{"id":866,"date":"2023-03-28T04:01:47","date_gmt":"2023-03-27T19:01:47","guid":{"rendered":"https:\/\/m365jp.xyz\/?p=866"},"modified":"2023-03-28T04:09:15","modified_gmt":"2023-03-27T19:09:15","slug":"mc533707-reminder-the-third-deployment-phase-for-cve-2022-37967-starts-with-updates-released-april-11-2023","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2023-03-28-mc533707-reminder-the-third-deployment-phase-for-cve-2022-37967-starts-with-updates-released-april-11-2023","title":{"rendered":"MC533707 | Reminder: The Third deployment phase for CVE-2022-37967 starts with updates released April 11, 2023"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<hr>\n<table id=\"section\">\n<tbody>\n<tr>\n<th width=\"95%\">MC533707 | Reminder: The Third deployment phase for CVE-2022-37967 starts with updates released April 11, 2023<\/th>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<table id=\"data\">\n<tbody>\n<tr>\n<th>Classification<\/th>\n<td>preventOrFixIssue<\/td>\n<\/tr>\n<tr>\n<th>Last Updated<\/th>\n<td>03\/27\/2023 18:02:55<\/td>\n<\/tr>\n<tr>\n<th>Start Time<\/th>\n<td>03\/27\/2023 18:02:54<\/td>\n<\/tr>\n<tr>\n<th>End Time<\/th>\n<td>04\/11\/2024 17:00:00<\/td>\n<\/tr>\n<tr>\n<th>Action Required By Date<\/th>\n<td>2023-04-11T17:00:00Z<\/td>\n<\/tr>\n<tr>\n<th>Message Content<\/th>\n<td>\n<div>Security hardening changes to address <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37967\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2022-37967<\/a> will enter the Third deployment phase with the release of updates on April 11, 2023, as outlined in  <a href=\"https:\/\/support.microsoft.com\/help\/5020805\" rel=\"noopener noreferrer\" target=\"_blank\">  KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967<\/a>. Each phase raises the default minimum for the security hardening changes for  <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37967\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2022-37967<\/a> and your environment must be compliant before installing updates for each phase onto your Domain Controller.<\/div>\n<div>  <\/div>\n<div><strong>When this will happen:<\/strong><\/div>\n<div><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37967\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2022-37967<\/a> will enter the Third deployment phase with the release of updates on April 11, 2023. There will also be two more   phases after the Third deployment phase; July 11, 2023 &#8211; Initial enforcement phase and October 10, 2023 &#8211; Full enforcement phases.<\/div>\n<div>  <\/div>\n<div><strong>How this will affect your organization:<\/strong><\/div>\n<div>Your environment must be compliant with the hardening changes before installing updates for each phase onto your Domain Controller. To enable all parts of the security hardening in your environment, it is recommended to move to enforcement mode as soon   as possible.<\/div>\n<div>  <\/div>\n<div><strong>What you need to do to prepare:<\/strong><\/div>\n<div>If you are using the workaround to disable PAC signature addition by setting the  <strong>KrbtgtFullPacSignature<\/strong>&nbsp;subkey to a value of&nbsp;<strong>0<\/strong>, you will no longer be able to use this workaround after installing updates released April 11, 2023. Your apps and environment will need to at least be compliant with  <strong>KrbtgtFullPacSignature<\/strong>&nbsp;subkey to a value of&nbsp;1 to install these updates on your Domain Controllers.<\/div>\n<div>If you are not using any workaround for issues related to <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37967\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2022-37967<\/a> security hardening, you might still need to address issues in your environment for the coming phases; July 11, 2023 &#8211; Initial enforcement phase and October 10, 2023 &#8211; Full enforcement phases.<\/div>\n<div>  <\/div>\n<div><strong>Additional information:<\/strong><\/div>\n<ul>\n<li><a href=\"https:\/\/support.microsoft.com\/help\/5020805\" rel=\"noopener noreferrer\" target=\"_blank\">KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967<\/a><\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37967\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2022-37967 &#8211; Security Update Guide &#8211; Microsoft &#8211; Windows Kerberos Elevation of Privilege Vulnerability<\/a><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<th>Machine Translation<\/th>\n<td>\n<div>CVE-2022-37967\u306b\u5bfe\u51e6\u3059\u308b\u305f\u3081\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5f37\u5316\u306e\u5909\u66f4\u306f\u3001<a href=\"https:\/\/support.microsoft.com\/help\/5020805\" rel=\"noopener noreferrer\" target=\"_blank\">KB5020805:CVE-2022-37967\u306b\u95a2\u9023\u3059\u308bKerberos\u30d7\u30ed\u30c8\u30b3\u30eb\u306e\u5909\u66f4\u3092\u7ba1\u7406\u3059\u308b\u65b9\u6cd5<\/a>\u3067\u8aac\u660e\u3055\u308c\u3066\u3044\u308b\u3088\u3046\u306b\u3001<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37967\" rel=\"noopener noreferrer\" target=\"_blank\">2023<\/a>\u5e744\u670811\u65e5\u306e\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u306e\u30ea\u30ea\u30fc\u30b9\u3067\u7b2c3\u5c55\u958b\u30d5\u30a7\u30fc\u30ba\u306b\u5165\u308a\u307e\u3059\u3002\u5404\u30d5\u30a7\u30fc\u30ba\u3067\u306f\u3001<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37967\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2022-37967<\/a>   \u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5f37\u5316\u306e\u5909\u66f4\u306e\u65e2\u5b9a\u306e\u6700\u5c0f\u5024\u304c\u5f15\u304d\u4e0a\u3052\u3089\u308c\u3001\u5404\u30d5\u30a7\u30fc\u30ba\u306e\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u3092\u30c9\u30e1\u30a4\u30f3 \u30b3\u30f3\u30c8\u30ed\u30fc\u30e9\u30fc\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u524d\u306b\u3001\u74b0\u5883\u304c\u6e96\u62e0\u3057\u3066\u3044\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/div>\n<div>  <\/div>\n<div><strong>\u3053\u308c\u304c\u767a\u751f\u3059\u308b\u5834\u5408:<\/strong><\/div>\n<div><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37967\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2022-37967\u306f\u30012023<\/a> \u5e744\u670811\u65e5\u306e\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u306e\u30ea\u30ea\u30fc\u30b9\u3067\u7b2c3\u5c55\u958b\u30d5\u30a7\u30fc\u30ba\u306b\u5165\u308a\u307e\u3059\u3002\u307e\u305f\u3001\u7b2c 3 \u5c55\u958b\u30d5\u30a7\u30fc\u30ba\u306e\u5f8c\u306b\u3055\u3089\u306b 2 \u3064\u306e\u30d5\u30a7\u30fc\u30ba\u304c\u3042\u308a\u307e\u3059\u30022023 \u5e74 7 \u6708 11 \u65e5 &#8211; \u6700\u521d\u306e\u9069\u7528\u30d5\u30a7\u30fc\u30ba\u3068 2023 \u5e74 10   \u6708 10 \u65e5 &#8211; \u5b8c\u5168\u306a\u9069\u7528\u30d5\u30a7\u30fc\u30ba\u3002<\/div>\n<div>  <\/div>\n<div><strong>\u3053\u308c\u304c\u7d44\u7e54\u306b\u4e0e\u3048\u308b\u5f71\u97ff:<\/strong><\/div>\n<div>\u74b0\u5883\u306f\u3001\u5404\u30d5\u30a7\u30fc\u30ba\u306e\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u3092\u30c9\u30e1\u30a4\u30f3 \u30b3\u30f3\u30c8\u30ed\u30fc\u30e9\u30fc\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u524d\u306b\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5f37\u5316\u306e\u5909\u66f4\u306b\u6e96\u62e0\u3057\u3066\u3044\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u74b0\u5883\u5185\u306e\u3059\u3079\u3066\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5f37\u5316\u3092\u6709\u52b9\u306b\u3059\u308b\u306b\u306f\u3001\u3067\u304d\u308b\u3060\u3051\u65e9\u304f\u5f37\u5236\u30e2\u30fc\u30c9\u306b\u79fb\u884c\u3059\u308b\u3053\u3068\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002<\/div>\n<div>  <\/div>\n<div><strong>\u6e96\u5099\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u306a\u3053\u3068:<\/strong><\/div>\n<div><strong>\u56de\u907f\u7b56\u3092\u4f7f\u7528\u3057\u3066\u3001KrbtgtFullPacSignature<\/strong>&nbsp;\u30b5\u30d6\u30ad\u30fc&nbsp;\u306e\u5024\u3092 <strong>0<\/strong> \u306b\u8a2d\u5b9a\u3057\u3066 PAC \u7f72\u540d\u306e\u8ffd\u52a0\u3092\u7121\u52b9\u306b\u3057\u3066\u3044\u308b\u5834\u5408\u30012023 \u5e74 4 \u6708 11 \u65e5\u306b\u30ea\u30ea\u30fc\u30b9\u3055\u308c\u305f\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u5f8c\u306f\u3001\u3053\u306e\u56de\u907f\u7b56\u3092\u4f7f\u7528\u3067\u304d\u306a\u304f\u306a\u308a\u307e\u3059\u3002\u30a2\u30d7\u30ea\u3068\u74b0\u5883\u306f\u3001\u30c9\u30e1\u30a4\u30f3 \u30b3\u30f3\u30c8\u30ed\u30fc\u30e9\u30fc\u306b\u3053\u308c\u3089\u306e\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u305f\u3081\u306b\u3001\u5c11\u306a\u304f\u3068\u3082  <strong>KrbtgtFullPacSignature<\/strong>&nbsp;\u30b5\u30d6\u30ad\u30fc&nbsp;\u306b\u5024 1 \u306b\u6e96\u62e0\u3057\u3066\u3044\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/div>\n<div><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37967\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2022-37967<\/a> \u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5f37\u5316\u306b\u95a2\u9023\u3059\u308b\u554f\u984c\u306e\u56de\u907f\u7b56\u3092\u4f7f\u7528\u3057\u3066\u3044\u306a\u3044\u5834\u5408\u3067\u3082\u3001\u6b21\u306e\u30d5\u30a7\u30fc\u30ba\u3067\u74b0\u5883\u5185\u306e\u554f\u984c\u306b\u5bfe\u51e6\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u30022023 \u5e74 7 \u6708 11 \u65e5 &#8211; \u6700\u521d\u306e\u9069\u7528\u30d5\u30a7\u30fc\u30ba\u3068 2023 \u5e74 10 \u6708 10 \u65e5 &#8211;   \u5b8c\u5168\u306a\u9069\u7528\u30d5\u30a7\u30fc\u30ba\u3002<\/div>\n<div>  <\/div>\n<div><strong>\u8ffd\u52a0\u60c5\u5831:<\/strong><\/div>\n<ul>\n<li><a href=\"https:\/\/support.microsoft.com\/help\/5020805\" rel=\"noopener noreferrer\" target=\"_blank\">KB5020805:CVE-2022-37967\u306b\u95a2\u9023\u3059\u308bKerberos\u30d7\u30ed\u30c8\u30b3\u30eb\u306e\u5909\u66f4\u3092\u7ba1\u7406\u3059\u308b\u65b9\u6cd5<\/a><\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37967\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2022-37967 &#8211; \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0 \u30ac\u30a4\u30c9 &#8211; \u30de\u30a4\u30af\u30ed\u30bd\u30d5\u30c8 &#8211; Windows Kerberos \u306e\u7279\u6a29\u306e\u6607\u683c\u306e\u8106\u5f31\u6027<\/a><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MC533707 | Reminder: The Third deployment phase for CVE-2022-37967 starts with updates released April 11, 2023 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-866","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/866","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=866"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/866\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=866"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=866"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=866"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}