• Smart card authentication might cause print and scan failures

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Smart card authentication might cause print and scan failures

    Author
    Topic
    #2460636

    Hardening changes coming 07/2022: Smart card authentication might cause print and scan failures

     

    On July 13, 2021, Microsoft released hardening changes for Windows Key Distribution Center Information Disclosure Vulnerability, CVE-2021-33764. With these changes, smart card (PIV) authentication might cause print and scan failures when you install updates released on July 13, 2021, or later versions on a domain controller (DC). The affected devices are smart card authenticating printers, scanners, and multifunction devices that don’t support either Diffie-Hellman (DH) for key exchange during PKINIT Kerberos authentication or don’t advertise support for des-ede3-cbc (“triple DES”) during the Kerberos AS request.

    A temporary mitigation, released in Windows Updates between July 29, 2021, and July 12, 2022, was made available for organizations that encountered this issue and couldn’t bring devices into compliance as required for CVE-2021-33764. However, starting in July 2022, this temporary mitigation will not be usable in security updates. The Windows July 2022 preview update will remove the temporary mitigation and will require compliant printing and scanning devices.

    As of July 19, 2022, there will be no further fallback option in later updates, and all non-compliant devices must be identified using the audit events starting in January 2022 and updated or replaced by the mitigation removal. To learn more, see KB5005408: Smart card authentication might cause print and scan failures.

    https://support.microsoft.com/en-us/topic/kb5005408-smart-card-authentication-might-cause-print-and-scan-failures-514f0bc5-ecde-4e5e-8c5a-2a776d7fb89a

    Translation:  the mandate will show up in the non security updates in July. I do not see any home/consumer impact.  For businesses I would review your copiers that use smart card authentication.

    Susan Bradley Patch Lady/Prudent patcher

    1 user thanked author for this post.
    Reply To: Smart card authentication might cause print and scan failures

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: