Microsoft Issues Emergency Fixes After Massive Patch Tuesday

A graphic illustration of a software update icon.
Source: da-kuk via Getty Images

Microsoft on Monday issued out-of-band updates to address several issues caused by this month's massive, record-setting Patch Tuesday.

The emergency patches fix problems with Remote Desktop Services (RDS) that came to light last week, as well as unintended side effects for Hyper-V virtual machines and USB audio devices following the historic update last week.

September's Patch Tuesday addressed a whopping 974 unique CVEs, smashing the previous record set earlier this year; by comparison, Microsoft patched 909 CVEs in all of 2023. The release clearly illustrates how AI has supercharged vulnerability reporting and led to an alarming number of CVEs. And it may also indicate that faulty patches could become more common with increasingly large updates for software vendors.

"I think we should expect this risk to increase as patch volumes continue to grow, but the relationship is not simply that more patches automatically mean more broken systems," Ensar Seker, chief information security officer (CISO) at threat intelligence vendor SOCRadar, tells Dark Reading.

The bigger issue, Seker says, is the complexity of the modern technology landscape, with increasingly interconnected operating systems, cloud services, virtualization platforms, drivers, identity components, and legacy technologies. "Every additional dependency and supported configuration expands the testing matrix, and it becomes extremely difficult to reproduce every enterprise environment before a patch is released," he says.

Fixing September Patch Tuesday Issues

Microsoft flagged the RDS issues on Friday, noting that some organizations may experience issues after installing the Patch Tuesday update.

"In some environments, RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at 'Please wait for the Remote Desktop Configuration,'" Microsoft said in a health status update. "Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, and File Explorer might also become unresponsive."

Microsoft also said the Windows Update page may stop responding and continuously display a loading indicator. Additionally, September's Patch Tuesday created issues for Hyper-V, as some host folder shares were suddenly unavailable in Hyper-V-based Linux VMs, as well as some USB audio devices in multichannel mode, which either failed to start or produce any sound.

Seker notes that with the increasingly rapid exploitation of vulnerabilities, organizations are under enormous pressure to patch faster, which creates "an unavoidable tension between security urgency and regression testing."

"What happened with Remote Desktop Services and Hyper-V is a good example of why patch management has effectively become part of operational resilience," he says. "Delaying patches can leave organizations exposed to active exploitation, but deploying a problematic update directly into production can disrupt critical services."

The best approach, Seker says, is not to deploy everything immediately and instead apply risk-based patching, using staged deployment rings, representative test environments, rollback capabilities, and enhanced monitoring.

"As patch volumes and software complexity increase," he says, "organizations need to become better at safely deploying patches rather than assuming vendors will be able to eliminate every unintended side effect before release."

Tyler Reguly, associate director of security R&D at Fortra, agrees and says security teams need to even more diligent about verifying patches before wide-scale deployment, because there are no independent bodies or regulatory agencies that will do that for them.

"This lack of external safeguards is why testing patches as they roll out is so critical and why we should never let ourselves get to the point of immediately pushing updates without proper testing," Reguly says.

source: DarkReading