As Susan Bradley details (see next post), in the past few hours Microsoft released a bunch of new Win10 cumulative updates: 4522016 for Win10 1903 452
[See the full post at: More on the unexpected manual-install-only Win10 cumulative updates and IE patch]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
More on the unexpected manual-install-only Win10 cumulative updates and IE patch
Home » Forums » Newsletter and Homepage topics » More on the unexpected manual-install-only Win10 cumulative updates and IE patch
- This topic has 38 replies, 15 voices, and was last updated 5 years, 8 months ago by
anonymous.
AuthorTopicwoody
ManagerSeptember 23, 2019 at 2:41 pm #1962616Viewing 19 reply threadsAuthorReplies-
PKCano
ManagerSeptember 23, 2019 at 2:48 pm #1962623KB4522007 has been added to AKB2000003 for Win7/8.1 for Group B (and whoever else needs it.)
1 user thanked author for this post.
-
anonymous
GuestSeptember 24, 2019 at 8:54 am #1963172I haven’t patched my win7 machine used for streaming since installing May 2019 patches for Group B. Would installing the following in the order presented be suffice? Is there anything I should skip?
Jun 2019 KB 4503269
Jun 2019 KB 4508772
Jul 2019 KB 4507456 SKIP as it’s not security-only
Aug 2019 KB 4517297
Sep 2019 KB 4516033 SKIP as it’s not security-only
KB 4516655 and KB 4474419
Sep 2019 (IE11) KB 4522007 -
PKCano
ManagerSeptember 24, 2019 at 8:54 am #1963181See AKB2000003 for direct Catalog downloads and notes.
-
-
-
EP
AskWoody_MVPSeptember 23, 2019 at 2:54 pm #1962629As I said in Susan’s post, I’m skipping these new Win10 updates since they only deal with recent 0day issues with Internet Explorer and they will not be delivered thru Windows Update nor thru WSUS. These new patches are available in the MS Update Catalog site only [aka. Catalog Only downloads]
-
DrBonzo
AskWoody PlusSeptember 23, 2019 at 3:37 pm #1962649A friendly reminder that if you do install the new IE 11 patch, that at least for Win 7 you should first install the latest SHA-2 (KB4474419) and SSU (KB4516655). That’s according to the MS support page here:
https://support.microsoft.com/en-us/help/4522007/cumulative-security-update-for-internet-explorer
This isn’t anything different from the September patches issued on Sept 10, so this is just a reminder.
-
b
AskWoody_MVPSeptember 23, 2019 at 4:54 pm #1962686A workaround appears to have been added which disables jscript.dll (but not default jscript9.dll).
At least, I couldn’t see the workaround listed earlier in CVE-2019-1367 for the IE zero-day.
(Chatter says the Chinese government has been actively exploiting this flaw against their minorities.)
-
anonymous
GuestSeptember 23, 2019 at 5:45 pm #1962702Mixed signals here, Win7 Pro x64. This post says no panic for the IE patch if IE isn’t used. The previous article by Susan indicates the vulnerability exists even if you don’t use IE. Grrr…
Was in no hurry for the monthly ordeal especially as this IE patch requires two latest Servicing Stack Updates first!!!
Group B but not doing the telemetry ones as the first of those took out my networking and required a full image and data restore from backup to get it back!
FWIW, twice in five years this has happened, but only due to MS updates…
-
nazzy
AskWoody PlusSeptember 23, 2019 at 5:52 pm #1962711 -
woody
ManagerSeptember 24, 2019 at 8:07 am #1963111Microsoft has been characteristically (and perhaps justifiably) silent on the subject.
At this point, all we know is that the patch is only available by manual download – and, to me, that means there’s no pressing need to install it now. The only info we have at this point describes an infection vector solely reliant on IE.
Let’s see if we find out any more today.
1 user thanked author for this post.
-
geekdom
AskWoody_MVPSeptember 24, 2019 at 8:45 am #1963176Microsoft has been characteristically (and perhaps justifiably) silent on the subject.
I think the problem is more potent than current explanations indicate.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender1 user thanked author for this post.
-
-
-
anonymous
GuestSeptember 23, 2019 at 6:13 pm #1962716? says:
so, does the Known Issue in this Security Update VBscript “Mitigation” preclude joining the lemmings at the cliff?
https://support.microsoft.com/en-us/help/4522007/cumulative-security-update-for-internet-explorer
-
b
AskWoody_MVPSeptember 23, 2019 at 6:36 pm #1962725It’s a quick check after patching to confirm whether VBscript is still disabled by default as recommended (or not).
I don’t see why that would affect anyone’s decision whether or not to install the IE jscript zero-day fix:
1 user thanked author for this post.
-
-
Mr. Natural
AskWoody LoungerSeptember 23, 2019 at 7:23 pm #1962745Unfortunately we still have some that use IE. I foresee a group policy change soon. We will likely force everyone over to Chrome. I know some of you shudder the thought but there is an .admx group policy file for Chrome. We have applied it in AD. You can manage just about any aspect of Chrome if you have the time to do so.
Red Ruffnsore
-
anonymous
Guest -
Geo
AskWoody Plus -
Geo
AskWoody Plus -
abbodi86
AskWoody_MVPSeptember 24, 2019 at 4:55 am #1962963It’s not the first time we get oob catalog-only updates, even Win10 CUs
v1903 already got release preview update
Cumulative Update for Windows 10 Version 1903 – KB4517211 (18362.385)v1909 got it too, but it’s the same build anyway
-
This reply was modified 5 years, 8 months ago by
abbodi86.
1 user thanked author for this post.
-
This reply was modified 5 years, 8 months ago by
-
EP
AskWoody_MVPSeptember 24, 2019 at 5:29 am #1962966unlike the KB4522016 update, the upcoming KB4517211 update should be available not only thru MS Update Catalog but also through windows update & WSUS as well – that one may be publicly released either by the end of this week or on Mon 9/30
-
This reply was modified 5 years, 8 months ago by
EP.
-
This reply was modified 5 years, 8 months ago by
-
abbodi86
AskWoody_MVP -
woody
Manager -
abbodi86
AskWoody_MVPSeptember 24, 2019 at 8:25 am #1963131https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/known-issues
The following known issue will be resolved by installing the KB4517211 update, due to be released in late September 2019.
1 user thanked author for this post.
-
-
-
anonymous
GuestSeptember 24, 2019 at 5:54 am #1962971 -
abbodi86
AskWoody_MVP
-
-
-
anonymous
GuestSeptember 24, 2019 at 7:43 am #1963059 -
ChrisAVWood
AskWoody Plus -
anonymous
GuestSeptember 24, 2019 at 8:36 am #1963137 -
abbodi86
AskWoody_MVP -
anonymous
Guest -
anonymous
Guest
-
-
-
Microfix
AskWoody MVPSeptember 24, 2019 at 9:00 am #1963188As per Bleeping Computer article
Rather than downloading the patch, surely the MSFT workaround to mitigate the vuln seems a quicker way..IMO
For 32-bit systems, enter the following command at an administrative command prompt:takeown /f %windir%\system32\jscript.dll cacls %windir%\system32\jscript.dll /E /P everyone:N
For 64-bit systems, enter the following command at an administrative command prompt:
takeown /f %windir%\syswow64\jscript.dll cacls %windir%\syswow64\jscript.dll /E /P everyone:N takeown /f %windir%\system32\jscript.dll cacls %windir%\system32\jscript.dll /E /P everyone:N
just curious..
Windows - commercial by definition and now function...1 user thanked author for this post.
-
geekdom
AskWoody_MVPSeptember 24, 2019 at 9:08 am #1963208Rather than downloading the patch, surely the MSFT workaround to mitigate the vuln seems a quicker way..IMO
Hence, why Microsoft’s haste to issue a patch immediately?
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender1 user thanked author for this post.
-
anonymous
GuestSeptember 25, 2019 at 6:54 pm #1965137Microfix said:
As per Bleeping Computer articleAccording to the same Bleeping Computer article:
CVE-2019-1367 can be exploited by potential attackers by redirecting their targets to a maliciously crafted website which would trigger a remote code execution attack if the victim uses a vulnerable version of Internet Explorer (i.e., 9, 10, and 11)
So only JScript.dll v9.0 (used by IE 9.0) & newer versions are vulnerable ? And IE 8.0 (with JScript.dll v5.8.x) is not vulnerable ?
Also, Microsoft .NET Framework uses the .NET implementation of JScript. There are several instances of Microsoft.JScript.dll on my Win 7 PC, which has .NET 2.0 & .NET 4.x.
Must these Microsoft.JScript.dll be disarmed as well using the takeown & cacls commands ?
-
-
jhvance
AskWoody Lounger -
Geo
AskWoody Plus -
geekdom
AskWoody_MVPSeptember 24, 2019 at 12:06 pm #1963359Windows 7 x64-systems
Two optional previews just showed in the Windows Update Queue
— 2019-09 Preview of Quality Rollup for .NET Framework 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1,4.7.2, 4.8 for Windows 7 and Server 2008 R2 for x64 (KB4516551)
https://support.microsoft.com/en-us/help/4516551/sep-19-2019-kb4516551— 2019-09 Preview of Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4516048)
https://support.microsoft.com/en-us/help/4516048/windows-7-update-kb4516048On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender-
This reply was modified 5 years, 8 months ago by
geekdom.
-
This reply was modified 5 years, 8 months ago by
-
mpw
AskWoody PlusSeptember 24, 2019 at 5:37 pm #1963682Windows 7 sp1 64bit
Windows Update 09/24/2019
Important
KB4474419 was offered even though I already had it installed. It installed again and now has today’s date as its installation date.
KB4516065 was offered and installed; no apparent problems.
Two .NET Framework updates are offered. KB4514602 is checked. KB4503548 is not checked. I did not install either one today.
Optional
A Monthly Quality Rollup KB4516048 and a .NET Framework KB4516551. Neither one is checked and I did not install.
There are a lot of KB numbers flying around this place. Many I have never seen in my Windows Update. Seems like Windows 10 and Windows 7 updates are all mixed together here.
Microsoft recommends that “Servicing stack update (SSU) (KB 4516655) or a later SSU update” be installed before the IE11 patch. I have not been offered KB4516655 and do not find it in my installed updates.
Does anyone here know anything about KB4516655? It is supposed to be necessary before installing KB4522007, which I think is the IE11 patch.
HP Pavilion Desktop TP01-0050 – 64 bit
Windows 10 Home Version 22H2
OS build 19045.5608
Windows Defender and Windows Firewall
Microsoft Office Home and Business 2019
-Version 2502(Build 18526.20168 C2R) -
PKCano
ManagerSeptember 24, 2019 at 6:27 pm #1963719KB4516655 is a Servicing Stack Update, which has to be installed exclusively (by itself). It will not show up in the Important Update queue in Windows Update if there are any other pending (checked or unchecked) updates.
If you install the updates you want to install, and hide any remaining ones, the SSU will appear. Or you can download it from the MS Catalog and manually install it.KB4474419 and KB4516655 are required to install KB4522007
-
mpw
AskWoody Plus
-
-
Viewing 19 reply threads - This topic has 38 replies, 15 voices, and was last updated 5 years, 8 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Office gets current release
by
Susan Bradley
3 hours, 38 minutes ago -
FBI: Still Using One of These Old Routers? It’s Vulnerable to Hackers
by
Alex5723
9 hours ago -
Windows AI Local Only no NPU required!
by
RetiredGeek
5 hours, 45 minutes ago -
Stop the OneDrive defaults
by
CWBillow
9 hours, 49 minutes ago -
Windows 11 Insider Preview build 27868 released to Canary
by
joep517
19 hours, 45 minutes ago -
X Suspends Encrypted DMs
by
Alex5723
21 hours, 57 minutes ago -
WSJ : My Robot and Me AI generated movie
by
Alex5723
22 hours, 15 minutes ago -
Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
by
Alex5723
22 hours, 52 minutes ago -
OpenAI model sabotages shutdown code
by
Cybertooth
23 hours, 29 minutes ago -
Backup and access old e-mails after company e-mail address is terminated
by
M W Leijendekker
11 hours, 39 minutes ago -
Enabling Secureboot
by
ITguy
18 hours, 39 minutes ago -
Windows hosting exposes additional bugs
by
Susan Bradley
1 day, 7 hours ago -
No more rounded corners??
by
CWBillow
1 day, 3 hours ago -
Android 15 and IPV6
by
Win7and10
16 hours, 57 minutes ago -
KB5058405 might fail to install with recovery error 0xc0000098 in ACPI.sys
by
Susan Bradley
1 day, 19 hours ago -
T-Mobile’s T-Life App has a “Screen Recording Tool” Turned on
by
Alex5723
1 day, 22 hours ago -
Windows 11 Insider Preview Build 26100.4202 (24H2) released to Release Preview
by
joep517
1 day, 17 hours ago -
Windows Update orchestration platform to update all software
by
Alex5723
2 days, 5 hours ago -
May preview updates
by
Susan Bradley
1 day, 17 hours ago -
Microsoft releases KB5061977 Windows 11 24H2, Server 2025 emergency out of band
by
Alex5723
1 day, 8 hours ago -
Just got this pop-up page while browsing
by
Alex5723
1 day, 21 hours ago -
KB5058379 / KB 5061768 Failures
by
crown
1 day, 19 hours ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
21 hours, 12 minutes ago -
At last – installation of 24H2
by
Botswana12
2 days, 21 hours ago -
MS-DEFCON 4: As good as it gets
by
Susan Bradley
17 hours, 59 minutes ago -
RyTuneX optimize Windows 10/11 tool
by
Alex5723
3 days, 9 hours ago -
Can I just update from Win11 22H2 to 23H2?
by
Dave Easley
1 day, 7 hours ago -
Limited account permission error related to Windows Update
by
gtd12345
3 days, 22 hours ago -
Another test post
by
gtd12345
3 days, 23 hours ago -
Connect to someone else computer
by
wadeer
20 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.