On at least Windows 10 20H2 (19042.1110), Get-WmiObject Win32_ShadowStorage returns $null when shadow copies are not configured and none exist.
This lead to $fixed = $false, when in fact the issue is fixed.
Recommend updating to the following:
#check shadow
if ($vulnerable -eq $true) {
$checkShadow = Get-WmiObject Win32_ShadowStorage -Property UsedSpace | Select-Object -ExpandProperty UsedSpace
if ((0 -eq $checkShadow) -or ($null -eq $checkShadow)) {
$shadowSucces = $true
Write-Host "Successfully deleted old volume shadow copies."
}
else {
$shadowSucces = $false
write-host "Shadow deletion failed. Security software may be blocking this action or check running permissions."
}
}
|
if (0 -eq $checkShadow) { |
On at least Windows 10 20H2 (19042.1110),
Get-WmiObject Win32_ShadowStoragereturns $null when shadow copies are not configured and none exist.This lead to
$fixed = $false, when in fact the issue is fixed.Recommend updating to the following:
HiveNightmare/Mitigation.ps1
Line 40 in 0428053