Skip to content

Windows PowerShell 2.0 must not be installed.

An XCCDF Rule

Description

Windows PowerShell 5.0 added advanced logging features that can provide additional detail when malware has been run on a system. Disabling the Windows PowerShell 2.0 mitigates against a downgrade attack that evades the Windows PowerShell 5.0 script block logging feature.

ID
SV-224859r958478_rule
Version
WN16-00-000420
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Uninstall the "Windows PowerShell 2.0 Engine".

Start "Server Manager".

Select the server with the feature.