Microsoft February Patch Failures Continue: KB3023607 vs. Cisco AnyConnect Client

Another patch released by Microsoft this month is causing problems. This time it is KB3023607,which was supposed to mitigate the POODLE vulnerability. Once applied, Cisco AnyConnect users are no longer able to connect to their VPN.

For more details, also see the Cisco bug report (requires login).

The issue appears to affect Windows 8.1, in which case running the application (vpnui.exe) in Windows 8 compatibility mode will fix the problem for now.


Johannes B. Ullrich, Ph.D.

I will be teaching next: Intrusion Detection In-Depth - SANS Cyber Safari 2022


4597 Posts
ISC Handler
Feb 13th 2015
Running vpnagent.exe in Windows 8 compatibility mode in addition to vpnui.exe was also necessary as a workaround. I wonder if anyone has tested the bad KB3023607 against other applications that could be impacted, such as Alt-N's MDaemon email server, for proper TLS negotiation?

Sign Up for Free or Log In to start participating in the conversation!