Security update for the Kerberos SNAME security feature bypass vulnerability in Windows Server 2008: July 11, 2017

Summary

A security feature bypass vulnerability exists in Microsoft Windows when Kerberos fails to prevent tampering with the SNAME field during ticket exchange. An attacker who successfully exploited this vulnerability could use it to bypass Extended Protection for Authentication.

To learn more about the vulnerability, go to CVE-2017-8495.

More Information

Important

  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Windows Update: FAQ.

Method 2: Microsoft Update Catalog

To get the stand-alone package for this update, go to the Microsoft Update Catalog website.

Deployment information

For deployment details for this security update, see the following article in the Microsoft Knowledge Base:

Security update deployment information: July 11, 2017

More Information

File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight-saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

Windows Server 2008 file information

Note: The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.

How to obtain help and support for this security update

Help for installing updates: Windows Update: FAQ

Security solutions for IT professionals: TechNet Security Support and Troubleshooting

Help for protecting your Windows-based computer from viruses and malware: Microsoft Secure

Local support according to your country: International Support

File Information

File hash information

File name

SHA1 hash

SHA256 hash

Windows6.0-KB4022746-ia64.msu

44793C0AEA6851D6E2511F096BF6F777BE01C5A2

09AD0ACE3D72B4E605FDB19143DEC8DA0AA6E050B6D141C7CD108B9BA569893A

Windows6.0-KB4022746-x64.msu

FD952A1CA1643A04F2BD8B3AA678E703E108C0E4

063782079C02278C4D65DCB18D606D3A8A766BF67EA6E027E3F0D7F71DE25DBF

For all supported ia64-based versions

File name

File version

File size

Date

Time

Platform

Kerberos.dll

6.0.6002.19810

1,403,392

11-Jun-2017

22:20

IA-64

Kerberos.dll

6.0.6002.24130

1,413,120

11-Jun-2017

21:47

IA-64

Kerberos.dll

6.0.6002.19810

502,784

11-Jun-2017

22:31

x86

Kerberos.dll

6.0.6002.24130

505,856

11-Jun-2017

21:52

x86

For all supported x64-based versions

File name

File version

File size

Date

Time

Platform

Kerberos.dll

6.0.6002.19810

661,504

11-Jun-2017

22:48

x64

Kerberos.dll

6.0.6002.24130

666,624

11-Jun-2017

22:09

x64

Kerberos.dll

6.0.6002.19810

502,784

11-Jun-2017

22:31

x86

Kerberos.dll

6.0.6002.24130

505,856

11-Jun-2017

21:52

x86

For all supported x86-based versions

File name

File version

File size

Date

Time

Platform

Kerberos.dll

6.0.6002.19810

502,784

11-Jun-2017

22:31

x86

Kerberos.dll

6.0.6002.24130

505,856

11-Jun-2017

21:52

x86

Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

Thank you for your feedback!

Thank you for your feedback! It sounds like it might be helpful to connect you to one of our Office support agents.

×