Is an ONTAP upgrade required to fix CVE-2022-38023 for Enforcement phase?
Applies to
- ONTAP 9
- Cloud Volumes ONTAP
- CVE-2022-38023
- Netlogon (NTLM Authentication)
Answer
Yes. All NTLM authentication will fail unless you upgrade to a fixed version of Bug 1514175.
Note: Enforcement Phase happens after July 11th 2023 Microsoft Hot Fix was applied
Additional Information
- If ONTAP upgrade is not available, contact Microsoft Support for options to roll back the July 11, 2023 patches:
- Does CVE-2022-38023 have any impact to ONTAP 9?
- How to manually upgrade Cloud Volumes Ontap(CVO) from BlueXP