We help IT Professionals succeed at work.

How to use WSUS server to install 'meltdown and spectre' related patches

Akulsh
Akulsh asked
on
How may I use WSUS server to install 'meltdown and spectre' related patches on my Windows 2012-R2 servers? I have enabled Critical, Security and Definition updates, but don't find  'meltdown and spectre' related patches in installed updates. Thanks.
Comment
Watch Question

JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
I do not think so. We DID update our servers but it was via BIOS updates (Servers 2012 R2 all) and that does not come via Windows Updates.

At this point, so far as I know, only Microsoft Surface can update Firmware via Windows Updates.
Exec Consultant
CERTIFIED EXPERT
Distinguished Expert 2019
Commented:
Useful site ans look out for your server type
https://blog.barkly.com/meltdown-spectre-patches-list-windows-update-help
 Do also catch the portion on
To help confirm whether updates have been implemented correctly Microsoft has provided a PowerShell script that system administrators can run to test Meltdown and Spectre mitigations
Latest July rollout for Win2012r2
https://support.microsoft.com/en-us/help/4338815
JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
Yes, those are the Windows Updates, but in my experience, BIOS should be updated first if possible.

We see Windows Updates occurring after BIOS updates are complete.

Author

Commented:
Thank you all.
I was not asking about Firmware. I have updated Dell firmware on all servers and have also applied Meltdown-Spectre related VMware patches. (Almost all servers are VMs.)

My question was specific to WSUS server and none of the responses addressed that.

Btan, that barkly.com link ("A Clear Guide to Meltdown and Spectre Patches"), despite catchy title, says nothing about WSUS server. However, your other link  was quite useful, as it points to KB4338831 which seems the latest and most complete patch.

I did not find this KB4338831 update in our WSUS server but was able to import it thru 'Catalog' and then approved it. Really baffled that Microsoft's own update server (WSUS) does not download it as a security update. Thanks.
JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
If the firmware is up to date then see if you can see updates via Windows Updates and that may help with WSUS

Author

Commented:
Please see my last posting.

Explore More ContentExplore courses, solutions, and other research materials related to this topic.