Windows – CVE-2021-36934 Work around

Edward Clepper 1 Reputation point
2021-07-25T13:57:21.133+00:00

Hi Everyone,

I hope someone can help me.

I am currently working in a Windows environment with an Active Directory server managing several servers and workstations

I am looking at implementing the work around for CVE-2021-36934 HiveNightmare

What I am unsure about is how implementing this work around will affect an Active Directory server

I have been searching online but am unable to find an answer

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,004 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Teemo Tang 11,401 Reputation points
    2021-07-26T03:00:03.797+00:00

    Hi,

    Microsoft confirmed the vulnerability as CVE-2021-36934 on July 20.
    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934
    From CVE-2021-36934 document, we can see Microsoft has issued a workaround to restrict access using the Command Prompt or PowerShell and then delete existing System Restore points.
    117755-image.png

    -------------------------------------------------------------------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Steve Bottoms 96 Reputation points
    2021-07-30T19:32:56.97+00:00

    Current home machine is Win10 v20H2 19042.1110; ICACLS check showed vulnerable files; ran remediation; still showed a couple vulnerable files. Rebooted, ran again; same two remaining files vulnerable (see attached). Yes, all ICACLS commands run from elevated command prompt.

    Suggestions? Thanks!
    SteveInReno

    .119477-failed-items.png

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.