Microsoft security advisory: Improperly issued digital certificates ...
Provides a link to Microsoft Security Advisory: Incorrectly issued digital certificates could allow spoofing.
Protections for CVE-2025-26647 (Kerberos Authentication)
When in Enforcement mode, if the domain controller receives a Kerberos authentication request with an unsafe certificate, it will log legacy Event ID: 21 and deny the request.
Mitigation Plan for Active Directory Certificate Services-based ...
The following sections will help you to identify, mitigate, and remedy Active Directory Certificate Services (AD CS)-issued certificates and requests that were affected by the vulnerability that is identified in Microsoft Security Advisory ADV170012.
Digital signatures and certificates - Microsoft Support
When you send a digitally-signed macro or document, you also send your certificate and public key. Certificates are issued by a certification authority, and like a driver’s license, can be revoked.
Applies To:
Excel for Microsoft 365, Word for Microsoft 365, PowerPoint for Microsoft 365, Access for Microsoft 365, Visio Plan 2, Excel 2024, PowerPoint 2024, Access 2024, Excel 2021, Word 2021, PowerPoint 2021, Access 2021, Visio Professional 2021, Visio Standard 2021, Excel 2019, Word 2019, PowerPoint 2019, Access 2019, Visio Professional 2019, Visio Standard 2019, Excel 2016, Word 2016, PowerPoint 2016, Access 2016, Visio Professional 2016, Visio Standard 2016
November 11, 2025—KB5068791 (OS Build 17763.8027)
To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance. For details and preparation steps, see Windows Secure Boot certificate expiration and CA updates.
Obtain a digital certificate and create a digital signature
If you do not want to purchase a digital certificate from a third-party certificate authority (CA), or if you want to digitally sign your document immediately, you can create your own digital certificate.
Applies To:
Excel for Microsoft 365, Word for Microsoft 365, Outlook for Microsoft 365, PowerPoint for Microsoft 365, Word 2024, Word 2021, Word 2019, Excel 2016, Word 2016, Outlook 2016, PowerPoint 2016, Office 2016
MS08-037: Vulnerabilities in DNS could allow spoofing
Resolves a reported vulnerability that could allow spoofing in implementations of DNS.
Frequently asked questions about the Secure Boot update process ...
To fix this, you need to reapply the 2023 certificate to the firmware’s DB using the recovery application. This is done by creating a recovery USB, then booting the affected device from that USB to restore the missing certificate.
MS09-056: Vulnerabilities in CryptoAPI could allow spoofing
Resolves vulnerabilities in Windows that could allow spoofing if the attacker gains access to the certificate that is used by the end-user for authentication.
Description of the security update for SharePoint Server 2019: July 21 ...
To apply this security update, you must have the release version of Microsoft SharePoint Server 2019 installed on the computer. To successfully run this security update, you must also have SharePoint Server 2019 Language Pack (KB5002753) installed on the computer.