Why doesn MBSA provide reboot pending status for the latest updates?
MBSA can only provide reboot pending status when the option to Check for Windows administrative vulnerabilities is selected in the GUI or by default if “/n Updates” is not added to the command-line utility (CLI) to suppress this feature. Reboot pending status is obtained directly from the Windows Update Agent (WUA) client on each target machine. As long as the security update was installed using a WUA-supported process (Windows Update, Microsoft Update, SMS w/ITMU, or WSUS Server), MBSA can report any required pending reboot. If an update has been installed manually or through a third-party installation process, MBSA is unable to report reboot pending state. For customers using the /xmlout option from the command-line utility, the pending reboot status is not available due to the limitation of using the /xmlout option. Workarounds may include running mbsacli.exe without any switches.