Vulnerability scan and Windows Update KB4025339

Federico Coppola 1,181 Reputation points
2020-10-14T22:09:53.797+00:00

Hi all,
In a company has been done a Vulnerability assessment using a dedicated software.
Vulnerability reports talks about a missing Windows Update on a VM with Windows 2016 Datacenter

The fix is install KB4025339 (more details here: https://www.tenable.com/plugins/nessus/101366)
I have seen that this WIndows Update is very old (year 2017) and I installed last windows update more or less a week ago.

After that I did not found this KB on Microsoft Catalog Update.

How can I solve it?
Thanks in advance

Federico

Windows for business Windows Server User experience Other
Windows for business Windows Server Devices and deployment Configure application groups
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2020-10-14T22:20:08.837+00:00

    Windows updates are now cumulative so the current update contains new fixes plus those of the previous cumulative updates.

    To bring windows current all that's needed is to install the latest SSU
    https://www.catalog.update.microsoft.com/Search.aspx?q=KB4576750

    followed by the latest cumulative update.
    https://www.catalog.update.microsoft.com/Search.aspx?q=KB4580346

    There's no harm in skipping those in between.

    Quality updates are cumulative, so installing the latest quality update is sufficient to get all the available fixes for a specific Windows 10 feature update, including any out-of-band security fixes and any servicing stack updates that might have been released previously.
    https://learn.microsoft.com/en-us/windows/deployment/update/get-started-updates-channels-tools

    How can I solve it?

    May need to ask the vendor about the problematic report.

    --please don't forget to Accept as answer if the reply is helpful--


7 additional answers

Sort by: Newest
  1. kearly37 1 Reputation point
    2021-09-20T21:44:05.513+00:00

    Tenable has a note that says that a registry or group policy setting must be changed for eh fix to take effect.


  2. Anonymous
    2020-10-19T17:34:49.013+00:00

    Glad to hear of success.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  3. Federico Coppola 1,181 Reputation points
    2020-10-19T17:33:10.277+00:00

    Dear @Anonymous ,
    I have upgraded to the lastest CU using our WSUS server with success.

    I will try to execute again vulnerability scan.

    Best regards
    Federico

    0 comments No comments

  4. Anonymous
    2020-10-16T14:42:14.457+00:00

    That's fine, follow up by installing the latest cumulative update.
    https://www.catalog.update.microsoft.com/Search.aspx?q=KB4580346

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.