Re: SMS Not Seeing Updates Needed by XP Clients

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Elton (Elton_at_discussions.microsoft.com)
Date: 06/28/04


Date: Mon, 28 Jun 2004 01:27:01 -0700

Thanks Richard - Just for others who may be reading this the majority of differences between MBSA and Windows Update are listed here:
http://support.microsoft.com/default.aspx?kbid=306460
Regards
Elton

"Richard Threlkeld <MVP>" wrote:

> Security Rollups aren't detected, the updates that comprise them are. You
> can push this out via standard Software Distribution.
>
> Product updates, like 828026 for WMP below, aren't critical security updates
> so they are not detected by the MBSA. Again, standard Software Distribution
> can push this out. Same thing goes for 831167.
>
> The Software Distribution process I mentioned above can be seen here:
> http://www.microsoft.com/technet/prodtechnol/sms/sms2003/patchupdate.mspx
>
> And yes, MS is aware that these limitations are problems and they are
> working on fixing :)
>
> --
> Richard Threlkeld
> Microsoft MVP - SMS
>
> Management Blog: http://www.msmvps.com/Threlkeld/
>
> Join the SMS email discussion list today:
> http://lists.listleague.com/mailman/listinfo/mssms
>
> "Elton" <Elton@discussions.microsoft.com> wrote in message
> news:7F954071-5212-43E1-952A-BEE51077428E@microsoft.com...
> > Adam,
> >
> > Further to this issue, can I clarify what seems to be the reasoning and
> then post a further question.
> >
> > The reason that differences occur between Windows Update and the SMS SUS
> feature pack is because the security catalogs they use are different. MS are
> working on gettting these the same but in the meantime???
> >
> > I have a test client PC with XPsp1a install - clean install. I have
> deployed the updates to the PC and it has installed the appropriate one.
> >
> > When using windows update website on the client I get 7 updates to install
> that aren't requested by the SMS SUS feature Pack (scan tool) these are
> > 814078, 819696, 839643 - are listed with a note in MBSA
> > 837009 - not detected by MBSA
> >
> > The following are listed by Windowsupdate but should be detected by MBSA:
> 826939 - Rolled up update for Windows XP
> > 828026 - Patch for Media Player URL behaviour
> > 831167 - Patch for IE correct error for SSL and HTTPs
> >
> > Could you tell me why the above 3 are not listed as an update being
> required in MBSA?
> > Also what is MS's best practise for deploying those updates that are
> listed as notes or not supported by MBSA?
> >
> > Regards
> >
> > Elton
> >
> >
> > "Adam Welker [MSFT]" wrote:
> >
> > > 837009 is OE which is not supported by MBSA.
> > > 831167 is a critical update. Critical does not equate to security and
> MBSA
> > > only detects security updates.
> > > 839643 is a Direct Play update. DirectX is not supported by MBSA.
> > > 819696 is another DirectX update.
> > > 814078 is on the list of exceptions. MBSA is not able to detect this
> > > update.
> > >
> > > For a complete list of products which are supported by MBSA and a list
> of
> > > update exceptions which cannot be detected by MBSA please see KB 306460.
> > >
> > > --
> > > Adam Welker
> > > This posting is provided "AS IS" with no warranties, and confers no
> rights.
> > >
> > >
> > >
>
>
>



Relevant Pages

  • RE: MBSA: error occurred while scanning for security updates. (0x8
    ... security updates. ... The Windows Firewall is turned off on all machines that are logged onto the ... Also I assumed as I am running the MBSA scan from an internal server ... [CallerId = MBSA] ...
    (microsoft.public.windowsupdate)
  • Re: Hardening IIS
    ... > Besides running the IIS lockdown tool and MBSA, ... > firewall and all the updates and patches, what steps can be taken to ... would be of any use to someone who knows enough to use lockdown and MBSA ... The server could be perfectly secure but the web app/site it is running ...
    (microsoft.public.security)
  • Re: MBSA ans SUS
    ... I run MBSA on a secure Windows 2000 Active ... > Directory network which also has a SUS server on it. ... performed against the list of approved security updates on the ... about all the security updates released by Microsoft. ...
    (microsoft.public.security)
  • Re: 843183 MBSA-12 Urgent: Unsupported security scan tool - please u
    ... Inventory Tool and the Microsoft Office Inventory Tool for Updates, ... exsisting SMS20 site to using SMS2003 where MBSA 1.2 is supported. ... > when I invoke the dstribute software updates wizard the list of available ...
    (microsoft.public.sms.admin)
  • Re: latest security updates not showing on the Wizard list
    ... Also, just to verify, make sure you are using the latest SMS SUS FP using ... MBSA 1.2 as 1.1 has problems with picking up certain updates, ...
    (microsoft.public.sms.admin)