DocumentationAPI ReferenceRelease Notes
Release Notes

Security Update Package Installer 3.3.4 release notes

🆕 New features

There are no new features in this release.

✨ Enhancements

There are no enhancements in this release.

🛠️ Issues resolved

Product areaDescriptionResolution
SecurityAn update package could be altered after it passed a security check.Update packages are now protected from tampering after they're verified.
SecurityCertain update processes were vulnerable to attacks that could run unauthorized commands.These processes are now protected against this type of attack.
SecurityUpdate files and logs had overly open permissions, allowing unauthorized access.File and folder permissions are now properly restricted.
SecuritySome update scheduling features could be accessed without logging in.These features now require proper authentication.
SecurityUpdate status notifications could be sent by unauthorized users.Notifications now require proper authentication.
SecurityA data lookup feature was vulnerable to unauthorized database access.This feature is now protected against unauthorized access.
SecurityThe check that verifies a trusted software publisher could be tricked.This check now correctly verifies the publisher's identity.
SecurityAn update process could install files that weren't properly verified.All files are now verified before installation.
SecurityUnexpected input could cause the update service to crash.The service now handles unexpected input without crashing.
SecurityUpdate files could be extracted to unintended locations.Files are now extracted only to their intended location.
SecurityA cleanup process could remove the wrong folder.Cleanup now only affects the correct folder.
SecurityA safeguard against files being placed outside their intended folder could be bypassed.This safeguard is now more reliable and cannot be bypassed.
SecurityUpdate packages signed with a revoked security certificate could still be trusted.Revoked certificates are no longer trusted.
SecuritySome older update files were automatically trusted without proper verification.All update files are now consistently verified.
SecurityA system utility could be tricked into writing log data to the wrong location.This utility now writes logs to a secure location.
SecuritySome network communications didn't properly verify the server they connected to.These communications now properly verify the destination server.
SecurityA feature that checks for new updates could be triggered without authorization.This feature now requires proper authentication.
SecurityInternal communication used to verify user sessions didn't fully confirm the other party's identity.This communication now properly verifies identity.
SecurityA permissions check always reported users as administrators, regardless of their actual access level.This check now correctly reflects each user's actual access level.
SecurityA critical update feature, including the ability to restart the system, could be triggered without authorization.This feature now requires proper authentication.
UpgradeA required update step could be permanently skipped if it wasn't needed yet when the update was downloaded, even if it became needed later.This step is now checked again right before installation.
UpgradeAn update step could fail if it ran before Windows finished processing the previous update after a restart.The system now waits for Windows to finish before continuing.
UpgradeOn some Windows Server 2016 systems, an unexpected restart during an update could prevent later security updates from installing.Updates now install successfully even after this type of restart.

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.