Real-Time Detection Of PetitPotam (CVE-2021-36942) Vulnerability
PKI Spotlight® automatically checks if your MS ADCS environment is vulnerable to the PetitPotam NTLM relay attack (CVE- 2021-36942) which could allow an attacker to completely take over an Active Directory Forest.
View All PKI Spotlight FeaturesPKI Spotlight in Action
Real-Time Detection Of PetitPotam (CVE-2021-36942) Vulnerability
Why does it matter?
PKI Spotlight automatically checks if your MS ADCS environment is vulnerable to the PetitPotam NTLM relay attack (CVE- 2021-36942) which could allow an attacker to completely take over an Active Directory Forest.
PKI Spotlight will monitor and alert when:
- NTLM authentication is allowed by the host and by Certificate Authority Web Enrollment website in IIS
OR when any of the following conditions exist:
- Extended Protection for Authentication (EPA) for Certificate Authority Web Enrollment is disabled
- Extended Protection for Authentication (EPA) for Certificate Enrollment Web Service is disabled
- The Certificate Authority Web Enrollment website in IIS is configured to accept non-TLS connections (HTTP vs HTTPS)
In addition, PKI Spotlight will provide Best Practice Recommendations on:
- Settings for Web.config file created by the Certificate Enrollment Web Service (CES) role
- How to disable NTLM authentication on Domain Controllers
- How to disable NTLM on any ADCS Servers using group policy
Connect With Us for Certainty in Security
If you’re ready to learn more about our essential solutions for your essential PKI, reach out today. Book time with one of our specialists to discuss your needs and how we can meet and exceed your business requirements.
CONTACT US
Email: hello@pkisolutions.com
Phone: +1 (971) 231-5523
Corporate Headquarters
5331 S. Macadam Ave, Suite 330
Portland, Oregon 97239