[Troubleshooting] Windows Vulnerability Patching
  

Siva Posted 23 May 2023 01:50

ES Manager shows that the endpoint requires a patching (KB 5016629), but when clicked on Patch it shows "Patching failed"

We can refer to several logs when troubleshooting vulnerability patching issues on Windows.

1. Download Log – This is the log where we can see the agent downloads particular KB patch from the download server.
C:\Program Files\SF\EDR\agent\var\log\sfpatch\patch\down\

2. Install Log – Here we can see the agent tries to install the downloaded .cab patch using Windows built-in DISM tool.
C:\Program Files\SF\EDR\agent\var\log\sfpatch\patch\install\

3. Patch log – This is a general log that briefly shows the combination of download and installation of the KB patch.
C:\Program Files\SF\EDR\agent\var\log\sfpatch\patch

4. DISM log – The agent installs patch using the Windows DISM command.
C:\Windows\Logs\DISM\

5. CBS Log – This log shows all the changes made on the Windows system file.
C:\Windows\Logs\CBS\CBS.log

6. Download the patch as (.msu) installer from Microsoft Catalog portal in order to determine if there is issue with DISM install method.

7. Retrieve the installed patch details on the endpoint. (cmd > systeminfo.exe)

8. Compare the installed patch on endpoint and the KB5016629 details as shown in Microsoft Catalog. We can see the the endpoint had already installed a newer patch (KB5026368) that replaces KB5016629.

In this scenario, the vulnerability patch can be ignored as the endpoint had already installed a newer KB patch.

Like this topic? Like it or reward the author.

Creating a topic earns you 5 coins. A featured or excellent topic earns you more coins. What is Coin?

Enter your mobile phone number and company name for better service. Go

Moderator on This Board

3
1
2

Started Topics

Followers

Follow

1
0
4

Started Topics

Followers

Follow

18
8
0

Started Topics

Followers

Follow

Trending Topics

Board Leaders