My next class:

Microsoft February Patch Failures Continue: KB3023607 vs. Cisco AnyConnect Client

Published: 2015-02-13. Last Updated: 2015-02-13 17:32:03 UTC
by Johannes Ullrich (Version: 1)
1 comment(s)

Another patch released by Microsoft this month is causing problems. This time it is KB3023607,which was supposed to mitigate the POODLE vulnerability. Once applied, Cisco AnyConnect users are no longer able to connect to their VPN.

For more details, also see the Cisco bug report https://tools.cisco.com/bugsearch/bug/CSCus89729 (requires login).

The issue appears to affect Windows 8.1, in which case running the application (vpnui.exe) in Windows 8 compatibility mode will fix the problem for now.

 

---
Johannes B. Ullrich, Ph.D.
STI|Twitter|LinkedIn

1 comment(s)
My next class:

Comments

Running vpnagent.exe in Windows 8 compatibility mode in addition to vpnui.exe was also necessary as a workaround. I wonder if anyone has tested the bad KB3023607 against other applications that could be impacted, such as Alt-N's MDaemon email server, for proper TLS negotiation?
-rogerc

Diary Archives