Re: Patch confusion

From: David Wang [Msft] (someone_at_online.microsoft.com)
Date: 03/22/04


Date: Mon, 22 Mar 2004 04:12:14 -0800

Service Packs are cumulative. How patches roughly work is this:
- Service Pack are rollup of everything released prior to it.
- QFE are point-fixes for certain issues and may add/remove
functionality/fixes of other QFE since the last Service Pack on rare
occassions
- Security Rollup is a like a mini Service Pack of just the security-related
fixes, all integrated (addresses the QFE rare issues)

The reason it is complicated is because customers are complicated. Some
customers want point-fixes for issues and infrequent Service Pack rollups.
Others only want cumulative security fixes augmented by infrequent Service
Pack rollups. Still others just want to have the latest all the time, and
others want very infrequent Service Pack releases. To make as many people
happy, patches are what you see, and nothing is compulsory.

For people who don't want to manage all this, Windows Update should handle
it all. On clean OS installs, I usually go to Windows Update and pick up
the latest Service Pack first. Then, I start selecting all security rollups
and install them, and then individual security patches in chronological
order. Last, I go over all the non-mandatory updates to see if I want any of
them.

As for securing an IIS box -- patches are only part of the story. You are
still responsible for configuring your server securely, balanced against
usability and functionality. Security patches are merely fixes made by
Microsoft to close unexpected issues and assumes you have secured your
server (i.e. patches do not secure your server ; patches mitigate particular
vulnerabilities and says nothing about your server's security).

-- 
//David
IIS
This posting is provided "AS IS" with no warranties, and confers no rights.
//
"Jay" <contij@jbb.com> wrote in message
news:2E816EA7-F87C-4FFA-B891-9EE86F00712B@microsoft.com...
Just installed Win2k server with IIS 5.0, ran windows update, OS is now at
service pack 4.
I've downloaded several of the IIS 5.0 patches posted in technet, all seem
to req. service pack 2. Does this mean the service pack 4 I'm on now has all
the necessary security patches in place. Is there anything else I need to do
to secure this IIS box ? Many thanks.


Relevant Pages

  • Huge results discrepency between Windows Update & Update Catalog?
    ... To download post XP Service Pack 2 updates and security ... order to get that web site to work properly. ... web site and it found a whole bunch of security updates (around 23 MB ... any of the security type of patches that the "Microsoft Update" site ...
    (microsoft.public.windowsupdate)
  • [Full-Disclosure] RE: new internet explorer exploit (was new worm)
    ... >The known ingredient it uses is: ... XP service pack 2 Release candidate 1 patches this exploit. ... The code used by this worm to exploit it's users at least partly is (i ...
    (Full-Disclosure)
  • Re: Creating XP update cd
    ... updates since service pack 2 and burn them to a cd? ... You can even integrate those patches into your Windows XP ... How to use the Windows Update Catalog ... Creating an Integrated Installation ...
    (microsoft.public.windowsupdate)
  • Re: Microsoft Antispyware & NETBIOS Messenger
    ... When I reboot it is again AUTOMATIC. ... worse than a hole that you do see and thus monitor. ... You mention that you have all the patches which implies that you're using ... service pack two and it should be disabled automatically unless you, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: New Computer - Need Service Packs on CD
    ... Service Pack 1, and I can't get my internet connection to work ... You can download and save all updates for later use - including service ... You can even integrate those patches into your Windows XP ... How to use the Windows Update Catalog ...
    (microsoft.public.windowsxp.newusers)

Loading