Microsoft Issues Emergency Fixes After Massive Patch Tuesday
Microsoft released out-of-band updates to address several unexpected issues stemming from September's Patch Tuesday, a record-breaking update that included 974 CVEs. The problems centered around Remote Desktop Services (RDS) causing connection instability and issues with Hyper-V virtual machines and USB audio devices. Microsoft stressed the importance of risk-based patching and thorough testing before deploying updates to mitigate potential disruptions and exploitation.
Microsoft issued out-of-band updates on Monday to address several unexpected problems resulting from September's Patch Tuesday, a record-setting update that included 974 unique CVEs. The primary issues revolved around Remote Desktop Services (RDS), where some organizations experienced unstable connections, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at ‘Please wait for the Remote Desktop Configuration.’ Additionally, September’s Patch Tuesday created problems for Hyper-V, as some host folder shares were suddenly unavailable in Hyper-V-based Linux VMs, and some USB audio devices in multichannel mode either failed to start or produce any sound.
Microsoft flagged the RDS issues on Friday, noting that organizations might encounter problems after installing the Patch Tuesday update. The company’s health status update highlighted the potential for Microsoft Management Console (MMC), RDS Licensing Diagnoser, and File Explorer to become unresponsive.
“I think we should expect this risk to increase as patch volumes continue to grow, but the relationship is not simply that more patches automatically mean more broken systems,” Ensar Seker, chief information security officer (CISO) at threat intelligence vendor SOCRadar, tells Dark Reading. He emphasized the complexity of the modern technology landscape, with increasingly interconnected operating systems, cloud services, virtualization platforms, drivers, identity components, and legacy technologies, which expands the testing matrix and makes reproducing every enterprise environment before a patch is released difficult.
Microsoft stressed the importance of risk-based patching, using staged deployment rings, representative test environments, rollback capabilities, and enhanced monitoring. Tyler Reguly, associate director of security R&D at Fortra, agreed, stating that security teams need to be even more diligent about verifying patches before wide-scale deployment, as there are no independent bodies or regulatory agencies to perform that verification for them. Delaying patches can leave organizations exposed to active exploitation, but deploying a problematic update directly into production can disrupt critical services.
