Click here to get back home

Discrepancy between MS Update and MSBSA

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Discrepancy between MS Update and MSBSA Mike Bailey 08-23-2005
Posted by Mike Bailey on August 23, 2005, 12:30 pm
Please log in for more thread options
How is it that I get two totally different security reports from MS
Update and from MSBSA? I just don't understand this! I don't know
which one to trust and to go by.


Here are the results form MS Update:

High Priority(0)
Software, Optional(0)
Hardware, Optional (1)
No high -priority updates for your computer are available.
----------------------------------------------------------------------------
Here are the results form Microsoft Baseline Security Analysis:

Office Updates 1 update is missing.
SQL 1 critical security updates are missing. 1 products are
using a service pack not at the latest version or have other Server/MSDE
warnings.
MSXML 1 products are using a service pack not at the latest
version or have other warnings.
Windows 1 security updates could not be confirmed.


Mike B.


Posted by Hairy One Kenobi on August 23, 2005, 11:06 pm
Please log in for more thread options
> How is it that I get two totally different security reports from MS
> Update and from MSBSA? I just don't understand this! I don't know
> which one to trust and to go by.

MS Update is targeted at the OS, not the OS *and everything that you're
running on it*

HTH

Hairy One Kenobi

Disclaimer: the opinions expressed in this opinion do not necessarily
reflect the opinions of the highly-opinionated person expressing the opinion
in the first place. So there!




Posted by keith on August 24, 2005, 8:51 pm
Please log in for more thread options
Microsoft say the following:
===============================
MBSA and Windows Update (WU) analyze systems in different ways. WU for
instance only carries critical updates for the Windows operating system,
whereas MBSA will report missing security updates for the Windows operating
system and other Microsoft products such as SQL Server.

There are also cases where security updates are re-released, such as
MS02-008 and MS02-009. MBSA will always ensure that you have the latest
version of the update installed on your system. If you have the original
version of the MS02-008 or MS02-009 update, MBSA will indicate that the
update is not installed, since a newer release is available. However,
Windows Update may not indicate that a newer version is available since it
may be looking for different elements on the system to identify if this
update is present or not. Microsoft is working to resolve this inconsistency
so that MBSA, Windows Update, Microsoft Software Update Services, and SMS
security patch management will all use the same rules for determining the
presence of an update on Windows systems. This will ensure consistency for
all customers with the tool that best meets their needs. In the mean time,
users are encouraged to view the security bulletin for those updates that
they may have installed in the past that MBSA reports as missing to ensure
they indeed have the most recent version.
================================

See http://www.microsoft.com/technet/security/tools/mbsaqa.mspx or
http://www.microsoft.com/technet/security/tools/mbsa2/qa.mspx for more.

--
Cheers
Keith

> How is it that I get two totally different security reports from MS Update
> and from MSBSA? I just don't understand this! I don't know which one to
> trust and to go by.
>
>
> Here are the results form MS Update:
>
> High Priority(0) Software, Optional(0)
> Hardware, Optional (1)
> No high -priority updates for your computer are available.
> ----------------------------------------------------------------------------
> Here are the results form Microsoft Baseline Security Analysis:
>
> Office Updates 1 update is missing.
> SQL 1 critical security updates are missing. 1 products are
> using a service pack not at the latest version or have other Server/MSDE
> warnings.
> MSXML 1 products are using a service pack not at the latest
> version or have other warnings.
> Windows 1 security updates could not be confirmed.
>
>
> Mike B.




Similar ThreadsPosted
what to use for internal update infrastructure? July 18, 2006, 4:06 pm
Base Smart Card CSP Update December 7, 2005, 3:12 pm
Allow update of properties without allowing password changes, etc February 2, 2006, 10:29 am
IRS/Websense Update Phishing Alerts March 23, 2006, 10:17 am
Security Update MS06-033 / KB 917283 July 26, 2006, 4:22 am
922706 Update and certificate for computer July 17, 2008, 8:51 am
2nd try: 922706 Update and certificate for computer July 22, 2008, 5:16 am
Allow users to update Flash, Shockwave, Java May 24, 2006, 4:27 am
Dynamic DNS Update Corruption of Active Directory January 10, 2007, 12:39 pm
Having a custom warning message to update srvr logs June 8, 2005, 10:34 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap