image credit: Pexels

Microsoft releases out-of-band update to fix Kerberos auth issues caused by a patch for CVE-2022-37966

November 23, 2022

Microsoft released an out-of-band update to address issues caused by a recent Windows security patch that causes Kerberos authentication problems.

Microsoft Patch Tuesday security updates for November 2022 addressed a privilege escalation vulnerability, tracked as CVE-2022-37966, that impacts Windows Server.

An attacker can trigger this flaw to gain administrator privileges on vulnerable systems.

“An unauthenticated attacker could conduct an attack that could leverage cryptographic protocol vulnerabilities in RFC 4757 (Kerberos encryption type RC4-HMAC-MD5) and MS-PAC (Privilege Attribute Certificate Data Structure specification) to bypass security features in a Windows AD environment.” reads the advisory published by Microsoft.

Read More on Security Affairs