Re: Deploy Security Patch with SMS 2003

From: Adam Welker [MSFT] (adamwel_at_online.microsoft.com)
Date: 07/08/04


Date: Thu, 8 Jul 2004 08:18:27 -0700

Chris,
The answer isn't really acceptable to us either, but its the only one we
have at the momement. We are working very hard however to get a better
answer for you and the rest of our customers who struggle with this issue.

-- 
Adam Welker
This posting is provided "AS IS" with no warranties, and confers no rights.
"Chris Faigle" <Chris Faigle@discussions.microsoft.com> wrote in message
news:4AF2E8D5-BAA3-4735-A9AF-D613B9486761@microsoft.com...
> Critical updates? Security fix?  What is the difference and why should I
care?  Why did we go through all this hassle to set up SMS 2003 if we cannot
easily push out patches that computers are getting automatically through
WindowsUpdates?  Why have this crazy convoluted automated detection process
if it isn't even going to work for something which at the end of the day is
a one bit registry change.
>
> I guess since the patch doesn't solve the real problem anyway, why should
it have  a (relatively simple) mechanism to push it out, particularly since
these holes have been known for such a long time.
>
> I do not have all day every day week in and week out to mess with fixing
up Microsoft's errors compounded by ridiculousness like this.
>
> This answer is entirely unacceptable.
>
> Chris Faigle
> IS Security
> University of Richmond
>
>
>
> "Shafqat Khan [MSFT]" wrote:
>
> > <copying from another thread about this patch>
> >
> > This will not be added to mssecure.xml and will not be detected by MBSA
1.2.
> > This was released as a critical update and is not categorized as a
security
> > fix. It is a settings change to block one way of exploiting the
> > vulnerability. One can still use SMS to deploy this settings change
script.
> > See guidance at:
> >
> > Deploying Software Updates Using the SMS Software Distribution Feature:
> >
> >
http://www.microsoft.com/technet/prodtechnol/sms/sms2003/patchupdate.mspx
> >
> >
> > 867832 How to distribute software updates that are not detected by the
> > Microsoft Baseline Security Analyzer in Systems Management Server 2003
> >
> >
> > "Chris Faigle" <Chris Faigle@discussions.microsoft.com> wrote in message
> > news:7386FDB8-43E9-4D0C-84BC-9F8E6F0323B9@microsoft.com...
> > > KB870669 has not shown up on our SMS 2003 server either, even though
it is
> > set to sync every two hours.  Can Microsoft please provide more
information
> > on this?
> > >
> >
> >
> >


Relevant Pages

  • Re: Deploy Security Patch with SMS 2003
    ... IS Security ... > Deploying Software Updates Using the SMS Software Distribution Feature: ... > Microsoft Baseline Security Analyzer in Systems Management Server 2003 ...
    (microsoft.public.sms.swdist)
  • Re: "New Security Upgrade" emailed from MS Technical services
    ... Microsoft NEVER sends Email with attachments. ... To protect the safety and security of your computer: ... Install ALL Critical Updates IMMEDIATELY. ... "bob" wrote in message ...
    (microsoft.public.security.virus)
  • Re: How to get a list of hotfixes?
    ... I need a list of all security and critical updates that have been released ... Messaging and Security, MCT, MCITP, MCTS and other stuff ... a Microsoft Certified Gold Partner ...
    (microsoft.public.windows.server.clustering)
  • Re: Critical Updates vs. Security Updates
    ... Hi Bob - You might be able to figure out what you need using this tool: ... > those that were not security related were nonetheless designated ... are there any critical updates that are not security ... Based on my understanding of Microsoft terminology, ...
    (microsoft.public.windowsupdate)
  • PBX Security
    ... I return with the reasons I freaked when I saw what a PBX ... ANY extension, and not just any user can do that, with proper ... cryptographic controls on software updates for a PBX. ... relevant and enforced security policy, security conscious users, etc and ...
    (Pen-Test)