Real-Time Detection Of PetitPotam (CVE-2021-36942) Vulnerability

PKI Spotlight® automatically checks if your MS ADCS environment is vulnerable to the PetitPotam NTLM relay attack (CVE- 2021-36942) which could allow an attacker to completely take over an Active Directory Forest.

View All PKI Spotlight Features
Schedule a Demo

PKI Spotlight in Action

Real-Time Detection Of PetitPotam (CVE-2021-36942) Vulnerability

Why does it matter?

PKI Spotlight automatically checks if your MS ADCS environment is vulnerable to the PetitPotam NTLM relay attack (CVE- 2021-36942) which could allow an attacker to completely take over an Active Directory Forest.

PKI Spotlight will monitor and alert when:

  • NTLM authentication is allowed by the host and by Certificate Authority Web Enrollment website in IIS

OR when any of the following conditions exist:

  • Extended Protection for Authentication (EPA) for Certificate Authority Web Enrollment is disabled
  • Extended Protection for Authentication (EPA) for Certificate Enrollment Web Service is disabled
  • The Certificate Authority Web Enrollment website in IIS is configured to accept non-TLS connections (HTTP vs HTTPS)

In addition, PKI Spotlight will provide Best Practice Recommendations on:

  • Settings for Web.config file created by the Certificate Enrollment Web Service (CES) role
  • How to disable NTLM authentication on Domain Controllers
  • How to disable NTLM on any ADCS Servers using group policy

Connect With Us for Certainty in Security

If you’re ready to learn more about our essential solutions for your essential PKI, reach out today. Book time with one of our specialists to discuss your needs and how we can meet and exceed your business requirements.

CONTACT US

Email: hello@pkisolutions.com
Phone: +1 (971) 231-5523

Corporate Headquarters

5331 S. Macadam Ave, Suite 330
Portland, Oregon 97239