<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
    <link>http://forum.geizhals.at/feed.jsp?id=856329</link>
    <description>Geizhals-Forum</description>
    <item>
      <title>Re(3): Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7384064.html#7384064</link>
      <description>Und Ihr habt keinen NDA-Knebel? Schweinerei. &lt;img src="smile.gif" width="16" height="19" align="absmiddle" alt=":)"/&gt;&lt;br/&gt;</description>
      <pubDate>Thu, 20 Nov 2014 20:55:39 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7384064.html#7384064</guid>
      <dc:creator>Fly</dc:creator>
      <dc:date>2014-11-20T20:55:39Z</dc:date>
    </item>
    <item>
      <title>Re(7): Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7384063.html#7384063</link>
      <description>Na dann hast eh letzte Woche schon deine Arbeit getan. &lt;img src="zwinker.gif" width="16" height="19" align="absmiddle" alt=";)"/&gt;&lt;br/&gt;</description>
      <pubDate>Thu, 20 Nov 2014 20:54:39 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7384063.html#7384063</guid>
      <dc:creator>Fly</dc:creator>
      <dc:date>2014-11-20T20:54:39Z</dc:date>
    </item>
    <item>
      <title>Re(7): Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383637.html#7383637</link>
      <description>Jo, die EX13 CUs waren wirklich alle schlimm. &lt;br/&gt;</description>
      <pubDate>Thu, 20 Nov 2014 07:20:11 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383637.html#7383637</guid>
      <dc:creator>nightmare11at</dc:creator>
      <dc:date>2014-11-20T07:20:11Z</dc:date>
    </item>
    <item>
      <title>Re(6): Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383531.html#7383531</link>
      <description>Bin ich froh dass ich nur für die Clients zuständig bin &lt;img src="smile.gif" width="16" height="19" align="absmiddle" alt=":-)"/&gt;&lt;br&gt;&lt;br&gt;Die Updates gehen zuerst an ein Handvoll auserlesene Benutzer, und wann alles funktioniert und nichts in den Medien aufscheint, gehen sie drei Tage später an alle User... Die Server werden von Kollegen betreut...&lt;br/&gt;</description>
      <pubDate>Wed, 19 Nov 2014 20:03:34 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383531.html#7383531</guid>
      <dc:creator>Ardjan</dc:creator>
      <dc:date>2014-11-19T20:03:34Z</dc:date>
    </item>
    <item>
      <title>Re(6): Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383452.html#7383452</link>
      <description>Hab's auf Heise auch schon gelesen..&lt;br&gt;Bei den ersten Exchange 2013 CUs wars genau so...&lt;br&gt;Ein Griff ins WC nach dem anderen momentan&lt;br/&gt;</description>
      <pubDate>Wed, 19 Nov 2014 16:50:03 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383452.html#7383452</guid>
      <dc:creator>tridh</dc:creator>
      <dc:date>2014-11-19T16:50:03Z</dc:date>
    </item>
    <item>
      <title>Re(5): Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383423.html#7383423</link>
      <description>Naja, unsere SQL Server erlebten einen noch nie dagewesenen Performanceeinbruch. Das Problem haben auch andere. Nach Deinstallation des Patches normalisiert sich sofort wieder alles.&lt;br/&gt;</description>
      <pubDate>Wed, 19 Nov 2014 16:07:11 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383423.html#7383423</guid>
      <dc:creator>nightmare11at</dc:creator>
      <dc:date>2014-11-19T16:07:11Z</dc:date>
    </item>
    <item>
      <title>Re(4): Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383232.html#7383232</link>
      <description>Hast du Infos zu den Problemen?&lt;br&gt;Gröbere Probleme zu erwarten?&lt;br/&gt;</description>
      <pubDate>Wed, 19 Nov 2014 12:22:58 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383232.html#7383232</guid>
      <dc:creator>tridh</dc:creator>
      <dc:date>2014-11-19T12:22:58Z</dc:date>
    </item>
    <item>
      <title>Re(3): Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383231.html#7383231</link>
      <description>&lt;blockquote&gt;&lt;em&gt; Wir sind Premier Kunden.&lt;br&gt;&lt;/em&gt;&lt;/blockquote&gt;&lt;br&gt;Ah ok&lt;br&gt;&lt;br&gt;&lt;blockquote&gt;&lt;em&gt; Wir haben letzte Woche auch den TLS Bug gepatched und jetzt haben wir das&lt;br&gt;gepatched.&lt;br&gt;Die Server hängen Großteils eh im WSUS aber wir müssen solche Patches ASAP&lt;br&gt;einspielen wegen Security,&lt;br&gt;&lt;/em&gt;&lt;/blockquote&gt;&lt;br&gt;Hier auch. Aber der TLS Fix hat uns vmtl. mehr Probleme bereitet als die Lücke selbst... &lt;img src="surprise.gif" width="16" height="19" align="absmiddle" alt="8-O"/&gt;&lt;br/&gt;</description>
      <pubDate>Wed, 19 Nov 2014 12:22:05 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383231.html#7383231</guid>
      <dc:creator>nightmare11at</dc:creator>
      <dc:date>2014-11-19T12:22:05Z</dc:date>
    </item>
    <item>
      <title>Re(2): Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383217.html#7383217</link>
      <description>Wir sind Premier Kunden.&lt;br&gt;Wir haben letzte auch den TLS Bug gepatched und jetzt haben wir das gepatched.&lt;br&gt;Die Server hängen Großteils eh im WSUS aber wir müssen solche Patches ASAP einspielen wegen Security, Menschenleben usw...&lt;br&gt;&lt;br&gt;&lt;br/&gt;</description>
      <pubDate>Wed, 19 Nov 2014 12:01:01 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383217.html#7383217</guid>
      <dc:creator>tridh</dc:creator>
      <dc:date>2014-11-19T12:01:01Z</dc:date>
    </item>
    <item>
      <title>Re(2): Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383218.html#7383218</link>
      <description>Wir sind Premier Kunden.&lt;br&gt;Wir haben letzte Woche auch den TLS Bug gepatched und jetzt haben wir das gepatched.&lt;br&gt;Die Server hängen Großteils eh im WSUS aber wir müssen solche Patches ASAP einspielen wegen Security, Menschenleben usw...&lt;br&gt;&lt;br&gt;&lt;br/&gt;</description>
      <pubDate>Wed, 19 Nov 2014 12:01:01 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383218.html#7383218</guid>
      <dc:creator>tridh</dc:creator>
      <dc:date>2014-11-19T12:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383189.html#7383189</link>
      <description>Habs auch schon gelesen. IMHO ziemlich kritisch.&lt;br&gt;Nachdem SChannel Update von letzter Woche, bin ich aber mit einer schnellen Verteilung sehr, sehr, sehr, sehr, sehr, sehr vorsichtig! Das habens ja ordentlich verbockt!&lt;br&gt;&lt;br&gt;&lt;br&gt;PS. Von welchem Dienst hast du Mail bekommen?&lt;br/&gt;</description>
      <pubDate>Wed, 19 Nov 2014 11:17:28 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383189.html#7383189</guid>
      <dc:creator>nightmare11at</dc:creator>
      <dc:date>2014-11-19T11:17:28Z</dc:date>
    </item>
    <item>
      <title>Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383152.html#7383152</link>
      <description>Haben wir gestern Abend bekommen.&lt;br&gt;&lt;br&gt;&lt;br&gt;Today Microsoft released an out-of-band security update to address an issue affecting Microsoft Windows.&amp;nbsp;&amp;nbsp;&lt;br&gt; &lt;br&gt;This security update resolves a privately reported vulnerability in Microsoft Windows Kerberos KDC that could allow an attacker to elevate unprivileged domain user account privileges to those of the domain administrator account. An attacker could use these elevated privileges to compromise any computer in the domain, including domain controllers. &lt;br&gt; &lt;br&gt;An attacker must have valid domain credentials to exploit this vulnerability. The affected component is available remotely to users who have standard user accounts with domain credentials; this is not the case for users with local account credentials only. When this security bulletin was issued, Microsoft was aware of limited, targeted attacks that attempt to exploit this vulnerability&lt;br&gt; &lt;br&gt;This security update is rated Critical for all supported editions of Windows Server 2003, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2.&lt;br&gt; &lt;br&gt;The update is also being provided on a defense-in-depth basis for all supported editions of Windows Vista, Windows 7, Windows 8, and Windows 8.1. Severity ratings do not apply for these operating systems because the vulnerability addressed in this bulletin is not present. This update provides additional defense-in-depth hardening that does not fix any known vulnerability. &lt;br&gt; &lt;br&gt;Note The update is available for Windows Technical Preview and Windows Server Technical Preview. Customers running these operating systems are encouraged to apply the update, which is available via Windows Update.&lt;br&gt; &lt;br&gt;In addition to the new security bulletin, Microsoft has revised security bulletin MS14-066. The revision addresses known issues that a small number of customers experienced with the new TLS cipher suites that were included in the original release. Customers running Windows Server 2008 R2 or Windows Server 2012 who installed the 2992611 update prior to the November 18 reoffering should reapply the update. See Microsoft Knowledge Base Article 2992611 for more information. &lt;br&gt;&lt;br/&gt;</description>
      <pubDate>Wed, 19 Nov 2014 10:16:43 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383152.html#7383152</guid>
      <dc:creator>tridh</dc:creator>
      <dc:date>2014-11-19T10:16:43Z</dc:date>
    </item>
    <item>
      <title>Kerberos KDC - Microsoft Security Bulletin (Out-of-Band) Release</title>
      <link>http://forum.geizhals.at/t856329,7383144.html#7383144</link>
      <description>Haben wir gestern Abend bekommen.&lt;br&gt;Jetzt wird mal wild gepatched...&lt;br&gt;&lt;br&gt;Today Microsoft released an out-of-band security update to address an issue affecting Microsoft Windows.&amp;nbsp;&amp;nbsp;&lt;br&gt; &lt;br&gt;This security update resolves a privately reported vulnerability in Microsoft Windows Kerberos KDC that could allow an attacker to elevate unprivileged domain user account privileges to those of the domain administrator account. An attacker could use these elevated privileges to compromise any computer in the domain, including domain controllers. &lt;br&gt; &lt;br&gt;An attacker must have valid domain credentials to exploit this vulnerability. The affected component is available remotely to users who have standard user accounts with domain credentials; this is not the case for users with local account credentials only. When this security bulletin was issued, Microsoft was aware of limited, targeted attacks that attempt to exploit this vulnerability&lt;br&gt; &lt;br&gt;This security update is rated Critical for all supported editions of Windows Server 2003, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2.&lt;br&gt; &lt;br&gt;The update is also being provided on a defense-in-depth basis for all supported editions of Windows Vista, Windows 7, Windows 8, and Windows 8.1. Severity ratings do not apply for these operating systems because the vulnerability addressed in this bulletin is not present. This update provides additional defense-in-depth hardening that does not fix any known vulnerability. &lt;br&gt; &lt;br&gt;Note The update is available for Windows Technical Preview and Windows Server Technical Preview. Customers running these operating systems are encouraged to apply the update, which is available via Windows Update.&lt;br&gt; &lt;br&gt;In addition to the new security bulletin, Microsoft has revised security bulletin MS14-066. The revision addresses known issues that a small number of customers experienced with the new TLS cipher suites that were included in the original release. Customers running Windows Server 2008 R2 or Windows Server 2012 who installed the 2992611 update prior to the November 18 reoffering should reapply the update. See Microsoft Knowledge Base Article 2992611 for more information. &lt;br&gt;&lt;br/&gt;</description>
      <pubDate>Wed, 19 Nov 2014 10:16:43 GMT</pubDate>
      <guid>http://forum.geizhals.at/t856329,7383144.html#7383144</guid>
      <dc:creator>tridh</dc:creator>
      <dc:date>2014-11-19T10:16:43Z</dc:date>
    </item>
  </channel>
</rss>
