Good morning,
We are running discoveries against some data centers and the problem we are facing is the following:
Some of the servers are Windows Server 2019 and a recent patch by Microsoft has been activated by default from Nov 8th, 2022(KB5004442).
The problem is that any server containing Windows Server 2019 returns a credentials error when we try to connect to it to make the scan. We were able to pinpoint the problem to DCOM security settings that were rolled out by Microsoft. (https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c)
For now, there is a workaround by disabling this through a registry key. This opens security holes though and will also only be available until March 23.
How can we continue performing scans after that date?
Is there any configuration we need to update/change?
Finally, I would like to know if it is possible to make the remote calls from the Insight Discovery tool to the servers using a higher authentication. Is it?
Thanks a lot,
Victor.
Hello again,
This is quite urgent, as we need to put the patch in place.
Is there any way to be able to continue gathering information of those servers?
Thanks.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.