Richtlijnen voor detectie en implementatie van Microsoft-beveiligingsupdates

Van toepassing op
Windows 7 Service Pack 1 Windows 7 Enterprise Windows 7 Professional Windows 7 Ultimate Windows 7 Home Premium Windows 7 Home Basic Windows 7 Enterprise Windows 7 Professional Windows 7 Ultimate Windows 7 Home Premium Windows 7 Home Basic Windows Server 2008 R2 Service Pack 1 Windows Server 2008 R2 Standard Windows Server 2008 R2 Enterprise Windows Server 2008 R2 Datacenter Windows Server 2008 R2 Standard Windows Server 2008 R2 Enterprise Windows Server 2008 R2 Datacenter Windows Server 2008 Service Pack 2 Windows Server 2008 for Itanium-Based Systems Windows Server 2008 Datacenter Windows Server 2008 Enterprise Windows Server 2008 Standard Windows Server 2008 Web Edition Windows Server 2008 for Itanium-Based Systems Windows Server 2008 Datacenter Windows Server 2008 Enterprise Windows Server 2008 Standard Windows Server 2008 Web Edition Windows Vista Service Pack 2 Windows Vista Business Windows Vista Enterprise Windows Vista Home Basic Windows Vista Home Premium Windows Vista Starter Windows Vista Ultimate Windows Vista Enterprise 64-bit Edition Windows Vista Home Basic 64-bit Edition Windows Vista Home Premium 64-bit Edition Windows Vista Ultimate 64-bit Edition Windows Vista Business 64-bit Edition Windows Vista Business Windows Vista Enterprise Windows Vista Home Basic Windows Vista Home Premium Windows Vista Starter Windows Vista Ultimate Windows Vista Enterprise 64-bit Edition Windows Vista Home Basic 64-bit Edition Windows Vista Home Premium 64-bit Edition Windows Vista Ultimate 64-bit Edition Windows Vista Business 64-bit Edition Microsoft Windows Server 2003 Service Pack 2 Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Service Pack 3 Microsoft Windows XP Home Edition Microsoft Windows XP Professional Office Professional 2010 Office Professional Plus 2010 Office Standard 2010

INLEIDING

Als onderdeel van onze voortdurende inzet om detectiehulpmiddelen en implementatieaanbevelingen voor beveiligingsupdates te leveren, levert Microsoft deze detectie- en implementatierichtlijnen voor alle updates die worden uitgebracht tijdens een releasecyclus van Microsoft Security Response Center (MSRC).

Deze leidraad bevat aanbevelingen die zijn gebaseerd op de soorten scenario's die zich kunnen voordoen in verschillende omgevingen met Microsoft-besturingssystemen. In deze richtlijnen vindt u instructies voor het gebruik van de volgende hulpprogramma's:

  • Windows Update
  • Microsoft Update
  • De Microsoft Baseline Security Analyzer (MBSA)
  • Windows Server Update Services (WSUS)
  • Microsoft Configuratiebeheer voor System Center 2007 (Configuration Manager 2007)
  • Microsoft Systems Management Server (SMS) 2003
  • Het uitgebreide inventarisatiehulpmiddel voor beveiligingsupdates

In dit artikel wordt de Microsoft-software beschreven die mogelijk niet wordt ondersteund door bepaalde detectie- en implementatieproducten in deze lijst.

Opmerking: Microsoft heeft de ondersteuning voor SMS 2.0 beëindigd op 12 april 2011. Voor SMS 2003 heeft Microsoft ook de ondersteuning voor de Security Update Inventory Tool (SUIT) op 12 april 2011 beëindigd. Klanten wordt aangeraden een upgrade uit te voeren naar Configuratiebeheer voor System Center 2007. Voor klanten die SMS 2003 Service Pack 3 blijven gebruiken, is de SMS 2003 Inventory Tool for Microsoft Updates (ITMU) ook een optie.

Meer informatie

Detectie en implementatie

Omgevingen waarin beveiligingsupdates worden gedetecteerd en geïmplementeerd met behulp van Windows Update, Microsoft Update en de website van Office voor Mac

Windows Update

http://update.microsoft.com/windowsupdate Windows Update ondersteunt de volgende producten:

  • Windows XP
  • Windows Server 2003
  • Windows Vista
  • Windows Server 2008
  • Windows 7
  • Windows Server 2008 R2

Microsoft Update

http://update.microsoft.com/microsoftupdate Microsoft Update ondersteunt de volgende producten niet:

  • Visual Studio 2002
  • Visual Studio 2003
  • Platform SDK: GDI+
  • Alle Macintosh-producten
  • MSN Messenger
  • Windows Live Messenger

Website van Office voor Mac

http://www.microsoft.com/mac/ De website Office voor Mac ondersteunt de volgende producten:

  • Microsoft Office 2004 voor Mac
  • Microsoft Office X voor Mac
  • Microsoft Office 2008 voor Mac
  • Microsoft Office 2011 voor Mac

Omgevingen waarin beveiligingsupdates worden gedetecteerd met behulp van Microsoft Baseline Security Analyzer (MBSA) versie 2.2

MBSA 2.2 ondersteunt de volgende producten niet:

  • Visual Studio 2002 of Visual Studio 2003
  • Platform SDK: GDI+
  • Alle Macintosh-producten
  • MSN Messenger of Windows Live Messenger

Offline en Online scans

  • Online scan
    Een online scan vindt plaats wanneer het systeem dat wordt gescand met MBSA 2.2 verbinding heeft met Microsoft Update. Dit wordt weergegeven in het ingevulde scanrapport.
  • Offlinescan
    Een offlinescan vindt plaats wanneer het systeem dat wordt gescand met MBSA 2.2 wordt beheerd door WSUS of zich in een beveiligde offlineomgeving bevindt die het systeem dwingt de Wsusscn2.cab offlinecatalogus te gebruiken.

Omgevingen waarin beveiligingsupdates worden gedetecteerd en geïmplementeerd met behulp van Windows Server Update Services (WSUS)

U kunt beveiligingsupdates detecteren en implementeren als u het volgende item gebruikt:

  • WSUS 3.0 SP2

WSUS biedt geen ondersteuning voor de volgende producten:

  • Visual Studio 2002
  • Visual Studio 2003
  • Platform SDK: GDI+
  • Alle Macintosh-producten
  • MSN Messenger
  • Windows Live Messenger

Omgevingen waarin beveiligingsupdates worden gedetecteerd en geïmplementeerd met behulp van SMS 2003 of Configuration Manager 2007

U kunt beveiligingsupdates detecteren en implementeren als u een van de volgende items gebruikt:

  • SMS 2003 samen met het SUS Feature Pack
  • SMS 2003 samen met de Inventory Tool for Microsoft Updates (ITMU)
  • Configuration Manager 2007

Notities

  • SMS 2003 Service Pack 3 (SP3) biedt ondersteuning voor en is vereist voor beheer van Windows Vista en Windows Server 2008.
  • Voor SMS 2003 met het SUS Feature Pack is het Extended Security Update Inventory Tool vereist om alle beveiligingsupdates te detecteren.
  • SMS 2003 in combinatie met de ITMU en Configuration Manager 2007 ondersteunen de volgende producten niet:

    • Visual Studio 2002
    • Visual Studio 2003
    • Platform SDK: GDI+
    • Alle Macintosh-producten
    • MSN Messenger
    • Windows Live Messenger
  • SMS 2003 en het SUS-functiepakket bieden geen ondersteuning voor de volgende producten:

    • Microsoft Expression Web
    • Microsoft Expression Web 2
    • Microsoft Host Integration Server 2000, 2004 en 2006
    • Report Viewer 2005
    • Report Viewer 2008
    • Windows Mediaspeler 11
    • Microsoft QL Server 2005
    • SQL Server 2008
    • Visual Studio 2008
    • Microsoft Exchange Server 2007
    • Exchange Server 2010
    • Het 2007 Office-systeem
    • Office 2010
    • Windows Internet Explorer 7, Internet Explorer 8 of Internet Explorer 9
    • Windows Vista
    • Windows 7
    • Windows Server 2008
    • Windows Server 2008 R2
    • Search Server 2008
    • Alle x64-versies van Windows of van SQL Server
    • Itanium-versies van Windows of van SQL Server
  • SMS 2003 met het SUS Feature Pack, SMS 2003 ITMU en Configuration Manager 2007 bieden geen ondersteuning voor Macintosh-producten.

Acroniemtabel

De volgende acroniemen zijn beschikbaar om u te helpen bij het lezen van de tabel in de sectie 'Overzicht van detectie- en implementatierichtlijnen'.

Acroniem Product
WU Windows Update
MU Microsoft Update
MBSA Microsoft Baseline Security Analyzer
WSUS WSUS 3.0
SUSFP SMS 2003 SUS Feature Pack
ITMU SMS 2003 Inventory Tool for Microsoft Updates
Configuration Manager 2007 Configuratiebeheer voor System Center 2007

Overzicht van detectie- en implementatierichtlijnen

De volgende tabel bevat een overzicht van de detectie- en implementatie-uitzonderingen voor elk product.

Over het algemeen ondersteunen MU, MBSA, WSUS, SMS ITMU en Configuration Manager 2007 allemaal dezelfde producten omdat ze allemaal zijn gebaseerd op dezelfde metagegevens.

Als een veld in een kolom leeg is, betekent dit dat er geen detectie- en implementatieprogramma van toepassing is op die kolom voor dat product.

Opmerking: deze tabel bevat niet alle Microsoft-producten. De tabel bevat de belangrijkste producten, zoals Windows en SQL Server. De sectie 'Andere producten' bevat producten waarvoor Microsoft een beveiligingsupdate heeft uitgebracht en waarvoor een uitzondering geldt voor een van deze producten. Nieuwe producten kunnen op elk moment worden toegevoegd.

Product Detectie en implementatie worden niet ondersteund Ondersteunde detectie en implementatie Windows Office SQL Server Exchange Server Andere producten
Windows XP WU, MU, MBSA, WSUS, SUSFP, ITMU, Configuration Manager 2007
Windows Server 2003 WU, MU, MBSA, WSUS, SUSFP, ITMU, Configuration Manager 2007
Windows Server 2008 SUSFP WU, MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Windows Server 2008 R2 SUSFP WU, MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Windows Vista SUSFP WU, MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Windows 7 SUSFP WU, MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Windows Internet Explorer 7, 8 en 9 SUSFP WU, MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Windows Mediaspeler 11 SUSFP WU, MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Itanium-versies van Windows SUSFP WU, MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Alle x64-versies van Windows SUSFP WU, MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Office 2003 MU, MBSA, WSUS, SUSFP, ITMU, Configuration Manager 2007
Het 2007 Office-systeem SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Office 2010 SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
SQL Server 2000 MU, MBSA, WSUS, SUSFP, ITMU, Configuration Manager 2007
SQL Server 2005 SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
SQL Server 2008 SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Itanium-versies van SQL Server SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Alle x64-versies van SQL Server SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Exchange Server 2003 MU, MBSA, WSUS, SUSFP, ITMU, Configuration Manager 2007
Exchange Server 2007 SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Exchange Server 2010 SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Alle Macintosh-producten MU, MBSA, WSUS, SUSFP, ITMU, Configuration Manager 2007
Microsoft Forefront Client Security 1.0 SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Host Integration Server 2000, 2004, 2006, 2009 en 2010 SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Microsoft Expression Media v1 en v2, Microsoft Expression Web 3 en 4 SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Windows Live SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Platform SDK: GDI+ MU, MBSA, WSUS, SUSFP, ITMU, Configuration Manager 2007
Search Server 2008 WU, SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007
Visual Studio 2002 of Visual Studio 2003 MU, MBSA, WSUS, ITMU, Configuration Manager 2007 SUSFP
Visual Studio 2005 en 2008 SUSFP MU, MBSA, WSUS, ITMU, Configuration Manager 2007

Veelgestelde vragen

Wat doet Microsoft om richtlijnen te geven over het implementeren van deze updates?

We raden systeembeheerders aan zich aan te melden voor de maandelijkse technische webcast voor meer informatie over beveiligingsupdates. De webcast vindt elke maand plaats. Ga naar de volgende Microsoft-website om u te registreren:

http://msevents.microsoft.com Zoek naar 'Beveiligingsbulletins (niveau 200)' en sorteer vervolgens op datum. Deze webcasts worden enkele maanden van tevoren gepland. Zorg er daarom voor dat u de specifieke maand en het jaar zoekt van de webcast die u wilt bekijken. 

Welke andere informatie moet ik weten over MBSA?

Ga naar de volgende Microsoft TechNet-website voor meer informatie over de programma's die MBSA momenteel ondersteunt:

http://technet.microsoft.com/en-us/security/cc184923.aspx Kan ik SMS of Configuratiebeheer voor System Center gebruiken om te bepalen of de updates vereist zijn? 

Ja. Sms helpt bij het detecteren en implementeren van deze beveiligingsupdates. SMS 2003 maakt samen met SUSFP gebruik van MBSA-versie 1.2.1-technologie voor detectie. Daarom heeft SMS 2003 samen met het SUS Feature Pack beperkingen die lijken op de beperkingen van MBSA versie 1.2.1.

Ga naar de volgende Microsoft TechNet-website voor meer informatie over SMS:

http://technet.microsoft.com/en-us/library/cc181833.aspx Het SUS-functiepakket is samen met het Extended Security Update Inventory Tool vereist om alle beveiligingsupdates op Windows en andere betrokken Microsoft-producten te detecteren.

Ga naar de volgende Microsoft-website voor meer informatie over de beperkingen van het SUS Feature Pack:

Software Update Services Feature Pack SMS 2.0 maakt samen met het SUS Feature Pack en SMS 2003 samen met het SUS Feature Pack ook gebruik van het Microsoft Office Inventory Tool om de vereiste beveiligingsupdates voor Microsoft Office-programma's zoals Microsoft Word te detecteren.

SMS 2003-klanten kunnen ITMU ook gebruiken om beveiligingsupdates te detecteren en te implementeren. ITMU maakt gebruik van technologie van Microsoft Update. Ga voor meer informatie over ITMU naar de volgende Microsoft-website:

http://technet.microsoft.com/en-us/systemcenter/bb676783 Configuration Manager 2007 maakt gebruik van WSUS 3.0 voor de detectie en implementatie van deze beveiligingsupdates. Dus alles wat wordt ondersteund door WSUS 3.0 wordt ook ondersteund door Configuration Manager 2007.