Microsoft continues its any-day-of-the-month patching policy with a highly anticipated preview of the April Win7 Monthly Rollup and a rushed patch for
[See the full post at: Friday night patch dump: KB 4088881, a flawed Win7 Monthly Rollup preview and KB 4089187, an IE fix]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Friday night patch dump: KB 4088881, a flawed Win7 Monthly Rollup preview and KB 4089187, an IE fix
Home » Forums » Newsletter and Homepage topics » Friday night patch dump: KB 4088881, a flawed Win7 Monthly Rollup preview and KB 4089187, an IE fix
- This topic has 43 replies, 19 voices, and was last updated 7 years, 1 month ago by
anonymous.
AuthorTopicwoody
ManagerMarch 24, 2018 at 8:19 am #177980Viewing 22 reply threadsAuthorReplies-
tom341
AskWoody Lounger -
grayslady
AskWoody LoungerMarch 26, 2018 at 11:30 am #178315I am Windows 7 (x64) Group B, as well. I updated through December, but have only applied IE patches for January and February. Since I only use IE about 6 times per year, after reading the comments below about the latest IE kerfuffle, I don’t think I’m going to update IE anymore. I haven’t experienced any issues on either 7 or IE 11 so far, and my current thinking is to produce a first-rate system clone and leave well enough alone. I’m sorry to say that I don’t think MS knows what it is doing anymore with updates. When I start seeing suggestions to tweak the BIOS or change registry settings–on my own, and not through a well-thought-out update–in order to accommodate poorly conceived patches that address questionable issues, I lose all trust.
1 user thanked author for this post.
-
anonymous
Guestanonymous
GuestMarch 24, 2018 at 4:03 pm #178015Does the IE Cumulative security update KB4096040ย address additionalย security vulnerabilities fromย KB4089187,ย or is it simply a patch that addresses internet explorer not opening?
The only info I could find:ย CVE-2018-0889 which reports a remote code execution vulnerabilityย that is addressed by KB4096040 but for only Windows 7 32-bit platform.
-
MrBrian
AskWoody_MVP -
anonymous
GuestMarch 25, 2018 at 1:07 pm #178117For a longer answer, a search for 4096040 on the security portal returns CVE-2018-0942, CVE-2018-0935, CVE-2018-0932, CVE-2018-0929, CVE-2018-0927, CVE-2018-0891 and CVE-2018-0889. All are “Published: 03/13/2018 | Last Updated : 03/23/2018” so note that date published. Also, all are listed as being fixed in 4096040 and 4088875, which is the March bundle, which would include 4089187. 4088881, which includes 4096040, is not listed. Also, searching for each of those CVE numbers has them listed as being fixed in 4089187 for Win 8.1. (Interestingly, CVE-2018-0889 is listed as being fixed in 4096040 in Win 7 32-bit and Win Server 2008 R2 for x64 only, while for Win 7 for x64 the fix is still listed as being in 4089187. Probably a slip.)
So, yep, seems like there are no new fixes in 4096040 and I’d say that if you can start IE with 4089187 or don’t use it and don’t care whether you can start it, you’re fine without installing 4096040.
(On a different note, those fixes for UCRT in KB4088881 seem important. Wonder when the bugs appeared and whether they were introduced by some security-only fixes too, and if so whether they’ll be fixed in the next security only patch as well. Why do I doubt it?)
4 users thanked author for this post.
-
anonymous
Guest
-
anonymous
GuestMarch 24, 2018 at 4:09 pm #178019What a nightmare.ย Microsoft continues to turn a blind eye to the confusion and havoc loosed upon the Windows ecosystem by its unending stream of hastily released, buggy patches and upgrades.
I’ve given up trying to keep track of it all — I already have a full-time job!
4 users thanked author for this post.
OscarCP
MemberMarch 24, 2018 at 4:58 pm #178054I looked for Friday’s update to the KB4089187 update for Windows 7, SP1. Following the usual bread crumbs trail I ended up in what was supposed to be its own page in the MS Catalog, after clicking on the link to it in the 23rd March, KB4089187 MS explanatory page.
But that landed me on one for the IE11 Security Update KB4096040. The date there was 23rd March, so it must be the correct update.
So: the number of the update to the update is quite different from that of the original one that — most curiously — is still the one given in the MS explanatory page.
More about this here: https://borncity.com/win/2018/03/24/internet-explorer-update-kb4096040-march-23-2018/
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV5 users thanked author for this post.
rhp52
AskWoody PlusMarch 24, 2018 at 6:32 pm #178066KB 4088875 disappeared from WU about 1-2 weeks ago and hasn’t returned. Meanwhile i now have KB4088881 in the optional section. My computer has started has been fine through all of this but in the last two days it has done some strange things. I’m going to be looking for some help here tomorrow to try to find out what gives.
Have a good night…..
Win 10 Pro v.20h2
1 user thanked author for this post.
MrBrian
AskWoody_MVPMarch 24, 2018 at 6:49 pm #178070“By the byโฆ for those of you who are manually installing the cumulative updates for Win10 1703 or 1607, thereโs now an explicit warning in the associated KB article”
The same warning has also been added to March 13, 2018โKB4088776 (OS Build 16299.309).
I don’t understand why Microsoft didn’t state that the same warning applies to updates installed via Window Update in v1607 and v1703, since these versions supposedly don’t bundle an SSU with a CU.
-
abbodi86
AskWoody_MVPMarch 26, 2018 at 10:49 am #178306I always have this update rule:
servicing stack update should always be installed/integrated first and alone in a separate sessionup until Windows 10 RTM, most cumulative updates metadata were explicitly require certain version of SSU to be installed before they got offered
but they started to neglect that later1 user thanked author for this post.
MrBrian
AskWoody_MVPMarch 24, 2018 at 7:25 pm #178075From Cumulative security update for Internet Explorer: March 23, 2018: “The fixes that are included in this cumulative update for Internet Explorer 4096040 are also included in the March 2018 Preview of Monthly Rollup. Installing the Preview of Monthly Rollup installs the fixes that are in this update.”
4 users thanked author for this post.
anonymous
GuestJim VS
AskWoody PlusMarch 25, 2018 at 3:54 am #178110This might not help anyone today, but just in case: consider that the alien Gouauld have taken control of MicroSuck. It is time to resurrect Richard Dean Anderson and the StarGate 1 team to get to the bottom of this.
If of course they are still available due to wear and tear on their psyches.
jimzdoats
anonymous
GuestMarch 25, 2018 at 6:54 pm #178217” I think of it as Mother Microsoftโs way of telling you that you really shouldnโt be using IE. Excuse my snark.” – LOL.
Well Mommie Dearest put the peanut butter and jelly on the outside of the sandwich this time. Possibly as some kind of punishment. I update IE only because it is
I am Group B, with Windows 7, x86. I got a WiFi problem (internet access kept dropping) as soon as I installed KB4096040. I had to remove it. The problem did not go away with the uninstall. Something got changed that was not reset with the uninstall. I had to re-image from last month’s full image backup. The WiFi was back to full working order after that. Microsoft must not have Netgear products onsite for testing updates (me being snarky, not naive).
I did an online search to see if the problem was wide spread, but found nothing. Maybe because the update to the update has not been widely installed as yet or the issue is isolated to Netgear WiFi.
-
anonymous
Guest
James Bond 007
AskWoody LoungerMarch 26, 2018 at 4:59 am #178273Microsoft has just updated the support documents (on 26 March) for KB4088875 (March 2018 Security-only Update) and KB4088878 (March 2018 Security Quality Rollup). A “Prerequisites” section has been added. It said :
If the version of PCI.SYS file is less than 6.1.7601.21744, please follow the step-by-step instructions outlined below before applying this update to physical or virtual machine:
(1) Take a backup of the following registry key and subkeys:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\PCI
(2) Copy the following VBScript (VBS), paste it in Notepad editor, save the file with โ.vbsโ extension, and run that โ.vbsโ File:
I have checked my Windows 7 systems and the version of the PCI.SYS file located in C:\Windows\System32\drivers is 6.1.7601.17514, which I believe is older than 6.1.7601.21744.
I take this to mean that if the things in the Prerequisites section are not done then I should not install either KB4088875 or KB4088878 on my Windows 7 systems. Microsoft has not said what will happen if I install the March updates without doing those things, however.
Do you guys think my interpretation is correct?
Hope for the best. Prepare for the worst.
-
MrBrian
AskWoody_MVPMarch 26, 2018 at 6:39 am #178277I believe that your interpretation is correct. However, an older version of the article linked to the same script at https://support.microsoft.com/en-us/help/3125574/convenience-rollup-update-for-windows-7-sp1-and-windows-server-2008-r2, which states that the fix can also be applied after installation.
This is also being discussed at https://www.askwoody.com/forums/topic/march-2018-patch-tuesday/#post-178170.
1 user thanked author for this post.
-
woody
Manager
-
T
AskWoody LoungerMarch 26, 2018 at 5:13 pm #178347That is insanity. We’re now fast approaching april with still no resolution to any of the issues in the updates (not in the preview either), a lot of us aren’t even being offered the rollup. While others are seeing the update but it’s unticked so won’t be installed automatically. What on earth is microsoft playing at? That’s a rhetorical question because i’m not convinced even they know.
1 user thanked author for this post.
anonymous
GuestMarch 26, 2018 at 9:05 pm #178369Wow, what a mess. Shouldn’t MS provide the updated PCI.sys instead? (I also have that older version.) Not quite sure what that script does but it seems risky. And without running it, would this mean that people are blocked from installing further updates? It’s all a mess.
1 user thanked author for this post.
-
MrBrian
AskWoody_MVPMarch 27, 2018 at 6:04 am #178443For the first time in March 2018, Microsoft is including pci.sys in a Windows 7 monthly rollup. The version included is 6.1.7601.24056. Evidence: file lists provided in relevant KB articles at https://support.microsoft.com/en-us/help/4009469/windows-7-sp1-windows-server-2008-r2-sp1-update-history.
It seems that Microsoft’s blacklisting of KB4088875 isn’t based upon the version of pci.sys present. I had an older version of pci.sys on my computer, but yet I was offered KB4088875 in Windows Update.
-
anonymous
Guest -
MrBrian
AskWoody_MVP
-
-
-
anonymous
Guest
bobcat5536
AskWoody LoungerMr. Natural
AskWoody LoungerMarch 26, 2018 at 10:25 am #178301In my 21+ years as a systems admin I don’t ever recall becoming confused about the status of which operating system updates I need installed to insure future updates install properly. In some instances we’re told to be sure the January delta update is installed despite the issues presented with that update. And in other instances Microsoft says to remove that and install the March delta update. And apparently going forward we are all to install the April delta update whenever that comes out and everything will be peachy keen after that. Isn’t it time that Microsoft be held accountable for this update nonsense?
Red Ruffnsore
1 user thanked author for this post.
-
anonymous
GuestMarch 26, 2018 at 6:18 pm #178339Well, the Windows 2000 days are over and things have changed. We let Windows Update pull the updates for our Windows Server 2012 R2 fleet and all is good. Sure, we hide a few well-known nonsense updates, but that’s it. Same for Windows Server 2016 and Windows 10 clients, except that hiding updates takes a different approach.
cesmart4125
AskWoody LoungerMarch 26, 2018 at 3:57 pm #178340I’m becoming concerned about not receiving some of the patches the rest of you are receiving for Win 7.ย In particular, kb 408875, kb 4088878, and kb 4089187 have not appeared this month.
Every month, I’ve downloaded all security patches and any patches labelled as important.ย However, I wait until shortly before the following month’s patches come out or Woody gives the all clear.ย I do not download previews.
Thanks in advance for your advice or information.
Win 7 Pro SP1, Office Pro SP2, Intel core 2 duo 1.80 GHz, 4 GB RAM
cesmart4125
AskWoody LoungerMarch 26, 2018 at 4:14 pm #178344How would I delete the second frog?ย Before I submitted my response, the indications were that I had only one attachment.
Also, I should mention that I’m considering an Apple laptop for my next computer.ย MS has made updating ridiculous –I’ve got to make a living, not spend all my time updating my computer.
2 users thanked author for this post.
-
DrBonzo
AskWoody PlusMarch 26, 2018 at 4:50 pm #178345I’ve had an iMAC for 6 months. Great machine. One update roughly once every 6 weeks or so and it installs without any drama. A bit different than Windows but still pretty easy to get used to. AND, it will save your sanity!
You won’t see KB 4088878 or KB4089187 offered in Windows Update because they are basically security only for Win 7 and IE 11, respectively. I was offered KB 4088875 (March Rollup which contains the 2 above security patches plus probably some feature updates) for about a couple days and then it disappeared from Windows Update presumably because of problems with it. I wouldn’t worry about not seeing it in Windows Update yet because there’s no way you want to install now anyway. Give it a week or 2 more.
1 user thanked author for this post.
-
OscarCP
MemberMarch 26, 2018 at 6:45 pm #178357Further to DrBonzo’s reply:
Because these updates are not offered by Windows Update, to get either the Windows 7 security only update or the IE11 update, one can follow these steps:
(1) Copy the KB number to the search field of a search engine (Google, etc.) and hit return.
(2) At or near the top of the list of search hits, you’ll see a link to Microsoft https://support.microsoft.com/en-us/help/KBnumber
(3) In that page there is an explanation of what the update is for and also, further down, a link to a page in the MS updates Catalogue.
(4) Clicking on that links puts one in the Catalogue page from where one can download the update for the several versions of, in this case, Windows 7, including yours.
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV1 user thanked author for this post.
-
Elly
AskWoody MVPMarch 26, 2018 at 6:53 pm #178361Hello cesmart4125,
You only had one attachment, but it was apparently placed twice within the message. I went ahead and fixed it.
I had KB408875 show up in Windows Update. I hid it. There were some problems reported with it… and people were reporting theirs had disappeared. I unhid it, and it vanished, and hasn’t shown up since. Some people have it show up unchecked. Group A needs to wait for Woody to give the all clear…
You can find the Security Only updates, KB 4088878 or KB4089187, at the Knowledge Base Article 2000003, courtesy of PKCano. However, wait for the Defcon Level to change, unless you are volunteering to test for the rest of us!
Non-techy Win 10 Pro and Linux Mint experimenter
1 user thanked author for this post.
Nibbled To Death By Ducks
AskWoody LoungerMarch 26, 2018 at 5:16 pm #178348Win 7 SP1 Pro 64 bit X86 Group “B”, WU set no “notify but don’t download”
This “patch rot” is slowly driving me mad. The following list showed up this AM, all “Important”:
KB4088875 (the Win 7 IP address killer)
KB4091290 (never got the KB4075211 in the first place, why do I need this?
KB2952664 (Telemetry snoop ware)
KB4088881 (I never install previews-the real stuff is scary enough)
For the love of Mike, won’t MS just pull KB4088875, fix it, reissue it, and THEN we’ll have somewhere to go from there?
I’ll just wait for Woody to give the all clear…I actually have parts of a life that don’t revolve around Redmond.
Unbelievable.ย And to think some of our nation’s defense systems have to deal with this Malarkey…
BTW, thanks to Woody, The Patch Lady and Mr. Brian for keeping us all abreast of this nonsense and steering us in the right direction!
P.S. If anyone can suggest a easy way of sifting through the WU “History” to find a particular item quickly, I’d appreciate it.
Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
--
"The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scottyanonymous
Guest-
MrBrian
AskWoody_MVPMarch 27, 2018 at 6:09 am #178444I ran the script on Sunday, just before installing KB4088875 on two computers. The script didn’t change anything on either of my computers, but your results may differ.
I haven’t researched this issue, but I would guess that failure to run the script beforehand might result in system changes that aren’t undone when uninstalling KB4088875.
-
anonymous
GuestMarch 27, 2018 at 3:20 pm #178451BTW: in the update catalogue (https://www.catalog.update.microsoft.com/Search.aspx?q=4088875) the updates still have the timestamp March 14th. So it looks as absolutely nothing has been done to these patches yet (yet= March 27th, 13.51 CET)
-
laidbacktokyo
AskWoody LoungerMarch 27, 2018 at 4:38 am #178425KB4088881 test install report:
Well no luck this time. The same 2 issues reported by me from Jan. 2018 are yet here.
Please refer to my late postย concerning these issuesย below:
1. The chaotic ErrorID9020 โ The Desktop Window Manager has encountered a fatal error (0x8898009b) is back in full;
2. The same chaotic leftoversย of the already closed windows in win7 taskbarย is also yet alive.
On the other hand Win7sp1x64Ultimate wasn’t visibly affected by any of 5 problems beyond AV registry keyย acknowledgedย by M$ itself.
Anyhowย KB4088881 is removed & put to hidden list, althoughย Internet Explorer 11 update v11.0.57ย KB4096040 installed separately and seems acceptable.
Rgds,
1 user thanked author for this post.
gborn
AskWoody_MVPMarch 28, 2018 at 3:25 am #178636Guess users of Windows 7 and Sever 2008 R2 are now sacked – the ne patches has nasty ‘known issues’ – and the old January 7 February (Meltdown) patches comes with a nasty surprise.
It seems, something went terribly wrong: January/February 2018 Meltdown patches from Microsoft opens even a bigger hole. No more exploit is necessary to access the memory from user processes (and even write it).
Seeย Windows 7 Jan./Feb. 2018 patches opens Total Meltdown vulnerability
Ex Microsoft Windows (Insider) MVP, Microsoft Answers Community Moderator, Blogger, Book author
https://www.borncity.com/win/
1 user thanked author for this post.
anonymous
GuestMarch 28, 2018 at 3:31 am #178633Elly, Susan, Woody, MrBrian,
Yesterday I installed the IE update KB 4089187 (and KB 890830) on my Group B Windows 7 Pro x64.No problems so far, although it took almost half an hour(!) for the system to integrate the update. I was tempted to force a restart, but I just let it do its thing and eventually it did install successfully.
Cheers
anonymous
GuestApril 12, 2018 at 4:23 am #184015im having issues.
after the welcome screen i only get a black screen with cursor. pulled eventvwr logs via boot cd and it seems explorer is crashing. same blackscreen even in safe mode. only safe mode with command prompt works.
i already tried system restore (fails), startup repair (cant repair) and sfc scannow (no integrity violations).
i suspect kb4088825 and nvidia 630m (360.95) incompatibility. only that kb was installed recently per system restore point. i cant uninstall it via command line since its a servicing stack and i dont know which msu to edit since there are many!
windows live chat not helpful at all. the tech just wants me to reinstall windows and insists the laptop isnt compatible with win10. grrr
any help would be appreciated
anonymous
GuestViewing 22 reply threads - This topic has 43 replies, 19 voices, and was last updated 7 years, 1 month ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Does windows update component store “self heal”?
by
Mike Cross
11 minutes ago -
Windows 11 Insider Preview build 27858 released to Canary
by
joep517
1 hour, 11 minutes ago -
Pwn2Own Berlin 2025: Day One Results
by
Alex5723
36 minutes ago -
Windows 10 might repeatedly display the BitLocker recovery screen at startup
by
Susan Bradley
1 hour, 18 minutes ago -
Windows 11 Insider Preview Build 22631.5409 (23H2) released to Release Preview
by
joep517
3 hours, 53 minutes ago -
Windows 10 Build 19045.5912 (22H2) to Release Preview Channel
by
joep517
3 hours, 54 minutes ago -
Kevin Beaumont on Microsoft Recall
by
Susan Bradley
10 hours, 55 minutes ago -
The Surface Laptop Studio 2 is no longer being manufactured
by
Alex5723
12 hours, 2 minutes ago -
0Patch, where to begin
by
cassel23
6 hours, 4 minutes ago -
CFPB Quietly Kills Rule to Shield Americans From Data Brokers
by
Alex5723
1 day, 1 hour ago -
89 million Steam account details just got leaked,
by
Alex5723
13 hours, 25 minutes ago -
KB5058405: Linux – Windows dual boot SBAT bug, resolved with May 2025 update
by
Alex5723
1 day, 10 hours ago -
A Validation (were one needed) of Prudent Patching
by
Nibbled To Death By Ducks
1 day, 1 hour ago -
Master Patch Listing for May 13, 2025
by
Susan Bradley
12 hours, 19 minutes ago -
Installer program can’t read my registry
by
Peobody
7 hours, 17 minutes ago -
How to keep Outlook (new) in off position for Windows 11
by
EspressoWillie
22 hours, 59 minutes ago -
Intel : CVE-2024-45332, CVE-2024-43420, CVE-2025-20623
by
Alex5723
1 day, 6 hours ago -
False error message from eMClient
by
WSSebastian42
1 day, 21 hours ago -
Awoke to a rebooted Mac (crashed?)
by
rebop2020
2 days, 6 hours ago -
Office 2021 Perpetual for Mac
by
rebop2020
2 days, 7 hours ago -
AutoSave is for Microsoft, not for you
by
Will Fastie
1 day, 4 hours ago -
Difface : Reconstruction of 3D Human Facial Images from DNA Sequence
by
Alex5723
2 days, 11 hours ago -
Seven things we learned from WhatsApp vs. NSO Group spyware lawsuit
by
Alex5723
1 day, 12 hours ago -
Outdated Laptop
by
jdamkeene
2 days, 16 hours ago -
Updating Keepass2Android
by
CBFPD-Chief115
2 days, 22 hours ago -
Another big Microsoft layoff
by
Charlie
2 days, 21 hours ago -
PowerShell to detect NPU – Testers Needed
by
RetiredGeek
19 hours, 3 minutes ago -
May 2025 updates are out
by
Susan Bradley
1 hour, 30 minutes ago -
Windows 11 Insider Preview build 26200.5600 released to DEV
by
joep517
3 days, 3 hours ago -
Windows 11 Insider Preview build 26120.3964 (24H2) released to BETA
by
joep517
3 days, 3 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.