| Open the IIS 10.0 Manager. |
Click the IIS 10.0 web server name.
Under IIS, double-click the "MIME Types" icon.
From the "Group by:" drop-down list, select "Content Type".
From the list of extensions under "Application", verify MIME types for OS shell program extensions have been removed, to include at a minimum, the following extensions:
If any OS shell MIME types are configured, this is a finding.