Back to Blog
Modern Data Center
Share
Over the last six months, we have been helping to make NetApp administrators aware of the Microsoft vulnerability update regarding the Netlogon RPC Elevation of Privilege Vulnerability (CVE-2022-38023) and its impact on NetApp ONTAP products. This vulnerability allows attackers to gain access to sensitive data and take over systems by exploiting the Netlogon authentication protocol and Windows administrators must apply the appropriate updates.
The update process involves implementing changes in multiple versions of Windows Server and requires a phased approach by Microsoft. Failure to complete the required updates could lead to serious security breaches and potential data loss. The first phase of implementation began on November 8, 2022, with the final phase scheduled for July 11, 2023.
NetApp has added support for Netlogon RPC Sealing in all ONTAP releases still in Full Support, and it is essential that NetApp Administrators take recommended actions before the June 13, 2023 “Enforcement by Default” phase and before the July 11, 2023 “Enforcement” phase for CVE-2022-38023. Failure to complete these actions could impact data availability and access from your NetApp storage system.
Below is a more detailed overview describing the Microsoft vulnerability, update timeline and the appropriate remediation steps for resolution. If you need assistance, please reach out to your EchoStor Account Executive to schedule a follow up discussion. If you’re unsure who your Account Executive is, please click here to fill in your information and we will follow up as quickly as possible.
1. Before the June 13, 2023 “Enforcement by Default” phase for CVE-2022-38023, either
• Apply the “Compatibility mode” RequireSeal = 1 registry key value to all Windows domain controllers (see the “Workaround” section of the bulletin for more details), or
• Upgrade all systems running ONTAP to one of the releases in the “Solution” section of the bulletin (or later, as available) – preferred.
2. Before the July 11, 2023 “Enforcement” phase for CVE-2022-38023, if not already upgraded, upgrade all systems running ONTAP to one of the releases in the “Solution” section of the bulletin (or later, as available).
• Note that for ONTAP 9, there is NO OTHER WORKAROUND that applies after the July 11, 2023 “Enforcement” phase for CVE-2022-38023.
To learn more, and ensure that you are protected, click the button below to fill out your information to speak with someone from EchoStor.
Tags
Matt Hoeg
Director, MDC Technology
EchoStor Technologies is named NetApp North America North Region Partner of the Year for FY’24 SAN JOSE, Calif.
EchoStor Technologies has been named NetApp Most Valuable Partner for its overall FY18 revenue, year over year growth, …
Insights on Integrating AI Tools for Enhanced Productivity in the Corporate World In this article, I delve into …