Installation BESClient 11.0.6.137 fails because of error 1920 or 1923

I have on several Windows 11 PC and virtual Windows Server 2019 and 2022 a big problem that the upgrade from 11.0.5 fails with error 1920 and on the BES Server with Error 1923.

The service can't be started by the installer nor manual. It happens on 8 out of 20 PC's / VM's.

Uninstall, clean some registry entries, reboot install like mentioned in HCL KB0077557 helps nothing.

Can't find any solution to resolve the problem, only going back to 11.0.5 "helps".

Error 1920 during installation indicates a service failed to start, usually due to insufficient permissions, locked files, or conflicting security software.

Maybe some Antivirus is interfering with the upgrade?

What if, from installed apps you uninstall the BigFix Client (this way the folders and settings stay untouched and your client won’t be reset) and then use the installer?

Is the client service set to run as Local System?

Thank you

No Antivirus except default M$ stuff.

I did try several installers

The upgrade from 11.0.5.204 to 11.0.6.137 failed because 1920 service could not start.

Uninstall 11.0.6.137 and install 11.0.4.60 ok, service is starting.

Upgrade from 11.0.4.60 to 11.0.6.137 failed because 1920 service could not start.

Uninstall 11.0.6.137 and install 11.0.5.204 ok, service is starting.

Client is set to run as Local System

Open a support ticket and provide upgrade log.

Did you get a solution for this?

We are seeing the same case in our deployment.

I did an upgrade last week in our Dev/QA instance from v11.0.3.

I upgraded the client on 25 virtual servers, mostly Windows 2019+ but also some 2016 and some Nix. It went 100% fine, no issues.

I just discovered that the culprit is the 0patch agent, no solution at the moment.

Did you stop the 0patch agent and verify that BigFix 11.0.6 agent started?

We don’t use 0patch on our environment but we use other tools. What this something that you found in a log or something else?

0patch has to be uninstalled, only then BesClient 11.0.6.137 is starting

No, I did not spend time anymore on this because life is too short… and I spent too much already.

My case CS1443710 at HCL is closed and from 0patch I did not get any respond. But I think it’s a problem with besclient 11.0.6.137 because 11.0.5.xx works fine, as all other versions in the past years.

0patch support just answered, let's see what they will discover. I’m pretty sure the problem is on the BesClient side.

From 0patch Support, thank you

Thank you, we were able to reproduce the issue: after installing the client, the BES Client service (11.0.6) would crash reliably when started when 0patchLoader.DLL was injected in it, and not crash when our DLL was not injected. The crash seems to be caused by stack overflow, i.e., stack running out due to some loop being executed in ntdll.dll causing all stack memory to be consumed. We don't know why this is happening and certainly doesn't look similar to any other compatibility/crash cases we've had before.

We also confirmed that BES Agent 11.0.5 does not have this issue. It would be very hard for us to discover what they changed in the last version to make it sensitive to 0patch DLL being present in the process.

The only reasonable course of action seems to be to exclude BESClient.exe from injection; we have added this information to our Help Center article so that other users will be able to search for it: https://support.0patch.com/hc/en-us/articles/29653873240082-Performance-impact-or-functional-problems-with-various-applications

Would you be so kind as to let the BigFix support know about this article so they can also refer users to it should any others reach out to them with the same issue?

3 Likes

BigFix strongly recommends to exclude its executables and folders from AV scanning/interactions: AV Exclusions on Windows

Thank you for this link, I just want to say that there was never a problem with besclient and 0patch in the last 6 years until besclient 11.0.6.137 was introduced.

That is exactly the same that I reported to the HCL BigFix support engineer who I am working with on this issue. We have been running BigFix for years and this is the first time we are seeing this issue.

Well, taking a procdump might shed some light… in any case, it’s well known dll injection can cause problem in the BigFix Agent.

Same issue here after upgrading to 11.0.6. BESClient fails to start after patching. Sometimes takes 12 times of restarting the service in order to get it to start. We were told the AV is the problem as well even though it’s set not to block anything and we don’t see anything being blocked in the logs. I believe the issue is with the upgrade since we didn’t notice this issues prior to the upgrade. We will be downgrading our agents for patching tonight to see if the issue persists.

Hey. Did you get anywhere with this? Thanks.

Not yet, I have a support case open with HCL BigFix. They are claiming it is our AV software but there have been no changes to the AV tool and this only happens with BigFix 11.0.6. Older versions work totally fine.