An interesting PDF (link below) from Daniel Portenlanger: Microsoft’s new patching policies have introduced new challenges to keeping Windows endpoint
[See the full post at: White paper: How to use Trend Micro Vulnerability Protection to patch virtually]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
White paper: How to use Trend Micro Vulnerability Protection to patch virtually
Home » Forums » Newsletter and Homepage topics » White paper: How to use Trend Micro Vulnerability Protection to patch virtually
- This topic has 14 replies, 6 voices, and was last updated 5 years, 3 months ago by
anonymous.
AuthorTopicwoody
ManagerViewing 4 reply threadsAuthorReplies-
zero2dash
AskWoody LoungerYou would think with all the telemetry collected, and built-in Defender, that MS could do this themselves on the fly – yet they don’t.
Meanwhile you’ve got Linux distributions adopting LivePatching… Ubuntu has had it since 14.04 LTS which came out years ago. Security patching without requiring a reboot – who’d’a’thunk’it.
1 user thanked author for this post.
-
MrJimPhelps
AskWoody MVP -
b
ManagerIf you recall, AskWoody.com documented the zero day fix from Adobe, Microsoft and others was breaking some applications. The site also indicated that uninstalling the software patch resolved those issues. Of course, that then reintroduces the vulnerability. In a corporate environment, having a patch break applications critical to a business could be a disaster.
Applications critical to a business is a stretch in this example. It was a golf game.
Does Daniel Portenlanger work for Trend Micro?
$40 or $60 per user per year?
Windows 11 Pro version 22H2 build 22621.2361 + Microsoft 365 + Edge
-
dportenlanger
AskWoody LoungerWoody had commented on the topic of a virtual patch in a previous post. I am a contractor and have many customers with different security suites. One customer had a license for Vulnerability Protection that was included with their Enterprise Security Suite. I used the experience to write a simple document for our peers to understand the technology.
The document uses the flash player exploit as an example. If you recall, there was a flash player update that broke VMware. There was also a Windows patch that broke virtual network cards. It is my opinion that those patch issues caused business critical failures.
1 user thanked author for this post.
-
b
Manager
-
-
-
anonymous
GuestJim,
I’m delighted Trend Micro has improved their product.
About 16 years ago I installed it, and then my computer filled up with viruses. The S**s at Trend Micro wouldn’t refund my money. Later in the same year, either PCWorld or PCMag stated this company would do the rest of us a favor if they quit making this product.
If someone else is considering changing their antimalware protection, I suggest checking AV-test or AV-comparatives. The latter is affiliated with the Austrian government and an Austrian university. My choice is to use the paid version of Malwarebytes’ and the free version of AVAST. Every four years, I buy the paid version of AVAST, but don’t install it.
Here’s hoping everyone’s antimalware works well!
anonymous
Guest-
anonymous
Guest -
anonymous
Guest -
anonymous
GuestSearch “Windows Defender ATP” It looks like they rolled EMET’s functionality into a paid application. Seems to call it “Exploit Protection.” Base Windows Defender may do it too if you have Real-Time Protection enabled, but the marketing talk on MS’s site makes it sound like “no.” Can’t say since there’s nothing really configurable in Defender.
-
anonymous
GuestIt’s also already there in Windows 10 built-in Defender Security Center. Open up the Defender app and select “App & browser control” and scroll to the bottom. If you click on “exploit protection settings” there are 2 tabs, one for systems settings and one to allow you to fine-tune settings for individual programs.
-
anonymous
GuestFYI at least two programs I have encountered so far forget/reset the configured w10 exploit protection (WDEP, formerly EMET) when installed updated or repaired:
Office 2013,2016
Adobe Reader DCAlso Office 2016 still doesn’t even support Control Flow Guard (CFG) even though microsoft introduced it 2014.
microsoft: “We’ve introduced anti-exploit technology, you can enable for whichever program you want and feel good about it, but office will forget/overwrite it’s own WDEP settings on every install, update, or repair, also we didn’t bother to compile office with CFG.”
-
-
-
anonymous
Guest-
anonymous
GuestMitja Kolsek of 0patch here. Per Trend Micro, their virtual patching is agentless and “uses intrusion detection and prevention technologies to shield vulnerabilities before they can be exploited”, which is in line with my standard understanding of virtual patching. So they sit between your vulnerable code and the environment (mostly network or file system) and detect+block attempts at exploiting known vulnerabilities.
In contrast, 0patch comes with an agent that actually patches the vulnerable code in memory of running processes, so while a virtual patch (essentially a collection of detection and action rules) might be bypassable by mutating an exploit, with a micropatched code there is really nothing to bypass because the vulnerability is “physically” no longer there.
These two technologies are to some extent competitive (some vulnerabilities can be patched well with both), and to some extent complementary (one can imagine vulnerabilities that are better/faster fixed with virtual patching, and ones for which 0patch is a better solution).
Both technologies are trying to solve the “security update gap“, further exacerbated by the above-described monolithic security updates that make users choose between functionality and security.
4 users thanked author for this post.
Viewing 4 reply threads - This topic has 14 replies, 6 voices, and was last updated 5 years, 3 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Strange problem after upgrade from Win10Pro 22H2 to Win11Pro 22H2
by
JohnH
1 minute ago -
Return Full Context Menus to File Explorer
by
RetiredGeek
1 hour, 43 minutes ago -
Unusual Activity on Startup
by
Kenneth Stephens
5 hours, 34 minutes ago -
Windows Backup – incremental possible?
by
colin_thames
3 hours, 46 minutes ago -
New HD addition??
by
weendoggy
9 hours, 29 minutes ago -
Defcon 4 and Windows 11
by
cmar6
10 hours, 33 minutes ago -
Add-ins keep disappearing
by
hession
7 hours, 57 minutes ago -
MS-DEFCON 4: Is Windows 11 really a disaster?
by
Susan Bradley
42 minutes ago -
The Takahē is not extinct afterall
by
lylejk
19 hours, 22 minutes ago -
How to unbloc W10pro from moving to W11
by
hession
1 day, 9 hours ago -
Windows 11, Surface, and Windows Copilot
by
Will Fastie
12 hours, 20 minutes ago -
Why File Explorer keeps me on Windows
by
Josh Hendrickson
4 hours, 36 minutes ago -
Uninstalr — “World’s best cup of coffee”
by
Deanna McElveen
1 hour, 35 minutes ago -
Locked out of your refurbished computer?
by
Susan Bradley
1 hour, 18 minutes ago -
Thunderbird 115: Changing font size in the Message Panel
by
WCHS
1 day, 7 hours ago -
Lenovo ThinkPad not updating to Windows 11 22H2
by
Gordski
7 hours, 19 minutes ago -
Android Security
by
Magic66
1 day, 10 hours ago -
What happened to the manual?
by
Susan Bradley
1 day ago -
OK to Restore Files From a Possibly Hacked Computer?
by
kc27
1 day, 23 hours ago -
Startup loop after adding new user and installing File Explore Patch
by
PFC
3 days, 1 hour ago -
RoboCops comes to NYPD. You have the right to remain cyborg
by
Alex5723
3 days, 6 hours ago -
iOS 17 : New Safari Privat Search Engines
by
Alex5723
3 days, 7 hours ago -
Photos App running in background
by
Tom
2 days, 3 hours ago -
IPV6 Issue Win10 22H2 August Update
by
Win7and10
3 days, 5 hours ago -
Windows 11 Insider Preview build 23550 released to DEV
by
joep517
4 days, 5 hours ago -
Windows 11 Build 22621.2361 (22H2) released to Release Preview
by
joep517
4 days, 5 hours ago -
Lately I’ve been getting qr code spam attacks
by
Susan Bradley
4 days, 9 hours ago -
ghacks Wants Edge – FF Browser Update to View – hack/redirect
by
CraigS26
3 days, 7 hours ago -
iOS 17 : If your new iPhone gets stuck on the Apple logo when you transfer…
by
Alex5723
4 days, 17 hours ago -
Apple zero days out – September 2023
by
Susan Bradley
5 hours, 2 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.