Flexis October 2024 Patch Recommendation

Patches Microsoft released in October 2024:

 

  • KB5044281: 2024-10 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems
  • KB5044277: 2024-10 Cumulative Update for Windows Server 2019 for x64-based Systems
  • KB5044293: 2024-10 Cumulative Update for Windows Server 2016 for x64-based Systems

Impacted Products:

Microsoft Windows

Microsoft Edge

(HTML-based)

Microsoft Edge

 (Chromium-based)

Internet Explorer

Microsoft Office and Microsoft Office Services and Web Apps

Windows Defender

Visual Studio

ASP.NET Core

Chakra Core

Microsoft Dynamics

.NET Framework

.NET Core

Please note the following information regarding the security updates:

Windows 10, version 1607 Mobile and Mobile Enterprise editions reached the end of support (EOS) on October 9, 2018. These editions will no longer be offered servicing stack updates.

Windows 10, version 1607 IoT Core edition reached the end of support on April 10, 2018. This edition will no longer be offered servicing stack updates.

Windows 10, version 1607 IoT Core Enterprise edition reached the end of support on April 9, 2019. This edition will no longer be offered servicing stack updates.

Windows 10, version 1607 Enterprise, Education, Pro, Home, and Pro for Workstation reached end of support on January 10, 2023. These editions will no longer be offered servicing stack updates.

Windows 10 Enterprise N 2016 LTSB and Windows 10 IoT Enterprise 2016 LTSB will reach the end of support on October 13, 2026.

To continue receiving these updates, we recommend updating to the latest update of Windows. For more information, see Get the latest Windows update.

Windows Server 2016 Datacenter edition, Nano Server installation, and Standard edition, Nano Server installation options reached the end of support on October 9, 2018.

Windows Server 2016 Essentials, Datacenter, Standard, Multipoint Premium Server, and Hyper-V Server will reach the end of support on January 12, 2027.

KB5044281: Windows Server 2022

Improvements

  • [Software Defined Networking (SDN)] New! The SDN API now performs better for large-scale deployments. Watch for load balancer connectivity issues after you install this update. If you have any, move the SDNAPI microservice to another node. An SDN admin can move the service. To do that, use the Move-ServiceFabricPrimaryReplica PowerShell cmdlet.
  • [MSIX applications] Fixed: When you install them from an HTTPS URI, they fail to open. This issue occurs when the download of the app is not complete. This damages the package.
  • [Task Manager] Fixed: It stops responding when you select the “Performance” tab.
  • [Direct Composition batched presentations] Fixed: A brief flash of triangles or boxes show on the screen. This issue affects browsers, like Microsoft Edge, and other apps.
  • [Input Method Editor (IME)] Fixed: When a combo box has input focus, a memory leak might occur when you close that window.
  • [AppLocker] Fixed: The rule collection enforcement mode is not overwritten when rules merge with a collection that has no rules. This occurs when the enforcement mode is set to “Not Configured.”
  • ​​​​​​​[Remote Desktop (known issue)] Fixed: Windows Servers might disrupt Remote Desktop connections across your company. This issue might occur if you use a legacy protocol in the Remote Desktop Gateway. An example protocol is Remote Procedure Call over HTTP. If the issue occurs, it is sporadic, like every 30 minutes. At that point, you lose sessions that you are signed in to. Then you must reconnect to the server. IT admins can track this as an end to the TSGateway service. It stops responding, with the exception code 0xc0000005.
  • [Containers (known issue)] Fixed: Container networking on Kubernetes might not work as you expect. Containers fail to reach external networks or communicate between pods. It might affect you when you use Calico to set up container networking on development or production instances. If affected, containers will not connect to the internet. The host’s firewall also blocks network traffic. When you ping external addresses, like ‘microsoft.com,’ you might get a general failure error message.

Known issues in this update

Symptom

After installing this security update, you might face issues with booting Linux if you have enabled the dual-boot setup for Windows and Linux in your device. Resulting from this issue, your device might fail to boot Linux and show the error message “Verifying shim SBAT data failed: Security Policy Violation. Something has gone seriously wrong: SBAT self-check failed: Security Policy Violation.”

The August 2024 Windows security update applies a Secure Boot Advanced Targeting (SBAT) setting to devices that run Windows to block old, vulnerable boot managers. This SBAT update will not be applied to devices where dual booting is detected. On some devices, the dual-boot detection did not detect some customized methods of dual-booting and applied the SBAT value when it should not have been applied.

Workaround

Please refer to the workaround mentioned in Windows release health site for this issue.

KB5044277: Win 10 Ent LTSC 2019 Win 10 IoT Ent LTSC 2019 Windows 10 IoT Core LTSC Windows Server 2019

Improvements

This security update includes improvements. Below is a summary of the key issues that this update addresses when you install this KB. If there are new features, it lists them as well. The bold text within the brackets indicates the item or area of the change we are documenting.

  • [FrameShutdownDelay] Fixed: The browser ignores its value in the “HKLM\SOFTWARE\Microsoft\Internet Explorer\Main” registry key.
  • ​​​​​​​[Remote Desktop (known issue)] Fixed: Windows Servers might disrupt Remote Desktop connections across your company. This issue might occur if you use a legacy protocol in the Remote Desktop Gateway. An example protocol is Remote Procedure Call over HTTP. If the issue occurs, it is sporadic, like every 30 minutes. At that point, you lose sessions that you are signed in to. Then you must reconnect to the server. IT admins can track this as an end to the TSGateway service. It stops responding, with the exception code 0xc0000005.

Known issues in this update

Microsoft is not currently aware of any issues with this update.

KB5044293: Win 10 Ent LTSB 2016 Win 10 IoT Ent LTSB 2016 Windows Server 2016

Improvements

This security update includes quality improvements. Below is a summary of the key issues that this update addresses when you install this KB. If there are new features, it lists them as well. The bold text within the brackets indicates the item or area of the change we are documenting.

 

​​​​​​​[Remote Desktop (known issue)] Fixed: Windows Servers might disrupt Remote Desktop connections across your company. This issue might occur if you use a legacy protocol in the Remote Desktop Gateway. An example protocol is Remote Procedure Call over HTTP. If the issue occurs, it is sporadic, like every 30 minutes. At that point, you lose sessions that you are signed in to. Then you must reconnect to the server. IT admins can track this as an end to the TSGateway service. It stops responding, with the exception code 0xc0000005.

Known issues in this update

Microsoft is not currently aware of any issues with this update.​​​​​​​