PetitPotam CVE 2021-36942 Vulnerability
Real-Time Detection Of PetitPotam (CVE-2021-36942) Vulnerability
Why does it matter?
PKI Spotlight automatically checks if your MS ADCS environment is vulnerable to the PetitPotam NTLM relay attack (CVE- 2021-36942) which could allow an attacker to completely take over an Active Directory Forest.
PKI Spotlight will monitor and alert when:
- NTLM authentication is allowed by the host and by Certificate Authority Web Enrollment website in IIS
OR when any of the following conditions exist:
- Extended Protection for Authentication (EPA) for Certificate Authority Web Enrollment is disabled
- Extended Protection for Authentication (EPA) for Certificate Enrollment Web Service is disabled
- The Certificate Authority Web Enrollment website in IIS is configured to accept non-TLS connections (HTTP vs HTTPS)
In addition, PKI Spotlight will provide Best Practice Recommendations on:
- Settings for Web.config file created by the Certificate Enrollment Web Service (CES) role
- How to disable NTLM authentication on Domain Controllers
- How to disable NTLM on any ADCS Servers using group policy
See the unseen with
PKI Spotlight®
Connect With Us for Certainty in Security
If you’re ready to learn more about our essential solutions for your essential PKI, reach out today. Book time with one of our specialists to discuss your needs and how we can meet and exceed your business requirements.
Contact Us
Email: hello@pkisolutions.com
Phone: +1 (971) 231-5523
Corporate Headquarters
1000 SW Broadway
Suite 1800
Portland, OR 97205

