If Microsoft File Server Remove VSS Protocol (MS-FSRVP) is not required, administrators should block the remote MS-FSRVP functionality for non-Domain Admins on the vulnerable host using RPC filters.
-
- Create a text file with the following content:
rpc filter add rule layer=um actiontype=permit add condition field=if_uuid matchtype=equal data=4FC742E0-4A10-11CF-8273-00AA004AE673 add condition field=remote_user_token matchtype=equal data=D:(A;;CC;;;DA) add filter add rule layer=um actiontype=block add condition field=if_uuid matchtype=equal data=4FC742E0-4A10-11CF-8273-00AA004AE673 add filter quit
- Use the netsh command line utility to import the RPC filter from an elevated administrator prompt:
netsh -f <FILTER_FILE_NAME>
- To confirm the filters are in place, you can view the current RPC filters using the following command:
netsh rpc filter show filter
- Create a text file with the following content:
See CERT Coordination Center Vulnerability Note VU:#405600 for additional details on protecting Active Directory Certificate Services from NTLM relay attacks.