Microsoft at it again; withdraws yet another buggy update KB 2949927

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
Microsoft seems to be at it again; first puts up a buggy update only to remove it
Microsoft engineers are sure having the roughest patch of their careers. They did the same thing last month (reported on comboupdates.com) and on Tuesday repeated it. A update containing several patches was released by Microsoft as a part of mega fix called Black Tuesday, for all the CVE’s reported to Microsoft. It seems that one of the update was causing the system reboots in loops after installation. The issue flared up all over the techforums and of course, Reddit, forcing, Microsoft to withdraw the update.

Microsoft Security Advisory 2949927
The said update released on Tuesday and described in Microsoft Security Advisory 2949927. Microsoft Security Advisory 2949927 has added SHA-2 hash algorithm signing and verification for Windows 7 and Windows Server 2008 R2. However the update seemed to be malworking causing the users to reboot their systems in a loop.

It was one of three proactive security feature updates released on Tuesday in addition to the eight patches of Windows and Office.

On Friday, October 17 Microsoft revised the 2949927 advisory with the following statement:

Removed Download Center links for Microsoft security update 2949927. Microsoft recommends that customers experiencing issues uninstall this update. Microsoft is investigating behavior associated with this update, and will update the advisory when more information becomes available.

Let’s start with the less upsetting patch, KB 2952664. It was released to the Automatic Update chute on Oct. 14, this month’s Black Tuesday. The ensuing uproar and the backlash on the tech forums was so bad as the patch failed to install on many Windows 7 machines and was giving error 80242016.

The more disconcerting patch, KB 2949927 mentioned above was one of the four botched patches.It is supposed to add SHA-2 hash signing and verification capability to Windows 7. But if a user tries installing, some machines reported to lead to multiple reboots failing with error 80004005

The workaround
There was a complex workaround has been proposed by Pavel Stastny on the TechNet forum and is further explained by Intros9 on Reddit.



Amidst the brouhaha, Microsoft quietly yanked off the patch on Thursday without any explanation. As of now, the article on Technet doesn’t describe the multiple-reboot failure problem, nor does the Security Advisory and the direct download links in the Security Advisory lead to “We are sorry, the page you requested cannot be found” pages.
 

Adhit Prakosho

Level 19
Verified
Top Poster
Well-known
Sep 14, 2014
929
But if a user tries installing, some machines reported to lead to multiple reboots failing with error 80004005

I installed the update, and no problems for 2 these days :)
KB_coy.png


Microsoft Security Advisory: Availability of SHA-2 hashing algorithm for Windows 7 and Windows Server 2008 R2: October 14, 2014

This update has been removed from the Download Center because of an issue with the update. Microsoft is researching this problem and will post more information in this article when the information becomes available. We recommend that customers who are experiencing issues with this update uninstall this update. To do this, follow these steps:
  1. Click Start, click Control Panel, click Programs and Features, and then click View installed updates.
  2. Select "Security update for Microsoft Windows (KB2949927)" and then click Uninstall.
For more information about how to uninstall an update, visit the following Microsoft webpage:
http://windows.microsoft.com/en-us/windows/remove-update#1TC=windows-7

Here's some info on bcdedit errors and possible problems/solutions: http://windows.microsoft.com/en-US/...vice-pack-1-sp1-installation-error-0x800F0A12

microsoft support : http://support.microsoft.com/kb/2949927
 
Last edited by a moderator:
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top