Windows 10: KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967

Discus and support KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967 in Windows 10 Gaming to solve the problem; In the article titled "KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967" there is a lot of talk about the registry value... Discussion in 'Windows 10 Gaming' started by its_Tricky83, Jul 13, 2023.

  1. KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967


    In the article titled "KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967" there is a lot of talk about the registry value KrbtgtFullPacSignature However, there is no mention of whether this value needs to be manually created, or if it is supposed to have been automatically created in due course with the install of the appropriate Windows Updates.Each of our Server 2016 Domain Controllers have seemingly never had the KrbtgtFullPacSignature registry value created and I'm starting to wonder why?Each server has had its OS updates apply including the most recent

    :)
     
    its_Tricky83, Jul 13, 2023
    #1
  2. pamowsky Win User

    KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967

    Hi, There is an enforcement due on the 11th July from Microsoft due to a security vulnerability, Please see under article:

    KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967 - Microsoft Support

    The November 8, 2022 Windows updates address security bypass and elevation of privilege vulnerabilities with Privilege Attribute Certificate (PAC) signatures. This security update addresses Kerberos vulnerabilities where an attacker could digitally alter PAC signatures, raising their privileges.

    To help secure your environment, install this Windows update to all devices, including Windows domain controllers. All domain controllers in your domain must be updated first before switching the update to Enforced mode.

    To learn more about this vulnerabilities, see CVE-2022-37967.

    Just a quick question, does it mean that any servers running 2003OS or 2008OS in an esatate would no longer work?

    The article doesnt appear to have been updated for a while.

    Thanks
     
    pamowsky, Jul 13, 2023
    #2
  3. AaronH03 Win User
    CVE-2022-30190 workaround for Windows 7

    The guidance for CVE-2022-30190 mentions deleting the MSDT URL Protocol as a workaround for this vulnerability.

    /blog/2022/05/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/

    However, the FAQ says "The registry key mentioned in the workaround section will not exist in earlier supported versions of Windows, so the workaround is not required."

    Does this mean there is no workaround for Windows 7 and the only solution is to install the July 2022 security update?
     
    AaronH03, Jul 13, 2023
    #3
  4. Tenforo Active Member

    KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967

    CVE-2022-30190 workaround for Windows 7

    This is a consumer-oriented peer-to-peer support forum. Support issues that may arise under Microsoft's Extended Security Updates (ESU) program are beyond the scope of this forum.

    Did you purchase ESU for 2022? If not, you do not have access to the July 2022 security update.

    If you did purchase ESU for 2022, see FAQ about Extended Security Updates (Ety= regarding technical support.

    As I understand the Guidance for CVE-2022-30190:

    • A remote code execution vulnerability exists when MSDT is called using the URL protocol
    • The MSDT URL protocol is not available in versions of Windows earlier than Windows Server 2019 & Windows 10 version 1809, i.e., the MSDT URL protocol isn't available in Windows 7.
    Thus, the vulnerability does not appear (to me) to exist in Windows 7. For a more definitive answer see the link above.
     
    Tenforo, Jul 13, 2023
    #4
Thema:

KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967

Loading...
  1. KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967 - Similar Threads - KB5020805 manage Kerberos

  2. Exchange CU13 and latest SU, yet external scans claim CVE-2022-41040 CVE-2022-41082...

    in Windows 10 Gaming
    Exchange CU13 and latest SU, yet external scans claim CVE-2022-41040 CVE-2022-41082...: Per Exchange Health Checker version 24.03.12.1700 this is my Exchange version. Build Number: 15.02.1258.032 Exchange IU or Security Hotfix Detected:Security Update for Exchange Server 2019 Cumulative Update 13 KB5036402We always run one CU behind the latest, and we pay for...
  3. blacklotus CVE-2022-21894

    in Windows 10 Gaming
    blacklotus CVE-2022-21894: What's the latest news on the Blacklotus vulnerability?as CVE-2022-21894I'm becoming paranoid just booting up. The NSA has issued mitigation remedy but also issues a strongly worded caution.... Such as if you don't know what you're doing don't try it because it's difficult....
  4. blacklotus CVE-2022-21894

    in Windows 10 Software and Apps
    blacklotus CVE-2022-21894: What's the latest news on the Blacklotus vulnerability?as CVE-2022-21894I'm becoming paranoid just booting up. The NSA has issued mitigation remedy but also issues a strongly worded caution.... Such as if you don't know what you're doing don't try it because it's difficult....
  5. blacklotus CVE-2022-21894

    in AntiVirus, Firewalls and System Security
    blacklotus CVE-2022-21894: What's the latest news on the Blacklotus vulnerability?as CVE-2022-21894I'm becoming paranoid just booting up. The NSA has issued mitigation remedy but also issues a strongly worded caution.... Such as if you don't know what you're doing don't try it because it's difficult....
  6. blacklocust CVE-2022-21894

    in Windows 10 Gaming
    blacklocust CVE-2022-21894: What's the latest news on the Blacklocust vulnerability?as CVE-2022-21894 https://answers.microsoft.com/en-us/windows/forum/all/blacklocust-cve-2022-21894/2d0c56b3-5ba4-43de-853c-0c1cd02adbaa
  7. KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967

    in Windows 10 Software and Apps
    KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967: In the article titled "KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967" there is a lot of talk about the registry value KrbtgtFullPacSignature However, there is no mention of whether this value needs to be manually created, or if it is supposed to...
  8. KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967

    in Windows 10 Installation and Upgrade
    KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967: In the article titled "KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967" there is a lot of talk about the registry value KrbtgtFullPacSignature However, there is no mention of whether this value needs to be manually created, or if it is supposed to...
  9. KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967

    in Windows 10 Gaming
    KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967: Hi, There is an enforcement due on the 11th July from Microsoft due to a security vulnerability, Please see under...
  10. KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967

    in Windows 10 Software and Apps
    KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967: Hi, There is an enforcement due on the 11th July from Microsoft due to a security vulnerability, Please see under...