QID 91798
Date Published: 2021-08-02
QID 91798: Microsoft Guidance For Mitigating NTLM Relay Attacks (ADV210003)
Microsoft has announced the availability of a new feature, Extended Protection for Authentication, on the Windows platform. This feature enhances the protection and handling of credentials when authenticating network connections using Integrated Windows Authentication (IWA).
To prevent NTLM Relay Attacks on networks with NTLM enabled, domain administrators, must ensure that services that permit NTLM authentication make use of protections such as Extended Protection for Authentication (EPA) or signing features such as SMB signing
QID Detection Logic:
Based on ADV210003 and KB5005413 , this authenticated QID checks if the values of the following keys is set to
HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters is 0 or 7.
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0 is 1 or 2.
and also checks for workaround applied in web.config file.
Successful exploitation of this attack allows attackers to take over windows domains.
CVEs related to QID 91798
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ADV210003 |
|
||
| KB5005413 |
|