Microsoft patched the patch on Tuesday which broke the authentication


This month’s patch Tuesday update from Microsoft had two big-news vulnerabilities CVE-2022-26923 And CVE-2022-26931Which Authentication security affected In Windows.

Although they were so-called EOP holes instead of RCE bugs (The height of privilegeInstead more serious problems Remote code execution), They were Yet the critical rateGiven that bugs have been applied to Active Directory (AD) and Windows Domain Controllers (DCs).

Name Domain controller That’s exactly what it says: DC is the server that oversees authentication and access control for users, computers, services, and devices for a complete network domain.

An old Latin satirical poem asks harshly, “Who sees the guards?” (Who will guard the guards themselves?), And in the case of a Windows network, the short answer is that the guard that guards everything else is your domain controller.

In other words, an authentication bypass against your domain controller can quickly compromise almost everything on your network.