DiscoverRunAs RadioFixing a Security Vulnerability in Active Directory with Steve Syfuhs
Fixing a Security Vulnerability in Active Directory with Steve Syfuhs

Fixing a Security Vulnerability in Active Directory with Steve Syfuhs

Update: 2025-06-04
Share

Description

Why would a security vulnerability take more than two years to fix? Richard chats with Steve Syfuhs about the evolution of the response to KB5015754. Originally published in 2022, the issue involved vulnerabilities in the on-premises certificate authority for Active Directory. Pushing a fix to force the immediate replacement of the certificates could have left users unable to log into Active Directory entirely. Steve explains how the gradual rollout of the fix allowed folks concerned (and paying attention!) to fix it immediately. At the same time, for everyone else, the fix happened as the existing certificates expired. But not every scenario is automatic - some require sysadmin intervention. So, how do you get their attention? The story leads to the February 11, 2025 update that could knock some users off Active Directory, but had an easy and quick fix. The final phase should be September 2025; hopefully, the last stragglers will be ready!

Links

Recorded April 10, 2025

Comments 
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Fixing a Security Vulnerability in Active Directory with Steve Syfuhs

Fixing a Security Vulnerability in Active Directory with Steve Syfuhs

Steve Syfuhs, Richard Campbell