Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Patch issues: MS09-035 and KB969898

Updated: 21 May 2010 | 1 comment
RichC's picture
+1 1 Vote
Login to vote

With MS09-035 it may be more of a Microsoft issue, however, with KB969898 it seems to be a reporting issue with Altiris.
 
I know there was already this thread that was open:  https://www-secure.symantec.com/connect/forums/ms09-035-kb973544-isnt-detected-applicable
but, as stated in that thread, MS did re-release this patch and i've been trying to get this last segment for over a week now.

MS09-035 as i'm sure most know is a wonderful mess of a Visual Studio patch.  They've already re-released it once.  I've gotten to the point where I have 35 machines remaining that need different portions of the patch and no matter how many times i've installed it, it keeps showing up as vulnerable. I've tried through the patch cycle, manually installing it, deploying from DS, even ripping it apart and using the msp within it (as suggested by a post I saw online about a conflict when VS wasn't installed with a 'typical' install or without Visual C++).  No dice.  Pretty much all of them need some combination of:

vs80sp1-kb971090
vs80sp1-kb973673
vs90sp1-kb971092
vs90sp1-kb973675
 

As for KB969898, it seems there's a reporting issue with any 2008 servers (there are a few others on the list, but the bulk are Server 2008)  It keeps saying they're vulnerable, but after some testing, the patch no longer applies or has already been applied.  I have over 30 machines still listed as vulnerable for this as well.

Any help is greatly appreciated.

Rich

Comments

KSchroeder's picture
21
Aug
2009
0 Votes 0
Login to vote

Check the rules

Rich,
AKB 42107 has links and information to several other articles that go into why this can happen.  It is a fairly common occurrence for the rules defined in the PMImport to need a bit of tweaking, particularly around non-default installs of applications.  In some cases, the rule may specify that a certain file must be version x.yyyy.zzzz.aaaa or higher to be "patched", but depending on the circumstance the file may not be present at all depending on the way the patch was installed.

Do you have an Altiris support contract?  If not, you should be able to report this (after verifying using the above) to support and get an incident opened.  It can be addressed in the next PMImport.

Thanks,
Kyle
Symantec Trusted Advisor

For Forum threads, please click "Mark as Solution" if answered.
For all content, please give a thumbs up if you agree with or support the post.