Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Run discovery agains Windows 2019 servers after the patch

Victor Parera December 24, 2022

Good morning,

We are running discoveries against some data centers and the problem we are facing is the following:

Some of the servers are Windows Server 2019 and a recent patch by Microsoft has been activated by default from Nov 8th, 2022(KB5004442).

The problem is that any server containing Windows Server 2019 returns a credentials error when we try to connect to it to make the scan. We were able to pinpoint the problem to DCOM security settings that were rolled out by Microsoft. (https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c)

For now, there is a workaround by disabling this through a registry key. This opens security holes though and will also only be available until March 23.

How can we continue performing scans after that date?

Is there any configuration we need to update/change?

Finally, I would like to know if it is possible to make the remote calls from the Insight Discovery tool to the servers using a higher authentication. Is it?

Thanks a lot,

Victor.

1 answer

0 votes
Victor Parera December 29, 2022

Hello again,

This is quite urgent, as we need to put the patch in place.

Is there any way to be able to continue gathering information of those servers?

Thanks.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
TAGS
AUG Leaders

Atlassian Community Events