The Kernel System State Check package contains a Kernel Update Compatibility Assessment Tool that administrators can use to determine whether the computers in an enterprise environment are compatible with security update MS10-015.   The package also contains a sample script that can be leveraged to help automate an enterprise wide compatibility assessment.







This package contains a tool called the Kernel Update Compatibility Assessment Tool that administrators can use to determine whether the computers in an enterprise environment are compatible with security update MS10-015. Use the scan to determine the compatibility of the computers in your organization. To run the tool on all computers in your organization, you can use the sample script. When you run the script, you will be prompted for a location where the tool will put a log file. The log file will give you detailed information about the compatibility of each computer in the environment, and will also contain information about other log files that are created during the scan. Once you are satisfied that the machines are in a compatible state, you can enable the update for the machines. If you have a large scale organization, the script can automate the compatibility check for you and issue the compatible configuration to all computers. How to Install the tool: 1. Download the tool from here: 2. Save the downloaded file to a temporary location (e.g. %TMP%) 3. Start Windows Explorer and navigate to the temporary location where the downloaded file was saved (e.g. %TMP%) 4. Double-click on the downloaded file (kccsp.exe) and follow the instructions. 5. Run the tool on your environment computers and if any computers are not in a compatible state, run the update on those computers and repeat the steps above. Prerequisites: Before you run the tool, you must make sure that the computers that you will scan are up to date. To do this, run the VMware Toolbox Update Windows Update command. To do this, follow these steps: 1. Run the kccsp.exe tool. 2. When prompted, select the Enable KCC SP checkbox. 3. The tool will scan your Windows environment and report any not compatible computers. When a computer fails the check, the tool will issue the appropriate configuration command for that specific computer and all computers that share the same dns domain. Kernel Update Compatibility Assessment Tool Manual: When you run the scan, it will ask you to provide a path to the log file where the tool will store the results of the scan. The default settings will save the results in a file called KCCSP_Results.txt. Logging can be enabled in the GUI interface by choosing the

The ‘Kernel System State Check’ package provides administrators with tools that help identify which computers in an enterprise environment are incompatible with security updates released by Microsoft. The recommended scope of the package is the entire enterprise network, although it can be used to check PCs, NUMA nodes, or servers on a network. The package includes the following four tools: o ‘KSC_FindUpdateBroken’ – Identifies computers that are not compatible with an update. o ‘KSC_CheckUpdate’ – Determines compatibility of the host. o ‘KSC_CheckUpdates’ – Determines compatibility of computers on a network and the enterprise wide update compatibility assessment process. o ‘KSC_ValidateUpdate’ – Determines the validity of a security update. In addition to these tools, the package includes the following ‘Help’ files that can be used to help communicate information to an enterprise about compatibility and best practices for updating computers running Windows Server 2008 R2 (WSSR2), Windows Server 2008 (WSSR), Windows Server 2003 (WSSR3), and Windows Server 2003 R2 (WS03R2). Kernel System State Check Requirements: The Kernel System State Check package can be installed on computers that are not managed by a System Center Configuration Manager 2007 (SCCM) server and that belong to a different Active Directory domain. The package is also a dependency of the Configuration Manager Client tools package, so it can be installed on computers that are managed by a SCCM server. KSC can also be installed on Windows Server 2008 R2 computers that are managed by a SCCM server. KSC should not be installed on Windows Server 2008 computers. KSC is a kernel mode package, so it cannot be installed on 32-bit versions of Windows. How to use the KSC tools: KSC_FindUpdateBroken – Copy KSC.exe to a path of your choice. – Run KSC_FindUpdateBroken. KSC_CheckUpdate – Copy KSC.exe to a path of your choice. – Run KSC_CheckUpdate and choose the file in step 1. KSC_CheckUpdates – Copy KSC.exe to a path of your choice. – Run KSC_CheckUpdates and choose the file in step 1. KSC_ValidateUpdate – Copy KSC.exe to a path of your choice. 91bb86ccfa

The Kernel System State Check utility is an automated compatibility utility used to check the compatibility of computers in an enterprise environment. This Windows Management Framework (WMF) utility will determine whether the computers are running the latest security updates, and will identify the compatibility problems that may exist. Kernel System State Check offers two output methods, the first method provides a graphical output and the other provides a text output. The text output is more useful when the compatibility problems have already been resolved. Below is a summary of the steps involved when determining the compatibility of a computer. You can check each step to learn more about each operation. 1) Find the computer Run the Kernel System State Check tool. The Tool will determine the computer name and IP address of the computer. 2) Run the compatibility assessment It is best to check the compatibility of all computers in your environment at the same time. Run the tool on all computers at the same time. a)You must grant administrative privileges to run the tool. Click OK. b)Click Check All, and all computers will be checked in order. c)After some time, you will see the Results. 3) Check the Results Review the results to see if any computers have compatibility issues. You can compare the numbers to the list of compatibility problems in the Results section. 4) Identify the compatibility issues If you want to see the problem details and resolution instructions, go to the Results page for that computer. If the computer has a fix available, the page will read Fix Available. Clicking on the error or Fix Available button will download the updated software. If the computer does not have a fix available, it will read Error Code. The appropriate error messages will be listed. a)Error code fields are displayed in the Results table in order from most significant to least significant. All the error codes are listed in order from most significant to least significant. Click the most significant error code to see the detail of that issue. Example: If a computer does not have any compatibility issues, it will display the following: There were no compatibility issues found on the computer. 5) View Reports You can view the compatibility reports of all computers at once in the Reports tab. 6) Download Solutions You can download updates for computers that have compatibility issues from the Reports tab of the tool. By default, the tool will attempt to download

An organization running an Enterprise or Server version of Windows Server, Windows Server Core, or Windows 8.1 can use the Microsoft® KCS™ Toolkit (KCS) to help administrators and help desk personnel make decisions about applying Windows updates to computers. KCS, which is based on the Microsoft® Windows® Server Update Services™ (WSUS) software update framework, provides a consistent means of accomplishing compatibility testing, which has historically been a manual and time-consuming process. The KCS Toolkit consists of a client tool and a server utility. Administrators can use the client tool to request a server side compatibility report from WSUS or WSUS Management (port 443) in the following manner. Get an Assigned Compatibility List To first retrieve a list of computers assigned to the administrator, the client tool can perform a GET operation via WSUS Management. This operation is done as follows. The GET operation can be made with the following variables {site_name}=Enterprise or Server, Windows Server Core or Windows 8.1 {server_name}=WSUS or WSUS Management Server Name. When using KCS, the server utility must be set to perform compatibility testing on clients. For compatibility testing to run, the server side functionality must be enabled in WSUS Management as outlined here. Create a Compatibility List To create a compatibility list, a POST operation can be performed by specifying the server and site name. The compatibility list can include: A list of the clients that are eligible to run update KB3035583. In order for the compatibility check to run, KCS requires that the existence of the update be validated. The existence of the update can be validated by running a GET operation on KB3035583 via WSUS Management. To run this operation, a variation of the following can be used In order to perform an update check, the file_id for KB3035583 (KB3035583.msu) must be specified. This file_id is based on the value returned from the following operation, which can be

