Microsoft reissues Windows server security patch

Shattered WindowsLast week, Microsoft pulled an important security patch it had issued for Active Directory Federation Services (AD FS), part of the Windows server software. The patch was supposed to fix a vulnerability in the software, which is commonly used to provide users with Single Sign-On access.

Unfortunately, the MS13-066 security update actually caused AD FS to stop working entirely in some circumstances.

As the vulnerability it was attempting to fix had only been privately reported, and was not believed to be being exploited in the wild, it's possible that the fix had actually turned into a bigger problem than the one it was attempting to solve - on Windows Server 2008 systems at least.

The good news is that Microsoft has now reissued MS13-066 and appears to be confident that it has done a better job this time.

MS13-066 advisory

This isn't the first time that Microsoft has been forced to re-release a security patch after problems were found in the original version, and it surely won't be the last.

I'm sure the company is hopeful, however, that it can keep such incidents to a minimum because of the disruption and downtime that buggy security patches can cause its customers.

Tags: , ,

Smashing Security podcast
Check out "Smashing Security", the new weekly audio podcast, with Graham Cluley, Carole Theriault, and special guests from the world of information security.

"Three people having fun in an industry often focused on bad news" • "It's brilliant!" • "The Top Gear of computer security"

Latest episode:

, ,

2 Responses

  1. Stew Green

    August 20, 2013 at 2:44 pm #

    Do you use auto-updates asked ? Graham 2 weeks ago
    ..well, some people keep auto-updates switched off, cos MS fixes often cause more problems than they solve..was what I was going to write.

    • Graham Cluley in reply to Stew Green.

      August 20, 2013 at 2:47 pm #

      I think auto updates normally work well for consumers, less well for businesses.

      In this case, it was a buggy update likely to hit companies rather than individuals.

Leave a Reply