Patch Management Group

 View Only
  • 1.  MS15-015 & MS15-011 Win Update Discrepancy?

    Trusted Advisor
    Posted Feb 18, 2015 09:33 AM

    Both bulletins appear to have installed through Symantec patch successfully.  Machines have been rebooted.

    The installed computers report shows all my test computers got both updates.  If I try to manually run the KB locally on the machines, it fails and says 'already installed."  However, windows update reports neither are installed.  I don't think I've ever had this happen in the last few years with Patch.  Once Symantec pushes the updates, it falls out of the needed microsoft windows update window.

    MS15-011 is especially important because of the group policy implications (see this link) so I need to make sure our clients really have it installed.

    When I look at the MS KB article for MS15-011, it mentions following file version check

    Appid.sys 6.1.7601.22736

    In system32 folder on my test PCs, the appid.sys file is only version 6.1.7601.17514 so I assume that's why win update is reporting this MS15-011 (KB3000483) is not installed.   MS15-015 similarly mentions that Appid.sys version being .22736.

    Anyone else seeing this discrepency?

    I put a ticket in with support, wish I caught this earlier...



  • 2.  RE: MS15-015 & MS15-011 Win Update Discrepancy?
    Best Answer

    Posted Feb 19, 2015 03:52 PM

    Just an FYI: Some operating systems have issues with IsApplicable=TRUE rule logic overtargetting and getting Exit Code: 2359302.

    Please view the following related Knowledge Management articles:

    MS15-011 - KM: TECH228493

    MS15-015 - KM: TECH228491

    These articles will be updated as the issues are resolved. 

     



  • 3.  RE: MS15-015 & MS15-011 Win Update Discrepancy?

    Trusted Advisor
    Posted Feb 20, 2015 12:17 PM

    Windows update seems to have corrected itself overnight.  Not sure what happened there.  Thanks for the followup, Joshua