Skip to content

[cve-2018-0886] Microsoft Changes CredSSP #1083

@cocoon

Description

@cocoon

Hi there,
as I have not seen it here already:

As most of you might already know, there was a recent Windows Update that makes changes to Windows Servers and Clients (CredSSP + mstcs) that might cause troubles in near future.

I have tested and found one constellation that doesn't work:

Client: Windows 10 x64 fully updated

-> connects to XRDP/NeutrinoRDP -> connects to:

Server: Windows 2016 fully patched + GPO "Encryption Oracle Remediation" set to "Force Updated Clients"

Error: An internal error has occured.

A direct connection from Windows 10 to the Windows Server 2016 is working.

Microsoft Patch Notes + Coming changes:
https://support.microsoft.com/en-us/help/4093492/credssp-updates-for-cve-2018-0886-march-13-2018

There are already some commits in FreeRDP to support the new protocol:
Examples:
FreeRDP/FreeRDP#4499
FreeRDP/FreeRDP#4510
https://github.com/FreeRDP/FreeRDP/pull/4504/files

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions