Windows 10: KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414

Discus and support KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414 in Windows 10 Software and Apps to solve the problem; Hi,I would like to know the ways to test the DCOM impact on a system once the hardening changes are effective.Thanks,Bharathy... Discussion in 'Windows 10 Software and Apps' started by Bharathy_h, Jul 15, 2022.

  1. KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414


    Hi,I would like to know the ways to test the DCOM impact on a system once the hardening changes are effective.Thanks,Bharathy

    :)
     
    Bharathy_h, Jul 15, 2022
    #1
  2. Brink Win User

    Windows Distributed Component Object Model (DCOM) Hardening changes

    Read more:
     
    Brink, Jul 15, 2022
    #2
  3. Microsoft December 2021 Security Updates

    December 2021 Security Updates

    Updates this Month

    This release consists of security updates for the following products, features and roles.

    • Apps
    • ASP.NET Core & Visual Studio
    • Azure Bot Framework SDK
    • BizTalk ESB Toolkit
    • Internet Storage Name Service
    • Microsoft Defender for IoT
    • Microsoft Devices
    • Microsoft Edge (Chromium-based)
    • Microsoft Local Security Authority Server (lsasrv)
    • Microsoft Message Queuing
    • Microsoft Office
    • Microsoft Office Access
    • Microsoft Office Excel
    • Microsoft Office SharePoint
    • Microsoft PowerShell
    • Microsoft Windows Codecs Library
    • Office Developer Platform
    • Remote Desktop Client
    • Role: Windows Fax Service
    • Role: Windows Hyper-V
    • Visual Studio Code
    • Visual Studio Code - WSL Extension
    • Windows Common Log File System Driver
    • Windows Digital TV Tuner
    • Windows DirectX
    • Windows Encrypting File System (EFS)
    • Windows Event Tracing
    • Windows Installer
    • Windows Kernel
    • Windows Media
    • Windows Mobile Device Management
    • Windows NTFS
    • Windows Print Spooler Components
    • Windows Remote Access Connection Manager
    • Windows Storage
    • Windows Storage Spaces Controller
    • Windows SymCrypt
    • Windows TCP/IP
    • Windows Update Stack
    Please note the following information regarding the security updates:

    Security Update Guide Blog Posts

    Date Blog Post

    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API

    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners

    December 8, 2020 Security Update Guide: Let’s keep the conversation going

    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Information

    • Windows 10 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows 7, Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    FAQs, Mitigations, and Workarounds

    The following CVEs have FAQs, Mitigations, or Workarounds. You can see these in more detail from the Vulnerabilities tab by selecting FAQs, Mitigations and Workarounds columns in the Edit Columns panel.

    Known Issues

    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To

    5008207 Windows 10, Version 1607, Windows Server 2016

    5008212 Windows 10, Version 2004, Windows Server, Version 2004, Windows 10, Version 20H2, Windows Server, Version 20H2, Windows 10, Version 21H1

    5008218 Windows 10, Version 1809, Windows Server 2019

    5008223 Windows Server 2022

    5008244 Windows 7, Windows Server 2008 R2 (Monthly Rollup)

    5008255 Windows Server 2012 (Security-only update)

    5008263 Windows 8.1, Windows Server 2012 R2 (Monthly Rollup)

    5008271 Windows Server 2008 (Security-only update)

    5008274 Windows Server 2008 (Monthly Rollup)

    5008277 Windows Server 2012 (Monthly Rollup)

    5008282 Windows 7, Windows Server 2008 R2 (Security-only update)

    5008285 Windows 8.1, Windows Server 2012 R2 (Security-only update)

    Released: Dec 14, 2021

    December 2021 Security Updates - Release Notes - Security Update Guide - Microsoft
     
    NICK ADSL UK, Jul 15, 2022
    #3
  4. KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414

    DCOM Error Event 10036 in PC Client Side

    Currently we are connecting OPC DA client to an remote OPC DA server using DCOM technology. OPC DA client can be connected to OPC DA Server. We got all tags from OPC DA Server and the values are good in OPC DA client but we found that there are DCOM errors detected in PC Client's Windows Event Viewer every 2 minutes as long as OPC DA client accesses the OPC DA Server.


    KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414 29f13084-6ccd-43bf-8dd4-9b944bece720?upload=true.png


    I read this article and the error 10036 should be on the PC server side but it's strange that the errors appear on the PC client side.

    KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass (CVE-2021-26414)


    KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414 e9ef81c4-95d4-4e94-bb14-1ecceea32db5?upload=true.png


    This is the example error that I got in PC client side, it mentioned the PC client device name but "from [OPC DA Server IP]"

    "The server-side authentication level policy does not allow the user [PC Client Device Name\User Name] SID XXXXXX from address [OPC DA Server IP] to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application."

    Could you please suggest how to fix the DCOM error detected in PC Client's Windows Event Viewer? Will the DCOM error affect connection / data transmission between Server and Client (such as causing error in Windows OS Server in the future)? Or we can ignore this error (because the connection between server-client is okay now)?

    Thank you
     
    Betaria_Hartari, Jul 15, 2022
    #4
Thema:

KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414

Loading...
  1. KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414 - Similar Threads - KB5004442—Manage changes DCOM

  2. BitLocker Security Feature Bypass Vulnerability CVE-2022-41099 and KB5025175

    in Windows 10 Gaming
    BitLocker Security Feature Bypass Vulnerability CVE-2022-41099 and KB5025175: Hello,This is a about CVE-2022-41099 and KB5025175.Firstly, the KB5025175 page provides PatchWinREScript_2004plus.ps1 and PatchWinREScript_General.ps1 as "Sample" scripts, presumably expecting us to read and understand them before running them.- Could we have a "download"...
  3. BitLocker Security Feature Bypass Vulnerability CVE-2022-41099 and KB5025175

    in Windows 10 Software and Apps
    BitLocker Security Feature Bypass Vulnerability CVE-2022-41099 and KB5025175: Hello,This is a about CVE-2022-41099 and KB5025175.Firstly, the KB5025175 page provides PatchWinREScript_2004plus.ps1 and PatchWinREScript_General.ps1 as "Sample" scripts, presumably expecting us to read and understand them before running them.- Could we have a "download"...
  4. BitLocker Security Feature Bypass Vulnerability CVE-2022-41099 and KB5025175

    in AntiVirus, Firewalls and System Security
    BitLocker Security Feature Bypass Vulnerability CVE-2022-41099 and KB5025175: Hello,This is a about CVE-2022-41099 and KB5025175.Firstly, the KB5025175 page provides PatchWinREScript_2004plus.ps1 and PatchWinREScript_General.ps1 as "Sample" scripts, presumably expecting us to read and understand them before running them.- Could we have a "download"...
  5. KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414

    in Windows 10 Installation and Upgrade
    KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414: Hi,I would like to know the ways to test the DCOM impact on a system once the hardening changes are effective.Thanks,Bharathy https://answers.microsoft.com/en-us/windows/forum/all/kb5004442manage-changes-for-windows-dcom-server/03479f22-5e50-4a2e-89e9-1cfa9d11dc7a
  6. KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414

    in Windows 10 Gaming
    KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass CVE-2021-26414: Hi,I would like to know the ways to test the DCOM impact on a system once the hardening changes are effective.Thanks,Bharathy https://answers.microsoft.com/en-us/windows/forum/all/kb5004442manage-changes-for-windows-dcom-server/03479f22-5e50-4a2e-89e9-1cfa9d11dc7a
  7. Updates - TCP/IP:  CVE-2021-24074, CVE-2021-24094, and CVE-2021-24086

    in Windows 10 News
    Updates - TCP/IP:  CVE-2021-24074, CVE-2021-24094, and CVE-2021-24086: Today Microsoft released a set of fixes affecting Windows TCP/IP implementation that include two Critical Remote Code Execution (RCE) vulnerabilities (CVE-2021-24074, CVE-2021-24094) and an Important Denial of Service (DoS) vulnerability (CVE-2021-24086). The two RCE...
  8. CVE-2019-1314 Windows 10 Mobile Security Feature Bypass Vulnerability Mobile

    in Windows 10 News
    CVE-2019-1314 Windows 10 Mobile Security Feature Bypass Vulnerability Mobile: Security Vulnerability Published: 10/08/2019 MITRE CVE-2019-1314 A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen. An attacker who successfully exploited this vulnerability...
  9. CVE-2019-0627 - Windows Security Feature Bypass Vulnerability

    in Windows 10 News
    CVE-2019-0627 - Windows Security Feature Bypass Vulnerability: A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard. An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine. To exploit the vulnerability,...
  10. CVE-2018-8512 - Microsoft Edge Security Feature Bypass Vulnerability

    in Windows 10 News
    CVE-2018-8512 - Microsoft Edge Security Feature Bypass Vulnerability: A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins. The vulnerability allows Microsoft Edge to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An attacker...