Microsoft: April Windows Server updates cause NTLM auth failures
ID: 1dc29533-ee9c-5e6d-8013-5a1d93de18c0
STIX ID: report--1dc29533-ee9c-5e6d-8013-5a1d93de18c0
Feed Name: Bleeping Computer
Microsoft acknowledged a known issue where April 2024 Windows Server security updates trigger spikes in NTLM authentication traffic and high load/failures on domain controllers—especially in environments with heavy NTLM usage and few primary DCs—affecting versions covered by KB5036909, KB5036896, KB5036899, KB5036960, KB5036969, KB5036967, and KB5036932. There is no root cause or fix yet; the only temporary mitigation is uninstalling the latest cumulative update via DISM, which also removes current security patches. Microsoft also noted separate problems with VPN connectivity following the April updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
