Windows PKI blog

News and information for public key infrastructure (PKI) and Active Directory Certificate Services (AD CS) professionals

Important Security Update for Windows Server: Active Directory Certificate Services Web Enrollment!

Important Security Update for Windows Server: Active Directory Certificate Services Web Enrollment!

  • Comments 1
  • Likes

An important security update, described in MS11-051 (http://go.microsoft.com/fwlink/?LinkId=217101) was released today. The update fixes a cross-site scripting vulnerability in the sample web enrollment ASP pages that are part of Active Directory Certificate Services Web Enrollment in Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2.

Important: Back up any sample web enrollment sample pages you modified (%windir%\system32\Certsrv) before applying MS11-051. After you apply the security update, you can integrate any changes you made to the original sample files into the new secure ASP sample pages. For more information, see Microsoft Knowledge Base Article 2518295 (http://support.microsoft.com/kb/2518295).

Comments
  • After patch applied, users recieved pop-up error that CSPs needed to be installed. I put origianl pages back in place and issue wnet away. Will have to research problem in lab on a non-production CA

Your comment has been posted.   Close
Thank you, your comment requires moderation so it may take a while to appear.   Close
Leave a Comment