Hotfixes for Windows Vista SP2
If you do not have Service Pack 2 for Windows Vista, you can download the update for free from Microsoft. Unlike previous versions of Windows, the service packs for Windows Vista do not stack. This means that, if you do not have Windows Vista SP1 installed, you must install it before you can install SP2.
Windows Vista Service Pack 1
Windows Vista Service Pack 2
If you have downloaded a bunch of hotfixes, you can install them with no user interaction. Just open an elevated command prompt, navigate to the folder containing the hotfixes, and run:
for %i in (*) do start /wait wusa "%i" /quiet /norestart
You can replace the “*” with “*x86*” or “*x64*” to pick only one type of hotfix, if the folder contains both.
Stay up to date
- If you would like to be notified when hotfixes are added to this list, you may use this RSS feed.
Here is the hotfix list for Windows Vista SP2:
| Applies to | Date | KB | Description | Download | WU? | |
| Vista SP2 | August 10, 2010 | 978886 | Vulnerabilities in TCP/IP could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 980436 | Vulnerabilities in SChannel could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 981852 | Vulnerabilities in Windows Kernel could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 981997 | Vulnerability in Movie Maker could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 982214 | Vulnerabilities in SMB Server could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 982316 | An update is available for the Windows Telephony Application Programming Interface (TAPI) | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 982664 | Compatibility View list update for Windows Internet Explorer 8: August 10, 2010 | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 982665 | Vulnerability in Cinepak codec could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 982799 | Vulnerabilities in the Tracing Feature for Services could allow an elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 2079403 | Vulnerability in Microsoft XML Core Services could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 2160329 | Vulnerabilities in Windows kernel-mode drivers could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | August 10, 2010 | 2183461 | Cumulative Security update for Internet Explorer | x86 x64 | Yes | |
| Vista SP2 | August 2, 2010 | 2286198 | Vulnerability in Windows Shell could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | July 13, 2010 | 976323 | Security update for Windows SMTP Service: April 13, 2010 and July 13, 2010 | x86 x64 | Yes | |
| Vista SP2 | July 13, 2010 | 2264107 | This update helps protect against DLL preloading vulnerabilities in software applications on the Windows platform. | x86 x64 | No | |
| Vista SP2 | June 22, 2010 | 982480 | June 2010 Cumulative Update for Media Center for Windows Vista | x86 x64 | Yes | |
| Vista SP2 | June 22, 2010 | 982519 | Application Compatibility Update for Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2: June 2010 | x86 x64 | Yes | |
| Vista SP2 | June 8, 2010 | 979482 | Security update for Asycfilt.dll (COM component): June 8, 2010 | x86 x64 | Yes | |
| Vista SP2 | June 8, 2010 | 979559 | Vulnerabilities in Windows Kernel-Mode drivers could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | June 8, 2010 | 980195 | Cumulative security update of ActiveX kill bits | x86 x64 | Yes | |
| Vista SP2 | June 8, 2010 | 980218 | Vulnerability in the OpenType Compact Font Format (CFF) driver could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | June 8, 2010 | 982666 | Vulnerability in Internet Information Services could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | June 3, 2010 | 982926 | Silverlight 4.0 | x86 x64 | Yes | |
| Vista SP2 | May 25, 2010 | 981793 | May 2010 cumulative time zone update for Windows operating systems | x86 x64 | Yes | |
| Vista SP2 | May 11, 2010 | 978542 | Vulnerability in Outlook Express and Windows Mail could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | April 27, 2010 | 980248 | Some font files are not updated when you install Microsoft Office 2010 on a computer that is running Windows Vista or Windows Server 2008 | x86 x64 | Yes | |
| Vista SP2 | April 27, 2010 | 980368 | A update is available that enables certain IIS 7.0 or IIS 7.5 handlers to handle requests whose URLs do not end with a period | x86 x64 | No | |
| Vista SP2 | April 13, 2010 | 977816 | Vulnerability in Microsoft MPEG Layer-3 codec could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | April 13, 2010 | 978338 | Vulnerability in Windows ISATAP Component could allow spoofing | x86 x64 | Yes | |
| Vista SP2 | April 13, 2010 | 978601 | Security update for Windows Authenticode Signature Verification: April 13, 2010 | x86 x64 | Yes | |
| Vista SP2 | April 13, 2010 | 979309 | Security update for Windows Cabinet File Viewer Shell Extension: April 13, 2010 | x86 x64 | Yes | |
| Vista SP2 | April 13, 2010 | 979683 | Vulnerabilities in Windows Kernel could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | April 13, 2010 | 980232 | Vulnerabilities in SMB client could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | April 13, 2010 | 981332 | Security update for Visual Basic Scripting (VBScript) 5.8: April 13, 2010 | x86 x64 | Yes | |
| Vista SP2 | March 23, 2010 | 962975 | Dynamic disks are marked as "Invalid" on a computer that is running Windows Server 2008 or Windows Vista when you bring the disks online, take the disks offline, or restart the computer if Data Protection Manager is installed | x86 x64 | No | |
| Vista SP2 | March 9, 2010 | 975561 | Vulnerability in Windows Movie Maker could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | March 9, 2010 | 975823 | The capacity of a Secure Digital (SD) card that is larger than 32 GB is reported incorrectly in Windows Vista and in Windows Server 2008 | x86 x64 | No | |
| Vista SP2 | March 9, 2010 | 980363 | A hotfix is available that adds features to the FastCGI module in IIS 7.0 | x86 x64 | No | |
| Vista SP2 | March 9, 2010 | 980423 | You experience several issues when you use Powershell cmdlets or AppFabric features in IIS 7.0 or IIS 7.5 | x86 x64 | No | |
| Vista SP2 | February 23, 2010 | 976264 | Application Compatibility Update for Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2: February 2010 | x86 x64 | Yes | |
| Vista SP2 | February 23, 2010 | 976662 | An update is available for the native JSON feature in Internet Explorer 8 | x86 x64 | Yes | |
| Vista SP2 | February 23, 2010 | 977864 | Cumulative Update for Windows Media Center TV Pack for Windows Vista | x86 x64 | Yes | |
| Vista SP2 | February 9, 2010 | 928201 | BitLocker Repair Tool to help recover data from an encrypted volume in Windows Vista or in Windows Server 2008 | x86 x64 | No | |
| Vista SP2 | February 9, 2010 | 928202 | BitLocker Recovery Password Viewer for Active Directory Users and Computers tool to view recovery passwords for Windows Vista | x86 x64 | No | |
| Vista SP2 | February 9, 2010 | 933246 | BitLocker Drive Preparation Tool | x86 x64 | No | |
| Vista SP2 | February 9, 2010 | 971468 | Vulnerabilities in SMB Server could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | February 9, 2010 | 974145 | Vulnerabilities in Windows TCP/IP could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | February 9, 2010 | 975560 | Security update for Quartz: February 9, 2010 | x86 x64 | Yes | |
| Vista SP2 | February 9, 2010 | 977165 | Vulnerabilities in Windows kernel could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | February 9, 2010 | 977377 | Vulnerability in TLS/SSL could allow spoofing | x86 x64 | No | |
| Vista SP2 | February 9, 2010 | 978251 | Vulnerabilities in SMB client could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | February 9, 2010 | 979099 | An update is available to remove the application manifest expiry feature from AD RMS clients | x86 x64 | Yes | |
| Vista SP2 | January 26, 2010 | 947821 | Description of the System Update Readiness Tool for Windows Vista | x86 x64 | Yes | |
| Vista SP2 | January 26, 2010 | 970807 | An update is available for Bluetooth pairing in Windows Vista | x86 x64 | No | |
| Vista SP2 | January 12, 2010 | 972270 | Vulnerability in the Embedded OpenType Font Engine could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | December 8, 2009 | 970430 | Update that implements Extended Protection for Authentication in the HTTP Protocol Stack (http.sys) | x86 x64 | Yes | |
| Vista SP2 | December 8, 2009 | 971737 | Update that implements Extended Protection for Authentication in Microsoft Windows HTTP Services (WinHTTP) | x86 x64 | Yes | |
| Vista SP2 | December 8, 2009 | 973917 | Update that implements Extended Protection for Authentication in Internet Information Services (IIS) | x86 x64 | Yes | |
| Vista SP2 | December 8, 2009 | 974318 | Vulnerabilities in the Internet Authentication service could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | November 24, 2009 | 973687 | When an application uses MSXML to process XHTML, redundant retrieval requests for well-known DTD files from the W3C Web server cause XHTML parsing to fail on a Windows-based computer | x86 x64 | Yes | |
| Vista SP2 | November 17, 2009 | 976470 | The "Date and Time" window shows "Date out of range" error message | x86 x64 | Yes | |
| Vista SP2 | November 16, 2009 | 975929 | The Meiryo UI font is available for Windows Vista and for Windows Server 2008 | x86 x64 | Yes | |
| Vista SP2 | November 10, 2009 | 969947 | Vulnerabilities in Windows kernel-mode drivers could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | November 10, 2009 | 973565 | Vulnerability in Web Service on devices could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | November 2, 2009 | 976749 | An update is available for Internet Explorer that resolves issues that occur after you apply security update 974455 | x86 x64 | Yes | |
| Vista SP2 | October 27, 2009 | 960362 | Windows Ribbon and Animation Manager Library | x86 x64 | Yes | |
| Vista SP2 | October 27, 2009 | 960568 | Windows Management Framework BITS | x86 x64 | No | |
| Vista SP2 | October 27, 2009 | 968930 | Windows Management Framework Core package (Windows PowerShell 2.0 and WinRM 2.0) | x86 x64 | Yes | |
| Vista SP2 | October 27, 2009 | 969084 | Remote Desktop Connection 7.0 client update for Remote Desktop Services (RDS) for Windows XP SP3, Windows Vista SP1, and Windows Vista SP2 | x86 x64 | No | |
| Vista SP2 | October 27, 2009 | 971035 | Your mini-DVD based camcorder is not recognized on a computer that is running Windows Vista or Windows Server 2008 | x86 x64 | No | |
| Vista SP2 | October 27, 2009 | 971512 | Windows Graphics, Imaging, and XPS Library | x86 x64 | Yes | |
| Vista SP2 | October 27, 2009 | 971513 | Windows Automation API | x86 x64 | Yes | |
| Vista SP2 | October 27, 2009 | 971514 | Windows Portable Devices Platform | x86 x64 | Yes | |
| Vista SP2 | October 27, 2009 | 972145 | "Internet Explorer" is mentioned in several UI phrases for Windows Media Player even though you disable Internet Explorer in Windows Vista | x86 x64 | Yes | |
| Vista SP2 | October 27, 2009 | 975889 | October 2009 update is available for the Customer Experience Improvement Program (CEIP) in Windows Vista and in Windows Server 2008 | x86 x64 | No | |
| Vista SP2 | October 13, 2009 | 954155 | Security update for Windows Media Audio Voice Decoder: October 13, 2009 | x86 x64 | Yes | |
| Vista SP2 | October 13, 2009 | 971486 | Vulnerabilities in Windows kernel could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | October 13, 2009 | 974571 | Vulnerabilities in CryptoAPI could allow spoofing | x86 x64 | Yes | |
| Vista SP2 | October 13, 2009 | 975254 | Vulnerabilities in FTP Service for Internet Information Services could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | October 13, 2009 | 975467 | Vulnerability in the Local Security Authority Subsystem Service could allow denial of service | x86 x64 | Yes | |
| Vista SP2 | October 13, 2009 | 975517 | Vulnerabilities in SMB could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | September 8, 2009 | 967723 | MS09-048: Vulnerabilities in Windows TCP/IP could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | September 8, 2009 | 968816 | MS09-047: Security update for Windows Media Format Runtime, Windows Media Services, and Media Foundation: September 8, 2009 | x86 x64 | Yes | |
| Vista SP2 | September 8, 2009 | 970710 | MS09-049: Vulnerability in Wireless LAN AutoConfig Service could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | September 8, 2009 | 971961 | MS09-045: Vulnerability in JScript Scripting Engines could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | September 8, 2009 | 973768 | MS09-037: Security update for Microsoft HtmlInput Object ActiveX Control in Windows XP Media Center Edition, Windows Vista, and Windows Server 2008: August 11, 2009 | x86 x64 | Yes | |
| Vista SP2 | September 1, 2009 | 972036 | August 2009 Windows Vista and Windows Server 2008 Application Compatibility Update | x86 x64 | Yes | |
| Vista SP2 | September 1, 2009 | 973879 | You receive a "Stop 0x0000003E" error message when you try to install Windows Vista Service Pack 2 or Windows Server 2008 Service Pack 2 on a computer that has certain multiple processors | x64 | No | |
| Vista SP2 | August 25, 2009 | 958911 | An update for GDI+ for Windows operating systems | x86 x64 | No | |
| Vista SP2 | August 25, 2009 | 968912 | An update is available for Windows Vista and for Windows Server 2008 to extend KMS activation support for Windows 7 and for Windows Server 2008 R2 | x86 x64 | No | |
| Vista SP2 | August 25, 2009 | 971029 | Update to the AutoPlay functionality in Windows | x86 x64 | No | |
| Vista SP2 | August 11, 2009 | 956744 | Security update for Remote Desktop Client version 6.0 and 6.1: August 11, 2009 | x86 x64 | Yes | |
| Vista SP2 | August 11, 2009 | 970436 | Internet Explorer 8 stops responding when you use the IME Pad to enter East Asian characters in an Internet Explorer 8 window in Windows Vista or in Windows Server 2008 | x86 x64 | No | |
| Vista SP2 | August 11, 2009 | 971032 | Vulnerability in Message Queuing could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | August 11, 2009 | 971557 | Vulnerabilities in Windows Media file processing could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | August 11, 2009 | 971657 | Vulnerability in the Workstation Service could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | August 11, 2009 | 973540 | Security update for Windows Media Player: August 11, 2009 | x86 x64 | Yes | |
| Vista SP2 | August 7, 2009 | 960859 | Vulnerability in Telnet could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | August 7, 2009 | 968389 | Extended Protection for Authentication | x86 x64 | Yes | |
| Vista SP2 | July 17, 2009 | 952627 | Windows Vista Management Tools update for the release version of Hyper-V | x86 x64 | No | |
| Vista SP2 | July 14, 2009 | 961371 | Vulnerabilities in the Embedded OpenType Font Engine could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | July 14, 2009 | 970408 | A Bluetooth device stops working intermittently on a computer that is running Windows Vista Service Pack 2 | x86 x64 | No | |
| Vista SP2 | June 23, 2009 | 937286 | Windows Vista service pack stand-alone packages do not contain the updated Windows Vista Help files | x86 x64 | No | |
| Vista SP2 | June 23, 2009 | 943729 | Group Policy Preference Client Side Extensions for Windows Vista | x86 x64 | Yes | |
| Vista SP2 | June 23, 2009 | 970203 | Hyper-V Management Tools update for Windows Vista Service Pack 2 | x86 x64 | No | |
| Vista SP2 | June 9, 2009 | 961501 | Vulnerabilities in the Windows Print Spooler could allow remote code execution | x86 x64 | Yes | |
| Vista SP2 | June 9, 2009 | 968537 | Vulnerabilities in Windows Kernel could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | June 9, 2009 | 970238 | Vulnerability in RPC could allow elevation of privilege | x86 x64 | Yes | |
| Vista SP2 | March 19, 2009 | 944036 | Internet Explorer 8 | x86 x64 | No | |
| Vista SP2 | March 7, 2007 | 917607 | A download is available for Windows Vista and Windows Server 2008 that resolves an issue in which you cannot open Help files that require the Windows Help (WinHlp32.exe) program | x86 x64 | No |
Aaron, thank you for your reply. If that is the case, I wonder whether Microsoft will reinstate the hotfix, or it is just an unnecessary update. Your list of Windows hotfixes has been very helpful indeed, Aaron. Keep up the good work!
Hi, I just verified that the link is correct. The download must have been taken down by MS.
Why isn’t hotfix KB 2264107 available for download? Is there a problem for the direct link for this hotfix?
[...] Windows Vista Service Pack 2 [...]
Experimenting around with it, I notice some patches work, other’s do not. From what I can tell (not sure if I’m correct), if it comes across an update it doesn’t like, it stops processing any patches and finishes the install. The trick would be to find which one’s stop it, and which one’s actually do work. That method is very time consuming, Windows 7 may be as not so bad with it’s quick install, and lack of massive updates.
Thank you for that link on WAIK, I do think it’s the best route to go, but felt in the past it was a bit daunting to figure out, that guide is very good.
Yeah, that was a feature that I saw mentioned in an article by one Paul Thurrott (dump all of the hotfixes into an “updates” folder on the DVD), but upon further reading and experimentation, I don’t think it actually works. If it really is that simple, let me know, and I’ll try it again.
I find that since new hotfixes usually come out every other week, it’s too much of a hassle to keep an “up to date” DVD. So these days, I just install using a regular Vista SP2 DVD, and then update the machine using the command prompt method that I have up on the top of this page.
Maybe if you were deploying a lot of machines at once, it would help to have an install DVD with all of the hotfixes integrated. So, here is a guide on integrating hotfixes using WAIK.
Great Site, and appreciate the work you put in to it.
On the old site, there were instructions where if you can alter the vista iso, you can create a folder and put updates in to it, and vista will pick them up and install them automatically. Do you still have those instructions?
Thanks Aaron for this service. I have sent countless people here after learning that their update module was not working properly . So until we fixed the problem , I had them download and install those missing hotfixes to keep their Windows safer.
Again thanks for hard work.
Flashorn.