Full Report
Microsoft has released emergency Windows updates to address a known issue affecting local audit logon policies in Active Directory Group Policy. [...]
Analysis Summary
# Vulnerability: Emergency Windows Updates Address Active Directory Audit Logon Policy Issues
## CVE Details
- CVE ID: Not provided in the context, as this targets a configuration/policy issue fixed by Out-of-Band (OOB) updates rather than a specific vulnerability affecting functionality.
- CVSS Score: Not applicable/provided.
- CWE: Not applicable/provided.
## Affected Systems
- Products: Windows 11 (23H2, 22H2), Windows Server 2022, Windows 10 Enterprise LTSC 2019, Windows Server 2019, Windows 10 LTSB 2016, Windows Server 2016, Azure Stack HCI (version 22H2).
- Versions: Specific versions tied to the installation of previous updates that caused this condition.
- Configurations: Environments utilizing Active Directory where specific audit logon policies were misconfigured or improperly handled due to prior updates. (Mainly relevant in enterprise environments).
## Vulnerability Description
Microsoft released emergency Out-of-Band (OOB) updates to address an issue primarily affecting enterprise environments where Active Directory (AD) audit logon policies were causing problems, possibly related to log collection or compliance requirements following a previous software update. The specific technical flaw leading to the policy issue is not detailed, but the fix is intended to restore proper function related to AD audit logon policy processing.
## Exploitation
- Status: Not exploited in the wild (as a security vulnerability); this is a functional/compliance patch.
- Complexity: Not applicable (functional issue).
- Attack Vector: Not applicable.
## Impact
- Confidentiality: Unknown/Not the primary driver.
- Integrity: Potential disruption to AD policy enforcement/logging mechanisms.
- Availability: Potential disruption to systems relying on correct AD audit logon processes, but the update itself is designed to restore availability/functionality.
## Remediation
### Patches
Microsoft released the following emergency, non-security OOB updates:
* **Windows 11, versions 23H2 and 22H2:** KB5058919
* **Windows Server 2022 / Azure Stack HCI, version 22H2:** KB5058920
* **Windows 10 Enterprise LTSC 2019 and Windows Server 2019:** KB5058922
* **Windows 10 LTSB 2016 and Windows Server 2016:** KB5058921
These updates are cumulative and replace all prior updates for the affected versions. They can be obtained via Windows Update or the Microsoft Update Catalog.
### Workarounds
The article suggests these updates should **only be installed by affected organizations**. No specific workarounds are mentioned, as the immediate solution is applying the OOB patch.
## Detection
- Detection methods focus on confirming the installation of the specified KB updates on the affected systems.
- Home users are unlikely to be affected.
## References
- Vendor advisories: [Microsoft: New emergency Windows updates fix AD policy issues](https://www.bleepingcomputer.com/news/microsoft/microsoft-new-emergency-windows-updates-fix-ad-policy-issues/)
- Relevant links - defanged:
* KB5058919: `hXXps://support.microsoft.com/help/5058919`
* KB5058920: `hXXps://support.microsoft.com/help/5058920`
* KB5058922: `hXXps://support.microsoft.com/help/5058922`
* KB5058921: `hXXps://support.microsoft.com/help/5058921`
* Microsoft Update Catalog: `hXXps://catalog.update.microsoft.com/`