Microsoft SSL/TLS vulnerability MS14-066

Want to help support this blog? Try out Oh Dear, the best all-in-one monitoring tool for your entire website, co-founded by me (the guy that wrote this blogpost). Start with a 10-day trial, no strings attached.

We offer uptime monitoring, SSL checks, broken links checking, performance & cronjob monitoring, branded status pages & so much more. Try us out today!

Profile image of Mattias Geniar

Mattias Geniar, November 12, 2014

Follow me on Twitter as @mattiasgeniar

It’s peanut butter patching time. And it’s urgent: MS14-066 Vulnerability in Schannel Could Allow Remote Code Execution (2992611).

This security update resolves a privately reported vulnerability in the Microsoft Secure Channel (Schannel) security package in Windows. The vulnerability could allow remote code execution if an attacker sends specially crafted packets to a Windows server.

This security update is rated Critical for all supported releases of Microsoft Windows. For more information, see the Affected Software section.

The security update addresses the vulnerability by correcting how Schannel sanitizes specially crafted packets. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability.

The update is shipped via regular Windows/Microsoft updates.

Install Windows Updates

For anyone still on Windows XP, questioning if they should upgrade … guess what, the fix isn’t released for Windows XP machines. Here’s your incentive!

How does the exploit work?

A very detailed posted emerged where they trigger the MS14-066 vulnerability. It goes into a lot of details on how they found the actual bug by looking at the updated DLL files and how the SSL/TLS stack can be exploited.



Want to subscribe to the cron.weekly newsletter?

I write a weekly-ish newsletter on Linux, open source & webdevelopment called cron.weekly.

It features the latest news, guides & tutorials and new open source projects. You can sign up via email below.

No spam. Just some good, practical Linux & open source content.