CVE-2020-1472 [zerologon] no events with warnings 5827,5828,5829,5830 and 5831

Anton Krasnogortsev 1 Reputation point
2021-01-21T08:41:44.397+00:00

Good day! As part of "Managing Changes to Netlogon Secure Channel Connections Related to CVE-2020-1472", I tried to locate events 5827,5828,5829,5830 and 5831 in the System logs on our domain controllers.

Despite the presence of vulnerable test machines (win7), none of the ones mentioned in the article (https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon- secure-channel-connections-assoc) events, no domain controller logs.

The "Domain Controller: Allow Vulnerable Netlogon Secure Channel Connections" policy is currently enabled and specifies permissions (for the old DC with 2008R2) and prohibitions (for the test machine with Win7). A Win7 machine in the current situation does not experience any problems in operation, despite the ban.

At the moment, we cannot, in our environment, perform the "Step 2a. SEARCH" of the specified instruction, since there are no events in the logs

For what reason may the specified events not be displayed in the log?

The controllers receive updates constantly. The latter were from 01/13/2021 (for windows server 2019). Our domain consists of servers: Windows Server 2019 Standard 1809 (17763.1697), Windows Server 2012 R2 (9600), and one 2008 R2 for decommissioning.

Note: since we still have one DC since 2008 R2, the domain level is 2008 R2.

============ in Russian ============

Добрый день! В рамках "Управление изменениями в подключениях безопасного канала Netlogon, связанными с CVE-2020-1472", я попытался обнаружить события 5827,5828,5829,5830 и 5831 в журналах "система" на контроллерах нашего домена.

Не смотря на наличие уязвимых тестовых машин (win7), ни одного из указанных в статье (https://support.microsoft.com/ru-ru/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc) событий, в журналах контроллеров домена нет.

Политика "Контроллер домена: разрешить уязвимые подключения безопасного канала Netlogon" в данный момент включена и в ней указанны разрешения (на старый КД c 2008R2) и запреты (на тестовую машину с Win7). Машина с Win7 в текущей ситуации не испытывает проблем в работе, не смотря на запрет.

В данный момент, мы не можем, в своей среде, выполнить "Шаг 2a. ПОИСК" указанной инструкции, так как событий нет в журналах

По какой причине могут не отображаться указанные события в журнале?

Обновление контроллеры получают постоянно. Последние были от 13.01.2021 (для windows server 2019). Наш домен состоит из серверов: Windows Server 2019 Standard 1809 (17763.1697), Windows Server 2012 R2 (9600), и одного 2008 R2 - под вывод из эксплуатации.

Замечание: ввиду того что у нас все еще используется один КД с 2008 R2, уровень домена именно 2008 R2.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,474 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Vicky Wang 2,646 Reputation points
    2021-01-22T09:03:41.353+00:00

    Hi,

    Thank you for posting in our forum

    There is a detailed method to solve the error in the link, you can try it first, you can continue to update if there is no solution

    reference:
    https://dirteam.com/sander/2020/08/11/knowledgebase-you-experience-warnings-with-eventid-5829-on-domain-controllers/

    https://borncity.com/win/2020/09/12/windows-10-v1607-update-kb4571694-creates-id-5827-events-bricks-mmc/

    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.

    Hope this information can help you

    Best wishes

    Vicky

    0 comments No comments

  2. Vicky Wang 2,646 Reputation points
    2021-01-25T08:52:37.907+00:00

    Hi,

    Just checking in to see if the information provided was helpful.
    Please let us know if you would like further assistance.

    Best Regards,
    Vicky

    0 comments No comments

  3. Vicky Wang 2,646 Reputation points
    2021-01-27T09:26:21.53+00:00

    Hi,

    Just checking in to see if the information provided was helpful.

    Please let us know if you would like further assistance.

    Best Regards,
    Vicky

    0 comments No comments