Microsoft warns of problems with Schannel security update

Page 1 of 2 12 LastLast

    Microsoft warns of problems with Schannel security update


    Posted: 16 Nov 2014
    Microsoft has issued a warning in the knowledge base article for the MS14-066 update released this past week. The company has provided a workaround, but is not recommending that users avoid the update or uninstall it.

    The update fixed at least one critical vulnerability in Schannel, Microsoft's implementation of SSL/TLS encryption. It has widely been considered highly critical and last week we urged users to apply the update as soon as possible.

    But some users who apply the update are having serious problems. The issues occur in configurations in which TLS 1.2 is enabled by default and negotiations fail. When this happens, according to Microsoft, "TLS 1.2 connections are dropped, processes hang (stop responding), or services become intermittently unresponsive." There may also be an event ID 36887 in the System event log withe description "A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 40."
    Source

    A Guy
    A Guy's Avatar Posted By: A Guy
    16 Nov 2014



  1. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #1

    Microsoft warns of problems with Schannel security update


    Microsoft has issued a warning in the knowledge base article for the MS14-066 update released this past week. The company has provided a workaround, but is not recommending that users avoid the update or uninstall it.

    The update fixed at least one critical vulnerability in Schannel, Microsoft's implementation of SSL/TLS encryption. It has widely been considered highly critical and last week we urged users to apply the update as soon as possible.

    But some users who apply the update are having serious problems. The issues occur in configurations in which TLS 1.2 is enabled by default and negotiations fail. When this happens, according to Microsoft, "TLS 1.2 connections are dropped, processes hang (stop responding), or services become intermittently unresponsive." There may also be an event ID 36887 in the System event log withe description "A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 40."
    Microsoft warns of problems with Schannel security update | ZDNet
      My Computer


  2. Posts : 20,583
    Win-7-Pro64bit 7-H-Prem-64bit
       #2

    Thanks for the heads up :)
      My Computer


  3. Posts : 1,167
    W10 32 bit, XUbuntu 18.xx 64 bit
       #3

    Do this affect users that pay bills online? Is this the out of bound update? Is it just I.E.?
      My Computer


  4. Posts : 350
    Windows 7 Pro x64
       #4

    I read it twice and I still don't understand it. They put out a harmful update and they expect all of us to download it? Why would anyone want to download a mess like that?
    They're not planning an update to fix it? Am I missing something here or what?
    Last edited by Dallas 7; 23 Nov 2014 at 07:06.
      My Computer


  5. Posts : 53,365
    Windows 10 Home x64
    Thread Starter
       #5

    Microsoft reissues fixed Schannel update

    Microsoft has re-released the MS14-066 update in order to address problems it caused for some users.

    In addition to fixing a highly critical vulnerability in Schannel (Microsoft's implementation of SSL/TLS), MS14-066 added several new ciphers to the TLS suite. The ciphers caused severe problems for some users and Microsoft released instructions on how to remove them.

    It now appears that the ciphers apply only to Windows 7, Windows Server 2008 R2, Windows 8.x, and Windows Server 2012 systems. Microsoft says that the problems were observed only on Windows Server 2008 R2 and Windows Server 2012, and only by a few users on those.
    Source

    A Guy
      My Computer


  6. Posts : 1,167
    W10 32 bit, XUbuntu 18.xx 64 bit
       #6

    A Guy said:
    Microsoft reissues fixed Schannel update

    Microsoft has re-released the MS14-066 update in order to address problems it caused for some users.

    In addition to fixing a highly critical vulnerability in Schannel (Microsoft's implementation of SSL/TLS), MS14-066 added several new ciphers to the TLS suite. The ciphers caused severe problems for some users and Microsoft released instructions on how to remove them.

    It now appears that the ciphers apply only to Windows 7, Windows Server 2008 R2, Windows 8.x, and Windows Server 2012 systems. Microsoft says that the problems were observed only on Windows Server 2008 R2 and Windows Server 2012, and only by a few users on those.
    Source

    A Guy

    A Guy,

    What is not really clear, is how to install the update for the update. I am not so sure myself.

    2992611-x??.msu
    3018238-x??.msu

    https://support.microsoft.com/kb/2992611

    Plus it won't let you check them. I think if you have 2992611 you don't need to install 2992611 you just need to install 3018238. Right now I think those download are being blocked. I think this just applies to Internet explorer but I am not sure. Do you know where you can download 3018238, I have 2992611?


    Another alternative you might be able to disable TLS in Internet explorer but that may not be a good idea.
      My Computer


  7. Posts : 53,365
    Windows 10 Home x64
    Thread Starter
       #7

    If you installed the update, and are on 7, you don't need to do anything. The problem did not seem to be with 7

    Microsoft says that the problems were observed only on Windows Server 2008 R2 and Windows Server 2012, and only by a few users on those.
    A Guy
      My Computer


  8. Posts : 1,449
    Windows 7 ultimate 64-bit
       #8

    Well; I did get a notice that there is a update for windows waiting to be installed; however; now that i see this; Im probably not going to install it because the last thing i need is to have issues where windows will hang, etc. as im sure others feel the same way. My ? is how the heck can Microsoft put out a download that can cause these issues and expect us to download and install it
      My Computer


  9. Posts : 1,167
    W10 32 bit, XUbuntu 18.xx 64 bit
       #9

    matts6887 said:
    Well; I did get a notice that there is a update for windows waiting to be installed; however; now that i see this; Im probably not going to install it because the last thing i need is to have issues where windows will hang, etc. as im sure others feel the same way. My ? is how can Microsoft put out a download that can cause these issues and expect us to download and install it
    matts6887

    That update is different. I notice I already had 2992611 installed but don't have the 3018238 installed. The way Guy is talking, it doesn't affect windows 7 users.

    If I am correct, this update should be installed.

    MS14-068: Vulnerability in Kerberos could allow elevation of privilege: November 18, 2014
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 19:36.
Find Us