404 Tech Support

Microsoft updates IE New Tab page to nag for Windows 10

March’s Patch Tuesday includes a bad example of Microsoft abusing the security update cycle. KB3139929 is an actual security update. It resolves remote code execution vulnerabilities.

This security update resolves several reported vulnerabilities in Internet Explorer. The most severe of these vulnerabilities could allow remote code execution if a user views a specially crafted webpage in Internet Explorer.

There are several “nonsecurity-related fixes that are included in this security update” :

While all of the other fixes in MS16-023 seem to address legitimate bugs, KB3146449 is actually adware that introduces a pop-up layer ad to the New Tab page of Internet Explorer for Windows 7 and Windows 8 computers on non-domain computers. The ad is in the form of a blue banner that states “Microsoft recommends upgrading to Windows 10”.

As KB3146449 is installed as part of 3139929, you cannot install the Windows 10 advertisement “patch”. Instead, you would have to remove KB3139929 and leave your computer vulnerable.

If you do not use IE, you are already on Windows 10, or your computer is joined to a domain, this may not be too concerning. However, the bundling of non-security updates with security updates and the inability to uninstall specific updates is a scary foreshadowing of Microsoft’s desperation to upgrade computers to Windows 10.