News: 1653051610

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft patches the patch that broke Windows authentication

(2022/05/20)


Microsoft has released an out-of-band patch to deal with an authentication issue that was introduced in the May 10 Windows update.

Elizabeth Tyler, cyber security consultant on Microsoft's Detection and Response Team, confirmed the fix to worried administrators early this morning.

Yes, fixed and released 19 May.

CU:

WS 2022: KB5015013

WS, version 20H2: KB5015020

WS 2019: KB5015018

WS 2016: KB5015019

Standalone:

WS 2012 R2: KB5014986

WS 2012: KB5014991

WS 2008 R2 SP1: KB5014987

WS 2008 SP2: KB5014990 — Elizabeth Tyler (@MSetyler) [1]May 20, 2022

[2]Multiple administrators complained last week that after installing the May 10 patch, they experienced authentication failures across several systems.

Tyler [3]said at the time: "We know the root cause is the subject name is incorrectly used to map the cert to a machine account in AD rather than the DNSHostname in the subject alternative name on DCs that have installed 5b and we're working it."

An entry then turned up in the lengthy list of known issues for the patch in which Microsoft warned that, after installing the May 10 patch on domain controllers, there might be issues with some services.

[4]

"These services," it said, "include Network Policy Server (NPS), Routing and Remote access Service (RRAS), Radius, Extensible Authentication Protocol (EAP), and Protected Extensible Authentication Protocol (PEAP).

[5]Start your engines: Windows 11 ready for broad deployment

[6]Bing! Microsoft tests search box in the middle of Windows 11 desktop

[7]Microsoft-backed robovans to deliver grub in London

[8]Warning: Windows update breaks authentication for some server admins

"An issue has been found related to how the domain controller manages the mapping of certificates to machine accounts."

As with many updates, the May 10 patch was an important one, and [9]included fixes for "high severity" elevation-of-privilege vulnerabilities that could occur when the Kerberos Distribution Center (KDC) serviced a certificate-based authentication request.

[10]

Backing out of the update apparently resolved the problems but, as one user [11]observed , "this is quite a critical patch but seems to break quite a key role!"

Administrators would be forgiven for feeling that patches to fix patches seem to be becoming a little too common over the years. ®

Get our [12]Tech Resources



[1] https://twitter.com/MSetyler/status/1527554744201490432?ref_src=twsrc%5Etfw

[2] https://www.theregister.com/2022/05/12/windows_server_update_authentication_errors/

[3] https://twitter.com/MSetyler/status/1524845205349879841

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yoe7Ip-OEdnmrxiazVwK8AAAAE8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://www.theregister.com/2022/05/19/windows_11_deployment/

[6] https://www.theregister.com/2022/05/19/windows_insider_desktop_search_box/

[7] https://www.theregister.com/2022/05/19/selfdriving_microsoft_wayve/

[8] https://www.theregister.com/2022/05/12/windows_server_update_authentication_errors/

[9] https://support.microsoft.com/en-gb/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16#bkmk_compatmode

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yoe7Ip-OEdnmrxiazVwK8AAAAE8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.reddit.com/r/sysadmin/comments/um9qur/patch_tuesday_megathread_20220510/i861pev/

[12] https://whitepapers.theregister.com/



"patches to fix patches seem to be becoming a little too common"

Pascal Monett

Okay, I'll be the first to admit that networking is not always easy, especially when you're a vendor with an uncountable number of variations to handle.

Still, I stand by the idea that having a Quality Control team to test and wean out the at least some of the problems would go a long way to make these out-of-band patches rarer than they are.

Re: "patches to fix patches seem to be becoming a little too common"

Captain Scarlet

Seems like the original programmers may be long gone, so essential knowledge of how different legacy services are impacted has been lost.

Re: "patches to fix patches seem to be becoming a little too common"

EnviableOne

seems a little bit of schadenfreude that they managed to lay them all off in an effort to save costs

Lee D

It's not a "patch" if it does 10 unrelated things and breaks domain controllers.

re: it's not a patch

Steve Davies 3

agreed. More like a sneak peek of the clusterfuck that Windows is fast becoming.

Never mind... When Azure hosts all your windows systems this will all be a thing of the past other than 'glitches' like this will mean total TITSUP and MS sticking their collective fingers in their ears and shouting 'read the small print' and denying any liability for their mistakes.

meanwhile... those of us who saw the runes with W10 and left the ship even before the W11 drone strike will be laughing all the way to the bank and keeping their customers happy

Re: re: it's not a patch

Evil Scot

You assume that your bank hasn't adopted Azure.

Total Software Borkage happens there too.

Brewster's Angle Grinder

I'll give you the ten unrelated things.

But you know how bugs are - they lay hidden for long enough and other code becomes dependent on the buggy behaviour so that when you fix them, a whole bunch of downstream things break.

In the war of wits, he's unarmed.