Information

Microsoft has revealed a vulnerability in Microsoft Windows Kerberos KDC. It affects all modern versions of Windows, including Windows Server 2003/2008/2012, Vista, 7, 8, 8.1.

Please refer to Microsoft TechNet article for details:

Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780)

Impact

Microsoft has revealed a vulnerability in Microsoft Windows Kerberos KDC that could allow an attacker to elevate unprivileged domain user account privileges to those of the domain administrator account. An attacker could use these elevated privileges to compromise any computer in the domain, including domain controllers. An attacker must have valid domain credentials to exploit this vulnerability. The affected component is available remotely to users who have standard user accounts with domain credentials; this is not the case for users with local account credentials only. When the security bulletin was issued, Microsoft was aware of limited, targeted attacks that attempt to exploit this vulnerability.

This security update is rated Critical for all supported editions of Windows Server 2003, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2.

Resolution

This guide contains instructions how to install Update KB3011780 on a Parallels Virtuozzo Containers for Windows servers.

Below you may find a compatibility table.

PVC version PVC Update that provides compatibility for KB3011780
PCW 6.0 Compatible since VZU600016
PVCfW 4.6 Compatible since VZU460078
PVCfW 4.5 Incompatible
PVCfW 4.0 Incompatible

For Compatible versions

KB3011780 is compatible since update VZU600016 for PCW 6.0 and VZU460078 for PVCfW 4.6. Procedure to address MS14-068 is straightforward:

  1. Install latest available VZU update
  2. Reboot the Hardware Node
  3. Install KB3011780
  4. Reboot Hardware Node

For the hosts that reached Windows Support Pack End-Of-Life:

If no Windows updates are detected after installing the VZU update, please check the following article: Windows updates are not detected: Windows Service Pack reached End-Of-Life .

For Incompatible PVC versions:

PVCfW versions that reached End of Life are considered incompatible - updates with support for KB3011780 will not be released. Therefore, if you're using PVCfW 4.0 or PVCfW 4.5, you'll need to upgrade up to PVCfW 4.6 in order to be able to install the update. For upgrade instructions refer to documentation.

Internal content