Managing private patches for Kaspersky Endpoint Security for Windows
Show applications and versions that this article concerns
- Kaspersky Endpoint Security 12 for Windows (all versions)
- Kaspersky Endpoint Security 11.11 for Windows (version 11.11.0.452)
- Kaspersky Endpoint Security 11.10 for Windows (version 11.10.0.399)
- Kaspersky Endpoint Security 11.9 for Windows (version 11.9.0.351)
- Kaspersky Endpoint Security 11.8 for Windows (version 11.8.0.384)
- Kaspersky Endpoint Security 11.7 for Windows (version 11.7.0.669)
How to download the latest cumulative patch
- Sign in to your account on Kaspersky CompanyAccount.
- Click New request → Submit a request to technical support.
- Fill out the fields: Protection scope, Product, Product version.
If a cumulative patch is available for your application version, you will be recommended to download and install it.
How to create an installation package with a patch
- Download the required version of Kaspersky Endpoint Security for Windows from the Kaspersky Security Center network folder or the Kaspersky website.
- Unpack the application installation package if it was downloaded from the Kaspersky website.
- Depending on how you create the installation package, do the following:
- If you create the installation package based on the downloaded package, put the patch files in the folder together with Kaspersky Endpoint Security for Windows.
- If you create an installation package based on the existing application package in Kaspersky Security Center, copy the patch files to the exec folder.
When creating an installation package of KESW version 12.5 and later, in addition to the .msp patch file, also add the .kcat digital signature file that comes with the patch file in a ZIP archive.
If the digital signature file is missing from the installation package, the following error will occur during installing the patch: “Error 27228: Signature file verification error”. - Create a new installation package based on the KUD file in the folder where the patch files are located.
- Create a task to install the application together with the patch.
You can download the patch for your application version in Kaspersky CompanyAccount using these instructions.
How to create a patch installation package
- Open Kaspersky Security Center.
- Go to Advanced → Remote installation → Installation packages.
- Click Create installation package.
- Select Create an installation package for the specified executable file.
- Enter a name for the package and click Next.
- Click Browse and specify the path to the patch installation file in the .msp format.
The patch must be located in a separate folder. When creating a patch installation package for KESW version 12.5 and later, the .kcat digital signature file, which is provided in a ZIP archive along with the patch file, must be in the folder as well.
If the digital signature file is missing from the installation package, the following error will occur during installing the patch: “Error 27228: Signature file verification error”. - In the Executable file command line (optional) field, enter:
- Select the check box Copy entire folder to the installation package and click Next.
- Click Finish.
How to install the patch
Locally through the Installation wizard
- Run the executable file of the patch.
- Follow the instructions in the Installation Wizard.
Locally through the command line in the silent mode
- Open the command line on the client device.
- Run the following command:
Remotely through Kaspersky Security Center
- Open Kaspersky Security Center.
- Go to Advanced → Remote installation → Installation packages.
- Open the context menu of the created package and select Install application.
- Choose one of the options:
- Install on group of managed devices. Choose this option if you have already included devices in the administration groups.
- Select devices for installation. Choose this option if you have no devices in administration groups, or if you need to install the application to specific devices.
- Select devices or groups of devices on which the patches will be installed and click Next.
- Select the Do not re-install application if it is already installed checkbox.
- Follow the steps of the remote installation wizard.
- At the Select accounts to access devices step, add the user account with the administrator permissions on selected devices and click Next.
- Click Next → Finish.
- Run the patch installation task.
How to get a patch installation or removal log
To troubleshoot issues that may occur during installation or removal of the patch, get a log file:
- On the client device, open:
- The system folder where temporary files are located (during remote installation)
e.g. C:\Windows\Temp - The folder where user’s temporary files are located (during local installation)
e.g. C:\Users\Username\App Data\Local\Temp
- The system folder where temporary files are located (during remote installation)
- Save the msi****.log files.
How to check if the patches are installed on client devices
Locally
To get the list of patches installed on a managed device:
- Right-click the Kaspersky Endpoint Security icon on Windows taskbar.
- In the context menu, select About.
- Go to Start → Control Panel → Programs and Features and click View installed updates in the upper-left corner.
Remotely through Kaspersky Security Center
To get the list of patches installed in the network:
- Open Kaspersky Security Center, select the Administration Server and go to the Reports tab.
- Right-click Report on Kaspersky software versions and select Properties.
- Go to the Fields tab.
- Select the Installed checkbox in the Details fields and click OK.
- Right-click Report on Kaspersky software versions and select Show report.
In the report, you will see the list of patches installed on the devices in the network.
To get the list of patches installed on a client device:
- Open Kaspersky Security Center and go to Managed devices.
- Open the properties of the device.
- Go to Applications, select Kaspersky Endpoint Security for Windows and open its properties.
Information about installed patches will be displayed in the list of installed updates.
To view the list of devices on which a patch is installed:
- Open Kaspersky Security Center and go to Device selections.
- Click Advanced → Create a selection.
- Enter a name for the selection and click ОК.
- Click Selection properties.
- Go to Conditions, choose the created selection and click Properties.
- Go to Application, specify the Critical update name and click OK.
The search results will appear in the list of devices.
How to remove a patch
Locally through the installation wizard
- Go to Control Panel → Programs and Features.
- Click View installed updates in the upper-left corner.
- In the context menu of the patch, click Delete.
Locally through the command line
- Open the command line on the client device.
- To remove the patch:
msiexec /i {GUID KESW} MSIPATCHREMOVE={GUID PrivateFix} EULA=1 PRIVACYPOLICY=1 /qnInstead of {GUID KESW} and {GUID PrivateFix}, enter the relevant GUID for your application and patch version.
Remotely through Kaspersky Security Center from all devices in the network
- In the Administration Console, go to Advanced → Application management → Software updates.
- Configure the filter settings of the list to display the installed patches, in case they are hidden.
- Open the properties of the patch to remove.
- Select the status Declined in the Update approval drop-down list.
After running a task to update anti-virus databases, the patch will be removed from all devices in the network.
Remotely through Kaspersky Security Center from the selected device or group of devices
- In the Administration Console, go to Advanced → Remote installation → Installation packages.
- In the right frame, click Create installation package.
- Select Create an installation package for the specified executable file.
- Enter a name for the package and click Next.
- Create a new .bat file and specify in it the command to remove the patch from the command line:
msiexec /i {GUID KESW} MSIPATCHREMOVE={GUID PrivateFix} EULA=1 PRIVACYPOLICY=1 /qnInstead of {GUID KESW} and {GUID PrivateFix}, enter the relevant GUID for your application and patch version.
- Save the file and go back to the Administration Console.
- Click Browse and specify the path to the created .bat file
- Click Next → Finish.
- Create a remote installation task with this installation package for a device or a group of devices.
- Run the task to remove the patch.
How to get a GUID of the patch
Patch GUID
To view the GUID from the patch file:
- Open the properties of the installation file of the patch.
- Go to the Details tab.
Information about the GUID will be displayed in the Edition line.
To view the GUID on a client device managed by Windows 10 or Windows Server 2019 and earlier:
- Go to Control Panel → Programs and Features.
- Click View installed updates in the upper-left corner.
- Press Alt.
- Go to View → Choose details.
- Select the Update ID checkbox and click OK.
Information about the GUID will be displayed in the list of installed updates.
GUID KESW
To learn the KESW GUID, run the command below on the device with Kaspersky Endpoint Security installed:
You can also learn the GUID for your version of Kaspersky Endpoint Security for Windows in this article.