Microsoft reissues Windows server security patch

Shattered WindowsLast week, Microsoft pulled an important security patch it had issued for Active Directory Federation Services (AD FS), part of the Windows server software. The patch was supposed to fix a vulnerability in the software, which is commonly used to provide users with Single Sign-On access.

Unfortunately, the MS13-066 security update actually caused AD FS to stop working entirely in some circumstances.

As the vulnerability it was attempting to fix had only been privately reported, and was not believed to be being exploited in the wild, it’s possible that the fix had actually turned into a bigger problem than the one it was attempting to solve – on Windows Server 2008 systems at least.

The good news is that Microsoft has now reissued MS13-066 and appears to be confident that it has done a better job this time.

Sign up to our free newsletter.
Security news, advice, and tips.

MS13-066 advisory

This isn’t the first time that Microsoft has been forced to re-release a security patch after problems were found in the original version, and it surely won’t be the last.

I’m sure the company is hopeful, however, that it can keep such incidents to a minimum because of the disruption and downtime that buggy security patches can cause its customers.

Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and is the co-host of the popular "Smashing Security" podcast. Follow him on Twitter, Mastodon, Threads, Bluesky, or drop him an email.

2 comments on “Microsoft reissues Windows server security patch”

  1. Do you use auto-updates asked ? Graham 2 weeks ago
    ..well, some people keep auto-updates switched off, cos MS fixes often cause more problems than they solve..was what I was going to write.

    1. Graham CluleyGraham Cluley · in reply to Stew Green

      I think auto updates normally work well for consumers, less well for businesses.

      In this case, it was a buggy update likely to hit companies rather than individuals.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.