In June 2021, Microsoft delivered a security update in response to CVE-2021-26414 which added a registry key to harden DCOM configurations. In June 2022, a patch was released which turns this registry key on by default and applies the changes, but in March 2023 this registry key will no longer be able to be manually disabled by an administrator. This will impact many systems utilizing legacy OPC-DA configurations.
In this episode of Tech Bytes, Isabella Sarna and Luke Turner from the SolutionsPT Technical Support team break down what is happening, which products will be affected and the impact you may see when these changes are made permanent.
Further resources on what is happening and what steps to take are available below:
AVEVA/Wonderware Documents:
Knowledge and Support Center - System Platform/ AVEVA Plant SCADA/ Citect / AVEVA Edge and InduSoft Web Studio
https://softwaresupportsp.aveva.com/
Wonderware Security Bulletin WW21-105 - Technology Matrix
https://gcsresource.aveva.com/Technol...
Microsoft Documents:
KB500442—Manage changes for Windows DCOM Server Security Feature Bypass (CVE-2021-26414)
https://support.microsoft.com/en-us/t...
CVE-2021-26414 - Security Update Guide - Microsoft - Windows DCOM Server Security Feature Bypass
https://msrc.microsoft.com/update-gui...