Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > MBSA and restarts

Reply
Thread Tools Display Modes

MBSA and restarts

 
 
Jerrold
Guest
Posts: n/a

 
      06-12-2008
Has anybody had MBSA say a reboot isn't needed after a patch install even
though a reboot is needed?

I'm using MBSA command line to detect what patches our machines need then
after running patches with /quiet and /norestart switches I run MBSA again to
make sure they installed and if any reboots are needed. The problem I've run
into is testing some Office patches with the Office applications open I see
the oHotFix logs say a reboot is needed but MBSA never reports back that a
reboot is needed. This is with MBSA 2.1 on XP and Win2k.
 
Reply With Quote
 
 
 
 
MowGreen [MVP]
Guest
Posts: n/a

 
      06-12-2008
You'd be better off asking this in the MBSA newsgroup:

http://www.microsoft.com/communities...&lang=en&cr=us

Forwarded for the poster's convenience.

Jerrold wrote:

> Has anybody had MBSA say a reboot isn't needed after a patch install even
> though a reboot is needed?
>
> I'm using MBSA command line to detect what patches our machines need then
> after running patches with /quiet and /norestart switches I run MBSA again to
> make sure they installed and if any reboots are needed. The problem I've run
> into is testing some Office patches with the Office applications open I see
> the oHotFix logs say a reboot is needed but MBSA never reports back that a
> reboot is needed. This is with MBSA 2.1 on XP and Win2k.



MowGreen [MVP 2003-2008]
===============
*-343-* FDNY
Never Forgotten
===============
 
Reply With Quote
 
Doug Neal [MSFT]
Guest
Posts: n/a

 
      06-25-2008
This issue is covered in the MBSA 2.1 FAQ located at
http://technet.microsoft.com/en-us/s.../cc184922.aspx and indicates

Q: Why doesn't MBSA provide reboot pending status for the latest updates?
MBSA can only provide reboot pending status when the option to Check for
Windows administrative vulnerabilities is selected in the GUI or by default
if "/n Updates" is not added to the command-line utility (CLI) to suppress
this feature. Reboot pending status is obtained directly from the Windows
Update Agent (WUA) client on each target machine. As long as the security
update was installed using a WUA-supported process (Windows Update,
Microsoft Update, SMS w/ITMU, or WSUS Server), MBSA can report any required
pending reboot. If an update has been installed manually or through a
third-party installation process, MBSA is unable to report reboot pending
state.

For customers using the /xmlout option from the command-line utility, the
pending reboot status is not available due to the limitation of using the
/xmlout option. Workarounds may include running mbsacli.exe without any
switches. This requires the full installation of MBSA (not the "MBSA Lite"
installation option to simply install a few necessary files for patch
scanning only). This will check the Administrative Vulnerabilities. If there
is a pending reboot, it will be reported as listed below:

Issue: Incomplete Updates
Score: Check failed (non-critical)
Result: A previous software update installation was not completed. You must
restart your computer to finish the installation. If the incomplete
installation was a security update, then the computer may be at risk until
the computer is restarted.

Another workaround is to query the following registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Upda teExeVolatile. More
details on the use of this registry key and the values that may be
represented can be found at Microsoft Knowledge Base article 832475.



--
--

Doug Neal [MSFT]


This posting is provided "AS IS" with no warranties, and confers no rights.

If newsgroup discussion with experts and MVPs is unable to solve a problem
to your satisfaction, feel free to contact PSS for support on the Microsoft
Baseline Security Analyzer (MBSA). Information is available at the following
link:
http://support.microsoft.com/default.aspx

This e-mail address does not receive e-mail, but is used for newsgroup
postings only.
"MowGreen [MVP]" <> wrote in message
news:...
> You'd be better off asking this in the MBSA newsgroup:
>
> http://www.microsoft.com/communities...&lang=en&cr=us
>
> Forwarded for the poster's convenience.
>
> Jerrold wrote:
>
>> Has anybody had MBSA say a reboot isn't needed after a patch install even
>> though a reboot is needed?
>>
>> I'm using MBSA command line to detect what patches our machines need then
>> after running patches with /quiet and /norestart switches I run MBSA
>> again to make sure they installed and if any reboots are needed. The
>> problem I've run into is testing some Office patches with the Office
>> applications open I see the oHotFix logs say a reboot is needed but MBSA
>> never reports back that a reboot is needed. This is with MBSA 2.1 on XP
>> and Win2k.

>
>
> MowGreen [MVP 2003-2008]
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
MBSA 0x80244008 Mordock Windows Update 0 05-13-2006 05:38 PM
MBSA and Windows 2003 SP1 R2 Rob Windows Update 1 03-13-2006 12:27 PM
MBSA support Shaik Windows Update 3 09-17-2005 04:30 PM
MBSA & HFNetChkPro Vic Windows Update 1 08-17-2005 12:35 PM
MBSA 2.0 Annien1 Windows Update 2 07-07-2005 06:04 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59