Skip to content

Windows Server 2022 must not have Windows PowerShell 2.0 installed.

An XCCDF Rule

Description

Windows PowerShell 5.x added advanced logging features that can provide additional detail when malware has been run on a system. Disabling the Windows PowerShell 2.0 mitigates against a downgrade attack that evades the Windows PowerShell 5.x script block logging feature.

ID
SV-254278r958478_rule
Version
WN22-00-000410
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Uninstall the "Windows PowerShell 2.0 Engine".

Start "Server Manager".

Select the server with the feature.