Quantcast
Channel: Ivanti User Community: Message List
Viewing all articles
Browse latest Browse all 12704

Re: LANDesk says patch is needed but machines are already patched

$
0
0

That's what you need .

 

So - to explain:

 

The reason shown is:  "File C:\Windows\System32\scavengeui.dll  version is less than the minmum version specified."

 

Has the main "culprits" here. The definition (whichever one it is) you're scanning for here, is (possibly among other things) checking for SCAVENGEUI.DLL - it must be of "version X" to be seen as being patched.

 

Now - vulscan checked that file, and found that it didn't have the "minimum expected" version (i.e. - if it were truly patched, it should be this version or higher). Having had a look for your vulnerability on Microsoft's basic pages ( http://support.microsoft.com/kb/2852386 ) it looks like you need to reboot your devices. I'm suspecting that you might have a "Pending File Rename" situation (i,e, - Windows has queued the relevant file for an update, but has to do so upon reboot, because the file is in use).

 

You may want to reboot a device in question, and then re-scan it (or JUST scan against this vulnerability to speed things up) ... that's usually where this sort of problem comes from. In RARE cases, there's actual problems replacing the file properly (does happen - even Windows 7 OS'es can "go weird" from time to time) ... but that's pretty rare in my personal experience. See if clearing out Pending File Rename via reboot will help you out here.

 

To explain WHY vulscan checks files - rather than "just believing" that a patch is installed, we verify registry keys, files and so on to make sure that this is indeed so (not all patch installs ARE as successful as they'd have you believe). So it's an additional layer of paranoia, if you want, to help you make sure that your boxes are REALLY patched .


Viewing all articles
Browse latest Browse all 12704

Trending Articles