News: 1663690512

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Admins run into Group Policy problems after Win10 update

(2022/09/20)


A recent cumulative update to Windows 10 is causing headaches for IT administrators who are experiencing problems with their Group Policy Object (GPO) capabilities.

Specifically, admins are complaining that after installing the [1]KB5017308 update for OS Builds 19042.2006, 19043.2006, and 19044.2006 that was introduced in the September 13 Patch Tuesday batch of releases, the GPO was no longer able to create or keep shortcuts that are used by end users.

Many users found the only way to correct the issue was to uninstall KB5017308, which allows for normal GPO operations but also eliminates the upgraded security capabilities the update provided. That said, one independent adviser suggested users experiencing problems "pause" the update until a solution can be found.

[2]

"GPO file copy seems to not work properly (shortcuts lose their icon and batch file is blank)," one user posted on [3]Reddit , adding they "can no longer deploy programs from Lansweeper."

[4]

[5]

Another Reddit post echoed the problem.

"Specifically, we copy a batch file into public\documents, then copy a shortcut to the current user's desktop to run it," they wrote. "Since the update, the icons are not transferring over for the shortcut (ie they are blank icons now) and the batch file is actually empty when copied over. It also appears to stop us being able to deploy from Lansweeper, as soon as we uninstall, it fixes it."

[6]Fix network printing or keep Windows secure? Admins would rather disable PrintNightmare patch

[7]AstraLocker ransomware reportedly closes doors to pursue cryptojacking

[8]Windows 11 update blocking some users from logging in

[9]Microsoft fixes Windows 'idiosyncrasy' that hampered some SMB file transfers

On a [10]Microsoft support site , a user posted that they had "almost the identical problem. All OK when I uninstalled but a little apprehensive because of the security updates. Today the update installed again, and the exact same thing happened ... Again!!! Uninstalled .... Again!!!"

They said they were "waiting now for it to download and reinstall itself again which will probably cost me yet another 2 hours updating and uninstalling. We need this fixed now!!!"

[11]

Microsoft noted the update was made to address security issues in the operating system.

While many users pointed to manually uninstalling the update as the answer, some administrators in the Microsoft support sites have suggested users can fix the broken desktop shortcuts problem by unchecking the "run in user security context" setting.

One user wrote that they assumed the "run in security context" was needed for the %userprofile% variable to work, but found it isn't.

[12]

For its part, in its description of KB5017308, Microsoft outlined how users can remove the combined latest cumulative update (LCU) and service stack update (SSU) after they're installed.

The company said administrators can "use the DISM/Remove-Package command line option with the LCU package name as the argument. You can find the package name by using this command: DISM /online /get-packages. Running Windows Update Standalone (wusa.exe) with the /uninstall switch on the combined package will not work because the combined package contains the SSU. You cannot remove the SSU from the system after installation."

The Register has asked Microsoft for comment on the issue. We'll update the story with any response. ®

Get our [13]Tech Resources



[1] https://support.microsoft.com/en-gb/topic/september-13-2022-kb5017308-os-builds-19042-2006-19043-2006-and-19044-2006-e4ea187e-28e8-4d4b-808b-2794babdce4c

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yyo387THWtirb@Gv3EGuHQAAAFI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.reddit.com/r/sysadmin/comments/xdyvrs/patch_tuesday_gpo_issues/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yyo387THWtirb@Gv3EGuHQAAAFI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yyo387THWtirb@Gv3EGuHQAAAFI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/09/21/microsoft_printnightmare/

[7] https://www.theregister.com/2022/07/06/astralocker-ransomware-shutters-operations/

[8] https://www.theregister.com/2022/09/09/microsoft_windows_11_signin_block/

[9] https://www.theregister.com/2022/08/30/microsoft_windows_server_compression/

[10] https://answers.microsoft.com/en-us/windows/forum/all/windows-10-update-kb5017308-breaks-shortcuts/67156263-7536-44d1-a9d8-f93d18b8941c?page=1

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yyo387THWtirb@Gv3EGuHQAAAFI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yyo387THWtirb@Gv3EGuHQAAAFI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



Jan K.

Wonder how many hours globally are wasted while dealing with these "issues"?

Here's a tiny, free tip for Microsoft: stop packing multiple types of updates into single packages...

Asking Ms to stop force-feeding updates unto innocent users is probably a step too far...

Good grief.

daflibble

It certainly beats the cluster F&*k of individual hotfixes we used to have. Managing that tangled mess was no fun. Although I would appreciate MS having more of a testing team to find and fix these still too common issues before rolling them out to millions of paying customers would be nice

That's how they get you.

Anonymous Coward

The shift off individual updates was for two reasons, neither of them to do with making your life easier. It was primarily to cut down on QC time at Microsoft's end, and they only had to test the roll-ups, not individual patches and their dependencies. Second is wallpapered over the crippling problems with the client side of windows update on 2016 and earlier releases. So many small patches would take longer to apply then the roll-ups.

This simple acted as an enabler for the worst habits of the update team. The stopped even pretending to do real QC after the roll-ups were introduced, and even with the rollups the 2016 and earlier update code was cripplingly slow. Instead of addressing this by backporting the update code to the earlier OS versions, they hoped we'd all just jump on the then brand spanking new 2019 server.

So we as admins/users collectively went from finicky individual updates that were slow, to monolithic updates that are also buggy and slow, but if one 4.5 rating CVE fix in the rolloup is bad, you have to uninstall the 9.8 rated RCE fix that's also in there. It's not faster, it's not more reliable, but when there is a problem the result is a long exploitation window with tons of visibility.

The better solution is to fix the updater and installers so fixes can be grouped and tested, but individually blocked or rolled back, and so a 25mb patch file doesn't take 45m and a reboot to install. Reboots should be for installing hardware.

Apparently not just GPOs and shortcuts in a Domain

jeff_w87

All the shortcuts on my home Windows PC all of sudden ended up with a .url extension and would no longer work. Removing the .url extension from the name did not help either. It would be really nice if Microsoft would spend some of their billions to actually, properly QC this trash OS before sending out patches to have their users Beta test for them.

Re: Apparently not just GPOs and shortcuts in a Domain

ThatOne

> It would be really nice if Microsoft would spend some of their billions to actually, properly QC this trash OS

Seriously, why would they do such a stupid thing? Does it harm their bottom line? No. Does it improve profits? Yes.

An honest politician is one who when he is bought will stay bought.
-- Simon Cameron

There are honest journalists like there are honest politicians. When
bought they stay bought.
-- Bill Moyers