Microsoft released Patch Tuesday updates for Windows 10, 11, and Server earlier today. The one for the Server fixes an NTLM high-traffic bug. But there is no word on the accompanying LSASS crashes.
Lsass RSS
Microsoft confirmed yesterday that a VPN bug is affecting Windows 10 and 11, as well as Servers. Alongside that, the company has also confirmed that Server systems are also having NTLM traffic spikes.
Microsoft has released a set of out-of-band updates (OOB) to resolve issues with LSASS memory leaks in some Windows Server versions. Those updates include KB5037422, KB5037423, and KB5037426.
Microsoft has confirmed that a buggy Patch Tuesday implementation is causing an LSASS memory leak, leading to reboots of Windows Server DCs when trying to undergo Kerberos authentication.
Microsoft has released today the latest non-security preview optional update. The update, under KB5026436, addresses a ton of bugs on Windows 11 21H2. These are related to SMB, LSASS, NTFS, and more.
If you are on Windows 11, and you have encountered the LSA protection is off message recently, even though it is on, Microsoft has confirmed it's a bug. A workaround for it has also been provided.
Following the build on the Windows 11 22H2 Release Preview channel, Microsoft also rolled out a preview update on the Windows 11 21H2 with KB5022905 (Build 22000.1641). It fixes several issues.
Microsoft's Defender did really well in a recent LSASS credential dumping test by AV-Comparatives. The Redmond company is somewhat delighted with the results and shared some more details about it.
Microsoft Defender for Endpoint has done quite well in a new LSASS credentials dumping protection test recently conducted by AV-Comparatives. In the test, Defender has scored the full marks.