Microsoft KB Update (May 13, 2025) - Medium Severity

On May 13th, 2025, Microsoft distributed KB’s which conflict with existing Netwrix Threat Prevention (formerly StealthINTERCEPT) agents. If these KB’s are applied to your systems, they will conflict with current Netwrix Threat Prevention (formerly StealthINTERCEPT) agents as described below. Netwrix recommends delaying deployment of these KB’s until updated agents are deployed if the impacted event types are important to your organization.

The Netwrix development and QA teams are actively working on an agent update to be compatible with the new KB’s. We will send another notice with new agent versions in a few days.

:double_exclamation_mark: Important Details

If your organization does not use Netwrix Threat Prevention (formerly StealthINTERCEPT) on Server 2025 to capture or block NTLM Authentication activity or on Server 2022, 2019 and 2016 to capture or block Kerberos or NTLM Authentication activity or such events are not deemed important then you may elect to deploy the following MS KB’s in advance of updated agents.
No other aspect of Netwrix Threat Prevention (formerly StealthINTERCEPT) operation is impacted by the May 13th 2025 KB’s beyond what is described below. There is no adverse impact to the domain controllers if the KB’s are deployed without updating the Netwrix Threat Prevention (formerly StealthINTERCEPT) agents.

Severity: MEDIUM

Affected Products

  • Netwrix Threat Prevention for Active Directory
  • Netwrix Threat Manager for Active Directory
  • Netwrix Activity Monitor for Active Directory

Affected System(s):

  • Windows Server 2025 (for Active Directory)
  • Windows Server 2022 (for Active Directory)
  • Windows Server 2019 (for Active Directory)
  • Windows Server 2016 (for Active Directory)

Affected Platform/KB:

  • Windows Server 2025 KB5058411
  • Windows Server 2022 KB5058385
  • Windows Server 2019 KB5058392
  • Windows Server 2016 KB5058383

Affected Netwrix Threat Prevention Agents - all Prior to:

  • 7.5.0.188
  • 7.4.0.201
  • 7.3.9.286
  • 7.3.7.461

Impact:

Functional:

○ Server 2025 - KB5058411

Netwrix Threat Prevention (formerly StealthINTERCEPT) agents will lose the ability to capture or block NTLM Authentication events (Termsrv (JumpBox)

○ Expected ADMonitor_Logs Error:

  • Couldn’t resolve NlpLogonSamLogon for Windows Server 2022 (20348.2400)
  • Couldn’t resolve NlpUserValidate
  • Couldn’t resolve CConnectionEx::InitializeClientData (4 param)

○ Server 2022 - KB5058385

Netwrix Threat Prevention (formerly StealthINTERCEPT) agents will lose the ability to capture or block Kerberos and NTLM Authentication events

○ Expected ADMonitor_Logs Error:

  • Couldn’t resolve HandleTGSRequest

  • Couldn’t resolve I_GetASTicket

  • Couldn’t resolve NlpLogonSamLogon

  • Couldn’t resolve NlpLogonSamLogon

  • Couldn’t resolve NlpUserValidate (Old)

  • Couldn’t resolve NlpUserValidate

○ Server 2019 - KB5058392

Netwrix Threat Prevention (formerly StealthINTERCEPT) agents will lose the ability to capture or block Kerberos and NTLM Authentication events

○ Expected ADMonitor_Logs Error:

  • Couldn’t resolve HandleTGSRequest

  • Couldn’t resolve I_GetASTicket

  • Couldn’t resolve NlpLogonSamLogon

  • Couldn’t resolve NlpLogonSamLogon

  • Couldn’t resolve NlpUserValidate (Old)

  • Couldn’t resolve NlpUserValidate

○ Server 2016 - KB5058383

Netwrix Threat Prevention (formerly StealthINTERCEPT) agents will lose the ability to capture or block Kerberos and NTLM Authentication events

○ Expected ADMonitor_Logs Error:

  • Couldn’t resolve HandleTGSRequest

  • Couldn’t resolve I_GetASTicket

  • Couldn’t resolve NlpLogonSamLogon

  • Couldn’t resolve NlpLogonSamLogon

  • Couldn’t resolve NlpUserValidate (Old)

  • Couldn’t resolve NlpUserValidate

Stability:

○ No stability impact on any server platforms / Domain Controllers