SMB Signing not required Vulnerability

Federico Coppola 6 Reputation points
2020-11-12T10:06:43.803+00:00

Hi all,
After a vulnerability assessment I found this vulnerability about Windows Server machines

SMB Signing not required
https://www.tenable.com/plugins/nessus/57608

There are not shared folder with "Everyone" on File Servers. All folders has got a dedicated an Active Directory Security Group so I can filter users that can access.

After that, due to there are two production machines inside company, I had to enable SMBv1 on File Servers VM.
I know that these two production machines has got a custom firmware (I suppose that it is linux based).

I have found this two "how to" article:
https://www.gispp.org/2020/07/29/smb-signing-digital/
https://www.stigviewer.com/stig/windows_server_2016/2019-01-16/finding/V-73661

If it is possible, Can I improve security of file servers company (there are three file servers VM using DFS technology) without block the company?
Could SMBv1 generate this vulnerability?

How can I solve it?

Thanks so much
Federico

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Storage high availability | Other
{count} votes

1 answer

Sort by: Most helpful
  1. Xiaowei He 9,936 Reputation points
    2020-11-17T07:30:56.877+00:00

    Hi,

    Based on my understanding, you want to increase the security of using SMB file servers.

    SMBv1 has significant security vulnerabilities and we strongly encourage you not to use it. While disabling or removing SMBv1 might cause some compatibility issues with old computers or software. The benefits of mitigation should be weighed against potential disruptions to users. For more information on SMB, please review the following artilces:

    https://learn.microsoft.com/en-us/windows-server/storage/file-server/troubleshoot/detect-enable-and-disable-smbv1-v2-v3

    https://techcommunity.microsoft.com/t5/storage-at-microsoft/stop-using-smb1/ba-p/425858

    https://learn.microsoft.com/en-us/security-updates/SecurityBulletins/2017/ms17-010?redirectedfrom=MSDN

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/direct-hosting-of-smb-over-tcpip

    Thanks for your time!
    Best Regards,
    Anne

    -----------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.