More of the usual. KB 4034670 – Preview of the non-security part of next month’s Win 7 Monthly Rollup KB 4034663 – Preview of the non-security part of
[See the full post at: The usual non-security update previews are out, along with three non-security patches for Server 2008]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
The usual non-security update previews are out, along with three non-security patches for Server 2008
Home » Forums » Newsletter and Homepage topics » The usual non-security update previews are out, along with three non-security patches for Server 2008
- This topic has 31 replies, 10 voices, and was last updated 7 years, 8 months ago.
Tags: KB 4034663 KB 4034670 KB 4035038
AuthorTopicwoody
ManagerAugust 15, 2017 at 4:17 pm #129564Viewing 12 reply threadsAuthorReplies-
abbodi86
AskWoody_MVP -
abbodi86
AskWoody_MVP
-
-
ky41083
AskWoody LoungerAugust 15, 2017 at 7:21 pm #129569Well, let’s start here… they have this list of issues to fix, some of which have been on this list since .NET 4.7 was first released.
https://support.microsoft.com/en-us/help/4015088/known-issues-in-the-net-framework-4-7
Most of those issues were recently fixed on Windows 10 1703 by a 1703 rollup. As .NET 4.7 is considered part of 1703, it gets patched by Windows only rollups, outside of and in addition to (I’m assuming) the usual .NET rollups. Annoyed yet?
Now, MS is trying to bring those fixes (if not more) to all the other supported platforms. To date, this list of known issues, and lack of reasonable fixes, is the reason I have not deployed .NET 4.7 yet.
My guess, they are trying to get the .NET releases right, so people finally start deploying .NET 4.7 in the enterprise…
1 user thanked author for this post.
-
abbodi86
AskWoody_MVPAugust 15, 2017 at 8:30 pm #129576FYI, since July 2017 Preview, 4.6/4.6.1/4.6.2/4.7 updates had been reconciled (Microsoft wording) into one rollup update for all of them, and it’s based on 4.7 version
so even if you don’t install 4.7, you still get its updates on top of your downlevel version starting 4.6
4.5.2 is still separate
-
ky41083
AskWoody LoungerAugust 15, 2017 at 8:54 pm #129577I don’t “think?” the .NET 4.7 bits apply if you are on an older .NET, say 4.6.2 for example. I know when I run ngen.exe it still outputs the version code for 4.6.2…
Then on machines where 1703 has been installed, I am seeing the newer version code for .NET 4.7 when executing ngen.exe.
Not sure if that means the 4.7 specific changes in the 4.7 tagged rollups sit and wait until 4.7 is installed, or, if those rollups would reappear in WU after a fresh 4.7 upgrade, to be reapplied… and probably won’t find out till the end of this month.
-
abbodi86
AskWoody_MVPAugust 15, 2017 at 9:38 pm #129586Well, i’m not saying this as analysis or opinion, it’s a fact
the rollup updates part of the installed Framework, not all of it, and the changes and installed 4.7 files will become active
for Windows 8.1 (CBS), installing 4.7 later will not need to reinstall the rollup
but for Windows 7 (MSI), the rollup needs reinstallation after 4.71 user thanked author for this post.
-
ky41083
AskWoody Lounger
-
-
-
-
MrBrian
AskWoody_MVPAugust 15, 2017 at 9:28 pm #129582Revision 101 of https://support.microsoft.com/en-us/help/894199/software-update-services-and-windows-server-update-services-changes-in doesn’t mention the .NET monthly preview rollups. Revision 99 that was current earlier today did mention the .NET monthly preview rollups.
-
MrBrian
AskWoody_MVPAugust 16, 2017 at 8:26 pm #129735The August 2017 .NET monthly preview rollups have reappeared at https://support.microsoft.com/en-us/help/894199/software-update-services-and-windows-server-update-services-changes-in.
1 user thanked author for this post.
-
-
anonymous
GuestAugust 15, 2017 at 9:32 pm #129578I would say that KB4019276 to add TLS 1.1 and 1.2 on Win 2008 SP2 is interesting.
It is not categorized as security by MS, nor is it a security patch in the usual sense. More like a feature add.
But I would say that this feature add once installed (and configured!) improves security for schannel dependent communications. Arguably to a great extent depending on what the services are.
-Jim1 user thanked author for this post.
-
anonymous
Guest -
anonymous
Guest -
PKCano
ManagerAugust 16, 2017 at 2:10 pm #129685The “Previews” are the pre-release of the Rollup.
For example, the “Preview” of the August 2017 Security Monthly Quality Rollup will contain the August Rollup + the non-security patches for September. In Sept, it will be combined with the security updates to make the September Rollup.Although it supposedly contains the finished next month’s non-security updates, it is really for testing for those who need to be sure it is “going to work.” So, unless you are in the testing mode, let someone else be the Guinea Pig.
It is usually a rule not to install unchecked updates anyway.
-
anonymous
GuestAugust 16, 2017 at 2:53 pm #129698
-
-
-
Geo
AskWoody Plus -
radosuaf
AskWoody LoungerAugust 17, 2017 at 2:05 am #129753No sign of block for Skylake in Windows 8.1 :). According to this one:
https://blogs.windows.com/windowsexperience/2016/01/15/windows-10-embracing-silicon-innovation/
they should be already starting to get us cut off :). Is anybody following the situation with Kaby Lake? Is the block present in the latest rollups?
Fractal Design Pop Air * Thermaltake Toughpower GF3 750W * ASUS TUF GAMING B560M-PLUS * Intel Core i9-11900K * 4 x 8 GB G.Skill Aegis DDR4 3600 MHz CL16 * ASRock RX 6800 XT Phantom Gaming 16GB OC * XPG GAMMIX S70 BLADE 1TB * SanDisk Ultra 3D 1TB * Samsung EVO 840 250GB * DVD RW Lite-ON iHAS 124 * Windows 10 Pro 22H2 64-bit Insider * Windows 11 Pro Beta Insider -
ky41083
AskWoody LoungerAugust 17, 2017 at 4:53 am #129760 -
MrBrian
AskWoody_MVPAugust 18, 2017 at 8:00 am #129850You could ask at https://github.com/zeffy/wufuc.
1 user thanked author for this post.
-
ky41083
AskWoody LoungerAugust 19, 2017 at 11:16 pm #130033Ick, hate reading decompiled code… especially hate reading assembly code, makes my head hurt.
Based on what’s there, it would appear to be a static list that needs updating for marking additional CPU’s as “unsupported”. Unless I missed it, the actual list isn’t in the posted Github code, being that the Github code is just overriding the result returned from the function that looks at the list, not the actual list itself.
Based on the way the evaluation is written, it defaults the CPU type to “supported”, and only changes it to “unsupported” if the function that references the list returns a hit from said list.
Basically, all CPU’s default to supported, until they are added to a blacklist check MS clearly went out of the way to add, as this whole “IsCpuSupported” function did not exist in the code until very recently.
Which we more or less already knew. It is nice to see the code though. And going forward, know that CPU’s will default to supported, until MS gets around to adding them to the blacklist, and updating the blacklist via Windows updates.
So, to finally answer my own question, lol… newer CPU’s MS deems “unsupported” will in fact work, until they are cut off by a future update.
My big *** here and now is, what about hypervisors that pass through the CPU ID, rather than emulate it, like VMware. This blacklist check means you HAVE to run the Github posted memory patch referenced above, especially in an enterprise environment, in order to test future updates on Win 7/8.1 VM’s, hosted on systems using any blacklisted CPU.
1 user thanked author for this post.
-
ch100
AskWoody_MVPAugust 20, 2017 at 2:20 am #130037what about hypervisors that pass through the CPU ID, rather than emulate it, like VMware.
As far as I know, none of the hypervisors emulate CPU or RAM resources. They are managed, scheduled, but not emulated.
-
ky41083
AskWoody LoungerAugust 20, 2017 at 2:33 am #130039That’s how I meant it, and it’s too late to edit above now…
I meant, that hypervisors like VMware, don’t emulate the CPU to the guest, they use passthrough instead, because it’s more efficient.
Hypervisors like QEMU, do emulate the CPU to the guest, at an increase in overhead.
Hence, old VM’s migrated to new hardware will be immediately effected by all this, on the more efficient hypervisors enterprises are using.
-
ch100
AskWoody_MVPAugust 20, 2017 at 3:45 am #130044Hypervisors like QEMU, do emulate the CPU to the guest, at an increase in overhead.
XenServer hypervisor which uses QEMU emulation for I/O (without XenServer Tools installed) does passthrough of the CPU resources and RAM.
I don’t know of any hypervisor emulating CPU.
Maybe KVM? -
ky41083
AskWoody LoungerAugust 20, 2017 at 4:03 am #130046From: https://en.wikipedia.org/wiki/QEMU
“QEMU is a hosted virtual machine monitor: it emulates CPUs through dynamic binary translation and provides a set of device models, enabling it to run a variety of unmodified guest operating systems.”
You have to mix QEMU with things like Xen or KVM to remove the CPU emulation overhead. For example, using only QEMU’s I/O emulation layer on top of Xen, as you cited. From same source:
“QEMU is involved only in the emulation of hardware; the execution of the guest is done within Xen and is totally hidden from QEMU.”
KVM definitely doesn’t do CPU emulation, and can interact similarly with QEMU like Xen does.
Basically, the CPU passthrough you are seeing on Xen, is the Xen layer, not the QEMU layer.
1 user thanked author for this post.
-
-
MrBrian
AskWoody_MVPAugust 20, 2017 at 6:22 am #130051
-
-
-
-
abbodi86
AskWoody_MVPAugust 18, 2017 at 3:06 pm #129916.NET 4.7 (involve 4.6.x) got OOB updates
https://support.microsoft.com/en-us/help/4038923/
https://support.microsoft.com/en-us/help/4038922/
https://support.microsoft.com/en-us/help/4038921/ -
PerthMike
AskWoody PlusAugust 23, 2017 at 11:54 pm #130451I would say that KB4019276 to add TLS 1.1 and 1.2 on Win 2008 SP2 is interesting. It is not categorized as security by MS, nor is it a security patch in the usual sense. More like a feature add. But I would say that this feature add once installed (and configured!) improves security for schannel dependent communications. Arguably to a great extent depending on what the services are. -Jim
Indeed, I find this VERY interesting, since it really does qualify as a security patch if you run any sort of web server (in our case, our OWA) on a 2008 non-R2 server. Suddenly adding TLS 1.2 support to an internet-facing web server is a bit security fix for us.
Looks like there’s already been reports that installing this patch breaks FTP functionality (somehow messes up the ftp protocol packets), but I can live with that.
No matter where you go, there you are.
-
anonymous
GuestAugust 24, 2017 at 7:57 pm #130551Anyone faces any issue on the patch KB4019276 for supporting TLS 1.2 client? We installed the patch in our Windows Server 2008 SP2, and even though the TLS 1.2 server works, but the client does not, meaning we cannot connect to our client’s web API successfully because the client’s web API only supports TLS 1.2 which are not supported by sChannel in Windows Server 2008 SP2.
Anyone is aware of whether Microsoft plans to come out with the updated cipher suites for TLS 1.2 for Windows Server 2008 SP2?
-
-
abbodi86
AskWoody_MVPAugust 31, 2017 at 11:59 am #131469It seems .NET is going to get new Rollups soon (tonight?), and they are Security ones
https://support.microsoft.com/en-us/help/4035038
Notice
Previously, the .NET Framework Preview of Quality Rollup (KB 4035038) was released as an optional update. The improvements that were delivered in the Preview of Quality Rollup are now available in a Security and Quality Rollup (KB 4039114) as a recommended update. No new improvements were added since the Preview of Quality Rollup was released.
-
woody
Manager -
abbodi86
AskWoody_MVPAugust 31, 2017 at 8:19 pm #131554Well, nothing out yet (too early KB revision?)
but it’s interesting to see that KB4035038 article description itself and all sub-articles changed from “August 2017 Preview Rollups” to “Security and Quality Rollups”
this only applies to Windows 8.1 articles, Windows 7 still have the old description
https://support.microsoft.com/en-us/help/4035036 -
ch100
AskWoody_MVP
-
-
-
Viewing 12 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Login screen icon
by
CWBillow
3 hours, 36 minutes ago -
AI coming to everything
by
Susan Bradley
3 minutes ago -
Mozilla : Pocket shuts down July 8, 2025, Fakespot shuts down on July 1, 2025
by
Alex5723
11 hours, 3 minutes ago -
No Screen TurnOff???
by
CWBillow
11 hours, 25 minutes ago -
Identify a dynamic range to then be used in another formula
by
BigDaddy07
11 hours, 58 minutes ago -
InfoStealer Malware Data Breach Exposed 184 Million Logins and Passwords
by
Alex5723
23 hours, 35 minutes ago -
How well does your browser block trackers?
by
n0ads
9 hours, 52 minutes ago -
You can’t handle me
by
Susan Bradley
2 hours, 20 minutes ago -
Chrome Can Now Change Your Weak Passwords for You
by
Alex5723
2 hours, 29 minutes ago -
Microsoft: Over 394,000 Windows PCs infected by Lumma malware, affects Chrome..
by
Alex5723
1 day, 10 hours ago -
Signal vs Microsoft’s Recall ; By Default, Signal Doesn’t Recall
by
Alex5723
14 hours, 27 minutes ago -
Internet Archive : This is where all of The Internet is stored
by
Alex5723
1 day, 11 hours ago -
iPhone 7 Plus and the iPhone 8 on Vantage list
by
Alex5723
1 day, 11 hours ago -
Lumma malware takedown
by
EyesOnWindows
23 hours, 42 minutes ago -
“kill switches” found in Chinese made power inverters
by
Alex5723
1 day, 20 hours ago -
Windows 11 – InControl vs pausing Windows updates
by
Kathy Stevens
1 day, 20 hours ago -
Meet Gemini in Chrome
by
Alex5723
2 days ago -
DuckDuckGo’s Duck.ai added GPT-4o mini
by
Alex5723
2 days ago -
Trump signs Take It Down Act
by
Alex5723
2 days, 8 hours ago -
Do you have a maintenance window?
by
Susan Bradley
13 hours, 1 minute ago -
Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms
by
Nibbled To Death By Ducks
1 day, 10 hours ago -
Cox Communications and Charter Communications to merge
by
not so anon
2 days, 11 hours ago -
Help with WD usb driver on Windows 11
by
Tex265
3 hours, 47 minutes ago -
hibernate activation
by
e_belmont
2 days, 20 hours ago -
Red Hat Enterprise Linux 10 with AI assistant
by
Alex5723
3 days ago -
Windows 11 Insider Preview build 26200.5603 released to DEV
by
joep517
3 days, 3 hours ago -
Windows 11 Insider Preview build 26120.4151 (24H2) released to BETA
by
joep517
3 days, 3 hours ago -
Fixing Windows 24H2 failed KB5058411 install
by
Alex5723
1 day, 23 hours ago -
Out of band for Windows 10
by
Susan Bradley
3 days, 8 hours ago -
Giving UniGetUi a test run.
by
RetiredGeek
3 days, 15 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.