by

CISA Temporarily Removes CVE-2022-26925 from Known Exploited Vulnerability Catalog

Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow

You are subscribed to Cybersecurity Advisories for Cybersecurity and Infrastructure Security Agency. This information has recently been updated, and is now available.

05/13/2022 08:20 PM EDT

Original release date: May 13, 2022

CISA is temporarily removing CVE-2022-26925 from its
Known Exploited Vulnerability Catalog
 due to a risk of authentication failures when the May 10, 2022 Microsoft rollup update is applied to domain controllers. After installing May 10, 2022 rollup update on domain controllers, organizations might experience
authentication failures on the server or client for services, such as Network Policy Server (NPS), Routing and Remote access Service (RRAS), Radius, Extensible Authentication Protocol (EAP), and Protected Extensible Authentication Protocol (PEAP). Microsoft
notified CISA of this issue, which is related to how the mapping of certificates to machine accounts is being handled by the domain controller.

For more information see the Microsoft Knowledge Base article,
KB5014754—Certificate-based authentication changes on Windows domain controllers: Key Distribution Center registry key
.

Note: installation of updates released May 10, 2022, on client Windows devices and non-domain controller Windows Servers will not cause this issue and is still strongly encouraged. This issue only affects May 10, 2022 updates installed on
servers used as domain controllers. Organizations should continue to apply updates to client Windows devices and non-domain controller Windows Servers.

This product is provided subject to this
Notification
and this Privacy & Use policy.

Having trouble viewing this message? View
it as a webpage

You are subscribed to updates from the
Cybersecurity and Infrastructure Security Agency (CISA)
Manage Subscriptions  |  Privacy
Policy
  | 
Help

Connect with CISA:

Facebook  | 
Twitter  | 
Instagram  | 
LinkedIn  |  
YouTube


This email was sent to b13b3fdf.spsmail.cuny.edu@amer.teams.ms using GovDelivery Communications Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency · 707 17th St, Suite
4000 · Denver, CO 80202
GovDelivery logo

Write a Comment

Comment

  • Related Content by Tag