SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Microsoft Released Emergency Out-Of-Band Updates To Fix Windows Server Authentication Issues

Microsoft Released Emergency Out-Of-Band Updates To Fix Windows Server Authentication Issues

After the November patch Tuesday, Microsoft released emergency Out-Of-Band update to address authentication failures related to Kerberos delegation scenarios impacting Domain Controllers (DC). Firstly, these authentication issues impact systems that are running Windows Server 2019 and lower versions...

Nov 15, 2021By Shwetha G2 min read

After the November patch Tuesday, Microsoft released emergency Out-Of-Band update to address authentication failures related to Kerberos delegation scenarios impacting Domain Controllers (DC). Firstly, these authentication issues impact systems that are running Windows Server 2019 and lower versions with specific Kerberos delegation scenarios. Secondly, a vulnerability management software is essential.

Thirdly, Microsoft claims this security update “Addresses a known issue that might cause authentication failures related to Kerberos tickets you acquired from Service for User to Self (S4U2self).”

“The issue occurs, after you install the November 9 2021 security updates on domain controllers (DC) that are running Windows Server.” Auto patching is a solution for this.

However, on impacted systems, end-users cannot sign in to services or applications using Single Sign-On (SSO) in Active Directory on-premises or hybrid Azure Active Directory environments.

List of updates released by Microsoft for Emergency Out-Of-Band Update

  • KB5008602: Out-of-band on Windows Server 2019
  • KB5008601: Out-of-band on Windows Server 2016
  • KB5008603: Authentication fails on domain controllers in specific Kerberos scenarios on Windows Server 2012 R2
  • KB5008604: Authentication fails on domain controllers in specific Kerberos systems on Windows Server 2012
  • KB5008605: Authentication fails on domain controllers in specific Kerberos systems on Windows Server 2008 R2 SP1
  • KB5008606: Authentication fails on domain controllers in specific Kerberos systems on Windows Server 2008 SP2

Impact :

Moreover, the authentication issues prevent end-users in Active Directory on-premises or hybrid Azure Active Directory environments from signing in to services or applications using Single Sign-On (SSO).

Deployment updates:

Microsoft emergency Out-Of-Band update cannot be installed through Windows Update, and they will also not be installed automatically on affected DCs. If you installed earlier updates, only the new fixes contained in the update package would be downloaded and installed on your device. However, to install the above non-security updates, you have to search and download the standalone update package from Microsoft Update Catalog for respective KBs, or you can download using the below links.

1. KB5008602 – UPDATE
2. KB5008601 – UPDATE
3. KB5008603 – UPDATE
4. KB5008604 – UPDATE
5. KB5008605 – UPDATE
6. KB5008606 – UPDATE

Featured Posts

Open StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores
StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

CVE Research

StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

StyleSmuggler, an unpatched Magento and Adobe Commerce flaw letting attackers execute code without authentication via log poisoning, installing a persistent Linux backdoor that has already compromised live stores with no vendor patch available.

Sep 7, 2026

Open CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover
CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Vulnerability

CVE Research

CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover

Sep 7, 2026

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026