跳至內容

Trouble Installing Patch (KB5056579) on Windows EC2 Instance

0

We are running Windows EC2 instances in production. Instance type is m7i.xlarge and base image is Microsoft Windows Server 2025. We have patch manager setup with default baselines for windows. Patch manager approve patches after 7 days of being released and manually install those patches. But we are having trouble installing this particular update: 2025-07 Cumulative Update for .NET Framework 3.5 and 4.8.1 for Microsoft server operating system version 24H2 for x64 (KB5056579) After this update when we reboot instance its health check starts failing (2/3) and I can see this error (attached screenshot). Are we missing anything in our patching operations ? I have following this practice from few months. I have also tried installing same update on m6i.xlarge but encountered same issue.Enter image description here

已提問 3 個月前檢視次數 166 次
1 個回答
5

Considering below:

  1. Block KB5056579 Temporarily Since you're using Patch Manager with default baselines: • Create a custom baseline that explicitly excludes KB5056579 • Use Update Management in Systems Manager to block this patch until it's stable
  2. Test in Isolated Environment Before applying to production EC2s: • Spin up a test EC2 instance with the same image and patch manually • Monitor health checks and logs post-reboot
  3. Check EC2 Health Dependencies After reboot, if EC2 health checks fail: • Verify network drivers, TPM, and EC2 integration services are intact • Check C:\Windows\Logs\CBS\CBS.log and WindowsUpdate.log for patch-related errors
  4. Use DISM to Repair Run this on the EC2 instance before retrying the patch: DISM /Online /Cleanup-Image /RestoreHealth sfc /scannow
專家
已回答 3 個月前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。