tricky is Express UUP
Express UUP is basically a whole WinSxS folder, so copying is unreliable
the best is, when it prompt to restart, you start convert-UUP script and paste the path to download directory, i.e.
C:\Windows\SoftwareDistribution\Download\07172dda91861218ecc095600216d792I put this in Block Quotes to highlight it:
So, when YOU say unreliable like you said it to me before, YOU don’t really mean the Software is unreliable, which By The Way is what it sounded like… Just Sayn’ 🙂
YOU are saying the USERS are unreliable as to WHEN they copy the FILES in the TIMING of the UPGRADE PROCESS around the concept of RESTART.
You see I don’t have that problem because I am used to copying the “Install.esd” to be Decrypt.cmd, at that same timing. So if I am doing UUP, it is essentially the same just different directories.
Now my directory is different than yours and maybe even from time to time. So the instruction from ’10 Forums’ was to search for the folder in “SoftwareDistribution\Download\” that has ‘ESD’ in it. Is that correct? You don’t specify, from what I read in your Readme? For me it was ONE COMPLETE DIRECTORY.
the problem with 10 Forums is they adopted my first UUP converter release, but they didn’t cooperate with the following improved/fixed releases
OKAY GOT IT!!! 🙁
That is a Problem when you are put out of control of your own software, which is sad. Have you considered releasing it here? Maybe you could work with Kirsty to get a good succinct write up that is easy to understand for most people. Then you could Post that on Tools…. Just Sayn’ 😀
Would it make a substantial difference to your Testing Abbodi if, I rolled back my IP partition and did a UUP D/L and test your software on those files. I know you were asking if anybody had run it. I wished, I had at least Done that and copied the files.
Now however with my questions answered, I will at least know I am copying All of the Files that are needed.--------------------------------------
1. Tower Totals: 2xSSD ~512GB, 2xHHD 20 TB, Memory 32GB
SSDs: 6xOS Partitions, 2xW8.1 Main & Test, 2x10.0 Test, Pro, x64
CPU i7 2600 K, SandyBridge/CougarPoint, 4 cores, 8 Threads, 3.4 GHz
Graphics Radeon RX 580, RX 580 ONLY Over Clocked
More perishable2xMonitors Asus DVI, Sony 55" UHD TV HDMI
1. NUC 5i7 2cores, 4 Thread, Memory 8GB, 3.1 GHz, M2SSD 140GB
1xOS W8.1 Pro, NAS Dependent, Same Sony above.-----------------
1 user thanked author for this post.
-
PhotM
AskWoody LoungerMarch 4, 2017 at 5:02 pm #98954--------------------------------------
1. Tower Totals: 2xSSD ~512GB, 2xHHD 20 TB, Memory 32GB
SSDs: 6xOS Partitions, 2xW8.1 Main & Test, 2x10.0 Test, Pro, x64
CPU i7 2600 K, SandyBridge/CougarPoint, 4 cores, 8 Threads, 3.4 GHz
Graphics Radeon RX 580, RX 580 ONLY Over Clocked
More perishable2xMonitors Asus DVI, Sony 55" UHD TV HDMI
1. NUC 5i7 2cores, 4 Thread, Memory 8GB, 3.1 GHz, M2SSD 140GB
1xOS W8.1 Pro, NAS Dependent, Same Sony above.-----------------
1 user thanked author for this post.
abbodi86
AskWoody_MVPMarch 3, 2017 at 7:20 am #98488😀
Canonical = complete upgrade files
https://blogs.windows.com/windowsexperience/2017/03/02/an-update-on-our-unified-update-platform-uup/
1 user thanked author for this post.
Viewing 6 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Add serial device in Windows 11
by
Theodore Dawson
6 minutes ago -
Windows 11 users reportedly losing data due forced BitLocker encryption
by
Alex5723
19 minutes ago -
Cached credentials is not a new bug
by
Susan Bradley
3 hours, 53 minutes ago -
Win11 24H4 Slow!
by
Bob Bible
4 hours, 4 minutes ago -
Microsoft hiking XBox prices starting today due to Trump’s tariffs
by
Alex5723
1 hour, 15 minutes ago -
Asus adds “movement sensor” to their Graphics cards
by
n0ads
6 hours, 14 minutes ago -
‘Minority Report’ coming to NYC
by
Alex5723
2 hours, 24 minutes ago -
Apple notifies new victims of spyware attacks across the world
by
Alex5723
14 hours, 56 minutes ago -
Tracking content block list GONE in Firefox 138
by
Bob99
14 hours, 20 minutes ago -
How do I migrate Password Managers
by
Rush2112
10 minutes ago -
Orb : how fast is my Internet connection
by
Alex5723
11 hours, 53 minutes ago -
Solid color background slows Windows 7 login
by
Alex5723
1 day, 2 hours ago -
Windows 11, version 24H2 might not download via Windows Server Updates Services
by
Alex5723
1 day, 1 hour ago -
Security fixes for Firefox
by
Susan Bradley
1 hour, 34 minutes ago -
Notice on termination of services of LG Mobile Phone Software Updates
by
Alex5723
1 day, 13 hours ago -
Update your Apple Devices Wormable Zero-Click Remote Code Execution in AirPlay..
by
Alex5723
1 day, 22 hours ago -
Amazon denies it had plans to be clear about consumer tariff costs
by
Alex5723
1 day, 13 hours ago -
Return of the brain dead FF sidebar
by
EricB
1 day ago -
Windows Settings Managed by your Organization
by
WSDavidO61
3 hours, 38 minutes ago -
Securing Laptop for Trustee Administrattor
by
PeachesP
3 minutes ago -
The local account tax
by
Susan Bradley
1 day, 1 hour ago -
Recall is back with KB5055627(OS Build 26100.3915) Preview
by
Alex5723
2 days, 11 hours ago -
Digital TV Antenna Recommendation
by
Win7and10
2 days, 3 hours ago -
Server 2019 Domain Controllers broken by updates
by
MP Support
2 days, 23 hours ago -
Google won’t remove 3rd party cookies in Chrome as promised
by
Alex5723
3 days ago -
Microsoft Manager Says macOS Is Better Than Windows 11
by
Alex5723
3 days, 4 hours ago -
Outlook (NEW) Getting really Pushy
by
RetiredGeek
2 days, 6 hours ago -
Steps to take before updating to 24H2
by
Susan Bradley
4 hours, 30 minutes ago -
Which Web browser is the most secure for 2025?
by
B. Livingston
2 days, 11 hours ago -
Replacing Skype
by
Peter Deegan
1 day, 23 hours ago
Recent blog posts
Key Links
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
1 | 2 | 3 | ||||
4 | 5 | 6 | 7 | 8 | 9 | 10 |
11 | 12 | 13 | 14 | 15 | 16 | 17 |
18 | 19 | 20 | 21 | 22 | 23 | 24 |
25 | 26 | 27 | 28 | 29 | 30 | 31 |
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.