Security update for Bios 2.29 for T440 / T440s - what was the vulnerabil​ity?
Hi,
Can someone please share what the security vulnerability was for yesterday's bios?
Version 2.29
UEFI: 2.29 / ECP: 1.09
(Fix) Fixed security vulnerability.
(Fix) Fixed an issue that HDD partition data might not be captured by some UEFI application.
Thanks for the input however I disagree. All security exploits should be exposed except under certain conditions. Reading below, I do not believe it meets these conditions. This is what I found. I would like to know what has been changed in case a security flaw affected my data etc. To me it looks like they just don't want rollbacks of firmware as there was a security flaw in a previous firmware?
- If the UEFI BIOS has been updated to version 2.29 or higher, it is no longer
able to roll back to the version before 2.29 for security improvement.
Similar Messages
-
hi im trying to buy some song but its asking me for som questions
what was the first car you owned?
where was your leat favorte job?
i for got can u guys help mehi im trying to buy some song but its asking me for som questions
what was the first car you owned?
where was your leat favorte job?
i for got can u guys help me -
Is Apple going to release a security update for Snow Leopard to patch the new 'bash' bug?
What are the chances we will see Apple release a security update to patch this bash bug vulnerability? I really love snow leopard and don't want to update. At the same time, I don't want my computer to be vulnerable! Apple is still selling snow leopard, so are they still maintaining it?
STWriter wrote:
OSx 10.6.8 IS INFECTED TOO -- news says ALL for about 25 YEARS !
I posted a site link -- check the thread.
10.6 does have the bash bug (I confirmed that a few replies back in this thread, and I mentioned the 25 years in another reply to this thread). But that is NOT an infection. Bash did not catch it. The bug was not put there on purpose. And the bug itself does not actively do anything. It is a flaw that can allow a web server using server side scripts written in the bash shell scripting language, or a server side script that invokes bash. Or a user that allows anonymous remote ssh logins. Or has enabled the CUPS web management interface.
All of which was said before in this thread. Along with why it is most likely not a problem for the typical Mac consumer.
This is a serious problem for many web servers. And there are instructions for patching bash (see above).
The typical Mac user does not do the things that put them at risk. And if they know how to set their Mac up to put themselves at risk, they are knowledgable enough to follow the patching instructions. -
one of usb port in my macbook pro havent work after i ve updated latest security update for osx 10.7.5, how do i know what is cause that usb port is good or bad
On a Mac running v10.7.2, the only way to reinstall Safari is to reinstall OS X using OS X Recovery.
Safari 5.1.1 is for Snow Leopard. It will not run on a Mac with v10.7 installed. -
System exception running Configuration Wizard after installing several security updates for SP
Greetings,
Have a 2 server farm, SharePoint 2013 SP1, SQL and SharePoint. Windows Update has 15 updates downloaded and ready to install, 2 Server 2012 updates and 2 SharePoint updates, 11 Security Updates for SharePoint. So, I said yeah, go ahead and install them late
last night when I figured it wouldn't interrupt folks. (dumb move)
Windows Update took awhile, but no errors during the install. Rebooted the server as required. Once the server was back, jumped onto the server console and ran the Configuration Wizard to apply the updates to SharePoint. No problem, progressed through the
screens saying it was going to update, farm and sql information, etc. Config Wizard was going through the steps, then failed with the message: "Failed to register SharePoint services." and here's a link to the configuration log so have a jolly time
tracking it down, thank you very much.
I found the error in the log (down about 10,000 lines):
04/10/2015 03:00:02 12 ERR Task services has failed with an unknown exception
04/10/2015 03:00:02 12 ERR Exception: Microsoft.SharePoint.SPException ---> System.Runtime.InteropServices.COMException: <nativehr>0x80131904</nativehr><nativestack></nativestack>
at Microsoft.SharePoint.Library.SPRequestInternalClass.GetListsWithCallback(String bstrUrl, Guid foreignWebId, String bstrListInternalName, Int32 dwBaseType, Int32 dwBaseTypeAlt, Int32 dwServerTemplate, UInt32 dwGetListFlags, UInt32 dwListFilterFlags, Boolean bPrefetchMetaData, Boolean bSecurityTrimmed, Boolean bGetSecurityData, Boolean bPrefetchRelatedFields, ISP2DSafeArrayWriter p2DWriter, Int32& plRecycleBinCount)
at Microsoft.SharePoint.Library.SPRequest.GetListsWithCallback(String bstrUrl, Guid foreignWebId, String bstrListInternalName, Int32 dwBaseType, Int32 dwBaseTypeAlt, Int32 dwServerTemplate, UInt32 dwGetListFlags, UInt32 dwListFilterFlags, Boolean bPrefetchMetaData, Boolean bSecurityTrimmed, Boolean bGetSecurityData, Boolean bPrefetchRelatedFields, ISP2DSafeArrayWriter p2DWriter, Int32& plRecycleBinCount)
--- End of inner exception stack trace ---
at Microsoft.SharePoint.SPGlobal.HandleComException(COMException comEx)
at Microsoft.SharePoint.Library.SPRequest.GetListsWithCallback(String bstrUrl, Guid foreignWebId, String bstrListInternalName, Int32 dwBaseType, Int32 dwBaseTypeAlt, Int32 dwServerTemplate, UInt32 dwGetListFlags, UInt32 dwListFilterFlags, Boolean bPrefetchMetaData, Boolean bSecurityTrimmed, Boolean bGetSecurityData, Boolean bPrefetchRelatedFields, ISP2DSafeArrayWriter p2DWriter, Int32& plRecycleBinCount)
at Microsoft.SharePoint.SPListCollection.EnsureListsData(Guid webId, String strListName)
at Microsoft.SharePoint.SPListCollection.get_Count()
at Microsoft.SharePoint.Administration.SPAdministrationWebApplication.get_HealthRules()
at Microsoft.SharePoint.Administration.Health.SPHealthAnalyzer.RegisterRules(Assembly assembly)
at Microsoft.Office.InfoPath.Server.Util.HealthAnalyzerRegistration.RegisterHealthRules()
at Microsoft.Office.InfoPath.Server.Administration.FormsService.Update()
at Microsoft.SharePoint.PostSetupConfiguration.ServicesTask.InstallServiceInConfigDB(Boolean provisionTheServiceToo, String serviceRegistryKeyName)
at Microsoft.SharePoint.PostSetupConfiguration.ServicesTask.InstallServices(Boolean provisionTheServicesToo)
at Microsoft.SharePoint.PostSetupConfiguration.ServicesTask.Run()
at Microsoft.SharePoint.PostSetupConfiguration.TaskThread.ExecuteTask()
So I've been searching around trying to find a clue about this. I tried using PSConfig as well, no dice. I tried using my admin account, the farm account, and the initial setup account, no dice. So I gave in about 3:00 AM and took a break, rather than have
my head hit the keyboard. Left IIS down and SP down. Had some help this morning when someone started things back up for me. sigh. So the users have been in on the sites and doing all sorts of important and critical things, so rolling back to the last
backup is the last, last resort. (Fortunately, I did do a manual backup using a PowerShell script before starting all this.)
Help. Please.
The actual sites are up and seem to be working fine. Central Admin is down though, get a 500 Internal Server Error in the browser, so things aren't correct. Duh. The config wizard didn't finish.
Thanks much,
Steven0x80131904 translates to COR_E_SqlException. Typically this will be an MDF/LDF file out of space, or the volume that those files reside on being out of space. Check that first, then also check the SQLERROR log file for any issues.
Trevor Seward
Follow or contact me at...
  
This post is my own opinion and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs. -
Security Update for exchange server 2013SP1 KB3011140 Stops all services and failes to install
Hi All,
Over the past 2 days this update has tried to run on the server in the evening but ends up failing. When it fails it is causing all of our exchange services to stop working and when we try to check e-mails the following day we find out the e-mail service
has been offline since the update.
Is there anything specific we need to do before running this update?
Cheers,Hi,
As what Hotaka says, this update is available from
Windows Update. If it fails, we can also download and install the updates manually. The following stand-alone file is available for download from the Microsoft Download Center:
Download the security update for Exchange 2013 Service Pack 1 package now.
Download the security update for Exchange 2013 Cumulative Update 6 package now.
Regards,
Winnie Liang
TechNet Community Support -
KB2977326 - Security Update for SQL Server Service Pack 1 repeatedly fails to install
This update fails to install every day when I shut down my computer. Here is the WindowsUpdate.Log:
2014-12-02 15:50:11:469
420 44c
AU #########
2014-12-02 15:50:11:469
420 44c
AU # Initiating install at shutdown
2014-12-02 15:50:11:469
420 44c
AU # Approved updates = 1
2014-12-02 15:50:11:516
420 44c
AU <<## SUBMITTED ## AU: Install updates / installing updates [CallId = {685C12BB-7AA9-4A31-9620-8F306EEE31C3}]
2014-12-02 15:50:11:516
420 44c
Shutdwn InstallAtShutdown starts.
2014-12-02 15:50:11:516
420 1528
Agent *************
2014-12-02 15:50:11:516
420 1528
Agent ** START ** Agent: Installing updates [CallerId = AutomaticUpdates]
2014-12-02 15:50:11:516
420 1528
Agent *********
2014-12-02 15:50:11:516
420 1528
Agent * Updates to install = 1
2014-12-02 15:50:11:531
420 1528
Agent * Title = Security Update for SQL Server 2012 Service Pack 1 (KB2977326)
2014-12-02 15:50:11:531
420 1528
Agent * UpdateId = {E0D65CC4-3B13-4352-BD89-A28C5F4C5017}.200
2014-12-02 15:50:11:531
420 1528
Agent * Bundles 1 updates:
2014-12-02 15:50:11:531
420 1528
Agent * {C076E757-1A4F-44DB-823B-CFFC07CD7D38}.200
2014-12-02 15:50:11:547
420 16d8
Shutdwn InstallAtShutdown got install progress.
2014-12-02 15:50:12:327
420 d4c
Report CWERReporter finishing event handling. (00000000)
2014-12-02 15:50:20:548
420 44c
AU WARNING: Pending directive, 'Install Approval', is not applicable
2014-12-02 15:50:24:417
420 16d8
Shutdwn InstallAtShutdown got install progress.
2014-12-02 15:50:24:432
420 16d8
Shutdwn InstallAtShutdown got install progress.
2014-12-02 15:50:24:432
420 1528
DnldMgr Preparing update for install, updateId = {C076E757-1A4F-44DB-823B-CFFC07CD7D38}.200.
2014-12-02 15:50:25:119
2052 608
Misc =========== Logging initialized (build: 7.6.7600.320, tz: -0600) ===========
2014-12-02 15:50:25:119
2052 608
Misc = Process: C:\Windows\system32\wuauclt.exe
2014-12-02 15:50:25:119
2052 608
Misc = Module: C:\Windows\system32\wuaueng.dll
2014-12-02 15:50:25:119
2052 608
Handler :::::::::::::
2014-12-02 15:50:25:119
2052 608
Handler :: START :: Handler: Command Line Install
2014-12-02 15:50:25:119
2052 608
Handler :::::::::
2014-12-02 15:50:25:119
2052 608
Handler : Updates to install = 1
2014-12-02 15:50:25:119
420 16d8
Shutdwn InstallAtShutdown got install progress.
2014-12-02 15:52:23:991
420 44c
AU AU setting next sqm report timeout to 2014-12-03 21:52:23
2014-12-02 15:54:39:587
2052 608
Handler : WARNING: Command line install completed. Return code = 0x84b20001, Result = Failed, Reboot required = false
2014-12-02 15:54:39:587
2052 608
Handler : WARNING: Exit code = 0x8024200B
2014-12-02 15:54:39:587
420 16d8
AU >>## RESUMED ## AU: Installing update [UpdateId = {E0D65CC4-3B13-4352-BD89-A28C5F4C5017}]
2014-12-02 15:54:39:587
2052 608
Handler :::::::::
2014-12-02 15:54:39:587
2052 608
Handler :: END :: Handler: Command Line Install
2014-12-02 15:54:39:587
2052 608
Handler :::::::::::::
2014-12-02 15:54:39:587
420 16d8
AU # WARNING: Install failed, error = 0x80070643 / 0x84B20001
2014-12-02 15:54:39:587
420 16d8
Shutdwn InstallAtShutdown got install progress.
2014-12-02 15:54:39:711
420 1528
Report REPORT EVENT: {DFA9CDC8-334A-4E57-9588-77B8E980833D}
2014-12-02 15:54:39:587-0600 1
198 101
{E0D65CC4-3B13-4352-BD89-A28C5F4C5017}
200 80070643
AutomaticUpdates Failure
Content Install Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for SQL Server 2012 Service Pack 1 (KB2977326).
2014-12-02 15:54:39:727
420 1528
Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
2014-12-02 15:54:39:727
420 1528
Report WER Report sent: 7.6.7600.320 0x80070643 E0D65CC4-3B13-4352-BD89-A28C5F4C5017 Install 101 Unmanaged
2014-12-02 15:54:39:727
420 1528
Report CWERReporter finishing event handling. (00000000)
2014-12-02 15:54:39:805
420 1528
Agent *********
2014-12-02 15:54:39:805
420 16d8
AU Install call completed.
2014-12-02 15:54:39:805
420 1528
Agent ** END ** Agent: Installing updates [CallerId = AutomaticUpdates]
2014-12-02 15:54:39:805
420 16d8
AU # WARNING: Install call completed, reboot required = No, error = 0x00000000
2014-12-02 15:54:39:805
420 1528
Agent *************
2014-12-02 15:54:39:805
420 16d8
AU #########
2014-12-02 15:54:39:805
420 16d8
AU ## END ## AU: Installing updates [CallId = {685C12BB-7AA9-4A31-9620-8F306EEE31C3}]
2014-12-02 15:54:39:805
420 16d8
AU #############
jim...Hello,
Please examine the Summary.txt log file. The following article may help you locate the file on disk:
http://msdn.microsoft.com/en-us/library/ms143702(v=sql.110).aspx
If you find the sentence “A failure was detected for a previous installation” on the Summary.txt log file, please repair SQL Server using the following article:
http://msdn.microsoft.com/en-us/library/Cc646006(v=sql.110).aspx
If you find other errors, please share the content of the Summary.txt log file with us.
Hope this helps.
Regards,
Alberto Morillo
SQLCoffee.com -
How to uninstall/remove security update for SQL Server 2012
My requirement is to uninstall/remove security update for SQL
Server 2012 Service Pack 1 only. so are these below steps are correct or do I need to take any extra precaution for uninstallation?
Go to Control panelàProgramsà
Programs and FeaturesàInstalled Updrtes, right click on update and uninstall
As per my knowledge in SQL Server 2005, we cannot uninstall a service pack. we have to uninstall SQL Server 2005 completely, and reinstall SQL Server 2005 with previous service
packs and updates. but Starting SQL Server 2008, we can uninstall a service pack using Control Panel.
Rahulhttp://blogs.msdn.com/b/askjay/archive/2011/02/07/uninstalling-a-sql-server-service-pack.aspx
Best Regards,Uri Dimant SQL Server MVP,
http://sqlblog.com/blogs/uri_dimant/
MS SQL optimization: MS SQL Development and Optimization
MS SQL Consulting:
Large scale of database and data cleansing
Remote DBA Services:
Improves MS SQL Database Performance
SQL Server Integration Services:
Business Intelligence -
Security update for AIR 1.5 -- Mac PPC
Adobe Security Bulletin APSB10-16 indicates that AIR v2.0.2 and earlier need to be replaced, but since v2 only works on Mac Intel platforms, I need an update for v1.5.3. If not, what's the work-around? Uninstall AIR?
Hello,
Adobe has discontinued support for PowerPC-based computers and the Windows 2000 operating system on Adobe AIR 2 and will no longer provide security updates for Adobe AIR on these platforms. For full system requirement details, please see our AIR System Requirements page.
Customers are highly encouraged to stay on the latest AIR release available for their platform to ensure that they are on the most secure version available. For access to the last PowerPC supported runtime and SDK (AIR 1.5.3) please see our Archived Adobe AIR Runtime and SDK Versions page.
Thanks,
Chris -
Is there a recent security update for OSX version 10.6.8?
Is there a recent security update for OSX version 10.6.8?
I am getting more confused. I have Lion 10.7.5 and thought this would not be susceptible to SSL problem.
I also took Lanny's advice and went to "gotofail.com" and it said I was SAFE.
Can I assume I am OK?
Also,i have an ipod 4g and went to the same gotofail, and it also said I am safe. I have not udated the security patch as do not have sufficient space (need 2.7gig) but someone suggested a go around which I have not tried yet.
I am accessing the net via a Veiizon jet pak, and not using open networks.
Please comment -
HT1222 Are there any security updates for the Mac OS 10.4.11?
Are there any security updates for my G4 PowerPC OS 10.4.11?
No. Tiger is an obsolete and unsupported OS at this point. If there were any updates you would find them using Software Update.
-
I let my system download and install the latest security update for Safari yesterday, 28 Apr 14, and when it rebooted, it wouldn't let me login. Instead it took me to a utilities windown that allowed me to verify my h/d then told me it couldn't be repaired so I would need to save all of my documents (not sure how since it won't boot up) and reinstall OS X. Help!
terrelld,
if you’ve been making regular backups to date, then you could just restore from the last update which you’d made before installing the most recent Safari update. If you haven’t been making regular backups to date, you can try the method provided on this Apple page, in the “Instructions for backing up to an external hard disk via Disk Utility” section. If you’re not already making regular backups, then I’d highly recommend purchasing an external disk for use as a Time Machine backup destination once you’ve gotten this resolved, so that this sort of problem would be more easily resolved in the future. -
To Whom It May Concern,
I need the download for Adobe Shockwave Player Security Update for Shockwave Player Active X 12.0.3.133. So far all I have got is the run around. Please can someone help me get this update for my laptop?
Sincerely,
Lisa NewmanIs there a reason you need this SPECIFIC build? Because I was unable to locate it in three different places I looked.
There are FULL installers here: http://www.adobe.com/shockwave/download/alternates/#sp (version 11)
12.0.4.144 is here: http://get.adobe.com/shockwave/otherversions/ -
Are there critical or security updates for Macromedia Dreamweaver since Adobe took over?
Are there critical or security updates for Macromedia Dreamweaver Flash and Macromedia suite since Adobe took over? I can still use it but I am worried about security issues.
corpow wrote:
I have a new computer with Windows 7 and I thought of installing my old Macromedia Dreamweaver and using it to update my web site. However I don't know if I can still use it with Windows 7 and with no critical updates I am wondering what would happen.
Or if I reformat my old Windows XP computer and reinstall Macromedia Dreamweaver, would it be okay, or safe, security wise? Thanks.
What sort of security are you worried about? DW creates plain text files and they are as safe as any other text files you create with Notepad or Wordpad.
How old is your DW? I personally thing#k that it is time for you to get a new version so that you can create websites based on modern standards that are compatible with modern browsers.
Amazon should be able to sell you the product at a very competitive price.
Good luck. -
306MB security update for Skype for Business
Hi Microsoft or Community,
I went through a list of updates being shown by WIndows update (I'm on 8.1) and was stunned to see this
Security update for Skype for Business(KB3039779) 64Bit: 306MB
Security update for Skype for Business(KB3054946) 64Bit: 100.1MB
What's going on? What happened to the small and light messaging clients? I mean the above update is about 400MB that too, just security. Are you intending to update just skype or is this going to write all over the Windows 8 binaries. I believe the messaging client has to be/can be less that 50MB in total. Use the media, networking and security layers of the host OS, don't rewrite these in the messaging client. In fact the design philosphy from mobiles should carry over.
The biggest advantage MS has here is that you write the OS too where the security and multi-media capabilities should logically be added. If the 400MB above is updating those capabilities then call it a windows update.
For now I will uncheck the update box, so I don't install the above two patches. Please escalate this to MS product management and add to your product roadmap to design and release a compact skype.
Thanks and regards,
A Samel
[Topic title updated by moderator to be more descriptive. Original topic title was: "306MB security update for Skype"]Skype for Business and Skype for Windows desktop are two totally different products. You may look for help on your issues with Skype for Business on Microsoft Office Support. https://support.skype.com/en/faq/FA34552/i-m-having-issues-with-skype-for-business-where-can-i-get-help
Maybe you are looking for
-
Does table STPOX contain parent-child relationship between components
Hello I need to get a list of components of SO BOM. FM CS_BOM_EXPL_KND_V1 exports an output table STPOX. Does this table contain parent-child relationship between components? If yes , can somebody tell me which fields contain parent child id. thanks
-
ESS - Time Accounts- Exit button not working
We have implemented ESS Business Package, the Time Accounts application's Exit button is not working. When we click on Exit, it is not doing anything. In Development env it is working fine, but when it comes to quality it is not working. suggest me i
-
Sir, I tried the oracle utility SQLLDR.I created a table named TEST1(id Number primary key,var varchar2(50). I correcltly load data into TEST1 using normal load(not direct),bad file entries are filled with duplicate records When direct path load is u
-
Zen MicroPhoto or Micro stuck in Recovery Mode? Can't update firmware? Try this
I got these instructions from here: http://blog.opsan.com/archi've/2005/09/3/472.aspx This is the only thing that worked for me to get my broken Zen MicroPhoto up and running again. It was stuck in Recovery Mode and my XP SP2/WMP laptop wouldn't reco
-
Get Valuation Type (BWTAR) of the last material movements (MM)
Hi people, My requirement is to create a program to make negative adjustments to material stocks (using BAPI_GOODSMVT_CREATE). As incoming data I have the material along with the quantity to be adjusted. Plant (WERKS) and Storage location (LGORT) are