Not found security hardening registry for DCOM after apply June 2021 patch

Ka^peng 21 Reputation points
2021-07-22T10:55:30.51+00:00

KB5004442 - Manage changes for Windows DCOM Server Security Feature Bypass (CVE-2021-26414)

https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c

From above KB, I have the impression that I will be able to see the registry "RequireIntegrityActivationAuthenticationLevel" at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat after I apply the June 2021 patch. This seems not the case. I cannot see this registry even after I have applied the June 2021 patch. In this case, is that mean I actually need to manually create this registry & enable/disable it to test on the application functionality?

Windows for business | Windows Server | User experience | Other
{count} votes

Accepted answer
  1. Anonymous
    2021-07-23T01:57:47.813+00:00

    Hi,

    Thank you for posting your question to Q&A forum.

    Yes, your understanding is correct. You will need to manually set the registry.

    With the security update released on June 8, 2021 installed, hardening changes were disabled by default but with the ability to enable them using a registry key. That means you can manually create and set the registry "RequireIntegrityActivationAuthenticationLevel" at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat.

    Also, you could find the article Windows DCOM Server Security Feature Bypass CVE-2021-26414 mentioned this.

    117242-image.png

    Hope the information could help you.

    Thanks,

    ----------

    If the Answer is helpful, please click "Accept Answer" and upvote it. Thanks.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.