Microsoft fixes Windows Server bug causing crashes, NTLM auth failures
ID: 973a548a-e8bc-5f1e-a884-9b5ad08c6fc0
STIX ID: report--973a548a-e8bc-5f1e-a884-9b5ad08c6fc0
Feed Name: Bleeping Computer
Microsoft addressed a known issue introduced by April 2024 Windows Server updates that caused spikes in NTLM authentication traffic and, in some environments, LSASS crashes and domain controller reboots; fixes were released in the May 14, 2024 cumulative updates (KB5037782) and administrators are advised to install the update or, as a temporary workaround, remove the April LCU with DISM (with the caveat that rolling back removes security fixes). The bulletin also notes a separate zero-day exploited in the wild to deploy QakBot was fixed in the May Patch Tuesday updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
