You are currently offline, waiting for your internet to reconnect

MS15-097: Description of the security update for the graphics component in Windows: September 8, 2015

Support for Windows Server 2003 ended on July 14, 2015

Microsoft ended support for Windows Server 2003 on July 14, 2015. This change has affected your software updates and security options. Learn what this means for you and how to stay protected.

Important This article contains information that shows how to help lower security settings or how to turn off security features on a computer. You can make these changes to work around a specific problem. Before you make these changes, we recommend that you evaluate the risks that are associated with implementing this workaround in your particular environment. If you implement this workaround, you should take any appropriate additional steps to help protect the computer.
Summary
In addition to the changes that are listed for the vulnerabilities that are described in Microsoft Security Bulletin MS15-097, this security bulletin addresses a defense-in-depth update for the secdrv.sys driver, a third-party driver. The update turns off the service for the secdrv.sys driver. This may affect the ability to run some older games.

To learn more about the vulnerabilities, see Microsoft Security Bulletin MS15-097.
More information
Important
  • All future security and nonsecurity updates for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2 require update 2919355 to be installed. We recommend that you install update 2919355 on your Windows RT 8.1-based, Windows 8.1-based, or Windows Server 2012 R2-based computer so that you receive future updates.
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

Known issues in this security update

  • After you install this security update, some programs may not run. (For example, some video games may not run.) To work around this issue, you can temporarily turn on the service for the secdrv.sys driver by running certain commands, or by editing the registry.

    Note When you no longer require the service to be running, we recommend that you turn off the service again.

    Warning This workaround may make a computer or a network more vulnerable to attack by malicious users or by malicious software such as viruses. We do not recommend this workaround but are providing this information so that you can implement this workaround at your own discretion. Use this workaround at your own risk.

    To do this, type the following commands at an elevated command prompt. You should press Enter after you type each command.
    • To disable the driver's service, type the following command:
      sc config secdrv start= disabled
    • To set the driver's service to manual, type the following command:
      sc config secdrv start= demand
    • To enable the driver's service (and to set it to automatic), type the following command:
      sc config secdrv start=auto
    • To manually start the driver's service, type the following command:
      sc start secdrv
    • To manually stop the driver's service, type the following command:
      sc stop secdrv
ImportantThis section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:
322756How to back up and restore the registry in Windows


Or, you can edit the registry directly. To do this, follow these steps:
  1. Click Start, click Run, type regedit in the Open box, and then click OK.
  2. Locate and then click the following subkey in the registry:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\secdrv
  3. Right-click Start, and then click Modify.
  4. In the Value data box, do one of the following:
    • Type 4 to disable the driver's service, and then click OK.
    • Type 3 to set the driver's service to manual, and then click OK.
    • Type 2 to set the driver's service to automatic, and then click OK.
  5. Exit Registry Editor.
How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, seeGet security updates automatically.

Note For Windows RT and Windows RT 8.1, this update is available through Windows Update only.

Method 2: Microsoft Download Center

You can obtain the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

Click the download link in the following table that corresponds to the version of Windows that you are running. Find out if your computer is running the 32 or 64-bit version of Windows
More information

File information

The EnglishUnited States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal TimeUTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving timeDST) bias. Additionally, the dates and times may change when you perform certain operations on the files.

Windows Vista and Windows Server 2008 file information

  • The files that apply to a specific product, milestoneSPn), and service branchLDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.0.6002.19xxxWindows Vista SP2 and Windows Server 2008 SP2SP2GDR
    6.0.6002.23xxxWindows Vista SP2 and Windows Server 2008 SP2SP2LDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
Note The MANIFEST files.manifest) and MUM files.mum) that are installed are not listed.

For all supported x86-based versions of Windows Vista and Windows Server 2008

File nameFile versionFile sizeDateTimePlatform
Secdrv.sys4.3.86.020,48024-Aug-201513:59x86
Secdrv.sys4.3.86.020,48024-Aug-201514:00x86

For all supported x64-based versions of Windows Vista and Windows Server 2008

File nameFile versionFile sizeDateTimePlatform
Secdrv.sys4.3.86.023,04007-May-201423:47x64
Secdrv.sys4.3.86.023,04007-May-201423:51x64

Windows 7 and Windows Server 2008 R2 file information

  • The files that apply to a specific product, milestoneRTM, SPn), and service branchLDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.1.7601.18xxxWindows 7 and Windows Server 2008 R2SP1GDR
    6.1.7601.22xxxWindows 7 and Windows Server 2008 R2SP1LDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
Note The MANIFEST files.manifest) and MUM files.mum) that are installed are not listed.

For all supported x86-based versions of Windows 7

File nameFile versionFile sizeDateTimePlatform
Secdrv.sys4.3.86.020,48024-Aug-201515:02x86
Secdrv.sys4.3.86.020,48024-Aug-201515:03x86

For all supported x64-based versions of Windows 7 and Windows Server 2008 R2

File nameFile versionFile sizeDateTimePlatform
Secdrv.sys4.3.86.023,04003-Jun-201520:16x64
Secdrv.sys4.3.86.023,04003-Jun-201520:16x64

Windows 8 and Windows Server 2012 file information

  • The files that apply to a specific product, milestoneRTM,SPn), and service branchLDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.2.920 0.16 xxxWindows 8 and Windows Server 2012RTMGDR
    6.2.920 0.20 xxxWindows 8 and Windows Server 2012RTMLDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
Note The MANIFEST files.manifest) and MUM files.mum) that are installed are not listed.

For all supported x86-based versions of Windows 8

File nameFile versionFile sizeDateTimePlatform
Secdrv.sys4.3.86.020,48002-Jun-201214:32x86
Secdrv.sys4.3.86.020,48002-Jun-201214:32x86

For all supported x64-based versions of Windows 8 and Windows Server 2012

File nameFile versionFile sizeDateTimePlatform
Secdrv.sys4.3.86.023,04002-Jun-201214:32x64
Secdrv.sys4.3.86.023,04002-Jun-201214:32x64

Windows 8.1 and Windows Server 2012 R2 file information

  • The files that apply to a specific product, milestoneRTM,SPn), and service branchLDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.3.920 0.16 xxxWindows 8.1 and Windows Server 2012 R2RTMGDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
Note The MANIFEST files.manifest) and MUM files.mum) that are installed are not listed.

For all supported x86-based versions of Windows 8.1

File nameFile versionFile sizeDateTimePlatform
Secdrv.sys4.3.86.020,48018-Jun-201312:25x86

For all supported x64-based versions of Windows 8.1 and Windows Server 2012 R2

File nameFile versionFile sizeDateTimePlatform
Secdrv.sys4.3.86.023,04018-Jun-201314:48x64

How to obtain help and support for this security update

Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support
malicious attacker exploit
Properties

Article ID: 3086255 - Last Review: 09/08/2015 17:38:00 - Revision: 2.0

Windows Server 2012 R2 Datacenter, Windows Server 2012 R2 Standard, Windows Server 2012 R2 Essentials, Windows Server 2012 R2 Foundation, Windows 8.1 Enterprise, Windows 8.1 Pro, Windows 8.1, Windows RT 8.1, Windows Server 2012 Datacenter, Windows Server 2012 Standard, Windows Server 2012 Essentials, Windows Server 2012 Foundation, Windows 8 Enterprise, Windows 8 Pro, Windows 8, Windows RT, Windows Server 2008 R2 Service Pack 1, Windows 7 Service Pack 1, Windows Server 2008 Service Pack 2, Windows Vista Service Pack 2, Microsoft Windows Server 2003 Service Pack 2

  • kbregistry atdownload kbbug kbexpertiseinter kbfix kbsecbulletin kbsecurity kbsecvulnerability KB3086255
Feedback
m/c.gif?DI=4050&did=1&t=">