SSL/TLS use of weak RC4(Arcfour) cipher 3389

Williams Padilla 41 Reputation points
2021-02-17T19:48:05.12+00:00

Hello everyone

Can someone help me with this vulneravility? CVE-2013-2566, CVE-2015-2808
I disabled manually RC4 I share it here

69217-image.png

but when the security team re-evaluate it the vulnerability appear again, please someone with this issue?

My OS: Windows server 2016 Data Center

69222-image.png

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2021-02-18T03:44:20.817+00:00

    Hello @Williams Padilla ,

    Thank you for posting here.

    RC4 is not turned off by default for all applications.

    From the screenshot you provided, it seems you did not disable the RC4.

    We can use the following registry keys and their values to enable and disable RC4.
    69306-rc4.png

    And then check if it helps when the security team re-evaluate it the vulnerability appear again.

    Reference
    Microsoft security advisory: Update for disabling RC4
    https://support.microsoft.com/en-us/topic/microsoft-security-advisory-update-for-disabling-rc4-479fd6f0-c7b5-0671-975b-c45c3f2c0540

    Hope the information above is helpful.

    Should you have any question or concern, please fell free to let us know.

    Best Regards,
    Daisy Zhou


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.