Vulnerability scan and Windows Update KB4025339

Federico Coppola 1,181 Reputation points
2020-10-14T22:09:53.797+00:00

Hi all,
In a company has been done a Vulnerability assessment using a dedicated software.
Vulnerability reports talks about a missing Windows Update on a VM with Windows 2016 Datacenter

The fix is install KB4025339 (more details here: https://www.tenable.com/plugins/nessus/101366)
I have seen that this WIndows Update is very old (year 2017) and I installed last windows update more or less a week ago.

After that I did not found this KB on Microsoft Catalog Update.

How can I solve it?
Thanks in advance

Federico

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,902 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
1,044 questions
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2020-10-14T22:20:08.837+00:00

    Windows updates are now cumulative so the current update contains new fixes plus those of the previous cumulative updates.

    To bring windows current all that's needed is to install the latest SSU
    https://www.catalog.update.microsoft.com/Search.aspx?q=KB4576750

    followed by the latest cumulative update.
    https://www.catalog.update.microsoft.com/Search.aspx?q=KB4580346

    There's no harm in skipping those in between.

    Quality updates are cumulative, so installing the latest quality update is sufficient to get all the available fixes for a specific Windows 10 feature update, including any out-of-band security fixes and any servicing stack updates that might have been released previously.
    https://learn.microsoft.com/en-us/windows/deployment/update/get-started-updates-channels-tools

    How can I solve it?

    May need to ask the vendor about the problematic report.

    --please don't forget to Accept as answer if the reply is helpful--


7 additional answers

Sort by: Most helpful
  1. Federico Coppola 1,181 Reputation points
    2020-10-15T19:09:30.24+00:00

    Hi @Anonymous ,
    thanks so much for your suggestions!

    I will follow your steps during next days!

    Best regards
    Federico

    0 comments No comments

  2. Anonymous
    2020-10-15T19:10:50.693+00:00

    Glad to hear it was helpful.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  3. Federico Coppola 1,181 Reputation points
    2020-10-16T14:39:32.133+00:00

    Hi @Anonymous
    I have tried to download and install the latest SSU and latest cumulative update manually.
    Servers say that they have already these updates.

    33011-image.png

    In fact inside company there is a WSUS server and it sound stange me when this vulnerability tool notify me this vulnerability.
    Thanks for your help

    0 comments No comments

  4. Anonymous
    2020-10-16T14:42:14.457+00:00

    That's fine, follow up by installing the latest cumulative update.
    https://www.catalog.update.microsoft.com/Search.aspx?q=KB4580346

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.