Ask the Expert

Patching the Windows 2000 server

I recently ran WinVer and it came back with version 5 build 2195 SP 4 for my 2000 server. Do I need to apply any patches? How can I find out if the patches have been applied?

    Requires Free Membership to View

Winver is a Windows command that shows the version of Windows you are running, along with the build and version numbers of the most recent service pack installed. The release version of Windows 2000 is version 5.0, build 2195, so the only useful information it provides is the service pack number. Service packs are cumulative, meaning each new service pack contains all the fixes included with previous service packs plus any new fixes. Windows 2000 Service Pack 4 (SP4) is the latest service pack for Windows 2000.

To check whether you need to apply any patches released since SP4 you should run the Microsoft Baseline Security Analyzer (MBSA), which can check for uninstalled patches and updates. You can also scan your server against vulnerable configurations. To view the list of uninstalled security updates and links to the security bulletin that contains the patch, or instructions about obtaining the patch, open the result details link once the security updates check has run. Each security bulletin also includes information about registry values, file versions and configuration changes you can use to verify that the patch is installed. You can download MBSA for free at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/Tools/mbsahome.asp.

Run the MBSA on a scheduled basis to check for the latest operating system and components updates. I also recommend subscribing to the Microsoft Security Notification Service, which keeps subscribers informed of all the latest security problems and fixes. You can find details about it at http://register.microsoft.com/subscription/subscribeme.asp?ID=135.

In my opinion the easiest software solution to use for managing patch installation is HFNetChkPro from Shavlik Technologies. (Shavlick developed the HFNetChk scanning engine that MBSA uses.) There is a Basic Edition that is aimed at smaller organizations that do not need advanced patch management functions such as scheduled scans and e-mail support. You can find more information at http://www.shavlik.com/hfnetchk-windows.aspx.


Related Information
  • Learn how to manage patch installations

  • Find top tools for testing your online security.


  • This was first published in September 2005

    There are Comments. Add yours.

     
    TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

    REGISTER or login:

    Forgot Password?
    By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
    Sort by: OldestNewest

    Forgot Password?

    No problem! Submit your e-mail address below. We'll send you an email containing your password.

    Your password has been sent to: