Skip Links

Network World

Julie Bort

Nearly half of Microsoft's 2010 security patches have known problems

Yet Microsoft updates rarely seem to bring down users' systems

By Microsoft Subnet on Tue, 07/27/10 - 5:08pm.

Last month's fix of a broken Windows Server patch got me thinking -- just how often does Microsoft release a patch that it knows has problems? The answer: nearly half the time. How often are those problems so severe they fry your system? That's less clear, but it seems as if the answer is, "not all that often."

Microsoft patches with known problemsMicrosoft has so far released 45 updates in 2010, some fixing multiple vulnerabilities. Of them, 20 were released with a known problem (see list below) but of those, only two had issues severe enough to warrant a fix and re-release of the patch altogether. Those two patches were MS10-024 and MS10-025. Both were originally released during April's patch cycle. 024 was re-released in July after users began reporting that the patch hosed their systems and that Microsoft's workarounds didn't work. 025, also originally released in the April Patch Tuesday, was re-released two weeks later.

"The [025] bulletin was rated critical and affected Windows Media Services. On April 21st, Microsoft pulled the bulletin from their webpage as they found the patch did not fully fix the vulnerability as intended.  On April 27th, Microsoft re-released the bulletin as it addressed the vulnerability as originally intended.  With this bulletin, this had a pretty low impact on administrators as it only affected Windows 2000 SP4 with Windows Media Services installed.  This service is not installed by default, so this type of software scenario is typically quite rare," explains Jason Miller, data and security team manager for patch management vendor, Shavlik Technologies, Minneapolis.

The number of re-releases isn't a good indicator of how many bulletins hose a users's systems. As Miller notes, each bulletin may fix multiple vulnerabilities and if Microsoft changes one patch, it may not re-release the whole bulletin. Users might get a cumulative patch bulletin for the product (common for Internet Explorer, for instance). One would assume that these new fixes are rolled into the next service pack, too.

Additionally, Microsoft will re-release a bulletin not because the patch is faulty but because it is updating the list of software known to be affected (usually adding, not subtracting) or because Windows Update is just plain confused. "There are cases where a patch will be detected as missing when it is actually installed.  Microsoft has made changes to patches addressing these detection and deployment issues.  If the patch has already been applied, no action is required by the administrator as the vulnerability has been fixed," Miller adds.

Still, I wanted some measure of how many patches cause problems. So I counted the number of bulletins released in 2010 with stated known issues. This doesn't indicate how badly these issues might affect the performance of the machine it was meant to fix. For instance, below is the known issue and its fix for MS10-040, a June patch rated "important" that fixes a hole in IIS.

This security update could cause IIS application pools to not start on installations of Windows Server 2003 SP2 where IIS 6 may contain some SP1 binaries. In this case, the System log displays the following error message when the IIS service is started:

Event ID 1009, Description: A process serving application pool 'DefaultAppPool' terminated unexpectedly. The process id was '1234'

To resolve this problem, reapply Windows Server 2003 SP2 on the affected computers, and then install this security update.

This sounds like a patch that could hose a system, and yet the fix sounds reasonable -- make sure your WS2003 SP2 computers are fully running SP2.

According to my research, these are the 2010 patches with known issues:


MS10-003 MS10-019  MS10-024 MS10-039
MS10-004 MS10-020 MS10-031 MS10-040
MS10-011 MS10-021 MS10-033 MS10-041
MS10-015 MS10-022 MS10-036 MS10-044
MS10-017 MS10-023 MS10-038 MS10-045

A tip from a reader leads me to believe that despite known issues on all the above patches, Microsoft updates don't hose a system all that often. (Thank you George Heindel from Custom Computers.) A couple of weeks ago, a TechRepublic article posted the results of a unscientific poll that asked readers how often Windows patches break their system. Of the 841 respondents, 72% said patches hardly ever, or never, gave them problems. Only 5% reported that patches broke their systems every month -- poor souls.

Windows Patches breaking system

Check out these other posts from Microsoft Subnet

Like RSS? Subscribe to all Microsoft Subnet bloggers.
Like e-mail? Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)
Like Twitter? Follow All Microsoft Subnet bloggers on Twitter @microsoftsubnet

Follow Julie Bort on Twitter @Julie188 or connect with me on my Facebook Like Page

What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
About The Microsoft Update

Julie BortJulie Bort is the editor of Microsoft Subnet and Network World's Online Community Editor. She also writes the Open Source Subnet blog and is the editor responsible for the Cisco Subnet and Open Source Subnet web sites. If you have an idea for a blog, or a news tip on Microsoft, Cisco or Open Source technologies, contact her at jbort@nww.com, 970-482-6454 or follow Julie on Twitter @Julie188.

The Microsoft Subnet blog is the official blog of the Network World's Microsoft Subnet community. Microsoft Subnet is the independent voice of Microsoft customers and is your gateway to daily Microsoft news, blogs, opinion, books, prize giveaways and more. Visit the Microsoft Subnet index page daily, and while you are there, subscribe to the Microsoft newsletter.

Become a Facebook Fan of Julie Bort

Policy on comments: Respectful discussion is welcomed! However comments that use inappropriate language, consist of name calling or personal attacks, or include accusations of wrongdoing are not appropriate. Those comments will be deleted or edited

 

Most Discussed Posts

Blog Roll
Microsoft Subnet Home Page
http://www.networkworld.com/subnets/microsoft/
All Microsoft Subnet bloggers
http://www.networkworld.com/community/blogs/microsoft/feed
ActiveWin
http://www.activewin.com
Blake Handler The Road to Know Where
http://bhandler.spaces.live.com/
Dmitry's PowerBlog
http://dmitrysotnikov.wordpress.com/
Doug Brown,DABCC
http://www.dabcc.com
Ed Bott's Windows Expertise
http://www.edbott.com/weblog/
Joseph Tartakoff Microsoft Blog
http://blog.seattlepi.nwsource.com/microsoft/
Long Zheng istartedsomething
http://www.istartedsomething.com/
Mini-Microsoft
http://minimsft.blogspot.com/
Paul Thurrott's Supersite for Windows
http://www.winsupersite.com
Robert McLaws WindowsNow
http://www.windows-now.com
Scobleizer
http://scobleizer.com/
Techmeme
http://www.techmeme.com/
Todd Bishop's Microsoft Blog
http://www.techflash.com/Microsoft