Windows Kerberos crashes due to security updates

Microsoft investigates new known issue that causes corporate domain controllers to experience Kerberos authentication problems Patch Tuesday, November 10th.

Το Kerberos αντικατέστησε το πρωτόκολλο NTLM σαν το προεπιλεγμένο πρωτόκολλο ελέγχου ταυτότητας για συσκευές συνδεδεμένες στο σε όλες τις εκδόσεις των Windows πάνω από τα Windows 2000.

Authentication protocols allow authentication of users, computers and services, allowing authorized and users to access resources securely.

CVE-2020-17049 is a remote exploitation capability of the Kerberos Constrained Delegation (KCD) and exists in the way KDC determines whether service credentials can be used for KCD outsourcing.

Security updates behind authorization issues

"After installing KB4586781 on domain controllers (DC) and read-only domain controllers (RODC) in your environment, you may experience authentication problems in Kerberos," explains Microsoft.

"This is due to a problem with CVE-2020-17049 in these updates. As noted in CVE-2020-17049, there are three registry setting values ​​for PerformTicketSignature for testing, but in the current application you may experience different issues with each setting. ”

The problem only affects Windows servers, their devices and vulnerable applications in enterprise environments according to Microsoft.

Affected Windows platforms

Kerberos domain-controlled Windows devices that use MIT Kerberos spheres affected by this recently recognized issue include read-only domain controllers, as explained by Microsoft.

The server platforms affected by this issue are listed in the table below, along with the cumulative updates that cause domain controllers to experience problems with Kerberos authentication and post-installation ticket refresh.

Affected platforms
Servant Source of information
Windows Server, version 20H2 KB4586781
Windows Server, 2004 version KB4586781
Windows Server, 1909 version KB4586786
Windows Server, 1903 version KB4586786
Windows Server 2019 KB4586793
Windows Server 2016 KB4586830
Windows Server 2012 R2 KB4586845
Windows Server 2012 KB4586834

Microsoft is working to fix this known issue and will release an update with additional details as more are available .

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).