| MC533707 | Reminder: The Third deployment phase for CVE-2022-37967 starts with updates released April 11, 2023 |
|---|
| Classification | preventOrFixIssue |
|---|---|
| Last Updated | 03/27/2023 18:02:55 |
| Start Time | 03/27/2023 18:02:54 |
| End Time | 04/11/2024 17:00:00 |
| Action Required By Date | 2023-04-11T17:00:00Z |
| Message Content |
Security hardening changes to address CVE-2022-37967 will enter the Third deployment phase with the release of updates on April 11, 2023, as outlined in KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967. Each phase raises the default minimum for the security hardening changes for CVE-2022-37967 and your environment must be compliant before installing updates for each phase onto your Domain Controller.
When this will happen:
CVE-2022-37967 will enter the Third deployment phase with the release of updates on April 11, 2023. There will also be two more phases after the Third deployment phase; July 11, 2023 – Initial enforcement phase and October 10, 2023 – Full enforcement phases.
How this will affect your organization:
Your environment must be compliant with the hardening changes before installing updates for each phase onto your Domain Controller. To enable all parts of the security hardening in your environment, it is recommended to move to enforcement mode as soon as possible.
What you need to do to prepare:
If you are using the workaround to disable PAC signature addition by setting the KrbtgtFullPacSignature subkey to a value of 0, you will no longer be able to use this workaround after installing updates released April 11, 2023. Your apps and environment will need to at least be compliant with KrbtgtFullPacSignature subkey to a value of 1 to install these updates on your Domain Controllers.
If you are not using any workaround for issues related to CVE-2022-37967 security hardening, you might still need to address issues in your environment for the coming phases; July 11, 2023 – Initial enforcement phase and October 10, 2023 – Full enforcement phases.
Additional information:
|
| Machine Translation |
CVE-2022-37967に対処するためのセキュリティ強化の変更は、KB5020805:CVE-2022-37967に関連するKerberosプロトコルの変更を管理する方法で説明されているように、2023年4月11日の更新プログラムのリリースで第3展開フェーズに入ります。各フェーズでは、CVE-2022-37967 のセキュリティ強化の変更の既定の最小値が引き上げられ、各フェーズの更新プログラムをドメイン コントローラーにインストールする前に、環境が準拠している必要があります。
これが発生する場合:
CVE-2022-37967は、2023 年4月11日のアップデートのリリースで第3展開フェーズに入ります。また、第 3 展開フェーズの後にさらに 2 つのフェーズがあります。2023 年 7 月 11 日 – 最初の適用フェーズと 2023 年 10 月 10 日 – 完全な適用フェーズ。
これが組織に与える影響:
環境は、各フェーズの更新プログラムをドメイン コントローラーにインストールする前に、セキュリティ強化の変更に準拠している必要があります。環境内のすべてのセキュリティ強化を有効にするには、できるだけ早く強制モードに移行することをお勧めします。
準備するために必要なこと:
回避策を使用して、KrbtgtFullPacSignature サブキー の値を 0 に設定して PAC 署名の追加を無効にしている場合、2023 年 4 月 11 日にリリースされた更新プログラムをインストールした後は、この回避策を使用できなくなります。アプリと環境は、ドメイン コントローラーにこれらの更新プログラムをインストールするために、少なくとも KrbtgtFullPacSignature サブキー に値 1 に準拠している必要があります。
CVE-2022-37967 のセキュリティ強化に関連する問題の回避策を使用していない場合でも、次のフェーズで環境内の問題に対処する必要がある場合があります。2023 年 7 月 11 日 – 最初の適用フェーズと 2023 年 10 月 10 日 – 完全な適用フェーズ。
追加情報:
|