Came in to work today and coworkers were scrambling through event viewer and regedit, doing reboots to no evail. I did a quick search and found windows bunged up our RDS.
Turns out this update was from last week and the workaround was rolling back a version to a 9.8 CVE. Fortunately, Microslop issued an OOB fix literally this morning so we could use that.
Frickin Windows man.
Edit: forgot to add, my coworkers spent like 2 hours asking chatgpt and they were looking in to regedit to fix stuff while it took me a single search on DDG to find out it was a bad Windows update
Turn off automatic updates on RDS session hosts to stop things like this. I’d patch two or three session hosts first and hold the rest for a few days. Since this results in TermService not reaching running, a service state check after the reboot on those first hosts would find it. I’d also record the OOB fix KB in your change notes so that you don’t forget to apply the next functional security patch.
Disclosure: I build ET Ducky. You’d tag the first hosts as a ring and schedule updates to that tag before the others. The deployment pauses if services fail to come back after the reboot. https://etducky.com/documentation/patch-management
Yeah we do have policy that delays updates but for some reason, it didn’t go through. During investigating, we were wondering if a registry edit for autoupdate flag was the cause of this
Is your WUServer pointing to WSUS or going through Microsoft directly?
Probably ms directly, I don’t believe we have a dedicated update server
Huh. I haven’t heard a peep about this.
Really? I’m not even an server admin and it popped up in several tech feeds.
Boy am I glad to not have to deal with all the Windows shit.


