Fabian Bader · @fabian_bader
592 followers · 122 posts · Server infosec.exchange

There is an out of band patch scheduled for before end of this week. You will have to install the faulty one before you can apply the fix, so plan for a double reboot.

Source:
nitter.it/SteveSyfuhs/status/1

#KB5021131 #kerberos #rc4disaster #aes

Last updated 2 years ago

Fabian Bader · @fabian_bader
592 followers · 122 posts · Server infosec.exchange

I deleted my last post on the updated guidelines for CVE-2022-37966

The workaround mentioned in the article at the time was not meant as a workaround as SteveSyfuhs clarified.

nitter.it/SteveSyfuhs/status/1

It was therefore removed from the updated version of the article

support.microsoft.com/en-us/to

#KB5021131

Last updated 2 years ago

Fabian Bader :verified: · @fabian_bader
344 followers · 74 posts · Server infosec.exchange

Updated guidelines for
How to manage the Kerberos protocol changes related to CVE-2022-37966

ApplyDefaultDomainPolicy is the official workaround.

support.microsoft.com/en-us/to

#KB5021131 #kerberos #RC4 #aes

Last updated 2 years ago

Fabian Bader · @fabian_bader
592 followers · 122 posts · Server infosec.exchange

Why does set the default encryption type for session keys also to DES-CBC-CRC + DES-CBC-MD5? Shouldn't this value be set to 24 to only allow AES128 + AES256?

#KB5021131 #kerberos #patchtuesday

Last updated 2 years ago