thinktoday
thinktoday

Reputation: 1

KB5004442 - Windows DCOM Server Security Feature Bypass (CVE-2021-26414) having issue

After enabling the registry followed by the below doc. we are facing issues as access denied even after using RPC_C_AUTHN_LEVEL_PKT_INTEGRITY on WMI.

Windows Server 2019 Version 1809 (OS build 17763.2268). windows updated KB5006744

https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c

Upvotes: 0

Views: 2487

Answers (1)

DBarkov
DBarkov

Reputation: 1

Important Notes (for environments where the hotfix is not installed): The setting documented in KB5004442 does not remove the alerts from the DC Server, but it does restore traffic flow.If you do not enable the new setting documented in KB5004442 (while this is still possible), you can continue working with AD Query.This makes your Windows server vulnerable to CVE-2021-26414.

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk176148

Upvotes: 0

Related Questions