As part of an ongoing commitment to provide detection tools and deployment recommendations for security updates, Microsoft is delivering this detection and deployment guidance for all updates that are released during a Microsoft Security Response Center (MSRC) release cycle.
This guidance contains recommendations that are based on the kinds of scenarios that may exist in various Microsoft operating system environments. This guidance includes how to use tools such as the following tools:
Windows Update
Microsoft Update
Office Update
The Microsoft Baseline Security Analyzer (MBSA)
Windows Server Update Services (WSUS)
Microsoft System Center Configuration Manager (SCCM)
Microsoft Systems Management Server (SMS)
The Extended Security Update Inventory Tool
This article details the Microsoft software that may not be supported by one or some of the detection and deployment products that are in this list.
The products that are supported by this Web site are as follows:
Office 2000
Office 2002
Office 2003
The 2007 Office system
Exceptions
Office Update does not support 2007 Office components when they are installed on computers that are running Windows Vista or Windows Server 2008. You must use Microsoft Update instead.
Office Update does not support any Macintosh products.
The products that are supported by this Web site are as follows:
Microsoft Office 2001 for Mac
Microsoft Office 2004 for Mac
Microsoft Office X for Mac
Microsoft Office 2008 for Mac
Environments that detect security updates by using Microsoft Baseline Security Analyzer (MBSA) version 2.1
MBSA does not support the following:
Visual Basic 6.0, Visual Studio 2002 or Visual Studio 2003
Digital Image Suite 2006
SQL 7.0 or Microsoft Data Engine (MSDE) 1.0
Report Viewer 2005 or Report Viewer 2008
Visual FoxPro 8.0 Service Pack 1 (SP1) on Windows 2000 SP4
Visual FoxPro 9.0 SP1 or SP2 on Windows 2000 SP4
Platform SDK: GDI+
Any Office 2000 components
Any Macintosh products
Microsoft Works 8 when you use an offline scan Note For more information, see the "Offline and Online scans" section later in this section.
MSN Messenger or Windows Live Messenger
Offline and Online scans
Online scan
This is when the system that is scanned by MBSA 2.1 has connectivity to Microsoft Update. This is shown in the completed scan report.
Offline scan
This is when the system that is scanned by MBSA 2.1 is managed by WSUS or is in an offline secure environment that forces the system to use the
WSUSSCN2.CAB offline catalog.
Environments that detect and deploy security updates by using Windows Server Update Services (WSUS)
You can detect and deploy security updates if you use any of the following items:
WSUS 2.0 Service Pack 1 (SP1)
WSUS 3.0
WSUS 3.0 SP1
WSUS does not support the following:
Visual Basic 6.0, Visual Studio 2002 or Visual Studio 2003
Digital Image Suite 2006
SQL 7.0 or Microsoft Data Engine (MSDE) 1.0
Report Viewer 2005 or Report Viewer 2008
Visual FoxPro 8.0 Service Pack 1 (SP1) on Windows 2000 SP4
Visual FoxPro 9.0 SP1 or SP2 on Windows 2000 SP4
Platform SDK: GDI+
Any Office 2000 components
Any Macintosh products
MSN Messenger or Windows Live Messenger
Environments that detect and deploy security updates by using SMS 2.0, SMS 2003, or SCCM 2007
You can detect and deploy security updates if you use any of the following items:
Systems Management Server (SMS) 2.0 together with the SUS Feature Pack
Systems Management Server (SMS) 2003 together with the SUS Feature Pack
Systems Management Server (SMS) 2003 together with Inventory Tool for Microsoft Updates (ITMU)
System Center Configuration Manager (SCCM) 2007
Notes
Microsoft SMS 2003 Service Pack 3 (SP3) includes support for, and is required for, Windows Vista and Windows Server 2008 manageability.
The SMS SUS Feature Pack requires the Extended Security Update Inventory Tool to detect all the security updates.
To obtain the Extended Security Update Inventory Tool, visit the following Microsoft Web site:
SMS 2003 together with the ITMU and SCCM 2007 do not support the following products:
Visual Basic 6.0, Visual Studio 2002 or Visual Studio 2003
Digital Image Suite 2006
SQL 7.0 or Microsoft Data Engine (MSDE) 1.0
Report Viewer 2005 or Report Viewer 2008
Visual FoxPro 8.0 Service Pack 1 (SP1) on Windows 2000 SP4
Visual FoxPro 9.0 SP1 or SP2 on Windows 2000 SP4
Platform SDK: GDI+
Any Office 2000 components
Any Macintosh products
MSN Messenger or Windows Live Messenger
SMS together with the SUS Feature Pack does not support the following products:
Microsoft Expression Web and Microsoft Expression Web 2
Host Integration Server 2000, 2004, and 2006
Forefront Client Security 1.0 on Windows 2000 SP4
Report Viewer 2005 or Report Viewer 2008
Visual FoxPro 9.0 SP1 or SP2 on Windows 2000 SP4
The .NET Framework 2.0 and the .NET Framework 2.0 SP1 on Windows 2000 SP4
Windows Media Player 11
Digital Image Suite 2006
Microsoft Data Engine (MSDE) 1.0
SQL Server 2005
SQL Server 2008
Visual Studio 2008
Exchange 2007
Microsoft Works 8
The 2007 Office system
Windows Internet Explorer 7
Windows Vista
Windows Server 2008
Search Server 2008
Any x64-based versions of Windows or of SQL Server
Any Itanium-based versions of Windows or of SQL Server
The SMS SUS Feature Pack, SMS ITMU, and SCCM do not support any Macintosh products.
Acronym table
The following acronyms are provided to help with reading the table in the "Summary of detection and deployment guidance" section.
Collapse this tableExpand this table
Product
Acronym
Office Update
OU
Windows Update
WU
Microsoft Update
MU
Microsoft Baseline Security Analyzer
MBSA
WSUS 2.0 and WSUS 3.0
WSUS
SMS SUS Feature Pack
SUSFP
SMS Inventory Tool for Microsoft Updates
ITMU
System Center Configuration Manager 2007
SCCM
Summary of detection and deployment guidance
The following table summarizes the detection and deployment exceptions for each product.
Generally, MU, MBSA, WSUS, SMS ITMU, and SCCM all support the same products because they are all based off the same metadata.
When a field in a column is blank, it means there is no detection and deployment tool that applies to that column for that product.
Note This table does not include all Microsoft products. The table includes major products such as Windows and SQL. The "Other Products" section includes products for which Microsoft has released a security update, and there is an exception for one of these products. New products may be added at any time.
Collapse this tableExpand this table
Product
Detection and Deployment not supported
Detection and Deployment supported
Windows
Windows 2000
WU, MU, MBSA,WSUS, SUSFP, ITMU, SCCM
Windows XP
WU, MU, MBSA,WSUS, SUSFP, ITMU, SCCM
Windows Server 2003
WU, MU, MBSA,WSUS, SUSFP, ITMU, SCCM
Windows Server 2008
SUSFP
WU, MU, MBSA,WSUS, ITMU, SCCM
Windows Vista
SUSFP
WU, MU, MBSA,WSUS, ITMU, SCCM
Windows Internet Explorer 7
SUSFP
WU, MU, MBSA,WSUS, ITMU, SCCM
Windows Media Player 11
SUSFP
WU, MU, MBSA,WSUS, ITMU, SCCM
Any Itanium-based versions of Windows
SUSFP
WU, MU, MBSA,WSUS, ITMU, SCCM
Any x64-based versions of Windows
SUSFP
WU, MU, MBSA,WSUS, ITMU, SCCM
Office
Any Office 2000 components
MU, MBSA,WSUS, ITMU, SCCM
OU, SUSFP
Office XP
MU, MBSA,WSUS, SUSFP, ITMU, SCCM
Office 2003
MU, MBSA,WSUS, SUSFP, ITMU, SCCM
The 2007 Office system
SUSFP
MU, MBSA,WSUS, ITMU, SCCM
Microsoft Works 8
SUSFP
MU, MBSA,WSUS, ITMU, SCCM
Microsoft Works 8
MBSA when using an offline scan
SQL
Microsoft Data Engine (MSDE) 1.0
MU, MBSA,WSUS, SUSFP, ITMU, SCCM
SQL 7.0
MU, MBSA,WSUS, SUSFP, ITMU, SCCM
SQL Server 2000
MU, MBSA,WSUS, SUSFP, ITMU, SCCM
SQL Server 2005
SUSFP
MU, MBSA,WSUS, ITMU, SCCM
SQL Server 2008
SUSFP
MU, MBSA,WSUS, ITMU, SCCM
Any Itanium-based versions of SQL Server
SUSFP
MU, MBSA,WSUS, ITMU, SCCM
Any x64-based versions of SQL Server
SUSFP
MU, MBSA,WSUS, ITMU, SCCM
Exchange
Exchange 2003
MU, MBSA,WSUS, SUSFP, ITMU, SCCM
Exchange 2007
SUSFP
MU, MBSA,WSUS, ITMU, SCCM
Other Products
Any Macintosh products
MU, MBSA,WSUS, SUSFP, ITMU, SCCM
Digital Image Suite 2006
MU, MBSA,WSUS, SUSFP, ITMU, SCCM
Forefront Client Security 1.0 on Windows 2000 SP4
SUSFP
MU, MBSA,WSUS, ITMU, SCCM
Host Integration Server 2000, 2004 and 2006
SUSFP
MU, MBSA,WSUS, ITMU, SCCM
Microsoft Expression Web and Microsoft Expression Web 2
SUSFP
MU, MBSA,WSUS, ITMU, SCCM
MSN Messenger or Windows Live Messenger
MU, MBSA,WSUS, SUSFP, ITMU, SCCM
Platform SDK: GDI+
MU, MBSA,WSUS, SUSFP, ITMU, SCCM
Search Server 2008
OU, WU, SUSFP
MU, MBSA,WSUS, ITMU, SCCM
.NET Framework 2.0 and the .NET Framework 2.0 SP1 on Windows 2000 SP4
MU, MBSA,WSUS, ITMU, SCCM
Visual Basic 6.0, Visual Studio 2002 or Visual Studio 2003
What is Microsoft doing to provide guidance about how to deploy these updates?
We encourage system administrators to join the monthly technical webcast to learn more about security updates.
The webcast occurs every month. To register, visit the following Microsoft Web site:
Enter a Search request of "Security Bulletins (Level 200)" and then sort by date. These webcasts are scheduled several months in advance, so make sure that you look for the specific month and year that you want to view.
What other information should I know about MBSA?
For more information about the programs that MBSA currently supports, visit the following Microsoft TechNet Web page:
Can I use SMS or System Center Configuration Manager to determine whether the updates are required?
Yes. SMS helps detect and deploy these security updates. SMS 2.0 together with the SUS Feature Pack and SMS 2003 together with SUSFP use MBSA version 1.2.1 technology for detection. Therefore, SMS 2.0 together with the SUS Feature Pack and SMS 2003 together with the SUS Feature Pack have limitations that resemble the limitations of MBSA version 1.2.1.
For more information about SMS, visit the following Microsoft Web site:
The SUS Feature Pack together with the Extended Security Update Inventory Tool is required to detect all the security updates on Microsoft Windows and on other affected Microsoft products.
For more information about the limitations of the SUS Feature Pack, click the following article number to view the article in the Microsoft Knowledge Base:
306460
(http://support.microsoft.com/kb/306460/
)
Microsoft Baseline Security Analyzer (MBSA) returns note messages for some updates
SMS 2.0 together with the SUS Feature Pack and SMS 2003 together with the SUS Feature Pack also use the Microsoft Office Inventory Tool to detect the required security updates for Microsoft Office programs such as Microsoft Word.
SMS 2003 customers can also use ITMU to detect and deploy security updates. ITMU uses technology from Microsoft Updates. For more information about ITMU, visit the following Microsoft Web site:
System Center Configuration Manager 2007 uses WSUS 3.0 for detection and deployment of these security updates. Therefore, anything that is supported by WSUS 3.0 is also supported by System Center Configuration Manager 2007.