Kb4565539 windows 7 x64 скачать

Windows 7 Service Pack 1 Windows Server 2008 R2 Service Pack 1 Windows Embedded Standard 7 Service Pack 1 Windows Embedded POSReady 7 Windows Thin PC Еще…Меньше

Версия:

Обновление только для системы безопасности


НОВОЕ!

ВАЖНО! 
С июля 2020 г. все Центры обновлений Windows отключат функцию RemoteFX vGPU из-за уязвимости в системе безопасности. Дополнительные сведения см. в CVE-2020-1036 и KB4570006. После установки этого обновления попытки запуска виртуальных машин (ВМ), в которых включена функция RemoteFX vGPU, будут завершаться сбоем и будут появляться следующие сообщения:

Если повторно включить функцию RemoteFX vGPU, появится следующее сообщение:

  • «Не удается запустить виртуальную машину, так как все GPU с поддержкой RemoteFX отключены в диспетчере Hyper-V».

  • «Не удается запустить виртуальную машину, так как на сервере недостаточно ресурсов GPU».

  • «Видеоадаптер RemoteFX 3D больше не поддерживается. Если вы все еще используете этот адаптер, ваша безопасность под угрозой. Дополнительные сведения см. на странице (https://go.microsoft.com/fwlink/?linkid=2131976)”

ВАЖНО! Убедитесь, что обязательные обновления, приведенные в разделе Порядок получения обновления, установлены перед установкой этого обновления. 

ВАЖНО Некоторым клиентам, которые используют Windows Server 2008 R2 с пакетом обновления 1 (SP1) и активировали дополнение ESK для нескольких ключей активации (MAK) перед установкой обновлений от 14 января 2020 года, может потребоваться повторная активация их ключа. Повторная активация на соответствующих устройствах должна быть выполнена только один раз.  Дополнительные сведения об активации см. в этой записи блога.

ВАЖНО  Кабины сканирования WSUS будут по-прежнему доступны для Windows 7 SP1 и Windows Server 2008 R2 SP1. Если у вас есть подмножество устройств, работающих под управлением этих операционных систем без ESU, они могут отображаться как несовместимые в ваших наборах инструментов управления исправлениями и соответствия.

ВАЖНО Клиенты, которые приобрели Расширенное обновление безопасности (ESU) для локальных версий этих операционных систем, должны выполнить процедуры, описанные в KB4522133, чтобы продолжить получать обновления безопасности после окончания расширенной поддержки 14 января 2020 года. Для получения дополнительной информации о ESU и поддерживаемых выпусках см. KB4497181.

ВАЖНО! Начиная с 15 января 2020 года, будет появляться полноэкранное уведомление, в котором описывается риск продолжения использования Windows 7 с пакетом обновления 1 после окончания поддержки 14 января 2020 года. Это уведомление будет оставаться на экране, пока вы не совершите над ним какое-нибудь действие. Это уведомление появится только в следующих выпусках Windows 7 с пакетом обновления 1:

Примечание. Уведомление не будет отображаться на компьютерах, присоединенных к домену, и компьютерах в режиме киоска.

  • Начальная

  • Домашняя базовая

  • Домашняя расширенная

  • Профессиональная Если вы приобрели расширенное обновление безопасности (ESU), уведомление не будет отображаться. Дополнительные сведения см. в разделе Получение расширенных обновлений безопасности для подходящих устройств с Windows и Вопросы и ответы о жизненном цикле — расширенные обновления безопасности.

  • Максимальная

Улучшения и исправления

Это обновление для системы безопасности направлено на улучшение качества работы ОС. Ниже перечислены основные изменения.

  • Обновления системы безопасности для платформы и инфраструктур приложений Windows, приложений Windows, графических компонентов Windows, операций ввода и композиции Windows, основных компонентов Windows, ядра Windows, удаленного рабочего стола Windows и компонентов SQL Windows.

Дополнительные сведения об устраненных уязвимостях в системе безопасности см. в Руководстве по обновлению системы безопасности.

Известные проблемы, связанные с этим обновлением

Проблема

Возможное решение

После установки этого обновления и перезапуска устройства вы можете увидеть ошибку «Не удается настроить обновления Windows. Отмена изменений. Не выключайте компьютер» и обновление может отображаться как Ошибка в журнале обновления.

Такое может произойти в следующих случаях.

  • Если вы устанавливаете это обновление на устройство под управлением выпуска, который не поддерживается для ESU. Полный список поддерживаемых выпусков см. в статье KB4497181.

  • Если вы не установили и не активировали ключ надстройки ESU MAK.

Если вы приобрели ключ ESU и столкнулись с этой проблемой, убедитесь, что вы применили все необходимые компоненты и что ваш ключ активирован. Информацию об активации смотрите в этом посте блога. Сведения о предварительных условиях см. В разделе «Как получить это обновление» этой статьи.

Определенные операции, такие как переименование, выполняемые с файлами или папками на общем томе кластера (CSV), могут завершиться с ошибкой «STATUS_BAD_IMPERSONATION_LEVEL» (0xC00000A5). Это происходит при выполнении операции на узле владельца CSV из процесса, у которого нет прав администратора.

Выполните одно из следующих действий:

  • Выполните операцию из процесса с правами администратора.

  • Выполните операцию с узла, который не владеет томом CSV.

Корпорация Майкрософт работает над решением этой проблемы и предоставит обновление в ближайшем выпуске.

Порядок получения обновления

Перед установкой этого обновления

Необходимый компонент:

Вам необходимо установить перечисленные ниже обновления и перезапустить устройство перед установкой последнего накопительного пакета обновлений. Установка этих обновлений повышает надежность процесса обновления для устранения возможных проблем при установке накопительного пакета обновления и применении исправлений системы безопасности Майкрософт.

  1. Обновление стека обслуживания (SSU) от 12 марта 2019 г. (KB4490628).  Чтобы получить отдельный пакет для этого SSU, найдите его в каталоге Центра обновления Майкрософт. Это обновление необходимо для установки обновлений, которые подписаны только с помощью SHA-2.

  2. Последнее обновление для SHA-2 (KB4474419) выпущено 10 сентября 2019 года. Если вы используете Центр обновления Windows, последнее обновление для SHA-2 будет предложено вам автоматически. Это обновление необходимо для установки обновлений, которые подписаны только с помощью SHA-2. Дополнительные сведения об обновлениях для SHA-2 см. в статье Требования поддержки подписывания кода SHA-2 от 2019 г. для Windows и служб WSUS.

  3. Обновление SSU от 9 июня 2020 г. (KB4562030) или более позднее. Чтобы получить автономный пакет для этого SSU, найдите его в каталоге Центра обновления Майкрософт.

  4. Пакет подготовки лицензий расширенных обновлений системы безопасности (KB4538483), выпущенное 11 февраля 2020 г. Пакет подготовки к лицензированию ESU будет предложен вам от WSUS. Чтобы получить автономный пакет для пакета подготовки к лицензированию ESU, найдите его в каталоге Центра обновления Майкрософт.

После установки вышеуказанных элементов корпорация Майкрософт настоятельно рекомендует установить последнюю версию SSU (KB4565354). Если вы используете Центр обновления Windows, последнее обновление SSU будет предложено вам автоматически при условии, что вы являетесь клиентом ESU. Чтобы получить автономный пакет для последней версии SSU, найдите его в каталоге Центра обновления Майкрософт. Общие сведения о SSU см. в статьях Обслуживание обновлений стека и Обновления стека обслуживания (SSU): Часто задаваемые вопросы.

Установка этого обновления

Канал выпуска

Доступно

Следующий шаг

Центр обновления Windows и Центр обновления Майкрософт

Нет

См. другие варианты ниже.

Каталог Центра обновления Майкрософт

Да

Чтобы получить отдельный пакет для данного обновления, перейдите на веб-сайт каталога Центра обновления Майкрософт.

Службы Windows Server Update Services (WSUS)

Да

Это обновление будет автоматически синхронизироваться с WSUS, если вы настроите продукты и классификации следующим образом:

Продукт:  Windows 7 с пакетом обновления 1, Windows Server 2008 R2 с пакетом обновления 1, Windows Embedded Standard 7 с пакетом обновления 1, Windows Embedded POSReady 7, Windows Thin PC

Классификация: Обновления безопасности

Сведения о файлах

Чтобы получить список файлов, представленных в этом обновлении, загрузите информацию о файле для обновления 4565539.

Нужна дополнительная помощь?

Нужны дополнительные параметры?

Изучите преимущества подписки, просмотрите учебные курсы, узнайте, как защитить свое устройство и т. д.

В сообществах можно задавать вопросы и отвечать на них, отправлять отзывы и консультироваться с экспертами разных профилей.

Windows 7 Service Pack 1 Windows Server 2008 R2 Service Pack 1 Windows Embedded Standard 7 Service Pack 1 Windows Embedded POSReady 7 Windows Thin PC More…Less

Version:

Security-only update


NEW

IMPORTANT 
Starting in July 2020, all Windows Updates will disable the RemoteFX vGPU feature because of a security vulnerability. For more information about the vulnerability, seeCVE-2020-1036 and KB4570006. After you install this update, attempts to start virtual machines (VM) that have RemoteFX vGPU enabled will fail, and messages such as the following will appear:

If you re-enable RemoteFX vGPU, a message similar to the following will appear:

  • “The virtual machine cannot be started because all the RemoteFX-capable GPUs are disabled in Hyper-V Manager.”

  • “The virtual machine cannot be started because the server has insufficient GPU resources.”

  • «We no longer support the RemoteFX 3D video adapter. If you are still using this adapter, you may become vulnerable to security risk. Learn more (https://go.microsoft.com/fwlink/?linkid=2131976)”

IMPORTANT Verify that you have installed the required updates listed in the How to get this update section before installing this update. 

IMPORTANT Some customers who use Windows Server 2008 R2 SP1 and have activated their ESU multiple activation key (MAK) add-on before installing the January 14, 2020 updates might need to re-activate their key. Re-activation on the affected devices should only be required once.  For information on activation, see this blog post.

IMPORTANT WSUS scan cab files will continue to be available for Windows 7 SP1 and Windows Server 2008 R2 SP1. If you have a subset of devices running these operating systems without ESU, they might show as non-compliant in your patch management and compliance toolsets.

IMPORTANT Customers who have purchased the Extended Security Update (ESU) for on-premises versions of these operating systems must follow the procedures in KB4522133 to continue receiving security updates after extended support ends on January 14, 2020. For more information on ESU and which editions are supported, see KB4497181.

IMPORTANT Starting on January 15, 2020, a full-screen notification will appear that describes the risk of continuing to use Windows 7 Service Pack 1 after it reaches end of support on January 14, 2020. The notification will remain on the screen until you interact with it. This notification will only appear on the following editions of Windows 7 Service Pack 1:

Note The notification will not appear on domain-joined machines or machines in kiosk mode.

  • Starter.

  • Home Basic.

  • Home Premium.

  • Professional. If you have purchased the Extended Security Update (ESU), the notification will not appear. For more information, see How to get Extended Security Updates for eligible Windows devices and Lifecycle FAQ-Extended Security Updates.

  • Ultimate.

Improvements and fixes

This security update includes quality improvements. Key changes include:

  • Security updates to Windows App Platform and Frameworks, Windows Apps, Windows Graphics, Windows Input and Composition, Windows Fundamentals, Windows Kernel, Windows Remote Desktop, and Windows SQL components.

For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.

Known issues in this update

Symptom

Workaround

After installing this update and restarting your device, you might receive the error, “Failure to configure Windows updates. Reverting Changes. Do not turn off your computer,” and the update might show as Failed in Update History.

This is expected in the following circumstances:

  • If you are installing this update on a device that is running an edition that is not supported for ESU. For a complete list of which editions are supported, see KB4497181.

  • If you do not have an ESU MAK add-on key installed and activated.

If you have purchased an ESU key and have encountered this issue, please verify you have applied all prerequisites and that your key is activated. For information on activation, please see this blog post. For information on the prerequisites, see the «How to get this update» section of this article.

Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”. This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege.

Do one of the following:

  • Perform the operation from a process that has administrator privilege.

  • Perform the operation from a node that doesn’t have CSV ownership.

Microsoft is working on a resolution and will provide an update in an upcoming release.

How to get this update

Before installing this update

Prerequisite:

You must install the updates listed below and restart your device before installing the latest Rollup. Installing these updates improves the reliability of the update process and mitigates potential issues while installing the Rollup and applying Microsoft security fixes.

  1. The March 12, 2019 servicing stack update (SSU) (KB4490628).  To get the standalone package for this SSU, search for it in the Microsoft Update Catalog. This update is required to install updates that are only SHA-2 signed.

  2. The latest SHA-2 update (KB4474419) released September 10, 2019. If you are using Windows Update, the latest SHA-2 update will be offered to you automatically. This update is required to install updates that are only SHA-2 signed. For more information on SHA-2 updates, see 2019 SHA-2 Code Signing Support requirement for Windows and WSUS.

  3. The June 9, 2020 SSU (KB4562030) or later. To get the standalone package for this SSU, search for it in the Microsoft Update Catalog.

  4. The Extended Security Updates (ESU) Licensing Preparation Package (KB4538483) released February 11, 2020. The ESU licensing preparation package will be offered to you from WSUS. To get the standalone package for ESU licensing preparation package, search for it in the Microsoft Update Catalog.

After installing the items above, Microsoft strongly recommends that you install the latest SSU (KB4565354). If you are using Windows Update, the latest SSU will be offered to you automatically if you are an ESU customer. To get the standalone package for the latest SSU, search for it in the Microsoft Update Catalog. For general information about SSUs, see Servicing stack updates and Servicing Stack Updates (SSU): Frequently Asked Questions.

Install this update

Release Channel

Available

Next Step

Windows Update and Microsoft Update

No

See the other options below.

Microsoft Update Catalog

Yes

To get the standalone package for this update, go to the Microsoft Update Catalog website.

Windows Server Update Services (WSUS)

Yes

This update will automatically sync with WSUS if you configure Products and Classifications as follows:

Product:  Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Embedded Standard 7 Service Pack 1, Windows Embedded POSReady 7, Windows Thin PC

Classification: Security Updates

File information

For a list of the files that are provided in this update, download the file information for update 4565539.

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.

Компания Microsoft выпустила обновления для Windows 7 и Windows 8.1.

Вот список всех представленных обновлений:

KB4565541

;

KB4565540

;

KB4565524

;

KB4565539

;

KB4565541 имеет следующие исправления:

• Исправлена проблема, которая могла помешать некоторым приложениям печатать документы, содержащие графику или большие файлы, после установки обновлений Windows, выпущенных 9 июня 2020 года;
• Есть обновления безопасности для Windows App Platform and Frameworks, Windows Apps, Windows Graphics, Windows Input and Composition, Windows Fundamentals, Windows Kernel, Windows MSXML, Windows File Server and Clustering, Windows Remote Desktop, Internet Explorer, the Microsoft Scripting Engine и Windows SQL components;

KB4565540 имеет следующие исправления:

• Есть обновления безопасности для Windows App Platform and Frameworks, Windows Apps, Windows Graphics, Windows Input and Composition, Windows Fundamentals, Windows Kernel, Windows MSXML, Windows File Server and Clustering, Windows Remote Desktop и Windows SQL components;

KB4565524 имеет следующие исправления:

• Есть обновления безопасности для Windows App Platform and Frameworks, Windows Apps, Windows Graphics, Windows Input and Composition, Windows Fundamentals, Windows Kernel, Windows MSXML, Windows File Server and Clustering, Windows Remote Desktop и Windows SQL components;

KB4565539 имеет следующие исправления:

• Есть обновления безопасности для Windows App Platform and Frameworks, Windows Apps, Windows Graphics, Windows Input and Composition, Windows Fundamentals, Windows Kernel, Windows Remote Desktop, and Windows SQL components;

High   Plugin ID: 138460


This page contains detailed information about the KB4565539: Windows 7 and Windows Server 2008 R2 July 2020 Security Update Nessus plugin including available exploits and PoCs found on GitHub, in Metasploit or Exploit-DB for verifying of this vulnerability.

  • Plugin Overview
  • Vulnerability Information
    • Synopsis
    • Description
    • Solution
  • Public Exploits
  • Risk Information
  • Plugin Source
  • How to Run
  • References
  • Version

Plugin Overview


ID: 138460

Name: KB4565539: Windows 7 and Windows Server 2008 R2 July 2020 Security Update

Filename: smb_nt_ms20_jul_4565524.nasl

Vulnerability Published: 2020-07-14

This Plugin Published: 2020-07-14

Last Modification Time: 2021-11-30

Plugin Version: 1.12

Plugin Type: local

Plugin Family: Windows : Microsoft Bulletins

Dependencies:
ms_bulletin_checks_possible.nasl, smb_check_rollup.nasl, smb_hotfixes.nasl
Required KB Items [?]: SMB/MS_Bulletin_Checks/Possible

Vulnerability Information


Severity: High
Vulnerability Published: 2020-07-14
Patch Published: 2020-07-14
CVE [?]: CVE-2020-1085, CVE-2020-1147, CVE-2020-1267, CVE-2020-1333, CVE-2020-1346, CVE-2020-1351, CVE-2020-1354, CVE-2020-1359, CVE-2020-1360, CVE-2020-1365, CVE-2020-1371, CVE-2020-1373, CVE-2020-1374, CVE-2020-1384, CVE-2020-1389, CVE-2020-1390, CVE-2020-1396, CVE-2020-1397, CVE-2020-1400, CVE-2020-1401, CVE-2020-1402, CVE-2020-1403, CVE-2020-1407, CVE-2020-1408, CVE-2020-1409, CVE-2020-1410, CVE-2020-1412, CVE-2020-1419, CVE-2020-1421, CVE-2020-1427, CVE-2020-1428, CVE-2020-1430, CVE-2020-1432, CVE-2020-1435, CVE-2020-1436, CVE-2020-1437, CVE-2020-1438, CVE-2020-1468
CPE [?]: cpe:/o:microsoft:windows
Exploited by Malware: True

Synopsis

The remote Windows host is affected by multiple vulnerabilities.

Description

The remote Windows host is missing security update 4565539 or cumulative update 4565524. It is, therefore, affected by multiple vulnerabilities :

— A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage. The security update addresses the vulnerability by correcting how DirectWrite handles objects in memory. (CVE-2020-1409)

— An elevation of privilege vulnerability exists when the Windows Profile Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-1360)

— A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-1403)

— A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server. An attacker who successfully exploited this vulnerability could execute arbitrary code on the computer of the connecting client. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-1374)

— A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts. For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability:
(CVE-2020-1436)

— An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.
(CVE-2020-1354, CVE-2020-1430)

— An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2020-1468)

— An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.
(CVE-2020-1365, CVE-2020-1371)

— An elevation of privilege vulnerability exists in the way that the Windows Network Location Awareness Service handles objects in memory. An attacker who successfully exploited the vulnerability could allow an application with limited privileges on an affected system to execute code at a medium integrity level. (CVE-2020-1437)

— An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit this vulnerability: (CVE-2020-1397)

— A remote code execution vulnerability exists when Windows Address Book (WAB) improperly processes vcard files. (CVE-2020-1410)

— An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how the Windows Graphics Component handles objects in memory. (CVE-2020-1351)

— An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points. An attacker who successfully exploited this vulnerability could overwrite a targeted file that would normally require elevated permissions.
(CVE-2020-1333)

— A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1408)

— An elevation of privilege vulnerability exists when the Windows Modules Installer improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-1346)

— An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-1396)

— An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer. An attacker who exploited the vulnerability could cause the user to place a call without additional consent, leading to information disclosure of the user profile. For the vulnerability to be exploited, a user must click a specially crafted URL that prompts the Skype app.
(CVE-2020-1432)

— An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory. (CVE-2020-1402)

— A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the process responsible for deserialization of the XML content. (CVE-2020-1147)

— An elevation of privilege vulnerability exists when the Windows Cryptography Next Generation (CNG) Key Isolation service improperly handles memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-1359, CVE-2020-1384)

— An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1373, CVE-2020-1390, CVE-2020-1427, CVE-2020-1428, CVE-2020-1438)

— An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1085)

— A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. (CVE-2020-1412)

— A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2020-1400, CVE-2020-1401, CVE-2020-1407)

— An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-1389, CVE-2020-1419)

— This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause a denial of service on the target system’s LSASS service, which triggers an automatic reboot of the system. The security update addresses the vulnerability by changing the way that LSASS handles specially crafted authentication requests. (CVE-2020-1267)

— A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1435)

— A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. (CVE-2020-1421)

Solution

Apply Security Only update KB4565539 or Cumulative Update KB4565524.

Public Exploits


Target Network Port(s): 139, 445
Target Asset(s): Host/patch_management_checks
Exploit Available: True (Metasploit Framework, Exploit-DB, GitHub)

Exploit Ease: Exploits are available

Here’s the list of publicly known exploits and PoCs for verifying the KB4565539: Windows 7 and Windows Server 2008 R2 July 2020 Security Update vulnerability:

  1. Metasploit: exploit/windows/http/sharepoint_data_deserialization
    [SharePoint DataSet / DataTable Deserialization]
  2. Exploit-DB: exploits/aspx/webapps/48747.py
    [EDB-48747: Microsoft SharePoint Server 2019 — Remote Code Execution]
  3. Exploit-DB: exploits/aspx/webapps/50151.py
    [EDB-50151: Microsoft SharePoint Server 2019 — Remote Code Execution (2)]
  4. GitHub: https://github.com/H0j3n/EzpzSharepoint
    [CVE-2020-1147]
  5. GitHub: https://github.com/amcai/myscan
    [CVE-2020-1147]
  6. GitHub: https://github.com/michael101096/cs2020_msels
    [CVE-2020-1147]
  7. GitHub: https://github.com/pwntester/ysoserial.net
    [CVE-2020-1147]
  8. GitHub: https://github.com/xinali/articles
    [CVE-2020-1351]

Before running any exploit against any system, make sure you are authorized by the owner of the target system(s) to perform such activity. In any other case, this would be considered as an illegal activity.

WARNING: Beware of using unverified exploits from sources such as GitHub or Exploit-DB. These exploits and PoCs could contain malware. For more information, see how to use exploits safely.

Risk Information


CVSS Score Source [?]: CVE-2020-1435

CVSS V2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C

CVSS Base Score: 9.3 (High)
Impact Subscore: 10.0
Exploitability Subscore: 8.6
CVSS Temporal Score: 8.1 (High)
CVSS Environmental Score: NA (None)
Modified Impact Subscore: NA
Overall CVSS Score: 8.1 (High)

CVSS V3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CVSS Base Score: 8.8 (High)
Impact Subscore: 5.9
Exploitability Subscore: 2.8
CVSS Temporal Score: 8.4 (High)
CVSS Environmental Score: NA (None)
Modified Impact Subscore: NA
Overall CVSS Score: 8.4 (High)

STIG Severity [?]: I
STIG Risk Rating: High

Go back to menu.

Plugin Source


This is the smb_nt_ms20_jul_4565524.nasl nessus plugin source code. This script is Copyright (C) 2020-2021 and is owned by Tenable, Inc. or an Affiliate thereof.

#
# (C) Tenable Network Security, Inc.
#
# The descriptive text and package checks in this plugin were  
# extracted from the Microsoft Security Updates API. The text
# itself is copyright (C) Microsoft Corporation.
#

include('compat.inc');

if (description)
{
  script_id(138460);
  script_version("1.12");
  script_set_attribute(attribute:"plugin_modification_date", value:"2021/11/30");

  script_cve_id(
    "CVE-2020-1085",
    "CVE-2020-1147",
    "CVE-2020-1267",
    "CVE-2020-1333",
    "CVE-2020-1346",
    "CVE-2020-1351",
    "CVE-2020-1354",
    "CVE-2020-1359",
    "CVE-2020-1360",
    "CVE-2020-1365",
    "CVE-2020-1371",
    "CVE-2020-1373",
    "CVE-2020-1374",
    "CVE-2020-1384",
    "CVE-2020-1389",
    "CVE-2020-1390",
    "CVE-2020-1396",
    "CVE-2020-1397",
    "CVE-2020-1400",
    "CVE-2020-1401",
    "CVE-2020-1402",
    "CVE-2020-1403",
    "CVE-2020-1407",
    "CVE-2020-1408",
    "CVE-2020-1409",
    "CVE-2020-1410",
    "CVE-2020-1412",
    "CVE-2020-1419",
    "CVE-2020-1421",
    "CVE-2020-1427",
    "CVE-2020-1428",
    "CVE-2020-1430",
    "CVE-2020-1432",
    "CVE-2020-1435",
    "CVE-2020-1436",
    "CVE-2020-1437",
    "CVE-2020-1438",
    "CVE-2020-1468"
  );
  script_xref(name:"MSKB", value:"4565539");
  script_xref(name:"MSKB", value:"4565524");
  script_xref(name:"MSFT", value:"MS20-4565539");
  script_xref(name:"MSFT", value:"MS20-4565524");
  script_xref(name:"IAVA", value:"2020-A-0306-S");
  script_xref(name:"IAVA", value:"2020-A-0313-S");
  script_xref(name:"CISA-KNOWN-EXPLOITED", value:"2022/05/03");

  script_name(english:"KB4565539: Windows 7 and Windows Server 2008 R2 July 2020 Security Update");

  script_set_attribute(attribute:"synopsis", value:
"The remote Windows host is affected by multiple vulnerabilities.");
  script_set_attribute(attribute:"description", value:
"The remote Windows host is missing security update 4565539
or cumulative update 4565524. It is, therefore, affected by
multiple vulnerabilities :

  - A remote code execution vulnerability exists in the way
    that DirectWrite handles objects in memory. An attacker
    who successfully exploited this vulnerability could take
    control of the affected system. An attacker could then
    install programs; view, change, or delete data; or
    create new accounts with full user rights. There are
    multiple ways an attacker could exploit the
    vulnerability, such as by convincing a user to open a
    specially crafted document, or by convincing a user to
    visit an untrusted webpage. The security update
    addresses the vulnerability by correcting how
    DirectWrite handles objects in memory. (CVE-2020-1409)

  - An elevation of privilege vulnerability exists when the
    Windows Profile Service improperly handles file
    operations. An attacker who successfully exploited this
    vulnerability could gain elevated privileges.
    (CVE-2020-1360)

  - A remote code execution vulnerability exists in the way
    that the VBScript engine handles objects in memory. The
    vulnerability could corrupt memory in such a way that an
    attacker could execute arbitrary code in the context of
    the current user. An attacker who successfully exploited
    the vulnerability could gain the same user rights as the
    current user.  (CVE-2020-1403)

  - A remote code execution vulnerability exists in the
    Windows Remote Desktop Client when a user connects to a
    malicious server. An attacker who successfully exploited
    this vulnerability could execute arbitrary code on the
    computer of the connecting client. An attacker could
    then install programs; view, change, or delete data; or
    create new accounts with full user rights.
    (CVE-2020-1374)

  - A remote code execution vulnerability exists when the
    Windows font library improperly handles specially
    crafted fonts. For all systems except Windows 10, an
    attacker who successfully exploited the vulnerability
    could execute code remotely. For systems running Windows
    10, an attacker who successfully exploited the
    vulnerability could execute code in an AppContainer
    sandbox context with limited privileges and
    capabilities. An attacker could then install programs;
    view, change, or delete data; or create new accounts
    with full user rights. There are multiple ways an
    attacker could exploit the vulnerability:
    (CVE-2020-1436)

  - An elevation of privilege vulnerability exists when the
    Windows UPnP Device Host improperly handles memory.
    (CVE-2020-1354, CVE-2020-1430)

  - An information disclosure vulnerability exists when the
    Windows GDI component improperly discloses the contents
    of its memory. An attacker who successfully exploited
    the vulnerability could obtain information to further
    compromise the users system. There are multiple ways an
    attacker could exploit the vulnerability, such as by
    convincing a user to open a specially crafted document,
    or by convincing a user to visit an untrusted webpage.
    The security update addresses the vulnerability by
    correcting how the Windows GDI component handles objects
    in memory. (CVE-2020-1468)

  - An elevation of privilege vulnerability exists when the
    Windows Event Logging Service improperly handles memory.
    (CVE-2020-1365, CVE-2020-1371)

  - An elevation of privilege vulnerability exists in the
    way that the Windows Network Location Awareness Service
    handles objects in memory. An attacker who successfully
    exploited the vulnerability could allow an application
    with limited privileges on an affected system to execute
    code at a medium integrity level.  (CVE-2020-1437)

  - An information disclosure vulnerability exists in
    Windows when the Windows Imaging Component fails to
    properly handle objects in memory. An attacker who
    successfully exploited this vulnerability could obtain
    information to further compromise the user's system.
    There are multiple ways an attacker could exploit this
    vulnerability:  (CVE-2020-1397)

  - A remote code execution vulnerability exists when
    Windows Address Book (WAB) improperly processes vcard
    files.  (CVE-2020-1410)

  - An information disclosure vulnerability exists when the
    Windows Graphics component improperly handles objects in
    memory. An attacker who successfully exploited this
    vulnerability could obtain information to further
    compromise the users system. An authenticated attacker
    could exploit this vulnerability by running a specially
    crafted application. The update addresses the
    vulnerability by correcting how the Windows Graphics
    Component handles objects in memory. (CVE-2020-1351)

  - An elevation of privilege vulnerability exists when
    Group Policy Services Policy Processing improperly
    handle reparse points. An attacker who successfully
    exploited this vulnerability could overwrite a targeted
    file that would normally require elevated permissions.
    (CVE-2020-1333)

  - A remote code execution vulnerability exists when the
    Windows font library improperly handles specially
    crafted embedded fonts. An attacker who successfully
    exploited the vulnerability could take control of the
    affected system. An attacker could then install
    programs; view, change, or delete data; or create new
    accounts with full user rights.  (CVE-2020-1408)

  - An elevation of privilege vulnerability exists when the
    Windows Modules Installer improperly handles file
    operations. An attacker who successfully exploited this
    vulnerability could gain elevated privileges.
    (CVE-2020-1346)

  - An elevation of privilege vulnerability exists when
    Windows improperly handles calls to Advanced Local
    Procedure Call (ALPC). An attacker who successfully
    exploited this vulnerability could run arbitrary code in
    the security context of the local system. An attacker
    could then install programs; view, change, or delete
    data; or create new accounts with full user rights.
    (CVE-2020-1396)

  - An information disclosure vulnerability exists when
    Skype for Business is accessed via Internet Explorer. An
    attacker who exploited the vulnerability could cause the
    user to place a call without additional consent, leading
    to information disclosure of the user profile. For the
    vulnerability to be exploited, a user must click a
    specially crafted URL that prompts the Skype app.
    (CVE-2020-1432)

  - An elevation of privilege vulnerability exists when the
    Windows ActiveX Installer Service improperly handles
    memory.  (CVE-2020-1402)

  - A remote code execution vulnerability exists in .NET
    Framework, Microsoft SharePoint, and Visual Studio when
    the software fails to check the source markup of XML
    file input. An attacker who successfully exploited the
    vulnerability could run arbitrary code in the context of
    the process responsible for deserialization of the XML
    content.  (CVE-2020-1147)

  - An elevation of privilege vulnerability exists when the
    Windows Cryptography Next Generation (CNG) Key Isolation
    service improperly handles memory. An attacker who
    successfully exploited this vulnerability could run
    processes in an elevated context.  (CVE-2020-1359,
    CVE-2020-1384)

  - An elevation of privilege vulnerability exists in the
    way that the Windows Network Connections Service handles
    objects in memory. An attacker who successfully
    exploited the vulnerability could execute code with
    elevated permissions.  (CVE-2020-1373, CVE-2020-1390,
    CVE-2020-1427, CVE-2020-1428, CVE-2020-1438)

  - An elevation of privilege vulnerability exists in the
    way that the Windows Function Discovery Service handles
    objects in memory. An attacker who successfully
    exploited the vulnerability could execute code with
    elevated permissions.  (CVE-2020-1085)

  - A remote code execution vulnerability exists in the way
    that Microsoft Graphics Components handle objects in
    memory. An attacker who successfully exploited the
    vulnerability could execute arbitrary code on a target
    system.  (CVE-2020-1412)

  - A remote code execution vulnerability exists when the
    Windows Jet Database Engine improperly handles objects
    in memory. An attacker who successfully exploited this
    vulnerability could execute arbitrary code on a victim
    system. An attacker could exploit this vulnerability by
    enticing a victim to open a specially crafted file. The
    update addresses the vulnerability by correcting the way
    the Windows Jet Database Engine handles objects in
    memory. (CVE-2020-1400, CVE-2020-1401, CVE-2020-1407)

  - An information disclosure vulnerability exists when the
    Windows kernel fails to properly initialize a memory
    address. An attacker who successfully exploited this
    vulnerability could obtain information to further
    compromise the users system.  (CVE-2020-1389,
    CVE-2020-1419)

  - This security update corrects a denial of service in the
    Local Security Authority Subsystem Service (LSASS)
    caused when an authenticated attacker sends a specially
    crafted authentication request. A remote attacker who
    successfully exploited this vulnerability could cause a
    denial of service on the target system's LSASS service,
    which triggers an automatic reboot of the system. The
    security update addresses the vulnerability by changing
    the way that LSASS handles specially crafted
    authentication requests. (CVE-2020-1267)

  - A remote code execution vulnerability exists in the way
    that the Windows Graphics Device Interface (GDI) handles
    objects in the memory. An attacker who successfully
    exploited this vulnerability could take control of the
    affected system. An attacker could then install
    programs; view, change, or delete data; or create new
    accounts with full user rights.  (CVE-2020-1435)

  - A remote code execution vulnerability exists in
    Microsoft Windows that could allow remote code execution
    if a .LNK file is processed. An attacker who
    successfully exploited this vulnerability could gain the
    same user rights as the local user.  (CVE-2020-1421)");
  # https://support.microsoft.com/en-us/help/4565539/windows-7-update-kb4565539
  script_set_attribute(attribute:"see_also", value:"http://www.nessus.org/u?f84b756f");
  # https://support.microsoft.com/en-us/help/4565524/windows-7-update-kb4565524
  script_set_attribute(attribute:"see_also", value:"http://www.nessus.org/u?d3552b4f");
  script_set_attribute(attribute:"solution", value:
"Apply Security Only update KB4565539 or Cumulative Update KB4565524.");
  script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C");
  script_set_cvss_temporal_vector("CVSS2#E:H/RL:OF/RC:C");
  script_set_cvss3_base_vector("CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H");
  script_set_cvss3_temporal_vector("CVSS:3.0/E:H/RL:O/RC:C");
  script_set_attribute(attribute:"cvss_score_source", value:"CVE-2020-1435");

  script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
  script_set_attribute(attribute:"exploit_available", value:"true");
  script_set_attribute(attribute:"exploited_by_malware", value:"true");
  script_set_attribute(attribute:"metasploit_name", value:'SharePoint DataSet / DataTable Deserialization');
  script_set_attribute(attribute:"exploit_framework_metasploit", value:"true");

  script_set_attribute(attribute:"vuln_publication_date", value:"2020/07/14");
  script_set_attribute(attribute:"patch_publication_date", value:"2020/07/14");
  script_set_attribute(attribute:"plugin_publication_date", value:"2020/07/14");

  script_set_attribute(attribute:"plugin_type", value:"local");
  script_set_attribute(attribute:"cpe", value:"cpe:/o:microsoft:windows");
  script_set_attribute(attribute:"stig_severity", value:"I");
  script_end_attributes();

  script_category(ACT_GATHER_INFO);
  script_family(english:"Windows : Microsoft Bulletins");

  script_copyright(english:"This script is Copyright (C) 2020-2021 and is owned by Tenable, Inc. or an Affiliate thereof.");

  script_dependencies("smb_check_rollup.nasl", "smb_hotfixes.nasl", "ms_bulletin_checks_possible.nasl");
  script_require_keys("SMB/MS_Bulletin_Checks/Possible");
  script_require_ports(139, 445, "Host/patch_management_checks");

  exit(0);
}

include('smb_func.inc');
include('smb_hotfixes.inc');
include('smb_hotfixes_fcheck.inc');
include('smb_reg_query.inc');
include('install_func.inc');

get_kb_item_or_exit('SMB/MS_Bulletin_Checks/Possible');

bulletin = 'MS20-07';
kbs = make_list(
  '4565524',
  '4565539'
);

if (get_kb_item('Host/patch_management_checks')) hotfix_check_3rd_party(bulletin:bulletin, kbs:kbs, severity:SECURITY_HOLE);

get_kb_item_or_exit('SMB/Registry/Enumerated');
get_kb_item_or_exit('SMB/WindowsVersion', exit_code:1);

if (hotfix_check_sp_range(win7:'1') <= 0) audit(AUDIT_OS_SP_NOT_VULN);

share = hotfix_get_systemdrive(as_share:TRUE, exit_on_fail:TRUE);
if (!is_accessible_share(share:share)) audit(AUDIT_SHARE_FAIL, share);

if (
  smb_check_rollup(os:'6.1', 
                   sp:1,
                   rollup_date:'07_2020',
                   bulletin:bulletin,
                   rollup_kb_list:[4565524, 4565539])
)
{
  replace_kb_item(name:'SMB/Missing/'+bulletin, value:TRUE);
  hotfix_security_hole();
  hotfix_check_fversion_end();
  exit(0);
}
else
{
  hotfix_check_fversion_end();
  audit(AUDIT_HOST_NOT, hotfix_get_audit_report());
}


The latest version of this script can be found in these locations depending on your platform:

  • Linux / Unix:
    /opt/nessus/lib/nessus/plugins/smb_nt_ms20_jul_4565524.nasl
  • Windows:
    C:\ProgramData\Tenable\Nessus\nessus\plugins\smb_nt_ms20_jul_4565524.nasl
  • Mac OS X:
    /Library/Nessus/run/lib/nessus/plugins/smb_nt_ms20_jul_4565524.nasl

Go back to menu.

How to Run


Here is how to run the KB4565539: Windows 7 and Windows Server 2008 R2 July 2020 Security Update as a standalone plugin via the Nessus web user interface (https://localhost:8834/):

  1. Click to start a New Scan.
  2. Select Advanced Scan.
  3. Navigate to the Plugins tab.
  4. On the top right corner click to Disable All plugins.
  5. On the left side table select Windows : Microsoft Bulletins plugin family.
  6. On the right side table select KB4565539: Windows 7 and Windows Server 2008 R2 July 2020 Security Update plugin ID 138460.
  7. Specify the target on the Settings tab and click to Save the scan.
  8. Run the scan.

Here are a few examples of how to run the plugin in the command line. Note that the examples below demonstrate the usage on the Linux / Unix platform.

Basic usage:

/opt/nessus/bin/nasl smb_nt_ms20_jul_4565524.nasl -t <IP/HOST>

Run the plugin with audit trail message on the console:

/opt/nessus/bin/nasl -a smb_nt_ms20_jul_4565524.nasl -t <IP/HOST>

Run the plugin with trace script execution written to the console (useful for debugging):

/opt/nessus/bin/nasl -T - smb_nt_ms20_jul_4565524.nasl -t <IP/HOST>

Run the plugin with using a state file for the target and updating it (useful for running multiple plugins on the target):

/opt/nessus/bin/nasl -K /tmp/state smb_nt_ms20_jul_4565524.nasl -t <IP/HOST>

Go back to menu.

References


MSKB | Microsoft Knowledge Base:

  • 4565524, 4565539

MSFT | Microsoft Security Bulletin:

  • MS20-4565524, MS20-4565539

IAVA | Information Assurance Vulnerability Alert:

  • 2020-A-0306-S, 2020-A-0313-S

See also:

  • https://www.tenable.com/plugins/nessus/138460
  • http://www.nessus.org/u?d3552b4f
  • http://www.nessus.org/u?f84b756f
  • https://vulners.com/nessus/SMB_NT_MS20_JUL_4565524.NASL

Similar and related Nessus plugins:

  • 145867 — CentOS 8 : .NET Core (CESA-2020:2938)
  • 145908 — CentOS 8 : .NET Core 3.1 (CESA-2020:2954)
  • 138660 — Oracle Linux 8 : .NET / Core (ELSA-2020-2938)
  • 138661 — Oracle Linux 8 : .NET / 3.1 / Core (ELSA-2020-2954)
  • 138504 — RHEL 7 : .NET Core 2.1 on Red Hat Enterprise Linux (RHSA-2020:2937)
  • 138500 — RHEL 8 : .NET Core (RHSA-2020:2938)
  • 138505 — RHEL 7 : .NET Core 3.1 on Red Hat Enterprise Linux (RHSA-2020:2939)
  • 138609 — RHEL 8 : .NET Core 3.1 (RHSA-2020:2954)
  • 138842 — RHEL 8 : .NET Core (RHSA-2020:2988)
  • 138606 — RHEL 8 : .NET Core (RHSA-2020:2989)
  • 138453 — KB4558998: Windows 10 Version 1809 and Windows Server 2019 July 2020 Security Update
  • 138454 — KB4565483: Windows 10 Version 1903 and Windows 10 Version 1909 July 2020 Security Update
  • 138455 — KB4565489: Windows 10 Version 1803 July 2020 Security Update
  • 138456 — KB4565503: Windows 10 Version 2004 July 2020 Security Update
  • 138457 — KB4565508: Windows 10 Version 1709 July 2020 Security Update
  • 138458 — KB4565511: Windows 10 Version 1607 and Windows Server 2016 July 2020 Security Update
  • 138459 — KB4565513: Windows 10 July 2020 Security Update
  • 138461 — KB4565529: Windows Server 2008 July 2020 Security Update
  • 138462 — KB4565535: Windows Server 2012 July 2020 Security Update
  • 138463 — KB4565540: Windows 8.1 and Windows Server 2012 R2 July 2020 Security Update
  • 138465 — Security Update for .NET Core (July 2020)
  • 138466 — Security Update for .NET Core SDK (July 2020)
  • 138464 — Security Updates for Microsoft .NET Framework (July 2020)
  • 138512 — Security Updates for Microsoft SharePoint Server (July 2020)
  • 138473 — Security Updates for Microsoft Visual Studio Products (July 2020)

Version


This page has been produced using Nessus Professional 10.1.2 (#68) LINUX, Plugin set 202205072148.
Plugin file smb_nt_ms20_jul_4565524.nasl version 1.12. For more plugins, visit the Nessus Plugin Library.

Go back to menu.

  • Remove From My Forums
  • Вопрос

  • Hi,

    I cannot get KB4565539 to install on two servers running Windows Server 2008 R2 Service Pack 1. I can run the .msu package fine and it seems to install successfully, tells me that it needs to reboot to finish the update, but then upon reboot the package
    will fail (trying to apply the update before the login screen). I have the latest SSU on each server and have followed all of the steps/prerequisites in this article — https://support.microsoft.com/en-us/help/4565539/windows-7-update-kb4565539

    I found this helpful, but still neither 2020-07 Rollup (KB4565524) or 2020-07 Security only (KB4565539) will install after installing KB4565354 — https://docs.microsoft.com/en-us/answers/questions/30613/microsoft-windows-server-patches-not-installing-on.html

    I started a sfc scan and will run dism checks to see if anything is corrupted. I also checked out the CBS log and I see some errors but I’m not sure how to proceed. There is a lot in here, I took out what seems like it could help:

    ~

    2020-07-16 12:06:55, Info                  CBS    Appl: Selfupdate, Component: amd64_microsoft-windows-photo-image-codec_31bf3856ad364e35_0.0.0.0_none_1f323f66464683e5 (7.1.7601.18742), elevation:16,
    lower version revision holder: 7.1.7601.18325
    2020-07-16 12:06:55, Info                  CBS    Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: amd64_microsoft-windows-photo-image-codec_31bf3856ad364e35_7.1.7601.18742_none_eeadac95e75f3e9d,
    elevate: 16, applicable(true/false): 1
    2020-07-16 12:06:55, Info                  CBS    Appl: SelfUpdate detect, component: amd64_microsoft-windows-photo-image-codec_31bf3856ad364e35_7.1.7601.18742_none_eeadac95e75f3e9d, elevation: 16, applicable:
    1
    2020-07-16 12:06:55, Info                  CBS    Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed
    2020-07-16 12:06:55, Info                  CBS    Appl: Package: Package_3_for_KB3035126~31bf3856ad364e35~amd64~~6.1.1.2, Update: 3035126-6_neutral_GDR, Applicable: Applicable, Dis
    2020-07-16 12:06:55, Info                  CBS    External EvaluateApplicability, package: Package_3_for_KB3035126~31bf3856ad364e35~amd64~~6.1.1.2, package applicable State: Installed, highest update applicable
    state: Superseded, resulting applicable state:Superseded
    2020-07-16 12:06:55, Info                  CBS    Appl: detect Parent, Package: Package_4_for_KB3035126~31bf3856ad364e35~amd64~~6.1.1.2, Parent: WinEmb-Media-Support~31bf3856ad364e35~amd64~~6.1.7601.17514,
    Disposition = Detect, VersionComp: EQ, ServiceComp: EQ, BuildComp: EQ, DistributionComp: GE, RevisionComp: GE, Exist: present
    2020-07-16 12:06:55, Info                  CBS    Appl: detectParent: package: Package_4_for_KB3035126~31bf3856ad364e35~amd64~~6.1.1.2, no parent found, go absent
    2020-07-16 12:06:55, Info                  CBS    Appl: detect Parent, Package: Package_4_for_KB3035126~31bf3856ad364e35~amd64~~6.1.1.2, disposition state from detectParent: Absent
    2020-07-16 12:06:55, Info                  CBS    Appl: Evaluating package applicability for package Package_4_for_KB3035126~31bf3856ad364e35~amd64~~6.1.1.2, applicable state: Absent
    2020-07-16 12:06:55, Info                  CBS    EvaluateApplicability, package: Package_4_for_KB3035126~31bf3856ad364e35~amd64~~6.1.1.2, Package applicability: Absent.
    2020-07-16 12:06:55, Info                  CBS    External EvaluateApplicability, package: Package_for_KB3035126_SP1~31bf3856ad364e35~amd64~~6.1.1.2, package applicable State: Installed, highest update
    applicable state: Superseded, resulting applicable state:Superseded
    2020-07-16 12:06:55, Info                  CBS    External EvaluateApplicability, package: Package_for_KB3035126~31bf3856ad364e35~amd64~~6.1.1.2, package applicable State: Installed, highest update applicable
    state: Superseded, resulting applicable state:Superseded
    2020-07-16 12:06:55, Info                  CBS    Session: 30825355_544352502 initialized by client WindowsUpdateAgent.
    2020-07-16 12:07:08, Info                  CBS    Warning: Unrecognized packageExtended attribute.
    2020-07-16 12:07:08, Info                  CBS    Expecting attribute name [HRESULT = 0x800f080d — CBS_E_MANIFEST_INVALID_ITEM]
    2020-07-16 12:07:08, Info                  CBS    Failed to get next element [HRESULT = 0x800f080d — CBS_E_MANIFEST_INVALID_ITEM]
    2020-07-16 12:07:08, Info                  CBS    Warning: Unrecognized packageExtended attribute.

    ~

    much farther down in the CBS log:

    ~

    2020-07-16 12:12:30, Info                  CSI    0000006a@2020/7/16:16:12:30.312 CSI perf trace:
    CSIPERF:TXCOMMIT;447324
    2020-07-16 12:12:30, Info                  CSI    0000006b No more queue entries, deleted pending.xml
    2020-07-16 12:12:30, Info                  CBS    Startup: Primitive operations were successfully rolled back.
    2020-07-16 12:12:30, Error                 CBS    Startup: Completed rollback, startupPhase: 0. [HRESULT = 0x80004005 — E_FAIL]
    2020-07-16 12:12:30, Info                  CBS    Setting ExecuteState key to: CbsExecuteStateFailed
    2020-07-16 12:12:30, Info                  CBS    Doqe: Enabling Device installs
    2020-07-16 12:12:30, Info                  CSI    0000006c Cancelling transactions: [1:[78]»TI4.30825355_21249816:3/Package_for_KB4565539~31bf3856ad364e35~amd64~~6.1.1.11″[1]»]»

    2020-07-16 12:12:30, Info                  CSI    0000006d Creating NT transaction (seq 2), objectname [6]»(null)»
    2020-07-16 12:12:30, Info                  CSI    0000006e Created NT transaction (seq 2) result 0x00000000, handle @0x28c
    2020-07-16 12:12:30, Info                  CSI    0000006f@2020/7/16:16:12:30.890 CSI perf trace:
    CSIPERF:TXCOMMIT;99634
    2020-07-16 12:12:30, Info                  CBS    Clearing HangDetect value
    2020-07-16 12:12:30, Info                  CBS    Saved last global progress. Current: 1, Limit: 1, ExecuteState: CbsExecuteStateFailed
    2020-07-16 12:12:30, Info                  CBS    Doqe: Unlocking driver updates, Count 1
    2020-07-16 12:12:30, Info                  CBS    WER: Generating failure report for package: Package_for_KB4565539~31bf3856ad364e35~amd64~~6.1.1.11, status: 0x80070661, failure source: AI, start state:
    Staged, target state: Installed, client id: WindowsUpdateAgent
    2020-07-16 12:12:30, Info                  CBS    Failed to query DisableWerReporting flag.  Assuming not set… [HRESULT = 0x80070002 — ERROR_FILE_NOT_FOUND]
    2020-07-16 12:12:30, Info                  CBS    Failed to add %windir%\winsxs\pending.xml to WER report because it is missing.  Continuing without it…
    2020-07-16 12:12:30, Info                  CBS    Failed to add %windir%\winsxs\pending.xml.bad to WER report because it is missing.  Continuing without it…
    2020-07-16 12:12:30, Info                  CBS    Failed to submit WER report. [HRESULT = 0x800700a1 — ERROR_BAD_PATHNAME]
    2020-07-16 12:12:30, Info                  CBS    Failed to submit WER report. [HRESULT = 0x800700a1 — ERROR_BAD_PATHNAME]
    2020-07-16 12:12:30, Info                  CBS    WER: Failed to generate failure report for package: Package_for_KB4565539~31bf3856ad364e35~amd64~~6.1.1.11 [HRESULT = 0x800700a1 — ERROR_BAD_PATHNAME]
    2020-07-16 12:12:30, Info                  CBS    Failed to submit WER report for pending package: Package_for_KB4565539~31bf3856ad364e35~amd64~~6.1.1.11 [HRESULT = 0x800700a1 — ERROR_BAD_PATHNAME]
    2020-07-16 12:12:30, Info                  CBS    SQM: Reporting package change completion for package: Package_for_KB4565539~31bf3856ad364e35~amd64~~6.1.1.11, current: Staged, original: Staged, target:
    Installed, status: 0x80070661, failure source: AI, failure details: «Extended Security Updates AI installer
    80070661 38
    Install (upgrade) Microsoft-Windows-SLC-Component-ExtendedSecurityUpdatesAI, Culture=neutral, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=amd64, versionScope=NonSxS
    «, client id: WindowsUpdateAgent, initiated offline: False, execution sequence: 2370, first merged sequence: 2370
    2020-07-16 12:12:30, Info                  CBS    SQM: Failed to initialize Win SAT assessment. [HRESULT = 0x80040154 — Unknown Error]
    2020-07-16 12:12:30, Info                  CBS    SQM: average disk throughput datapoint is invalid [HRESULT = 0x80040154 — Unknown Error]
    2020-07-16 12:12:30, Info                  CBS    SQM: Upload requested for report: PackageChangeEnd_Package_for_KB4565539~31bf3856ad364e35~amd64~~6.1.1.11, session id: 142862, sample type: Standard
    2020-07-16 12:12:30, Info                  CBS    SQM: Ignoring upload request because the sample type is not enabled: Standard

    ~

    Any leads would be super appreciated as we really need this patch installed, thanks.

    *I am aware that 2008 R2 support ended in Jan 2020, multiple replication issues migrating to new version still working on it*

    • Изменено

      16 июля 2020 г. 17:11

  • Kb4490628 что за обновление windows 7
  • Kb5003791 активационный пакет для обновления до windows 10 версия 21h2 скачать
  • Kb4484071 скачать для windows 7 64 bit
  • Kb4490628 скачать для windows 7 64 bit скачать с официального
  • Kb5001716 что за обновление windows 10