July 8, 2025, Microsoft released KB 5062572 (targeting domain controllers from Windows Server 2008 R2 to 2022), addressing CVE‑2025‑49716 and strengthening access validation for Netlogon RPC.
- Potentially affected environments: Samba servers joined to an AD domain and using specific backends such as idmap_ad may experience authentication or ID mapping failures after the update.
- QNAP NAS status: QNAP NAS devices with default settings are not affected by this change, so you can safely apply the update.
- Important note: Users with non-default settings (e.g., idmap=ad) may be affected and should check their Samba configuration or consult their IT administrator before proceeding.
For details, please refer to Microsoft’s official documentation: