Register Free Newsletter Plus Membership
  • Home
    • Newsletters/Alerts
    • Forums
    • About
    • MS-DEFCON System
    • Master Patch List
    • Register
    • Login
Microsoft Patch Defense Condition level 4 There are isolated problems with current patches, but they are well-known and documented on this site.
SIGN IN Not a member? REGISTER PLUS MEMBERSHIP
  • Patch Lady – after .NET I get this?

    Posted on March 15, 2020 at 15:37 CDT by Susan Bradley • Comment in the Forums

    So on both a Surface Go and a Lenovo laptop after the install of optional, not security .NET KB4537572  on Windows 10 1909 I got a “pop” of the screen that normally you get when setting up a new computer or after a feature update.

    All I had to do was to click on skip for now, but the first time I thought it was a fluke, the second time I went… hang on… this happened just a few days ago and I think on the same update.

    In case you see it too… just hit skip.

    Note I don’t think this happens if you just let updates occur, in this case I scanned for and “sucked down” updates because I was in one case seeing what updates would be offered up, and in the second case it was a Surface that had been offline for a bit.

    Borncity reports seeing it as well and points to a registry key to block it.

    Windows 10 Patch Lady Posts
  • Widespread reports of problems with the second March Win10 cumulative update, KB 4551762, the SMBv3 patch

    Posted on March 14, 2020 at 08:38 CDT by woody • Comment in the Forums

    I was afraid this would happen. When Microsoft releases two security patches back-to-back, it’s rare that the second patch goes in without problems.

    I’m seeing lots of reports with problems with Thursday’s post-Patch-Tuesday cumulative update, KB 4551762.

    Günter Born kicked off the discussion on Borncity with Windows 10: KB4551762 causes errors 0x800f0988 and 0x800f0900.

    Mayank Parmar at Windows Latest has more complaint reports — and they’re extensive:

    • The aforementioned errors on installation
    • Random reboots
    • Performance hits (which are always hard to verify)

    People who already have installation issues will be lucky enough to have Windows to automatically repair the patch is manually removed. Alternatively, some will have to undergo the recovery process and reinstall their Windows 10 copy if the PC remains slow and buggy.

    We’re also getting lots of reports about the new cumulative update zapping user profiles, just like the original Patch Tuesday patch and last month’s cumulative update.

    There are no in-the-wild exploits of the SMBv3 security hole, although there are many Proof of Concept demos. Kevin Beaumont has tried and failed to crack it in a meaningful way. We’ve had a couple of anonymous posts that point to other potential problems, but I haven’t seen any of them in the real world.

    Finally, @Alex5723 notes that MS has changed the Knowledge Base article associated with the patch, with a worthwhile inclusion:

    SMB Compression is not yet used by Windows or Windows Server, and disabling SMB Compression has no negative performance impact.

    Microsoft also inserted a clarification (for Dummies like me!) explaining why the Server Core versions are the ones affected.

    ‘Softie Nate Warfield tweeted:

    Full Server is not released as part of the Windows Semi-Annual Channel releases; only Server Core.

    As such, Full Server is not affected, only the listed Server Core editions.

    Which is what numerous people told me here on the forum. Thanks, all!

    We’re still at MS-DEFCON 2.

    Windows Patches/Security CVE-2020-0796, KB 4551762, March 2020 Black Tuesday
  • CVE-2020-0796, the SMBv3 security hole, doesn’t pose an immediate threat

    Posted on March 13, 2020 at 16:52 CDT by woody • Comment in the Forums

    I’ve been sitting on pins and needles wondering when an in-the-wild exploit for the just-patched SMBv3 security hole might appear.

    Looks like it’s much harder than many folks expected. Kevin Beaumont just posted this:

    We’re going to stay at MS-DEFCON 2 for the foreseeable future, particularly because we’re seeing many more reports of the disappearing icons/temporary profile bug.

    Windows Patches/Security CVE-2020-0796, KB 4551762, March 2020 Black Tuesday
  • A little bit of light reading for the weekend

    Posted on March 13, 2020 at 16:20 CDT by woody • Comment in the Forums

    I just got this in the mail — it was sent to a long-abandoned, spam laden account — and figured I would pass it along. A bit of nostalgia to cap off a very troubling week…. It’s so nice of YAHOO, AOL & WINDOWS LIVE, MSN to top up the coffers this day 0 March 2020.

    Other Yahoo Mail Lottery
  • Heads up: Microsoft posts a fix for that SMBv3 security hole. Get ready to install this month’s Windows patches.

    Posted on March 12, 2020 at 10:57 CDT by woody • Comment in the Forums

    Microsoft just released the patch that it almost released on Tuesday. It’s the SMBv3 patch that’s set the security community on fire.

    KB 4551762, which fixes CVE-2020-0796 is a regular, old-fashioned Win10 cumulative update, but it’s only made for Win10 1903, 1909, Server  1903 Core and Server 1909 Core. (I still have no idea why only Server Core versions are affected.)

    Anyway, I’m going to keep my eyes open for any obvious problems and, if the coast looks reasonably clear, we may be moving to MS-DEFCON 3 or 4 pretty quickly.

    For now, hold off. There are no known exploits. But be ready to twitch that clicking finger.

    Will keep you posted.

    UPDATE: 24 hours later, I still haven’t seen an in-the-wild exploit. But there are many reports of a repeat of the “missing icon”/temporary profile bug associated with KB 4551762.

    Kevin Beaumont tweeted:

    For anybody pondering, I’ve tried various exploits for CVE-2020-0796 – with a default config and vulnerable Windows 10 install, Windows Defender detects the exploit attempt. If you have automatic updates enabled you will also have the patch already.

    It’s a significant security hole, but it doesn’t appear to be an imminent threat.

    Mayank Parmar has a recounting of the bugs in Windows Latest.

    Still watching.

    Windows Patches/Security CVE-2020-0796, KB 4551762, March 2020 Black Tuesday
  • Patch Lady – we have an out of band on that SMBv3

    Posted on March 12, 2020 at 10:48 CDT by Susan Bradley • Comment in the Forums

    https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796

    https://support.microsoft.com/en-us/help/4551762/windows-10-update-kb4551762

     

    At this time I”m not seeing active attacks and NO ONE should be STUPID enough to have port 445 a SMB file sharing port open to the web.  So I’m still in don’t panic, don’t install and let’s test mode.

    Windows Security CVE-2020-0796, KB 4541762
  • Patch Tuesday update: Disappearing SMBv3 patch, non-security Office patches, and a so-far-mild Patch Tuesday

    Posted on March 11, 2020 at 10:57 CDT by woody • Comment in the Forums

    Things look pretty stable at this point, although I’m seeing a disturbing number of Error  0x800f0900 on installs.

    If any of the old problems poked through into this round of updates, I haven’t seen any loud scream of pain about them. But the day is yet young.

    Admins, you have a tough day ahead, if you’re using SMBv3.

    Details in Computerworld Woody on Windows.

    Windows Patches/Security March 2020 Black Tuesday, SMBv3
  • It looks like the announced-but-not-fixed CVE-2020-0796 “CoronaBlue” vuln is only for Server 1903 and 1909

    Posted on March 11, 2020 at 08:21 CDT by woody • Comment in the Forums

    I’ll have more details about this shortly, but many of you admins are rightly concerned about the CVE-2020-0796 security hole, which was announced, then not announced, then announced again in Microsoft ADV200005 | Microsoft Guidance for Disabling SMBv3 Compression.

    Long story short, it looks like MS was poised to release a patch yesterday, then decided at the last minute to cancel the patch — but somehow word of the cancellation didn’t make it to at least two organizations that published details about it.

    It looks like the security hole only affects Win10 1903, 1909, Server 1903 and 1909. Per Florian Roth:

    There’s a lot of information available about the hole and countermeasures from Satnam Narang on Tenable, from Sergiu Gatlan at BleepingComputer, Catalin Cimpanu at ZDNet and, in the past couple of hours, Dan Goodin at Ars Technica. Those of you running networks with SMBv3 should take a look.

    If you’re running a network on Win7 or Server 2008 R2, you’re good. SMBv3 didn’t even exist back then. 🙂

    And if you aren’t in charge of a network, sit back and smile. You have other things to worry about.

    UPDATE: Catalin Cimpanu now says:

    I have now seen/talked to 3 different people claiming they found the bug in less than 5 minutes. I won’t be surprised if exploits pop up online by the end of the day.

    Windows Patches/Security CVE-2020-0796, SMBv3
  • Which patches were pulled?

    Posted on March 11, 2020 at 07:23 CDT by woody • Comment in the Forums

    Last night, the Microsoft Update Catalog listed 113 patches for “2020-03.”

    This morning, the count’s down to 110.

    Anybody know what happened to the three disappearing patches?

    Windows Patches/Security March 2020 Black Tuesday
  • Initial impressions of Patch Tuesday, March 2020

    Posted on March 10, 2020 at 12:15 CDT by woody • Comment in the Forums

    We have 113 new patches in the Microsoft Update Catalog.

    There’s a new Servicing Stack Update for Win10 version 1903 and 1909, KB 4541338. There’s also a new one for Win10 1809 and 1803, and for Win8.1.

    Dustin Childs’s report is up on the ZDI site:

    • 115 separately identified security holes (CVEs)
    • None of them are “Publicly known” or “Exploited.”

    CVE-2020-0852 is his top pick for a notable security hole. It’s a bug in Word that can be triggered if you preview a Word document in Outlook. The offered patches are for Office 2019 Click-to-Run, Mac Office 2016, Office Online Server, and Sharepoint Server 2019. Microsoft categorizes it as “Exploitation less likely.”

    Martin Brinkmann has his usual detailed, thorough analysis of the patches on ghacks.net.

    Microsoft hasn’t acknowledged the bugs in the “optional, non-security, C/D Week” patch for Win10 1903 and 1909, released late last month. No idea if this latest drop fixes any of the multitude of problems with KB 4535996. There’s also no mention I can find of the disappearing icon/temporary profile bug that’s been with us for the past month. But there is a humongous list of fixes to 1903 and 1909.

    Notably, the change lists for both Win10 1903 and 1909 are the same.

    No indication that Win10 version 2004 will ship today. I was half-way expecting it.

    UPDATE: Two hours later and I’m not seeing any major cries of pain. Stay tuned.

    Windows Patches/Security CVE-2020-0852, KB 4535996, KB 4541338, March 2020 Black Tuesday
  • Fresh reports of HP PC shortages

    Posted on March 9, 2020 at 15:28 CDT by woody • Comment in the Forums

    Just got a message from a reader:

    I wanted to report to you something that may pique your interest. I was tasked with ordering computers (HP) and I am finding out due to the Coronavirus coupled with Intel chip shortages that [it’s difficult to find HP] computers… to replace old Windows 7/Vista, yes Vista, machines.

    I did a search on many sites and stock is low and even Amazon and Google are struggling to find pcs that would fit the needs (I’m aiming at 16gb of ram, I5 processors at minimum).

    Are you encountering any problems getting new computers? There have been reports and rumors of chip shortages cascading into PC shortages, but I haven’t seen anything specifically about i5-level processors with 16 GB of RAM.

    Hardware HP shortages
  • Free tax prep?

    Posted on March 9, 2020 at 14:52 CDT by Susan Bradley • Comment in the Forums

    (USA centric post)

    The other day on the news I heard a story about free tax prep for those who earn under $69,000.

    Sounds great right?

    Well…but… when you look at the IRS web site and the offerings that they have from the various vendors, ALL of them have gotchas.

    Some age discriminate.  (yea, don’t you LOVE that!!)

    Most don’t offer free state tax filing…. or most don’t offer a free tax prep IF you live in a state that has no state tax.  Thus you’ll get a charge for filing your state return.

    Bottom line, like many things my Mom taught me, you get what you pay for and it’s not always free.

    Freeware Patch Lady Posts
  • « Older Entries
    Newer Entries »
DON'T MISS OUT!
Subscribe to the Free Newsletter
We promise not to spam you. Unsubscribe at any time.
Invalid email address
Thanks for subscribing!

Register
Lost your password?

Plus Membership

Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.

AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.


Get Plus!

Welcome to our unique respite from the madness.

It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.

Search Newsletters

Search Forums

Advanced Search

View the Forum

  • Recent Replies
  • My Replies
  • My Active Topics
  • New Posts in the Last day
  • Private Messages
  • Knowledge Base
  • How to use the Forums
  • All Forums
  • Search for Topics

    • Most popular topics
    • Topics with no replies
    • Recently active topics
    • New posts: Last day
    • New posts: Last three days
    • New posts: Last week
    • New posts: Last month
    • Topics with most replies
    • Latest topics

    Recent Topics

    • Firefox Red Panda Fun Stuff by Lars220
      3 hours, 7 minutes ago
    • How start headers and page numbers on page 3? by Davidhs
      6 hours, 40 minutes ago
    • Attack on LexisNexis Risk Solutions exposes data on 300k + by Nibbled To Death By Ducks
      1 hour, 15 minutes ago
    • Windows 11 Insider Preview build 26200.5622 released to DEV by joep517
      15 hours, 21 minutes ago
    • Windows 11 Insider Preview build 26120.4230 (24H2) released to BETA by joep517
      15 hours, 22 minutes ago
    • MS Excel 2019 Now Prompts to Back Up With OneDrive by lmacri
      5 hours, 4 minutes ago
    • Firefox 139 by Charlie
      17 hours, 45 minutes ago
    • Who knows what? by Will Fastie
      10 hours, 27 minutes ago
    • My top ten underappreciated features in Office by Peter Deegan
      16 hours, 6 minutes ago
    • WAU Manager — It’s your computer, you are in charge! by Deanna McElveen
      10 hours, 29 minutes ago
    • Misbehaving devices by Susan Bradley
      18 hours, 14 minutes ago
    • .NET 8.0 Desktop Runtime (v8.0.16) – Windows x86 Installer by WSmeyerbos
      1 day, 22 hours ago
    • Neowin poll : What do you plan to do on Windows 10 EOS by Alex5723
      27 minutes ago
    • May 31, 2025—KB5062170 (OS Builds 22621.5415 and 22631.5415 Out-of-band by Alex5723
      1 day, 20 hours ago
    • Discover the Best AI Tools for Everything by Alex5723
      19 hours, 48 minutes ago
    • Edge Seems To Be Gaining Weight by bbearren
      1 day, 10 hours ago
    • Rufus is available from the MSFT Store by PL1
      1 day, 18 hours ago
    • Microsoft : Ending USB-C® Port Confusion by Alex5723
      2 days, 21 hours ago
    • KB5061768 update for Intel vPro processor by drmark
      21 hours, 35 minutes ago
    • Outlook 365 classic has exhausted all shared resources by drmark
      20 hours, 18 minutes ago
    • My Simple Word 2010 Macro Is Not Working by mbennett555
      2 days, 17 hours ago
    • Office gets current release by Susan Bradley
      2 days, 20 hours ago
    • FBI: Still Using One of These Old Routers? It’s Vulnerable to Hackers by Alex5723
      4 days, 10 hours ago
    • Windows AI Local Only no NPU required! by RetiredGeek
      3 days, 18 hours ago
    • Stop the OneDrive defaults by CWBillow
      4 days, 11 hours ago
    • Windows 11 Insider Preview build 27868 released to Canary by joep517
      4 days, 20 hours ago
    • X Suspends Encrypted DMs by Alex5723
      4 days, 23 hours ago
    • WSJ : My Robot and Me AI generated movie by Alex5723
      4 days, 23 hours ago
    • Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor by Alex5723
      5 days ago
    • OpenAI model sabotages shutdown code by Cybertooth
      5 days ago

    Recent blog posts

    • Who knows what?
    • My top ten underappreciated features in Office
    • WAU Manager — It’s your computer, you are in charge!
    • Misbehaving devices
    • Office gets current release
    • Windows hosting exposes additional bugs
    • May preview updates
    • MS-DEFCON 4: As good as it gets

    My Profile

    Login and Registration

    • Log In
    • Register

    Key Links

    • > Computerworld's The Microsoft Patch Lady
    • > Computerworld's Woody on Windows
    • AskWoody Knowledge Base index
    • BlockaPatch tools
    • Gift subscription for Ask Woody Newsletter
    • Microsoft Answers Forum
    • Tasks for the Weekend YouTube Channel
    June 2025
    S M T W T F S
    1234567
    891011121314
    15161718192021
    22232425262728
    2930  
    « May    

    Remembering Woody

     

    Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.

    Mastodon profile for DefConPatch
    Mastodon profile for AskWoody

     

    Home • About • FAQ • Posts & Privacy • Forums • My Account
    Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts

    Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.