
Windows Elevation of Privilege Vulnerability (SeriousSAM)
CVE described on MSRC. Remediated using ECM (aka SCCM) Config Items:
$false check for compliance.In production, we found the need to remediate purge copies other than ClientAccessible ones; we've seen Backup and DataVolumeRollback types that couldn't be deleted.
Unfortunately, vssadmin cleary states that "only shadow copies that have the ClientAccessible type can be deleted."
In order to purge them anyway, we needed to shrink the size of the storage down to the smallest amount allowed (320MB); this will cause Windows to purge the oversized shadow copy.
We then bring it back to a normal/unbounded size.
All features and bug reports must be tracked as GitHub Issues before any work begins. Issues are the authoritative record of intent — PRs without a corresponding issue will not be merged.
All changes require a PR. Direct commits to the default branch are not permitted.
PR requirements:
Closes #N or Ref #N)CHANGELOG.md entry — one entry per issue, referencing the issue number for full context