Possible Bug - Group Policy: Domain controller: Allow vulnerable Netlogon secure channel connections

INTREPID 41 Reputation points
2020-11-01T23:59:43.58+00:00

POSSIBLE BUG: On Server 2012 R2, When the Policy "Domain controller: Allow vulnerable Netlogon secure channel connections"* is set to NOT DEFINED, this registry key STILL contains old PREVIOUSLY set entries (security descriptors) in the list!
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters]
"vulnerablechannelallowlist"

Details: When you enable the policy "Domain controller: Allow vulnerable Netlogon secure channel connections" and add a user account or security group and then later disable the policy by setting it to Not Defined, the associated registry key is NOT cleared.

*Reference: How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472
See Section Section 3b
https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
{count} votes

Answer accepted by question author
  1. Anonymous
    2020-11-02T00:02:00.29+00:00

    You can report here on uservoice.
    https://windowsserver.uservoice.com/forums/304618-installation-and-patching

    or optionally start a case here with product support. A card is required to secure the incident contract but confirmed bugs are never charged.
    https://support.serviceshub.microsoft.com/supportforbusiness

    --please don't forget to Accept as answer if the reply is helpful--

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. INTREPID 41 Reputation points
    2022-11-12T03:49:35.057+00:00

    Update: The bug has been fixed.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.