Just got a report from reader MB: I’m not sure what others are experiencing but, at my place of employment, KB4462923 appears to have changed the syst
[See the full post at: Report: The October Win7 Monthly rollup, KB 4462923, forces TLS 1.0]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Report: The October Win7 Monthly rollup, KB 4462923, forces TLS 1.0
Home » Forums » Newsletter and Homepage topics » Report: The October Win7 Monthly rollup, KB 4462923, forces TLS 1.0
- This topic has 43 replies, 19 voices, and was last updated 6 years, 6 months ago by
anonymous.
Tags: KB 4462923 TLS 1.0
AuthorTopicViewing 16 reply threadsAuthorReplies-
Microfix
AskWoody MVPNovember 9, 2018 at 12:51 pm #231757TLS 1.0 and SSL3 was supposed to have be dumped back in June 2016 in favor of TLS 1.2
a bit of background regarding the protocol:
https://www.varonis.com/blog/ssl-and-tls-1-0-no-longer-acceptable-for-pci-compliance/
and that article is 14 months old.Windows - commercial by definition and now function...1 user thanked author for this post.
-
anonymous
Guest
-
Mr. Natural
AskWoody LoungerNovember 9, 2018 at 1:15 pm #231766Just when you think the bumbling and fumbling at Microsoft couldn’t get any worse…..
Microsoft officially dropped support of TLS 1.0 just over a week ago on their Office 365 exchange servers. They gave plenty of warning, over a year for the deadline. Any of our hardware or older software that only used TLS 1.0 to send email had to be re-routed through an smtp relay server instead of pointing directly to Office 365 Exchange servers because Microsoft said TLS 1.0 will no longer be allowed to pass on October 31rst.
I can’t confirm the situation. We only have one 2008r2 server left and it does not do send mail. But this would not surprise me at all. Just as they discontinue the use of a protocol they release a patch that re-enables it which causes send mail failure.
This has become a comedy of errors in which it seems each new day brings a new failure from Microsoft.
Red Ruffnsore
-
Mr. Natural
AskWoody LoungerNovember 9, 2018 at 2:09 pm #231790So I decided to do a little more digging. I went to our Office 365 Exchange console and ran a message trace on outgoing email. I wanted to see if emails sent by users from Outlook were using TLS 1.2 which they should be. KB4462923 is installed on most of our W7 and W10 desktop computers. They are sending in TLS 1.2 format. However I see another issue with Office 365 Exchange servers.
Looking at all outgoing email I see a lot of emails showing as “Getting Status” and not showing that the emails have been delivered. These would be emails being exchanged with users in house which means they are going directory from Outlook on a user desktop to Office365 servers which send to another local user on our domain. No outside interference.
I confirmed the emails are delivered but obviously Microsoft has something else going on with Exchange as well because there are a lot of “Getting Status” along with a lot of “Resolved” reports showing up. The emails are getting delivered but something else going on in which Exchange is having a lot of delays in reporting the messages as being delivered.
So I can report our users are sending email using TLS 1.2 but something else is going on. Our relay servers are running Server 2012r2 so they are not affected.
Red Ruffnsore
anonymous
GuestNovember 9, 2018 at 1:54 pm #231778anonymous
GuestNovember 9, 2018 at 3:44 pm #231822? says:
If anyone wants to look:
https://docs.microsoft.com/en-us/windows-server/security/tls/tls-registry-settings
1 user thanked author for this post.
GoneToPlaid
AskWoody LoungerMarkAtHome
AskWoody PlusNovember 9, 2018 at 7:59 pm #231866I have not noticed anyone saying anything, but immediately after we reached Defcon 4, I had Windows Update do its thing. It seemed uneventful, but as soon as I opened Outlook 2010, images were no longer being downloaded along with their messages — image placeholders are all I see, and in order to view each email, I am forced to view it via one of my browsers (it doesn’t matter which one).
Since I have been using Outlook 2010 since it was released and I never experienced this before, I can only attribute it to the updates.
Anyone?
-
PKCano
ManagerNovember 9, 2018 at 8:07 pm #231868I don’t use Outlook. But there is a security setting (option) in most mail programs to allow automatic download of external pictures/objects (or not). I wonder if the option was reset by one of the latest Outlook/Office updates.
You might look through the options (probably security) and see if you can find the setting.Another approach would be to uninstall the Outlook updates one by one to see which caused the change, then reinstall all but the culprit.
-
The Surfing Pensioner
AskWoody PlusNovember 10, 2018 at 5:48 am #231950I doubt if an Outlook update is responsible. I always install all the Office security patches and am up-to-date now including October’s, but I still have the right-click option to download pictures on my Outlook emails – and it works! However, being in Group B, I do not install rollups.
-
Mr. Natural
AskWoody LoungerNoel Carboni
AskWoody_MVPNovember 10, 2018 at 2:35 am #231927I’m not sure the image thing is TLS-related.
As I recall that was a “step up in security” (with a step down in functionality) specifically done to reduce the automatic interpretation of message contents.
I use Outlook 2010 myself, and as I recall that change came in stages, and this was quite a while ago… I remember at one point being able to right-click on image placeholders and seeing the images, then later not being able to get it to load images at all (the placeholders just change from “right click to download” to “The linked image cannot be displayed”).
At this point I have simply stopped expecting eMail messages to be rich with image content. Life goes on. The important parts are almost always in the text anyway, and most eMail originators (e.g., the government) will include a “view in browser” link in mail that matters.
It’s mildly interesting that the product has become literally much less functional and yet we all just accept that, as though it’s inevitable in the name of security and progress. They have our brains washed well…
-Noel
Steve D.
AskWoody PlusNovember 10, 2018 at 10:13 am #232005I can’t promise this trick will work for all, but it did work for me with Outlook 2010 on both Windows 7 and 8.1. It’s simple enought to try and then reverse if you wish. Go to Internet Options via either Control Panel or I.E. In the Advanced tab, scroll down to the Security subsection. One of the options is “Do not save encrypted pages to disk”. If the box is checked, uncheck it, apply, and close out of it. Now see if the problem is fixed. I’d had this problem for quite a while, but after this fix, never again. Not exactly an intuitive place to look, huh!
2 users thanked author for this post.
-
Noel Carboni
AskWoody_MVPNovember 10, 2018 at 11:15 am #232016Yep, that works. Thank you!
Notably I seem to have to hover over the image placeholders to get them to load now, at least from existing eMail messages.
I need to do some research on what (intrusion? infection?) doing that might make possible that the setting presumably prevents…
Edit: I found a Microsoft article that claims, “The checkbox was slated to be retitled ‘Clear HTTPS cache when browser is closed’ but we unfortunately ran out of time.”
Clearly there’s a secondary implication to it when HTML content is being rendered in Outlook.
-Noel
1 user thanked author for this post.
-
The Surfing Pensioner
AskWoody PlusNovember 12, 2018 at 6:09 pm #232513I have just come to the conclusion that the picture content in Outlook 2010 emails is decidedly temperamental. As I wrote above, I had no problem on 10/11/18; but yesterday I had reason to re-install Firefox, my default browser. Lo, the pictures dropped out of my Outlook emails and no amount of clicking would get them back. I thought Oh no you don’t and have spent a large part of this evening twiddling with the settings in Outlook’s Trust Centre. Got my pictures back in the end, but I still can’t imagine why re-installing Firefox blocked them anyway……………….I had retained the same settings……………………..and of course if I have to re-install again, presumably the problem will recur………………………..It is these unaswered questions that keep us glued to the monitor…………………………………
-
Bob99
AskWoody MVPNovember 9, 2018 at 8:33 pm #231870Given the headline at the top of this thread, can someone please develop a post for more advanced users to see just what setting they have with respect to TLS 1.0 on their client (non server and non domain-joined) computer(s), and just maybe how to change it to at least a default of TLS 1.0 disabled and a minimum of TLS 1.1 enabled as the go-to protocol?
Something tells me this entails a setting deep within the registry to check and/or change.
The link in Anonymous’ post (#231822) above is of some help, but not much, in that it makes it seem as if the only way to truly disable TLS 1.0 and enable the higher protocols, like 1.1, 1.2 and 1.3, is to create some very specific registry entries in a somewhat “obscure” location. I’m not convinced that’s the only way; there’s got to be a setting already within the registry we can check and/or modify to produce the expected results as I describe above.
@abbodi86 , and @GoneToPlaid , (or any other MVP’s) any thoughts on this concept? Use Group Policy, perhaps, for those of us who have Win 7 Pro and above?-
Mr. Natural
AskWoody Lounger
mbhelwig
AskWoody LoungerNovember 9, 2018 at 11:34 pm #231897Re KB 4462923 – October 2018 updates —
On 2018-11-03 I did a TRIAL INSTALL on my home computer — see #230112
There is something very wrong with this update —
I found that Windows media player was no longer my default video player so I set VLC player as default (should have done it long ago)
I find that Firefox Browser (my default) now seems to be having difficulties in accessing websites and flashing when moving from one website to another.
I suspected my Internet connection first but it checked out ok.
Today, after reading of further problems reported above, I decided to revert back to my previous image before installing KB 4462923 (Using Macrium Reflect image).
I did so, and all the odd behavioral things disappeared. I installed the Dot Net updates offered —
KB 4054530 and Reboot computer / KB 4457918, and KB 4459922 and Reboot computer.All is now smooth and functioning as it should.
My Computer is now updated to December 2017 (as are the other seven I am responsible for)
It has been a terrible year for Microsoft Updates !!!!!!!!!!
~~~~~~~~~~~~~~~~~~~~
Regarding Windows 10 — I was talking to an IT friend of mine this morning, here in Australia. He works in a company of over 7000 spread around the world. He parted with this piece of info —
They are no longer allowed to use Windows 7, and have all been upgraded to Windows 10 (He suspects that a deal has been done with Microsoft but is not sure who made the decision). When I asked how he deals with the updating problems, he said that when something goes wrong, then he has to have his computer re-imaged. he is running into problems already. I referred him to this site.
MS are just rolling out a broken OS to get the numbers on the board.
Incidentally, he uses an Apple at home!!!!!!!!!!!!!!!!!
~~~~~~~~~~~~
mbhelwig
cesmart4125
AskWoody LoungerNovember 10, 2018 at 2:53 am #231929Interestingly, MS downloaded both TLS 1.0 and Windows Essentials installer on my home computer November 8.
Is Windows Essentials the same as Microsoft Security Essentials? Has this downloaded on anyone else’s computer? Does it cause problems?
Thanks in advance for your help.
Charles
Dell Latitude D630: Windows 7 34 bit SP1, MS Office 2010 Pro SP 2. Intel Core 2 Duo T7100
-
The Surfing Pensioner
AskWoody PlusNovember 12, 2018 at 6:20 pm #232518Windows Essentials is obsolete and no longer supported: https://support.microsoft.com/en-us/help/18614/windows-essentials
Possibly M/S thought you might like a copy for its antiquarian interest to go with the outdated TLS 1.0? I wonder whether more Windows 7 users are going to be offered retro software?
1 user thanked author for this post.
-
geekdom
AskWoody_MVPNovember 13, 2018 at 5:17 am #232578Windows Essentials 2012 was a useful suite of five or six programs. Although support ended January 10, 2017, the software remains useful. It is unlike that you will be able to use the installer, as any installation now requires an offline installer.
Microsoft Security Essentials is an anti-virus program with a small footprint and remains robust.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender1 user thanked author for this post.
cesmart4125
AskWoody LoungerNovember 10, 2018 at 3:03 am #231930Addendum: Since installing kb4462923, I can no longer add attachments to my replies on AskWoody. (The current attachment was originally attached to the previous message.) kb 4462923 is now uninstalled, and I just reverted to an image saved with Macrium Reflect.
-
Microfix
AskWoody MVPNovember 10, 2018 at 5:51 am #231952I had an issue yesterday whereby I could not upload an attachment (59kb jpeg) but, THAT was using linux. Just tried it today, and it works fine…go figure?!
Windows - commercial by definition and now function...1 user thanked author for this post.
-
cesmart4125
AskWoody LoungerNovember 12, 2018 at 10:38 am #232409The continuing saga of kb4462923 continues to unfold. MS on its own decided to load several updates this morning. Windows Update also wants me to install kb4054518, the quality roll up from 12/2017, along with several updates from March and April of 2018.
All this while WU is set to “never check for updates.” Truly amazing!
-
anonymous
GuestNovember 12, 2018 at 2:24 pm #232452Was there a maintenance task performed? Or some other identifiable selfhealing process triggered? This could be automatic, by scheduled task, or manual request such as the System File Checker command. Do you run scripts to address certain concerns, that may have also done this as an associated task within the script?
I’m ready to be outraged by Microsoft overreach, but want to clarify first.
1 user thanked author for this post.
-
cesmart4125
AskWoody Lounger -
anonymous
GuestNovember 14, 2018 at 7:29 pm #233256That surprises me. The two occasions that I saw something similar were a result of uninstalling a cumulative rollup. This action removed all the parts of the rollup, including pieces from earlier patches. Subsequent checks for updates, when the removed rollup is hidden, would list for important installation those required parts removed by the uninstall. My thought was you may have done something similar in the course of maintenance.
I have not seen Windows Update offer repeats of earlier patches, except as described above. I was hoping to read others posting similar experiences by now. I am unable to explain your report, and hope to learn more.
1 user thanked author for this post.
-
-
-
anonymous
Guestglnz
AskWoody PlusNovember 11, 2018 at 6:50 am #232168Win 7 Pro 64-bit machine at home (SOHO). I installed the October updates at Defcon 4 (Group A).
In Internet Options – Advanced, I see that SSL 2.0 and 3.0 are UNchecked and that TLS 1.0, 1.1 and 1.2 are checked. There is no box for TLS 1.3.
I don’t remember whether or not I had UNchecked TLS 1.0 in the past. But it is checked now.
I don’t YET have an email client on this machine, but I will in the next few months
What should I do? (AFTER coffee please.)
Thanks.
anonymous
GuestNovember 11, 2018 at 9:26 am #232191Susan Bradley
ManagerNovember 11, 2018 at 11:29 am #232216https://support.microsoft.com/en-us/help/4462927
Has he tried installing KB4462927?
Addresses an issue that makes it impossible to disable TLS 1.0 and TLS 1.1 when the Federal Information Processing Standard (FIPS) mode is enabled.
I’m not seeing side effects in my Win7’s.
Susan Bradley Patch Lady/Prudent patcher
1 user thanked author for this post.
TheSuffering
AskWoody Lounger-
anonymous
GuestNovember 12, 2018 at 2:24 pm #232451Hi to you, TheSuffering. I am being presumptuous when I read you to mean that you follow GroupA directions when you choose to update. Other GroupA adherents did so after reading Woody’s blogpost or associated Computerworld article from November 2nd.
General questions about October updates could be asked and reviewed in that AskWoody blog comment section. For more specific help on the unique trouble of a neglected update, you may want to start a question topic here:
https://www.askwoody.com/forums/forum/askwoody-support/windows/windows-7/ask-windows-7-questions-here/
There is space below the list of topics to give a title and write the Original Post for a new Question Topic. This can help isolate a dialogue for your conditions and reduce confusion.A quick response here would be to recognize that the new MS-DEFCON 2 rating is in response to the expected troubles come Tuesday, November 13th. It is reasonable to follow the advice Woody gave in the Computerworld article and links he referenced there. Just do not accept any Windows Update offering published in November 2018. (Previews are already forbidden in GroupA standards)
MarkAtHome
AskWoody PlusNovember 11, 2018 at 11:52 am #232224I don’t use Outlook. But there is a security setting (option) in most mail programs to allow automatic download of external pictures/objects (or not). I wonder if the option was reset by one of the latest Outlook/Office updates. You might look through the options (probably security) and see if you can find the setting. Another approach would be to uninstall the Outlook updates one by one to see which caused the change, then reinstall all but the culprit.
Thanks to you and everyone else, but I tried all of the offered suggestions prior to posting here, with no success. It appears that unless I trip over a solution, I will have to live with it.
anonymous
GuestNovember 11, 2018 at 7:04 pm #232302I am running Windows 7 in Group B mode and I use Outlook.
From my “Network and Sharing Center” page I clicked on Internet Options and then Advanced.
From there I found “use TLS 1.0” ticked. I removed this tick and ticked 1.2 but not 1.1.
Am I good to go? And since I have experienced any problems.
Thanks
-
anonymous
Guest
JCCWsusser
AskWoody LoungerNovember 12, 2018 at 7:55 am #232376I am not seeing issues here, either, but we haven’t disabled TLS 1.0 completely.
Comparing patched & unpatched machines, I haven’t been able to find any setting changed by KB4462923, but client settings are controlled by group policy. I’d like to see more detail (ex. version of Outlook affected, whether KB3140245 is installed, any visible change, exact symptoms/messages etc.)
Two articles that seem relevant:
https://docs.nexcess.net/article/how-to-allow-outlook-to-connect-over-tls-1-1-1-2.html
The registry entries recommended in the second article already exist by default in our Win7/Office 2016 MSI machines, including fresh loads.
Viewing 16 reply threads - This topic has 43 replies, 19 voices, and was last updated 6 years, 6 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
My Simple Word 2010 Macro Is Not Working
by
mbennett555
9 hours, 8 minutes ago -
Office gets current release
by
Susan Bradley
13 hours, 52 minutes ago -
FBI: Still Using One of These Old Routers? It’s Vulnerable to Hackers
by
Alex5723
1 day, 6 hours ago -
Windows AI Local Only no NPU required!
by
RetiredGeek
14 hours, 55 minutes ago -
Stop the OneDrive defaults
by
CWBillow
1 day, 7 hours ago -
Windows 11 Insider Preview build 27868 released to Canary
by
joep517
1 day, 17 hours ago -
X Suspends Encrypted DMs
by
Alex5723
1 day, 19 hours ago -
WSJ : My Robot and Me AI generated movie
by
Alex5723
1 day, 19 hours ago -
Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
by
Alex5723
1 day, 20 hours ago -
OpenAI model sabotages shutdown code
by
Cybertooth
1 day, 20 hours ago -
Backup and access old e-mails after company e-mail address is terminated
by
M W Leijendekker
1 day, 9 hours ago -
Enabling Secureboot
by
ITguy
1 day, 16 hours ago -
Windows hosting exposes additional bugs
by
Susan Bradley
2 days, 4 hours ago -
No more rounded corners??
by
CWBillow
2 days ago -
Android 15 and IPV6
by
Win7and10
1 day, 14 hours ago -
KB5058405 might fail to install with recovery error 0xc0000098 in ACPI.sys
by
Susan Bradley
2 days, 17 hours ago -
T-Mobile’s T-Life App has a “Screen Recording Tool” Turned on
by
Alex5723
2 days, 19 hours ago -
Windows 11 Insider Preview Build 26100.4202 (24H2) released to Release Preview
by
joep517
2 days, 14 hours ago -
Windows Update orchestration platform to update all software
by
Alex5723
3 days, 3 hours ago -
May preview updates
by
Susan Bradley
2 days, 14 hours ago -
Microsoft releases KB5061977 Windows 11 24H2, Server 2025 emergency out of band
by
Alex5723
2 days, 6 hours ago -
Just got this pop-up page while browsing
by
Alex5723
2 days, 19 hours ago -
KB5058379 / KB 5061768 Failures
by
crown
2 days, 16 hours ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
1 day, 18 hours ago -
At last – installation of 24H2
by
Botswana12
3 days, 18 hours ago -
MS-DEFCON 4: As good as it gets
by
Susan Bradley
16 hours, 24 minutes ago -
RyTuneX optimize Windows 10/11 tool
by
Alex5723
4 days, 6 hours ago -
Can I just update from Win11 22H2 to 23H2?
by
Dave Easley
2 days, 5 hours ago -
Limited account permission error related to Windows Update
by
gtd12345
4 days, 20 hours ago -
Another test post
by
gtd12345
4 days, 20 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.