Microsoft KB Update (September, 2025) – Medium Severity

On September 9, 2025, Microsoft released KB updates that conflict with Netwrix Threat Prevention (formerly StealthINTERCEPT) agents.
If these KBs are applied before updating the agents, certain AD authentication and replication events will no longer be captured or blocked.

Netwrix recommends delaying the deployment of these KBs if your organization relies on these event types. The Netwrix development and QA teams are working on updated agents compatible with these KBs and will send another notice when they are available.

:double_exclamation_mark: Important Details
If your organization does not use Netwrix Threat Prevention (formerly StealthINTERCEPT) for the following activity event collection, or such events are not deemed important, you may elect to deploy the following Microsoft KBs in advance of updated Netwrix Threat Prevention (formerly StealthINTERCEPT) agents.

No other aspect of Netwrix Threat Prevention (formerly StealthINTERCEPT) operation is impacted by the September 9, 2025 KBs beyond what is described below. There is no adverse impact to domain controllers if the KBs are deployed without updating the agents.

Event Types Affected:

  • Server 2025 Termsrv (Jumpbox) blocking
  • Server 2022 capture or block Kerberos or NTLM authentication activity
  • Server 2019 capture or block NTLM authentication activity
  • Server 2016 capture or block Kerberos or NTLM authentication activity, Capture or Block AD Replication activity

Severity: MEDIUM

Affected Products:

  • Netwrix Threat Prevention (formerly StealthINTERCEPT) for Active Directory
  • Netwrix Threat Manager (formerly StealthDEFEND) for Active Directory

Affected agent Builds - all prior to:

  • 7.5.0.234
  • 7.4.0.246
  • 7.3.9.317

Affected Systems:

  • Windows Server 2025
  • Windows Server 2022
  • Windows Server 2019
  • Windows Server 2016

Affected Microsoft KBs:

  • KB5065426 (Windows Server 2025)
  • KB5065432 (Windows Server 2022)
  • KB5065428 (Windows Server 2019)
  • KB5065427 (Windows Server 2016)

Impact:

Functional:

  • 2025 Server – KB5065426
    • Impact: Termsrv (JumpBox) blocking
    • Log:
Couldn't resolve CConnectionEx::InitializeClientData (4 param)
  • 2022 Server – KB5065432
    • Impact: Netwrix Threat Prevention / StealthINTERCEPT agents will lose the ability to capture or block Kerberos or NTLM authentication activity
    • Log:
Couldn't resolve KdcGetTicket  
Couldn't resolve NlpUserValidate
  • 2019 Server – KB5065428
    • Impact: Netwrix Threat Prevention / StealthINTERCEPT agents will lose the ability to capture or block NTLM authentication activity
    • Log:
Couldn't resolve NlpUserValidate
  • 2016 Server – KB5065427
    • Impact: Netwrix Threat Prevention / StealthINTERCEPT agents will lose the ability to capture or block Kerberos or NTLM authentication activity and capture or block AD Replication activity
    • Log:
Couldn't resolve I_RenewTicket  
Couldn't resolve NlpUserValidate  
Couldn't resolve IDL_DRSGetNCChanges

Stability:
No stability impact on any server platforms or domain controllers

3 Likes

I’m getting a 404 error when I try to download the latest 7.3.9.317 agent

Hi Jay - please use this link:

https://releases.netwrix.com/products/stealthintercept/7.3/stealthintercept-agent-7.3.9.317.exe

-Tony

1 Like

Thanks Tony that worked!

Thanks for flagging this!

The customer portal has now been updated so the 7.3.9.317 agent should download correctly from the portal.

1 Like

Thanks, I just checked and confirmed that it works! You guys rock!

1 Like