I have several computers on our network that our vulnerability scanner has flagged as missing the KB4551762 security update. When I run a Windows Update check on these computers it doesn’t download the update. I’ve also tried downloading the offline installer but when I run the install it says that the update doesn’t apply to this computer. I’ve gone trough the update history and the patch is not installed on these computers even though they are running the windows build that the patch applies to. I’m not sure what to do to remedy this.

3 Spice ups

I recommended to post this issue on TN-WSUS.

Forum link: Windows Server - Microsoft Q&A

Hope to see you on this forum.

Whether you install updates for clients through WSUS or through Windows Update?

Before you install the Cumulative Update - kb4551762, consider installing the latest Service Stack Update - KB4541338 first for the client. Check that your client is installing the latest service stack updates. If not, consider installing the latest service stack updates first.

1 Spice up

Something else to consider (I’ve had to run standalone updates for situations like this and had the same result) is to flag them as a false-positive. We use a third-party tool and MEMCM / SCCM for patching, and another third-party tool to verify that those updates are actually getting installed. I would check with your vulnerability scanner and verify if the patch being flagged has any issues within their tool. Something else to consider is the patch itself may be bad. Microsoft (for all the flak we all give them) does a pretty good job with the monthly cycle, but (like all of us) they do make mistakes. Iif the OS isn’t showing any errors or warnings in the logs for failed installs, and the standalone version is coming back as not needed you’re probably patched. If not - odds are good when an updated version of the patch is released it will work (if the issue is the patch is bad).

Could you clarify, when you try to manually install this update, do you get any error code?

I found this article, which describes a similar situation https://www.bleepingcomputer.com/news/microsoft/windows-10-kb4551762-security-update-fails-to-install-causes-issues/

Also here are some more useful links

https://www.reddit.com/search?q=KB4551762+&include_over_18=on

What is the source of the updates of your clients? WSUS or Windows Update
If your clients get updates by GPO, you may have to install - kb4549951. The update solves this issue.

Reference picture:


Reference link: March 12, 2020—KB4551762 (OS Builds 18362.720 and 18363.720) - EXPIRED - Microsoft Support