CVE-2020-16996HighCVSS 6.5

Kerberos Security Feature Bypass Vulnerability

Published
December 8, 2020
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Does this security fix require any additional steps in order to be protected from this issue? Yes, for guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see Managing deployment of RBCD/Protected User changes for CVE-2020-16996.

🎯 Affected products12

  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server, version 1903 (Server Core installation)
  • Windows Server, version 1909 (Server Core installation)
  • Windows Server, version 2004 (Server Core installation)
  • Windows Server, version 20H2 (Server Core Installation)

✅ Remediation

KB5000822 (Security Update) — fixed build 10.0.17763.1817 KB5000808 (Security Update) — fixed build 10.0.18363.1440 KB4592449 (Security Update) KB5000802 (Security Update) — fixed build 10.0.19043.867 KB5000803 (Security Update) — fixed build 10.0.14393.4283 KB5000847 (Monthly Rollup) — fixed build 6.2.9200.23298 KB5000840 (Security Only) KB5000848 (Monthly Rollup) — fixed build 6.3.9600.19968 KB5000853 (Security Only)

🔗 References (19)