April 2019 Microsoft Patching Issues

There are several Windows Patches released for April 2019 that are causing problems:

Applies to Windows 7, Windows 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012 and Windows Server 2012 R2.

  • Issues with computers running Sophos Endpoint Protection managed by Sophos Central or Sophos Enterprise Console that cause machines to become unresponsive.
  • Issues with Avast and Avira machines that cause machines to become unresponsive.


Solution if running Sophos:

If you are running Sophos, follow the below instructions:
– Add the following Windows exclusions to all Antivirus and HIPS policies in your Enterprise Console.

%programfiles%\Sophos\Sophos Anti-Virus

%programfiles(x86)%\Sophos\Sophos Anti-Virus

NP – only perform the above if the machine hasn’t rebooted.

If the machine has rebooted, uninstall all the April patches and apply the above solution.

Solution if running Avast:
Avast has released a micro-update to fix this issue.
Once the update has been maked ‘completed’, reboot your machine and leave for 15mins or so for the emergency updater to work. Then reboot the machine again.

Microsoft has temporarily blocked devices from receiving certain updates if Avira, Sophos or Avast are installed.

Sources:

https://community.sophos.com/kb/en-us/133945

https://kb.support.business.avast.com/GetPublicArticle?title=Windows-machines-running-Avast-for-Business-and-Cloud-Care-Freezing-on-Start-up