Patch fixlets updated with no release note

The following fixlets are showing a modification time of Mon, 18 Oct 2021 22:18:42 +0100 but I can find no release note to cover the change:

"MS16-019: Security Update for .NET Framework to Address Denial of Service - Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6/4.6.1 - KB3127233"
“MS16-019: Security Update for .NET Framework to Address Denial of Service - Windows Server 2008 R2 SP1 / Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6/4.6.1 - KB3127233 (x64)”
"MS16-041: Security Update for .NET Framework - Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6/4.6.1 - KB3143693"
“MS16-041: Security Update for .NET Framework - Windows Server 2008 R2 SP1 / Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6/4.6.1 - KB3143693 (x64)”

That is two KB numbers, 32- & 64-bit variants of each.

@bma @anjumyaseen - could you investigate please?

Hi @trn,
Not sure about the announcement part.
I couldn’t find anything either. However, I did ping the Patch team about this. For the fixlets listed, the existing patch urls in the actions were no longer available from Microsoft so they’ve been updated with new links to the patch binaries.

Hi @bma
Thanks for investigating

Another clutch for me to investigate this morning, all with modification time of Tue, 19 Oct 2021 23:42:53 +0100:

MS15-101: Vulnerabilities in .NET Framework Could Allow Elevation of Privilege - Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6 - KB3074233
MS15-101: Vulnerabilities in .NET Framework Could Allow Elevation of Privilege - Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6 - KB3074554
MS15-101: Vulnerabilities in .NET Framework Could Allow Elevation of Privilege - Windows Server 2008 R2 SP1 / Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6 - KB3074233 (x64)
MS15-101: Vulnerabilities in .NET Framework Could Allow Elevation of Privilege - Windows Server 2008 R2 SP1 / Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6 - KB3074554 (x64)
MS15-118: Security Update for .NET Framework to Address Elevation of Privilege - Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6 - KB3098001
MS15-118: Security Update for .NET Framework to Address Elevation of Privilege - Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6 - KB3098786
MS15-118: Security Update for .NET Framework to Address Elevation of Privilege - Windows Server 2008 R2 SP1 / Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6 - KB3098001 (x64)
MS15-118: Security Update for .NET Framework to Address Elevation of Privilege - Windows Server 2008 R2 SP1 / Windows 7 SP1 / Windows Server 2008 SP2 / Windows Vista SP2 - .NET Framework 4.6 - KB3098786 (x64)

To clarify, we have these old patches in ‘policy’ baselines that have long running actions. Each of these updates requires the baseline to be updated (and the reasons recorded) and the actions stopped and restarted. We don’t have any current clients that are applicable to these fixlets, but we do have these defensive actions running.

@trn,

MS is changing the patch binaries for these old updates and we are very frequently updating the fixlets.
Since these were very old KB’s and the changes happen frequently we were trying to avoid the noise/confusions around customers by not posting them in the forum announcement.

We will send out an BES Announcements for these changes going forward.

1 Like