Windows Server 2022 must not have Windows PowerShell 2.0 installed.
An XCCDF Rule
Description
Windows PowerShell 5.x added advanced logging features that can provide additional detail when malware has been run on a system. Disabling the Windows PowerShell 2.0 mitigates against a downgrade attack that evades the Windows PowerShell 5.x script block logging feature.
- ID
- SV-254278r958478_rule
- Version
- WN22-00-000410
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Uninstall the "Windows PowerShell 2.0 Engine".
Start "Server Manager".
Select the server with the feature.