Block remote MS-EVEN functionality with RPC Filters If Microsoft EventLog Remoting Protocol (MS-EVEN) is not required, administrators should block the remote MS-EVEN functionality on the vulnerable host using RPC filters. Create a text file with the following content:...
Microsoft Windows Machine Account NTLM Coercion via Authenticated MS-DFSNM
Block remote MS-DFSNM functionality with RPC Filters If Microsoft Distributed File System (DFS) Namespace Management Protocol (MS-DFSNM) is not required, administrators should block the remote MS-DFSNM functionality for non-Domain Admins on the vulnerable host using...
Microsoft Windows Machine Account NTLM Coercion via Authenticated MS-RPRN
Block remote MS-RPRN functionality with RPC Filters If Microsoft Print System Remote Protocol (MS-RPRN) is not required, administrators should block the remote MS-RPRN functionality on the vulnerable host using RPC filters. Create a text file with the following...
Microsoft Windows Machine Account NTLM Coercion via Authenticated MS-FSRVP
Block remote MS-FSRVP functionality with RPC Filters If Microsoft File Server Remove VSS Protocol (MS-FSRVP) is not required, administrators should block the remote MS-FSRVP functionality for non-Domain Admins on the vulnerable host using RPC filters. Create a text...
Microsoft Windows Machine Account NTLM Coercion via Authenticated LSARPC Spoofing
Block remote EFSRPC functionality with RPC Filters If Microsoft Encrypted File System Remote Protocol (MS-EFSRPC) is not required, administrators should block the remote EFSRPC functionality on the vulnerable host using RPC filters. Create a text file with the...
Insecure Java JMX Configuration
Table of Contents Option 1: Disable JMX Option 2: Configure a Whitelist Firewall Option 3: Configure User Authentication on the JMX Server Option 1: Disable JMX JMX is only required if you need remote management and monitoring of a Java-based application or the Java...
Netlogon Elevation of Privilege Vulnerability
Apply the February 9, 2021 Security Patch to the Host Microsoft released a patch on February 9, 2021 addressing this vulnerability. To install it, apply the latest security updates on every Domain Controller. For more information, see CVE-2020-1472 Security Bulletin
Remote Desktop Services Remote Code Execution
Table of Contents Option 1: Patch the Host Option 2: Enable NLA on the Host Option 1: Patch the Host Microsoft released patches, KB4493471 and KB4493472, addressing this vulnerability. Install one of the patches from the Microsoft Update Catalog for the corresponding...
Subdomain Takeover
Table of Contents Option 1: Remove Dangling CNAME Option 2: Update CNAME Option 1: Remove Dangling CNAME If the subdomain is no longer in use, then from your DNS zone, remove the subdomain’s DNS record. Review application code and configuration for references to...
VMware vCenter vROPS Plugin Remote Code Execution Vulnerability
Table of Contents Option 1: Upgrade vCenter Instance Option 2: Disable Plugins on Virtual Server Appliance Deployments Option 3: Disable Plugins on Windows-based vCenter Server Deployments Validation Option 1: Upgrade your vCenter Instance Upgrade the major release...
How can NodeZero help you?
Let our experts walk you through a demonstration of NodeZero, so you can see how to put it to work for your company.