Special alert By Susan Bradley November Domain controller update leads to memory leak Business patchers only: Microsoft has posted up a known side ef
[See the full post at: MS-DEFCON 3: Side effect with Domain patch]
Susan Bradley Patch Lady
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
Home » Forums » Newsletter and Homepage topics » MS-DEFCON 3: Side effect with Domain patch
Special alert By Susan Bradley November Domain controller update leads to memory leak Business patchers only: Microsoft has posted up a known side ef
[See the full post at: MS-DEFCON 3: Side effect with Domain patch]
Susan Bradley Patch Lady
Thanks for the heads-up. I’m going the regedit route on four DCs to which I applied November updates and OOB fixes in the past week. Notes:
I don’t see any reboot requirement for applying this fix?
Hi all, quite an unusual subkey for service param’s – I’d expect them to go to …\KDC\Parameters… but all docs I found so far are pointing to …\KDC . Is there a way to check if the setting of ‘zero’ successfully triggered the deactivation of the new bug – oops, sorry – feature?
Also, I do not understand M$ trend to force such changes at a certain point in time without leaving the option to deactivate it. What if a company has a hard dependency on it to stay turned of to still be able to keep their environment running?
BfN, -k
On Pro and Server editions you have the option on gpedit.msc or Group Policies to set Windows Update to download but not to install until you tell it to. That’s how I’m set on my PC and critical servers so that when I’m ready I install them.
On Windows 10 Pro, run gpedit.msc. Then Computer Configuration -> Administrative Templates -> Windows Components -> Windows Update. Then find Configure Automatic Updates. Set it to Enabled, set Configure automatic updating to 3 – Auto download and notify to install and uncheck install during automatic maintenance. If an OOB must be installed, go to Windows Update Catalog, download the required MSU and run it instead of clicking install on Windows Update.
This is enforcing better Kerberos to ensure that attackers can’t gain access to a domain. We complain that Microsoft isn’t doing enough to protect us from ransomware….. well these enforcement patches are pushing us to ensure we are better protected from ransomware. Because they may have impact, they are giving us time to deal with the issues.
Susan Bradley Patch Lady
Thanks for posting/writing these ‘special alerts’. I sure wish MS did a better job of stress testing their KB updates prior to release. I hope that not too many sysadmins got burnt this time around. Your special alerts are well worth the cost of this subscription and more. Thanks.
Database connections using Microsoft ODBC SQL Server driver might fail
After installing KB5019980, apps which use ODBC connections utilizing the Microsoft ODBC SQL Server Driver (sqlsrv32.dll) to access databases might fail to connect. You might receive an error within the app or you might receive an error from SQL Server, such as “The EMS System encountered a problem” with “Message: [Microsoft][ODBC SQL Server Driver] Protocol error in TDS Stream” or “Message: [Microsoft][ODBC SQL Server Driver]Unknown token received from SQL Server”.
If you are unsure if you are using any affected apps, open any apps which use a database and then open Command Prompt (select Start then type command prompt and select it) and type the following command:
tasklist /m sqlsrv32.dll
Next steps: We are working on a resolution and will provide an update in an upcoming release..
Affected platforms:
Client: Windows 11, version 22H2; Windows 10, version 22H2; Windows 11, version 21H2; Windows 10, version 21H2; Windows 10, version 21H1; Windows 10, version 20H2; Windows 10 Enterprise LTSC 2019; Windows 10 Enterprise LTSC 2016; Windows 10 Enterprise 2015 LTSB; Windows 8.1; Windows 7 SP1
Server: Windows Server 2022; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
Hey Susan!
Wanted to thank you for posting this. I was trying to conduct a live migration today to move several VM’s over to a new Hyper-V host on an AD network that had taken the November patches.
The Kerberos constrained delegation trust relationship between the old host and the new Hyper-V host was completely broken by the Nov 12th patch on the domain controller. Kept getting errors that one host could not connect to the other. (WinRM failures)
I installed the hot fix listed (KB KB5021655 from the MS download catalog for Server 2019) on the MS Status page link you provided on the Domain Controller and also applied the LSASS memory leak mitigation reg-key mentioned on the same page – again on that same DC.
It completely fixed the issue with my migration failures.
Weirdly, this particular customer informed me that all their workstations had been popping up an odd notification since Nov 12th asking them to lock and unlock their computer to refresh a password change . . . but none of them had recently changed their passwords. If the user complied with the lock/unlock process, the popup would repeat anyway at some random time – several times a day. That issue also went away once I installed this hotfix on the DC.
~ Group "Weekend" ~
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.