An interesting PDF (link below) from Daniel Portenlanger: Microsoft’s new patching policies have introduced new challenges to keeping Windows endpoint
[See the full post at: White paper: How to use Trend Micro Vulnerability Protection to patch virtually]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
White paper: How to use Trend Micro Vulnerability Protection to patch virtually
Home » Forums » Newsletter and Homepage topics » White paper: How to use Trend Micro Vulnerability Protection to patch virtually
- This topic has 14 replies, 6 voices, and was last updated 6 years, 11 months ago by
anonymous.
AuthorTopicViewing 4 reply threadsAuthorReplies-
zero2dash
AskWoody LoungerJune 14, 2018 at 10:24 am #197806You would think with all the telemetry collected, and built-in Defender, that MS could do this themselves on the fly – yet they don’t.
Meanwhile you’ve got Linux distributions adopting LivePatching… Ubuntu has had it since 14.04 LTS which came out years ago. Security patching without requiring a reboot – who’d’a’thunk’it.
1 user thanked author for this post.
-
MrJimPhelps
AskWoody MVPJune 14, 2018 at 10:48 am #197815I use Trend Micro for my Windows machines and my Android and iOS devices. I am very pleased with Trend Micro. Their software is very non-intrusive and highly-rated. And it is extremely simple to opt out of auto-renewal.
Group "L" (Linux Mint)
with Windows 10 running in a remote session on my file server -
b
AskWoody_MVPJune 14, 2018 at 3:44 pm #197882If you recall, AskWoody.com documented the zero day fix from Adobe, Microsoft and others was breaking some applications. The site also indicated that uninstalling the software patch resolved those issues. Of course, that then reintroduces the vulnerability. In a corporate environment, having a patch break applications critical to a business could be a disaster.
Applications critical to a business is a stretch in this example. It was a golf game.
Does Daniel Portenlanger work for Trend Micro?
$40 or $60 per user per year?
-
dportenlanger
AskWoody LoungerJune 14, 2018 at 4:08 pm #197895Woody had commented on the topic of a virtual patch in a previous post. I am a contractor and have many customers with different security suites. One customer had a license for Vulnerability Protection that was included with their Enterprise Security Suite. I used the experience to write a simple document for our peers to understand the technology.
The document uses the flash player exploit as an example. If you recall, there was a flash player update that broke VMware. There was also a Windows patch that broke virtual network cards. It is my opinion that those patch issues caused business critical failures.
1 user thanked author for this post.
-
b
AskWoody_MVP
-
-
anonymous
GuestJune 18, 2018 at 5:40 am #198508Jim,
I’m delighted Trend Micro has improved their product.
About 16 years ago I installed it, and then my computer filled up with viruses. The S**s at Trend Micro wouldn’t refund my money. Later in the same year, either PCWorld or PCMag stated this company would do the rest of us a favor if they quit making this product.
If someone else is considering changing their antimalware protection, I suggest checking AV-test or AV-comparatives. The latter is affiliated with the Austrian government and an Austrian university. My choice is to use the paid version of Malwarebytes’ and the free version of AVAST. Every four years, I buy the paid version of AVAST, but don’t install it.
Here’s hoping everyone’s antimalware works well!
-
-
anonymous
Guest -
anonymous
Guest -
anonymous
Guest -
anonymous
GuestJune 15, 2018 at 10:54 am #198047Search “Windows Defender ATP” It looks like they rolled EMET’s functionality into a paid application. Seems to call it “Exploit Protection.” Base Windows Defender may do it too if you have Real-Time Protection enabled, but the marketing talk on MS’s site makes it sound like “no.” Can’t say since there’s nothing really configurable in Defender.
-
anonymous
GuestJune 15, 2018 at 2:45 pm #198096It’s also already there in Windows 10 built-in Defender Security Center. Open up the Defender app and select “App & browser control” and scroll to the bottom. If you click on “exploit protection settings” there are 2 tabs, one for systems settings and one to allow you to fine-tune settings for individual programs.
-
anonymous
GuestJune 17, 2018 at 12:07 pm #198427FYI at least two programs I have encountered so far forget/reset the configured w10 exploit protection (WDEP, formerly EMET) when installed updated or repaired:
Office 2013,2016
Adobe Reader DCAlso Office 2016 still doesn’t even support Control Flow Guard (CFG) even though microsoft introduced it 2014.
microsoft: “We’ve introduced anti-exploit technology, you can enable for whichever program you want and feel good about it, but office will forget/overwrite it’s own WDEP settings on every install, update, or repair, also we didn’t bother to compile office with CFG.”
-
-
-
-
-
anonymous
Guest -
anonymous
GuestJune 19, 2018 at 5:27 am #198656Mitja Kolsek of 0patch here. Per Trend Micro, their virtual patching is agentless and “uses intrusion detection and prevention technologies to shield vulnerabilities before they can be exploited”, which is in line with my standard understanding of virtual patching. So they sit between your vulnerable code and the environment (mostly network or file system) and detect+block attempts at exploiting known vulnerabilities.
In contrast, 0patch comes with an agent that actually patches the vulnerable code in memory of running processes, so while a virtual patch (essentially a collection of detection and action rules) might be bypassable by mutating an exploit, with a micropatched code there is really nothing to bypass because the vulnerability is “physically” no longer there.
These two technologies are to some extent competitive (some vulnerabilities can be patched well with both), and to some extent complementary (one can imagine vulnerabilities that are better/faster fixed with virtual patching, and ones for which 0patch is a better solution).
Both technologies are trying to solve the “security update gap“, further exacerbated by the above-described monolithic security updates that make users choose between functionality and security.
4 users thanked author for this post.
-
Viewing 4 reply threads - This topic has 14 replies, 6 voices, and was last updated 6 years, 11 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
184 MILLION Passwords on FBook, Google, MS & Netflix hacked/leaked
by
ClearThunder
4 minutes ago -
T-Mobile’s T-Life App has a “Screen Recording Tool” Turned on
by
Alex5723
19 minutes ago -
Windows 11 Insider Preview Build 26100.4202 (24H2) released to Release Preview
by
joep517
3 hours, 5 minutes ago -
Windows Update orchestration platform to update all software
by
Alex5723
7 hours, 38 minutes ago -
May preview updates
by
Susan Bradley
9 hours, 16 minutes ago -
Microsoft releases KB5061977 Windows 11 24H2, Server 2025 emergency out of band
by
Alex5723
9 hours, 23 minutes ago -
Just got this pop-up page while browsing
by
Alex5723
7 hours, 19 minutes ago -
KB5058379 / KB 5061768 Failures
by
crown
1 hour, 16 minutes ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
49 minutes ago -
At last – installation of 24H2
by
Botswana12
23 hours, 10 minutes ago -
MS-DEFCON 4: As good as it gets
by
Susan Bradley
4 hours, 1 minute ago -
RyTuneX optimize Windows 10/11 tool
by
Alex5723
1 day, 11 hours ago -
Can I just update from Win11 22H2 to 23H2?
by
Dave Easley
1 day, 4 hours ago -
Limited account permission error related to Windows Update
by
gtd12345
2 days ago -
Another test post
by
gtd12345
2 days ago -
Connect to someone else computer
by
wadeer
1 day, 19 hours ago -
Limit on User names?
by
CWBillow
1 day, 22 hours ago -
Choose the right apps for traveling
by
Peter Deegan
1 day, 12 hours ago -
BitLocker rears its head
by
Susan Bradley
20 hours, 22 minutes ago -
Who are you? (2025 edition)
by
Will Fastie
19 hours, 19 minutes ago -
AskWoody at the computer museum, round two
by
Will Fastie
1 day, 14 hours ago -
A smarter, simpler Firefox address bar
by
Alex5723
2 days, 11 hours ago -
Woody
by
Scott
2 days, 20 hours ago -
24H2 has suppressed my favoured spider
by
Davidhs
19 hours, 59 minutes ago -
GeForce RTX 5060 in certain motherboards could experience blank screens
by
Alex5723
3 days, 10 hours ago -
MS Office 365 Home on MAC
by
MickIver
3 days, 4 hours ago -
Google’s Veo3 video generator. Before you ask: yes, everything is AI here
by
Alex5723
4 days ago -
Flash Drive Eject Error for Still In Use
by
J9438
19 hours, 44 minutes ago -
Windows 11 Insider Preview build 27863 released to Canary
by
joep517
4 days, 19 hours ago -
Windows 11 Insider Preview build 26120.4161 (24H2) released to BETA
by
joep517
4 days, 19 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.