New Patch Data Available (1.1.3.5338)

XML data version = 1.1.3.5338 Last modified on 02/15/2010

Product

– Added support for Acrobat Reader 9.3.1.

– Added support for Acrobat Reader 8.2.1.

– Added support for Adobe Acrobat 9.3.1 Professional.

– Added support for Adobe Acrobat 9.3.1 Standard.

– Added support for Adobe Acrobat 9.3.1 Pro Extended.

– Added support for Adobe Acrobat 8.2.1 Professional.

– Added support for Adobe Acrobat 8.2.1 Standard.

Security

– Added APSB-1007(QAR0932): Security Updates Available for Adobe Reader and Acrobat.

Revision

– Modified MSRT-001(Q890830): Added Windows 7 as affected products.

Concerns Regarding MS10-015

There is rising concern regarding MS10-015 causing BSOD on machines.  According to Microsoft and other sources in the Security world the issue is linked to Malware already on the machine when the patch is applied.  Microsoft has pulled the patch from WU likely to reduce impact to home users who are more likely to have Malware on their machines that could cause this, but the patch is still available in WSUS, SUS, and SCCM.  The patch is still available to Shavlik Customers as well.

 Shavlik Recommendations:

  • Adequate Patch Testing in place – Microsoft tests patches before release and Shavlik does additional testing in our environments to ensure detection logic is correct and there are no widespread issues encountered with patching the machine.  Lab testing can only do so much.  It is highly recommended to implement any level of testing in your environment as well.  This will ensure environment specific variables we cannot reproduce will not cause you issues.  Your testing could be a group of Virtual machines representing a cross section of machines in your environment or it could be IT and a select group of users and servers.

 

  • If you are concerned about the patch, are aware of recent Malware outbreaks in your environment, and\or patch testing resulted in machines encountering the BSOD, you can setup a template to scan for all other Security Patches except MS10-015.

Steps to do this:

  1. Go to Patch Groups on the Navigation Bar and create a new patch group.  Call it MS10-015 and click Add Patches
  2. Scroll down to MS10-015 and check the box and click select then click Save
  3. Create a New Scan Template.  Call it something like “Security Patches Except MS10-015”. This by default is setup to scan for all security patches
  4. In the Patch section select the Skip Selected and next to Patch Groups click … to browse and select your new patch group.
  5. Scan using this new template and you wills can for all security patches except MS10-015. 
  • If customers are experiencing a BSOD as a result of pushing MS10-015 they can contact Microsoft directly for support using the country specific numbers provided at support.microsoft.com/security. In North America, customers can call 1-866-PCSAFETY for this support.

New Patch Data Available (1.1.3.5334)

XML data version = 1.1.3.5334 Last modified on 02/12/2010

Product

– Added support for Adobe Flash Player 10.0.45.2.

– Added support for Adobe Flash Player 9.0.262.0.

Security

– Added APSB-1006(QFM1045): Security updates available for Adobe Flash Player.

Non Security

– Added MSWU-373(Q974561): Update for Office Word 2007: November 2009.

Revision

– Modified MS09-062(Q972580): Added Visio 2003 as affected product.

– Modified MSWU-352(Q976470): Fixed a issue where patch did not download properly in scan view.

New Patch Data Available (1.1.3.5326)

XML data version = 1.1.3.5326 Last modified on 02/09/2010

Security

MS10-003: Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution (978214)

MS10-004: Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (975416)

MS10-005: Vulnerability in Microsoft Paint Could Allow Remote Code Execution (978706)

MS10-006: Vulnerabilities in SMB Client Could Allow Remote Code Execution (978251)

MS10-007: Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (975713)

MS10-008: Cumulative Security Update of ActiveX Kill Bits (978262)

MS10-009: Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (974145)

MS10-011: Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (978037)

MS10-012: Vulnerabilities in SMB Server Could Allow Remote Code Execution (971468)

MS10-013: Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (977935)

MS10-014: Vulnerability in Kerberos Could Allow Denial of Service (977290)

MS10-015: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165)

New Patch Data Available (1.1.3.5312)

XML data version = 1.1.3.5312 Last modified on 02/04/2010

Product

– Added support for iTunes 9.0.3.

Security

– Added AI10-001(QAI0903): iTunes 9.0.3.

Revision

– Modified MSWU-235(Q951978): Fixed an issue where after installation patch shows as missing on some systems.

– Modified MSWU-305(Q953026): Fixed an issue where after installation patch shows as missing on some systems.

– Modified RP12-001(QRP1200): Fixed an issue where after installation patch shows as missing on some systems.

New Patch Data Available (1.1.3.5304)

XML data version = 1.1.3.5304 Last modified on 02/02/2010

Product

– Added support for Vista Business N.

Software Distribution

– Added SUN-JAVA(QJAVA61): Sun Java 6 update 18.

Revisions

– Modified MS10-002 (Q978207): Fixed an issue where patch did not uninstall successfully on some systems with IE7 or IE8.

– Modified MS10-002 (Q978207): Fixed an issue where patch did not show as missing on some systems running Windows XP x64 SP2 with IE6 SP1.

– Modified AI09-004 (QAI0900): Fixed an issue where patch did not download on some systems running Windows x64.

– Modified APSB-0603(Q916208): Patch is no longer supported by vendor. Added superceded by APSB-0720.

Shavlik NetChk Protect v7.2 Update 1 (SKB15726) Issue

Shavlik is experiencing an issue related to importing of scan results at a small number of customer sites who have applied the recently available NetChk Protect v7.2 Update 1 patch (SKB15726).  To mitigate this issue, we have pulled the v7.2 update 1 patch from our web site and from our XML data. 

You can verify if you have in fact applied v7.2 update 1 by going to your console and looking in the “Help – About” and your version number will be “v7.2.0 Build 343”.  If you have already applied this v7.2 update 1 patch (first available on Thursday, Jan. 28th in the early evening U.S. central time zone) to your NetChk Protect environment please refer to the recommendation below:

If you are running v7.2.0 Update 1 (i.e. v7.2 Build 343) AND are NOT seeing scan results when performing a patch scan; then please refer to the following Shavlik forum article: http://forum.shavlik.com/viewtopic.php?f=26&t=15823

IMPORTANT: Shavlik will advise all customers when the revised v7.2 update 1 patch is officially posted again and available for download.

New Patch Data Available (1.1.3.5292)

XML data version = 1.1.3.5292 Last modified on 01/21/2010

Security

– Added MS10-002(Q978207): Cumulative Security Update for Internet Explorer (978207).

– Added APSB-1003(QASW118): Security update available for Shockwave Player 11.5.2.606.

Software Distribution

– Added APSB-1002 (QAR0931): Adobe Reader 9.3.

Revisions

– Modified APSB-0919(QAF1043): Flash 10.0.42.34 added Windows 7 Software Distribution.

– Modified MS09-045(Q971961): Fixed an issue where patch did not show as missing on some systems running Windows Server 2003 x64 R2.

– Modified MS10-001(Q972270): Fixed an issue where uninstall was missing on some systems.

New Patch Data Available (1.1.3.5284)

XML data version = 1.1.3.5284 Last modified on 01/19/2010

Security

– Updated SUN-JAVA(QJAVA60): Sun Java JRE 6 Update 18.

Non Security

– Added MSWU-368(Q973917): Description of the update that implements Extended Protection for Authentication in Internet Information Services (IIS).

– Added MSWU-372(Q978551): Update for Microsoft Office 2003 (KB978551).

Revisions

– Modified MSWU-357(Q970430): Fixed an issue where patch would show as missing after installation of KB973917.

New Patch Data Available (1.1.3.5274)

XML data version = 1.1.3.5274 Last modified on 01/13/2010

Products

– Added support for Acrobat Reader 9.3.0.

– Added support for Acrobat Reader 8.2.0.

– Added support for Adobe Acrobat 9.3.0 Professional.

– Added support for Adobe Acrobat 9.3.0 Standard.

– Added support for Adobe Acrobat 9.3.0 Pro Extended.

– Added support for Adobe Acrobat 8.2.0 Professional.

– Added support for Adobe Acrobat 8.2.0 Standard.

Security

– Added APSB-1002(QAR0930): Security Updates Available for Adobe Reader and Acrobat.

Non Security

– Added MSWU-370(Q977839): Office Outlook 2007 Junk E-mail Filter update: January 12, 2010.

– Added MSWU-371(Q977840): Office Outlook 2003 Junk E-mail Filter update: January 12, 2010.

New Patch Data Available (1.1.3.5266)

XML data version = 1.1.3.5266 Last modified on 01/07/2010

Products

– Added support for Firefox 3.5.7.

– Added support for Firefox 3.0.17.

Security

– Added FF10-001(QFF3570): Firefox 3.5.7.

– Added FF10-002(QFF3171): Firefox 3.0.17.

– Added Windows XP Embedded Security patches.

Non Security

– Added MSWU-369(Q978557): Update for Microsoft Office Excel Viewer 2003 (KB978557).

– Added MSWU-270(Q959108): An update is available that disables the collection and transfer of Software Quality Metrics data by the Windows Portable Device (WPD) API.

Revisions

– Modified MSWU-356(Q976098): Fixed an issue where patch would show as missing after installation.