Better late than never… except in computing, of course. Delays in fixing bugs and covering security holes can be very costly, unless the problem has remained dormant for a long time. Technically, it is not the oldest bug Microsoft has fixed in Windows, but what is most striking is its importance to the corporate world, and the fact that it will not be eliminated from Windows Server 2003, even under extended support.
The bug has the potential to allow an attacker to take complete control of a computer, and affects any user connecting to a corporate network using the Active Directory service. This service has been with us since Windows 2000, which was released on February 17, 2000, almost fifteen years ago. In short, the bug enables an attacker to assume the role of a “man in the middle” and gain administrator privileges on affected systems, leading to the ever-dreaded remote code execution. The first curious fact about the bug is that the people at JAS Global Advisors and simMachines first reported it in January 2014, more than a year ago.
Why did Microsoft take so long?
JAS Global Advisors' official site explains it very simply: Unlike other high-profile bugs like Heartbleed and Shellshock, the problem is not an implementation issue, but a design one. In Redmond, they were forced to alter the internal structure of several core components in Windows while performing numerous regression tests and keeping all existing backward compatibility factors under watch. In other words, the problem was so advanced and complex that it required this much time, not to mention absolute confidentiality. JAS added that the process has been one of the best examples of “responsible disclosure” of vulnerabilities, which in part sounds like a low blow to you know who.
The good news is that the patches (plural, one to fix and one to reinforce) should arrive to almost all affected systems via Windows Update; otherwise, administrators (and interested users) can visit the dedicated pages for MS15-014 and MS15-011 and download the hotfixes manually.
Now, earlier I said “almost” all systems. Who is left out? Windows Server 2003. While a fix for MS15-014 is available, the reinforcement from MS15-011 will not see the light. Microsoft's explanation is that the architecture required to provide proper support for the patch simply does not exist in Windows Server 2003. The alternative would be to redo a good part of the operating system, which will not happen. Additionally, Windows Server 2003 still has five months of extended support. I imagine many companies planned to start their replacement protocols in July, but with this change in the rules of the game, more than one will be shooting daggers.
Source: Ars Technica