You should be able to decline it from the server. When they've oopsied before they have expired the offending update off the servers. The next time you sync it will expire off automatically. If it helps any I have folks that work for Microsoft confirming to me independently what the article said.
Windows 7 Update appears to be compromised?
These details of "Important" update, which I received this morning - 4:30 AM MT. Copied to Notepad:
(appears to be a language pack? 4.3 MB)
______________________________________________________
gYxseNjwafVPfgsoHnzLblmmAxZUiOnGcchqEAEwjyxwjUIfpXfJQcdLapTmFaqHGCFsdvpLarmPJLOZYMEILGNIPwNOgEazuBVJcyVjBRL
Download size: 4.3 MB
You may need to restart your computer for this update to take effect.
Update type: Important
qQMphgyOoFUxFLfNprOUQpHS
More information:
https://hckSLpGtvi.PguhWDz.fuVOl.gov
https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu
Help and Support:
https://IIKaR.ktBDARxd.plepVV.PGetGeG.lfIYQIHCN.mil
________________________________________________________________________
Did NOT install. After my MSE definitions updated, I repeated Windows Update. The above 'important' update did not reappear???
Did MS servers get compromised?
Thank you
Windows for home | Previous Windows versions | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
46 answers
Sort by: Most helpful
-
Anonymous
2015-09-30T20:15:50+00:00 -
Anonymous
2015-09-30T20:10:48+00:00 Thought first this was an ackward error since I thought my WSUS database had gone full this morning...
Didn't see the .gov and .edu extension before I had copied the gabbering text and searched for it in the web. Do still have problems removing the update from the WSUS server content though...
Microsoft should come with a more official statement than through quotes on ZDNet (nothing bad said about them).
Plurable source aknowledgement... from Microsoft... would be nice :)
-
Anonymous
2015-09-30T20:05:06+00:00 Don't panic: Microsoft mistakenly posted a 'test' Windows update patch | ZDNet:
http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/
-
Anonymous
2015-09-30T19:50:29+00:00 Microsoft updates have specific signed certificates provided only by Microsoft. What happened here was human oops.
Don't panic: Microsoft mistakenly posted a 'test' Windows update patch | ZDNet:
http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/
"A Microsoft spokesperson confirmed Wednesday that it had "incorrectly published a test update" and is in the process of removing it. "
-
Anonymous
2015-09-30T19:42:12+00:00 Technically, if you wanted to insert malicious software into an update that is signed, one way do it might be to find a nonsense piece of text that - when hashed - appears to match an existing hash from other contents.
That's the reason MD5 is useless now - you can pad almost any data to make it have almost any MD5 that you like if you spend enough time.
But, I have to admit, it sounds more like corruption, junk, internal testing, a mistake, etc. than anything else. But WE cannot be sure. Only MS can provide that answer. It wouldn't be unusual for a false-Microsoft-cert to be signed by some high-up certificate authority "for testing" which leaks out and allows someone to generate a valid, signed update with whatever they wanted in it.