The sorry is for all of us in the security community. The bad guys work together. The good guys expect someone else to spend the time.
Microsoft built an update that could not and did not take into account all of the third party vendor interactions. So one cannot expect them to magically 'fix this' without at least some effort on your part to provide log files. Since you apparently can
repro this, may I please ask that you do take the time to help all of us by working with Microsoft to get a better understanding of what virtual usb provided by VM/Vspehere is interacting with this update.
Please?
Email me at susan-at-msmvps.com and change the -at- to @ and I'll set up a free support case. If you never called Microsoft for a support case you should do that first, not last. Issues with security updates are always a free call.