![]() |
MS-DEFCON 2:
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it.
|
-
Microsoft releases KB 3213643, 2956078, 4011078, 4011052 to fix June Outlook security bugs
Home › Forums › AskWoody blog › Microsoft releases KB 3213643, 2956078, 4011078, 4011052 to fix June Outlook security bugs
Tagged: KB 3213643
- This topic has 24 replies, 12 voices, and was last updated 3 years, 8 months ago.
Viewing 15 reply threads-
AuthorPosts
-
-
July 27, 2017 at 3:30 pm #126732
-
July 27, 2017 at 5:04 pm #126753
EstherD
AskWoody LoungerYup. KB2956078 wasn’t there yesterday when I updated one of my two Win7 laptops. But it was there early this afternoon when I went to do the other one.
When I checked initially, the documentation page for KB2956078 was 404. But an hour or so later, it appeared as if by magic. You’d think MS could get its act together and release the docs simultaneously with the release of the patch files in WU. Nah.
Decided to install both KB3203467 and KB2956078 on both machines. So far, no problems. But then we don’t use Outlook, so I would expect (hope?) not to see any issues elsewhere in the system.
So why install any Outlook patches? Because the miscreants and ne’er-do-wells are much more clever than the MS engineers, and I don’t want to risk them finding a way to leverage Outlook bugs in ways that MS engineers failed to anticipate. Hence, I patch. Religiously. Ditto for Internet Explorer, which we also do not use.
Patching Group A*. Because I reserve the right not to install things I do not want, no matter how MS rates them, and I also install things that others in Group A might not install at all, or not as early as I do, e.g. the Outlook security patches.
-
July 27, 2017 at 7:31 pm #126772
anonymous
Guest-
July 27, 2017 at 8:26 pm #126785
EstherD
AskWoody LoungerCan’t speak to WSUS, but it sure didn’t look that way in WU earlier this afternoon, despite what it says on the KB2956078 documentation page.
Both patches were listed in the WU “Important section”, with KB3203467 unchecked and KB2956078 checked. And both patches were apparently installed when I asked WU to install the two of them together in a single batch. (Which is to say that WU did not give me the “1 patches installed; 1 patches unneeded” message that typically appears if one patch really is superseded by another one in the same install batch.)
However, now that I check more carefully, I find a VERY curious anomaly.
Both KB3203467 and KB2956078 are listed as successfully installed on the WU “Review your update history” page, with KB3203467 listed first and KB2956078 listed second.
BUT on the “Programs and Features” -> “View installed updates” page, KB2956078 appears TWICE, while KB3203467 does not appear at all!
So let me be the first (but probably not the last) to say: This does NOT give me great confidence in the current MS patch control process!
1 user thanked author for this post.
-
July 27, 2017 at 11:08 pm #126806
Bill C.
AskWoody PlusI installed the Outlook patch KB2956078, for Outlook 2010 (32bit) and KB3203467, the old bad patch for Outlook 2010 (32bit) using Windows Update. Both were shown as Important, but only the KB2956078 was pre-checked. Both downloaded, but KB2956078 started initializing and installing first. What was interesting was the original patch KB3203467 never initialized or installed. The green Successful screen appeared. I checked the View Update history and it showed todays patch as successful, but did not show the earlier patch. Using Control Panel, installed updates also did not show the original patch as installed, but today’s was there. A reboot and new run of WU did not show either patch, and the History and Control panel applet was the same.
A check with Belarc Advisor shows 2 missing updates. KB3203467 is one.
The other is KB 3212642. What is interesting is back in January 2017 when the Security Only Patch KB3212642 for Win7-64, a very small patch of 6.3MB was released I installed it at Defcon 3. It appears in both the history and in the Control panel applet, and it was not labeled as missing in Belarc. As we remember, there were no patches for February due to the Shadowbroker dump. However after the install of the March 2017 Security Only Patch KB4012212 Belarc began showing KB3212642 as missing. It still appears in the WU history and Control panel as installed.
I suspect todays patch does supercede the bad patch, as some others say, and it seems to support what abbodi86 said in Post #125979 back on July 21 about the Outlook 2016 patches.
Call it wishful thinking, but Outlook 2010 seems snappier.
1 user thanked author for this post.
-
July 28, 2017 at 9:54 am #126869
Bill C.
AskWoody PlusOne thing I just remembered when I looked back at my patching log notebook.
When I originally saw that Belarc was saying that the January 2017 Security Only patch KB3212642 was missing after the March install, I tried to install it again.
As the Group B patches are NOT supposed to be cumulative it should have been able to be installed. However, it said it was “not applicable.” This may be due to the urgency of the March patches possibly repatched the vulnerabilities addressed by the January patch.
I do not know and this is only conjecture on my non-expert part.
I suspect ch100 is on the right track with his post #126857 below.
-
-
-
July 28, 2017 at 12:07 am #126820
EstherD
AskWoody LoungerInteresting… I also use Belarc, but it gives me a clean bill of health… ALL security patches installed (based on defs version 2017.7.19.2)… despite the anomaly I described earlier.
Curiouser and curiouser. And less and less confidence that MS knows what it’s doing with patch control these days. Which is really BAD, because I have NO good way to test for most of these security flaws. So TRUST is the only thing I have to go on. And that’s evaporating faster than a puddle on a hot July day.
1 user thanked author for this post.
-
July 28, 2017 at 5:04 am #126849
Ed
AskWoody LoungerAm I missing something here? Is it necessary to install the known “bad patch” (which is still NOT checked) along with the “fix-all” patch (which IS checked)?
We’ve been relentlessly advised to NEVER install Important updates that are not already checked but from what I’m seeing in these previous posts it appears many are manually checking the unchecked “bad patch” for installation.
I do realize it’s still a bit early to know exactly what’s going on here so I’m holding off on the latest miracle patch for a while. I’m confident somebody here will share the PROPER technique for getting this long overdue Outlook patch screw-up straightened out.
1 user thanked author for this post.
-
July 28, 2017 at 5:34 am #126854
PKCano
ManagerAn unchecked patch in the “important updates” list usually means MS may deem it “recommended” but not “important” or “critical.” It usually implies that it not be installed.
If you have to have the fix now because it is causing problems, I would leave the old patch unchecked and install the checked one. The old patch may disappear (become unnecessary) after the fix is installed. If the fix says “not applicable” than you may have to install the other first.
At any rate, if you can live without the fix, it may be worthwhile to hold off for a couple of days to see if it creates any problems of its own .
1 user thanked author for this post.
-
July 28, 2017 at 6:05 am #126857
ch100
AskWoody_MVPThis is more subtle than it appears to be at first sight.
I have seen patches which are unchecked when scanning from the Never check for updates setting and unchecked when scanning from Download but do not install while the log says that they are throttled due to regulation (which does not mean that they should not be installed, but that the servers are overloaded for the moment).
In a different context or order of installation, the same patches would be checked under Download but do not install or install Auto and unchecked under Never check.
A typical one is KB3021917 for Windows 7.
What is the conclusion after all those facts? My conclusion is that KB3021917 is provided for install but not in all contexts. A bug in the Microsoft WU?
-
-
-
July 28, 2017 at 5:13 am #126848
anonymous
Guest-
July 28, 2017 at 5:18 am #126852
PKCano
ManagerIf you are having severe problems because of the previous bugs, it might be a good idea to go ahead and install the patches – you can always uninstall them.
But if the bugs are not “bugging” you, it might be a good idea to wait a few days and see if there are others problems caused by the new patches..
-
-
July 28, 2017 at 5:35 am #126855
-
July 28, 2017 at 3:22 pm #126936
-
July 29, 2017 at 4:22 pm #127083
anonymous
Guest-
July 29, 2017 at 4:27 pm #127086
-
-
July 31, 2017 at 2:35 am #127241
-
July 31, 2017 at 10:37 am #127295
-
August 1, 2017 at 4:53 am #127385
TJ
AskWoody Plus-
August 1, 2017 at 9:13 am #127420
L95
AskWoody PlusI have Outlook 2010, and in the June list of patches KB3203467 appeared as an “Important” Security update but the box wasn’t checked. In early July, when Woody gave the go-ahead to install the June patches, I sent a message to PKCano (AskWoody MVP) and I asked whether I should check the box for KB3203467. He replied by telling me to leave it unchecked. So that’s what I did. He also said Microsoft will probably roll out the fixes later in July. Then on July 27, Woody’s article in PC World came out stating that Microsoft released four patches to fix the June Outlook Security bugs. However for some reason, KB3203467 wasn’t discussed in his article. On July 31, when I checked for available updates, KB3203467 was still listed as an Important Security update, and the box was still unchecked. But it also listed KB2956078 as an Important Security Update for Outlook 2010. and for this one, the box was checked. So I went ahead and installed KB2956078, but I continued to leave the box for KB3203467 unchecked. Then after that, I did another check for updates, and now KB3203467 no longer appears as an available update. The KB3203467 eventually disappeared from the list but I had to wait until KB2956078 to be installed for that to happen. So it looks like PKCano’s advice to me from early July is correct (and likewise also his advice in the July 29 posting shown above). Thanks to PKCano for the advice.
-
-
August 1, 2017 at 9:49 am #127427
-
August 2, 2017 at 4:22 pm #127788
anonymous
GuestI’ve been holding off installing any of the June MS Office updates (running Outlook 2010).
In the past I have been offered the unchecked Outlook KB3203467, then recently the checked KB2956078.
Today I checked and without having done anything the KB3203467 was gone.
I installed all offered and checked MS Office updates (8 total).
Hope all will be well.
-
August 2, 2017 at 5:21 pm #127793
-
-
August 3, 2017 at 12:26 pm #127891
anonymous
Guest -
August 9, 2017 at 6:12 pm #128696
-
-
AuthorPosts
Viewing 15 reply threads -
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments. Click here for details and to sign up.
Search Newsletters
Search Forums
Recent Replies
Hamsa Vicerra on How can I locate Bitlocker key in OEM refurb HP laptop?
11 minutes agoDriftyDonN on MS-DEFCON 2 – Deferring the April Updates
36 minutes agoanonymous on New smartphone? Great! Now don’t charge it past 80%
47 minutes agocastiel on The ides of March
2 hours, 57 minutes agoHamsa Vicerra on How can I locate Bitlocker key in OEM refurb HP laptop?
3 hours, 5 minutes agoMoonshine on 20H2 Printer Queue Icon now missing from Task Bar
3 hours, 36 minutes agoTex265 on 20H2 Printer Queue Icon now missing from Task Bar
3 hours, 50 minutes agoOscarCP on Talli-ho! The hunt for Planet X (or a neighbourig black hole?) is afoot!
3 hours, 51 minutes agoMoonshine on Upgrade Firefox…recommendations please.
3 hours, 53 minutes agoMicrofix on Upgrade Firefox…recommendations please.
4 hours, 11 minutes agoMoonshine on 20H2 Printer Queue Icon now missing from Task Bar
4 hours, 12 minutes agoMicrofix on Tips to protect a Laptop without battery?
4 hours, 22 minutes agoZaphyrus on Tips to protect a Laptop without battery?
4 hours, 28 minutes agoMicrofix on Standalone installer script for Windows 7 ESU, regardless the license
4 hours, 31 minutes agoCraigS26 on April Patch Tuesday out – Exchange once again
4 hours, 42 minutes agoStill Anonymous on How much RAM does your computer have?
4 hours, 45 minutes agoRetiredGeek on 1809 and SMBv1 – Still not fully fixed in 20H2
4 hours, 45 minutes agoglnz on 1809 and SMBv1 – Still not fully fixed in 20H2
5 hours, 21 minutes agobbearren on April Patch Tuesday out – Exchange once again
5 hours, 22 minutes agoMicrofix on Tips to protect a Laptop without battery?
5 hours, 55 minutes agoanonymous on Upgrade Firefox…recommendations please.
5 hours, 57 minutes agoPKCano on April Patch Tuesday out – Exchange once again
6 hours, 4 minutes agoMicrofix on April Patch Tuesday out – Exchange once again
6 hours, 8 minutes agoCWBillow on Mapping a drive
6 hours, 24 minutes agoAlex5723 on Upgrade Firefox…recommendations please.
6 hours, 24 minutes agoPaul T on Upgrade Firefox…recommendations please.
6 hours, 37 minutes agoPaul T on iOS : FCC Speed Test
6 hours, 40 minutes agoAlex5723 on Upgrade Firefox…recommendations please.
6 hours, 44 minutes agoPKCano on MS-DEFCON 2 – Deferring the April Updates
6 hours, 45 minutes agoAlex5723 on Tips to protect a Laptop without battery?
6 hours, 50 minutes ago
Recent Topics
-
Computer suddenly shows in home network as media device
3 hours, 49 minutes ago
-
Windows 10 Insider build 19043.928 (21H1) released to Beta & RP
1 hour, 49 minutes ago
-
20H2 Printer Queue Icon now missing from Task Bar
3 hours, 36 minutes ago
-
Tips to protect a Laptop without battery?
4 hours, 23 minutes ago
-
April Patch Tuesday out – Exchange once again
4 hours, 42 minutes ago
-
Microsoft Account linking to X-Box ID
11 hours, 50 minutes ago
-
iOS : FCC Speed Test
6 hours, 41 minutes ago
-
Power crash when updating
21 hours, 11 minutes ago
-
USB 3.0 slows down by a factor of 10x when not used
11 hours, 40 minutes ago
-
Upgrade Firefox…recommendations please.
3 hours, 53 minutes ago
-
Two links the get to Outlook online?
13 hours, 13 minutes ago
-
Am I FLoCed? A New Site to Test Google’s Invasive Experiment
1 day, 5 hours ago
-
20H2 and NVMe SSDs
13 hours, 25 minutes ago
-
Why KB2999226 installed today?
12 hours, 1 minute ago
-
Error 4605 Command is not available
1 day, 9 hours ago
-
legitimate interest
1 day, 16 hours ago
-
How to customize and manage your Microsoft Account
1 day ago
-
New smartphone? Great! Now don’t charge it past 80%
47 minutes ago
-
Check or change Win10’s file-sharing encryption level
1 day, 19 hours ago
-
Freeware Spotlight — Killer
1 day, 19 hours ago
-
Known Issue Rollback
23 hours, 51 minutes ago
-
Dism RestoreHealth shows two “Versions” and Q re 20H2 “Experience”
2 days, 5 hours ago
-
Firefox SSD capacity usage ?
1 day, 7 hours ago
-
Android : New Wormable Malware Spreads by Creating WhatsApp Auto-Replies
2 days, 11 hours ago
-
KB4092436 – can neither install it or hide it
2 days, 9 hours ago
-
MS-DEFCON 2 – Deferring the April Updates
36 minutes ago
-
Tasks for the weekend – April 10, 2021 – change your Office
10 hours, 27 minutes ago
-
Grandma, what big updates you have!
2 days, 20 hours ago
-
Mapping a drive
6 hours, 24 minutes ago
-
vssvc?
1 day, 17 hours ago
Search for Topics
Recent blog posts
- April Patch Tuesday out – Exchange once again
- How to customize and manage your Microsoft Account
- New smartphone? Great! Now don’t charge it past 80%
- Check or change Win10’s file-sharing encryption level
- Freeware Spotlight — Killer
- Known Issue Rollback
- MS-DEFCON 2 – Deferring the April Updates
- Tasks for the weekend – April 10, 2021 – change your Office
Key Links
Copyright © 2004 – 2021 AskWoody Tech LLC. All rights reserved.