How to Remediate OS-Related Patches Using WSUS Server via Saner CVEM

Modified on Wed, 13 Aug at 1:51 PM


Product Version: 6.5.0.0


Overview

This article provides a step-by-step guide to remediate operating system (OS) related patches using a WSUS (Windows Server Update Services) server via the Saner CVEM console. Following this procedure ensures that the required patches are successfully approved and deployed to target devices.


Procedure

1. Before Patch Approval

a. Identify Missing Patches

  1. In the Saner CVEM console, review the Missing Patches list.


  2. Note down the relevant KB number (e.g., KB5041016).

b. Verify Patch Availability on WSUS

  1. On the WSUS server, search for the identified patch using its KB number.
    A screenshot of a computer 
Description automatically generated


  2. Check its current approval status (Approved or Not Approved).

c. Attempt Remediation Without Approval (Testing)

  1. From the Saner CVEM console, attempt to remediate the patch without approval.
    A screenshot of a computer 
Description automatically generated


  2. The remediation will fail with the reason:
    "The required patch is not found in the software repository."


2. After Patch Approval

a. Approve the Patch in WSUS

  1. On the WSUS server, search for the specific KB number.
    A screenshot of a computer 
Description automatically generated


  2. Right-click the patch and select Approve.

b. Select Target Devices

  1. In the approval window, choose the appropriate computer group.
    A screenshot of a computer error 
Description automatically generated


  2. Select Approved for Install and click OK.

c. Confirm Approval

  1. A confirmation popup will appear indicating successful approval.
    A screenshot of a computer error 
Description automatically generated


  2. Click Close to complete the approval process.

d. Retry Remediation via Saner CVEM

  1. Go to the Saner CVEM console and re-initiate the remediation.
    A screenshot of a computer 
Description automatically generated 


  2. The patch deployment should now complete successfully.


Additional Notes

  • Ensure the WSUS server is synchronized with Microsoft Update to have the latest patch catalogue.

  • Use the Saner CVEM console to monitor the remediation process and verify successful patch deployment.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article