This article provides mitigation steps to address .NET Remoting vulnerabilities in environments where Enterprise Vault is deployed. It outlines firewall configuration, best practices, and access control recommendations to minimize exposure to potential threats.
To mitigate the .NET Remoting vulnerabilities, configure the firewall appropriately in the network(s) where the Enterprise Vault servers and clients reside. The essential part of the mitigation is tightly controlling access to Microsoft RPC dynamic TCP ports on EV servers. Follow the guidelines below for configuring the network:

Fig 1:Network segment 1 for end user machines and network segment 2 for EV and other servers. Segment 2 shows firewalls protecting the EV servers, to allow only trusted hosts to connect to Windows dynamic RPC ports.
Ensure that the latest Windows updates have been installed on the Enterprise Vault server.
The eDiscovery/Discovery Accelerator and Arctera Surveillance/Compliance Accelerator servers can be protected from such .NET Remoting attacks by applying the following guidelines:
Mitigating .NET remoting vulnerabilities on Enterprise Vault servers