Windows DCOM Server Security Feature Bypass
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? This vulnerability requires that a user with an affected version of Windows access a malicious server. An attacker would have to host a specially crafted server share or website. An attacker would have no way to force users to visit this specially crafted server share or website, but would have to convince them to visit the server share or website, typically by way of an enticement in an email or chat message.
Do I need to take further steps to be protected from this vulnerability? Yes. The security updates released on June 8, 2021 enable RPC_C_AUTHN_LEVEL_PKT_INTEGRITY on DCOM clients by default and provide full protection after manually setting RequireIntegrityActivationAuthenticationLevel = 1 on DCOM servers using the steps in Managing changes for Windows DCOM Server Security Feature Bypass (CVE-2021-26414). Note that a reboot is required after making any changes to the RequireIntegrityActivationAuthenticationLevel registry key. Microsoft recommends enabling full protection as soon as possible to identify any OS and application intermobility issues between Windows and non-Windows operating systems and applications. With the June 14, 2022 security updates, RPC_C_AUTHN_LEVEL_PKT_INTEGRITY on DCOM servers is now enabled by default. Customer who need to do so can still disable it by using the RequireIntegrityActivationAuthenticationLevel registry key. If I install the updates and take no further action, what will be the impact? Installing the security updates released on June 8, 2021 enables client side protections in a pure Windows environment but does not provide any protection in environments with non-Windows DCOM client. Organizations will need to identify and mitigate any interop issues between Windows and non-Windows operating systems and applications before the third phase, when the hardening on DCOM servers is enabled by default and will no longer have the ability to be disabled. Installing the security updates released on June 14, 2022 enables the registry key by default so that DCOM servers enforce an Authentication-Level of RPC_C_AUTHN_LEVEL_PKT_INTEGRITY or higher for activation. How does Microsoft plan to address this vulnerability? Microsoft is addressing this vulnerability in a phased rollout. The initial deployment phase starts with the Windows updates released on June 8, 2021. The updates will enable customers to verify that any client/server applications in their environment work as expected with the hardening changes enabled. The second phase, planned for an June 14, 2022, programmatically enables the hardening on DCOM servers by default that can be disabled via the RequireIntegrityActivationAuthenticationLevel registry key if necessary. The third phase, planned for March 14, 2023, enables the hardening on DCOM servers by default and will no longer have the ability to be disabled. By this point, you must resolve any compatibility issues with the hardening changes and applications in your environment. Are there system events available that will help me identify the client devices that will be impacted by the change? Yes. See the New DCOM error events section of Managing changes for Windows DCOM Server Security Feature Bypass (CVE-2021-26414). While the first security updates to address this vulnerability were released on June 2021, we recommend that you install the updates released on September 2021 to enable DCOM event logs that were added with those updates.
🎯 Affected products41
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows 10 Version 21H1 for 32-bit Systems
- Windows 10 Version 21H1 for ARM64-based Systems
- Windows 10 Version 21H1 for x64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- +11 more not shown
✅ Remediation
KB5023702 (Security Update) — fixed build 10.0.17763.4131 KB5014701 (Security Update) — fixed build 10.0.18363.2344 KB5014699 (Security Update) — fixed build 10.0.19043.1766 KB5023705 (Security Update) — fixed build 10.0.20348.1607 KB5023696 (Security Update) — fixed build 10.0.19042.2728 KB5023698 (Security Update) — fixed build 10.0.22000.1696 KB5023696 (Security Update) — fixed build 10.0.19044.2728 KB5023787 (ServicingStackUpdate) — fixed build 10.0.10240.19802 KB5023697 (Security Update) — fixed build 10.0.14393.5786 KB5014748 (Monthly Rollup) — fixed build 6.1.7601.25984 KB5014742 (Security Only) — fixed build 6.1.7601.25984 KB5014738 (Monthly Rollup) — fixed build 6.3.9600.20402 KB5014746 (Security Only) — fixed build 6.3.9600.20402 KB5023755 (Monthly Rollup) — fixed build 6.0.6003.21966 KB5023754 (Security Only) — fixed build 6.0.6003.21966 KB5023769 (Monthly Rollup) — fixed build 6.1.7601.26415 KB5023759 (Security Only) — fixed build 6.1.7601.26415 KB5023756 (Monthly Rollup) — fixed build 6.2.9200.24168 KB5023752 (Security Only) — fixed build 6.2.9200.24168 KB5023765 (Monthly Rollup) — fixed build 6.3.9600.20865 KB5023764 (Security Only) — fixed build 6.3.9600.20865
🔗 References (35)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26414
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023702
- referencehttps://support.microsoft.com/help/5023702
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014701
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014699
- referencehttps://support.microsoft.com/help/5014699
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023705
- referencehttps://support.microsoft.com/help/5023705
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023696
- referencehttps://support.microsoft.com/help/5023696
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023698
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023787
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023697
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014748
- referencehttps://support.microsoft.com/help/5014748
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014742
- referencehttps://support.microsoft.com/help/5014742
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014738
- referencehttps://support.microsoft.com/help/5014738
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014746
- referencehttps://support.microsoft.com/help/5014746
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023755
- referencehttps://support.microsoft.com/help/5023755
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023754
- referencehttps://support.microsoft.com/help/5023754
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023769
- referencehttps://support.microsoft.com/help/5023769
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023759
- referencehttps://support.microsoft.com/help/5023759
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023756
- referencehttps://support.microsoft.com/help/5023756
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023752
- referencehttps://support.microsoft.com/help/5023752
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023765
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023764