{"id":33505,"date":"2024-03-15T00:02:00","date_gmt":"2024-03-14T23:02:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=33505"},"modified":"2024-08-06T23:26:22","modified_gmt":"2024-08-06T21:26:22","slug":"update-on-windows-handening-in-2024-2025-march-2024","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2024\/03\/15\/update-on-windows-handening-in-2024-2025-march-2024\/","title":{"rendered":"Update on Windows hardening in 2024\/2025 &#8211;  March 2024"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Windows\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Windows-klein.jpg\" alt=\"Windows\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2024\/03\/15\/update-zur-windows-hrtung-in-2024-2025-stand-mrz-2024\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]A quick note for administrators in corporate environments. Microsoft carries out so-called hardening measures for Windows (clients and servers) over longer periods of time. This involves hardening (securing) functions via Windows Update on certain key dates. Some of these hardening measures are also scheduled for 2024 and 2025. Microsoft has recently updated its corresponding schedule.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg06.met.vgwort.de\/na\/9b35786cca9b4e28822718c8bf47139d\" alt=\"\" width=\"1\" height=\"1\" \/>Hardening Windows against security threats is a key element of Microsoft's ongoing security strategy to protect installations. Microsoft has published a support article <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5036534-latest-windows-hardening-guidance-and-key-dates-eb1bd411-f68c-4d74-a4e1-456721a6551b\" target=\"_blank\" rel=\"noopener\">KB5036534: Latest Windows hardening guidance and key dates<\/a> which was updated on March 10, 2024 (our colleagues <a href=\"https:\/\/bsky.app\/profile\/deskmodder.de\/post\/3kngduksapd2z\" target=\"_blank\" rel=\"noopener\">noticed<\/a> it).<\/p>\n<p><a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5036534-latest-windows-hardening-guidance-and-key-dates-eb1bd411-f68c-4d74-a4e1-456721a6551b\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"KB5036534: Latest Windows hardening guidance and key dates\" src=\"https:\/\/i.postimg.cc\/LshRmNz8\/image.png\" alt=\"KB5036534: Latest Windows hardening guidance and key dates\" \/><\/a><\/p>\n<p>I'll skip the hardening measures that have already been implemented (you can read about them in the article above or in the blog post <a href=\"https:\/\/borncity.com\/win\/2024\/01\/09\/important-dates-for-windows-hardening-in-2024\/\">Important dates for Windows hardening in 2024<\/a> from January 2024). However, Microsoft is planning the following dates for the coming months<\/p>\n<ul>\n<li><strong>April 2024: <\/strong>Secure Boot bypass protections <a href=\"https:\/\/support.microsoft.com\/help\/5025885\" target=\"_blank\" rel=\"noopener\">KB5025885<\/a> (Phase 3). This is about managing Windows Start Manager lockouts for Secure Boot changes related to CVE-2023-24932. This phase will add additional protections for the Boot Manager. This phase will begin on April 9, 2024 at the earliest.<\/li>\n<li><strong>Oktober 2024 (or later):<\/strong> Secure Boot bypass protections <a href=\"https:\/\/support.microsoft.com\/help\/5025885\">KB5025885<\/a> (Phase 3). Mandatory Enforcement-Mode. The overrides (Code Integrity Boot policy and Secure Boot disallow list) are enforced programmatically after the installation of Windows updates on all affected systems without being able to be deactivated.<\/li>\n<li><strong>February 2025 (or later):<\/strong> Certificate-based authentication <a href=\"https:\/\/support.microsoft.com\/help\/5014754\" target=\"_blank\" rel=\"noopener\">KB5014754<\/a> (Phase 3). Full Enforcement-Mode. This involves changes to certificate-based authentication on Windows domain controllers. The vulnerabilities CVE-2022-34691, CVE-2022-26931 and CVE-2022-26923, allow privilege escalation. This can occur when the Kerberos Key Distribution Center (KDC) processes a certificate-based authentication request. If a certificate cannot be uniquely assigned, authentication is denied.<\/li>\n<\/ul>\n<p>This means that administrators may have some work to do on the next patchday.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]A quick note for administrators in corporate environments. Microsoft carries out so-called hardening measures for Windows (clients and servers) over longer periods of time. This involves hardening (securing) functions via Windows Update on certain key dates. Some of these hardening &hellip; <a href=\"https:\/\/borncity.com\/win\/2024\/03\/15\/update-on-windows-handening-in-2024-2025-march-2024\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[69,194],"class_list":["post-33505","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-security","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33505","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=33505"}],"version-history":[{"count":5,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33505\/revisions"}],"predecessor-version":[{"id":34729,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33505\/revisions\/34729"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=33505"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=33505"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=33505"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}