Patch Tuesday updates spark errors when creating Hyper-V VMs
- Reference: 1671039056
- News link: https://www.theregister.co.uk/2022/12/14/microsoft_patch_tuesday_vm/
- Source link:
The software giant is warning the problem can arise after installing the [1]KB5021249 or [2]KB5021237 [3]updates on Windows Server or Azure Stack HCI hosts that are managed by System Center Virtual Machine Manager (SCVMM) and are in software-defined networking (SDN)-enabled environments with a network controller.
The issue affects Windows Server 2019 and Windows Server 2022.
[4]
Windows administrators trying to create "a new Network Adapter (also called a Network Interface Card or NIC) joined to a VM network or a new Virtual Machine (VM) with a Network Adapter joined to a VM network" could see errors pop up, Microsoft engineers [5]wrote in an update in the Windows Health Dashboard.
[6]
[7]
Windows admins may get messages warning about Ethernet connection errors when creating a new VM or network adapter on an existing VM, if an SDN software load balancer service fails, or if an SDN RAS Gateway service fails, according to Microsoft.
Existing VMs with existing network adapters won't have connection issues after installing the update, the company said. Only new network adapters created after installing KB502129 will be affected.
[8]Windows Server domain controllers may stop, restart after recent updates
[9]Microsoft's attempts to harden Kerberos authentication broke it on Windows Servers
[10]Microsoft squashes six security bugs already exploited in the wild
[11]Unofficial fix emerges for Windows bug abused to infect home PCs with ransomware
Microsoft engineers are working on a fix for the problem that will be included in an upcoming release. In the meantime, the company has developed a workaround.
Users can open an elevated PowerShell window on all SCVMM-managed Hyper-V hosts by hitting the Start button and typing "powershell," then right clicking or long pressing on it. They can then select "Run as Administrator" and run the following commands:
[12]
$lang = (Get-WinSystemLocale).Name
C:\Windows\system32\wbem\mofcomp.exe C:\Windows\system32\wbem\en-US\VfpExt.mfl
C:\Windows\system32\wbem\mofcomp.exe C:\Windows\system32\wbem\VfpExt.mof
[13]
In addition, they can find a script for the workaround for large-scale deployments and a post-install script to be integrated with patching tools. Both scripts are available [14]here .
Users don't have to reboot a system after applying the workaround, according to Microsoft. ®
Speaking of Microsoft... The Windows giant [15]said on Tuesday it has suspended several third-party developer accounts that would submit malicious operating system hardware drivers for Microsoft to cryptographically sign. It has also, we're told, taken steps to block the use of this code.
Those drivers, once approved by Microsoft, would be trusted by people's Windows PCs, and could be used by miscreants on compromised machines to help fully take over systems. Essentially, someone would find a way to get onto a victim's computer, gain admin access, and then load one of these drivers to achieve further control over the system.
As discovered, disclosed to Microsoft, and this week publicly detailed by [16]SentinelOne , [17]Mandiant , and [18]Sophos , cybercrime crews successfully managed to get their malicious drivers certified by Microsoft via its Windows Hardware Developer Program.
This includes a so-called POORTRY kernel-mode driver that would be used to kill off security and antivirus tools on the compromised Windows PC. This code was, it's reported, used to help infect networks with ransomware. It's said that the Hive gang and others made use of the drivers.
It would be great if Microsoft didn't approve malicious drivers submitted to its developer programs. "Microsoft Partner Center is also working on long-term solutions to address these deceptive practices and prevent future customer impacts," the biz said.
Get our [19]Tech Resources
[1] https://support.microsoft.com/en-us/topic/december-13-2022-kb5021249-os-build-20348-1366-d5fe7608-bc9d-4055-a88c-fb2fd3d5fd45
[2] https://support.microsoft.com/en-us/topic/december-13-2022-kb5021237-os-build-17763-3770-8c1506cc-e030-4cf1-8cd6-774091f46f34
[3] https://www.theregister.com/2022/12/14/microsoft_december_patch_tuesday/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y5pVmeMsP90J@qHz4xM4nQAAAJE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#2978msgdesc
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5pVmeMsP90J@qHz4xM4nQAAAJE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y5pVmeMsP90J@qHz4xM4nQAAAJE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/11/28/microsoft_windows_server_lsass/
[9] https://www.theregister.com/2022/11/21/microsoft_kerberos_fix_windows/
[10] https://www.theregister.com/2022/11/09/microsoft_november_2022_patch_tuesday/
[11] https://www.theregister.com/2022/11/01/microsoft_motw_malware_flaw/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5pVmeMsP90J@qHz4xM4nQAAAJE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y5pVmeMsP90J@qHz4xM4nQAAAJE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://support.microsoft.com/en-us/topic/win12b-issue-in-system-center-virtual-machine-manager-3aeadda7-1c37-4005-b5cc-a18fba0017e1
[15] https://msrc.microsoft.com/update-guide/vulnerability/ADV220005
[16] https://www.sentinelone.com/labs/driving-through-defenses-targeted-attacks-leverage-signed-malicious-microsoft-drivers/
[17] https://www.mandiant.com/resources/blog/hunting-attestation-signed-malware
[18] https://news.sophos.com/en-us/2022/12/13/signed-driver-malware-moves-up-the-software-trust-chain/
[19] https://whitepapers.theregister.com/
Patch Tuesday : Something's broken
BAU.
Move along there. Nothing new to see.
MicroShit has pooped again.
MS Edge on Win7
As MS has repeatedly reminded me, MS Edge has reached end-of-life on Win7. Somebody forgot to tell MS.
I had the 'canary' distribution (that's canary as in coal mine, a bleeding-edge distribution). Unfortunately, after telling us that it would not be updated any further ... it was updated. With a version that does not work on Win7.
Trying to fix that by rolling back lost all bookmarks, so I'm not feeling pleased.
Re: MS Edge on Win7
1) Stop running Windows 7.
2) Stop running Edge.
3) Take backups.
4) If you insist on just pushing updates to your systems, at least utilise the fact that you can stop updates on 7 quite easily, and then checkpoint, test, rollback them individually as necessary.
5) Stop running "bleeding-edge" and then complaining that you have blood on your shirt.
Almost like this huge multi-national corporation which supplies military, government, huge business, millions of customers around the world, could afford to create an automated testing suite that deploys updates to a variety of configurations of machines automatically and continuously in their massive cloud datacenters, and tests basic functionality of a huge raft of settings and processes, so that obvious errors like this flag in their testing BEFORE they roll them out to the entire planet.
Ah, good. Unintelligible copy&paste scripts on the Internet to fix security problems. I'll run those as soon as I use my credit card to release my free iPhone from the postal service and see what the guy in the van outside wants to show me.
Pro tip
Stop using microsoft products, problem sorted