Windows update or another installer is "blocked" by Application and Device Control
search cancel

Windows update or another installer is "blocked" by Application and Device Control

book

Article ID: 258573

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Installation of Windows patch/update is getting blocked on a system by Application and Device Control policy of Symantec Endpoint Protection (SEP).
 
Entries like below are found when checked in View Logs> Client Management and clicking on View Logs> Control Log on SEP client:

12/26/2022 9:32:03 PM    502    Minor and Above : (10)    Block    [AC8-3.1] Block saving .exe, .dll and .msi files - Caller SHA256=3df0f238e7fee405a75defea05fcebb15219d24f778c4f6530ddd6e2ab383dfa    File Write    0x0    12/26/2022 9:30:59 PM    12/26/2022 9:30:59 PM    All Applications | [AC8-3.1] Block saving .exe, .dll and .msi files    5528    C:\Windows\SoftwareDistribution\Download\Install\Windows-KB890830-x64-V5.108.exe

Environment

SEP 14.3 RU3 and later

Cause

In-built Application Control rule: Stop software installers [AC8], [AC8-3.1 - Block saving .exe, .dll and .msi files] is blocking the execution of .exe of Windows Patch/KB

Resolution

This Rule Set (Stop software installers [AC8]) is not enabled by default.

As enabled and blocking, modify it as follows on Symantec Endpoint Protection Manager (SEPM) console:

  • Click on Policies> Application and Device Control
  • Right-click on the Application and Device Control being used and click Edit.
  • Click on Application Control to get the list of Rule Sets applied
  • Select "Stop software installers [AC8]" and click Edit
  • Click on All Applications under Rules and add an exclusion for C:\Windows\SoftwareDistribution\*  as follows:
      

Note: In some scenarios, there will be additional exclusions required for certain Windows updates.
Example: Windows 10 servicing stack update (KB5054682)
Microsoft now combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). SSUs improve the reliability of the update process to mitigate potential issues while installing updates.
This update uses "TiWorker.exe" and will get blocked. The details of it can be found under Control Log as follows:
[AC8-3.1] Block saving .exe and .dll files - Caller SHA256=77da08ee0fd4631a2e3239cd16f0aa304c3395796eee21068e8183272e21a4c6
All Applications | [AC8-3.1] Block saving .exe and .dll files
C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.5547_none_7e02b5467c95ffef\TiWorker.exe
C:\Windows\SoftwareDistribution\Download\b0f02d17d323c4b231063dae09c0387f\inst\_SSU-19041.5676-x64.cab_\amd64_microsoft-windows-s..-installers-onecore_31bf38

For it to work, below exclusion needs to be added as well:
C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.5547_none_7e02b5467c95ffef\TiWorker.exe

Similarly, need to add the path of any other program which if getting blocked by this rule, such as C:\temp\sepclientinstaller.exe