Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-1139 | 3.024 | SV-29592r1_rule | ECSC-1 | Medium |
Description |
---|
The default Windows configuration enables the option to save the password used to gain access to a remote server using the dial-up networking feature. With this option enabled, an unauthorized user who gains access to a Windows machine would also have access to remote servers with which the machine uses dial-up networking to communicate. Disabling this option will introduce another layer of security and help limit the scope of any security compromise to the local machine. |
STIG | Date |
---|---|
Windows 2003 Domain Controller Security Technical Implementation Guide | 2014-04-07 |
Check Text ( None ) |
---|
None |
Fix Text (F-86r1_fix) |
---|
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> “MSS: (DisableSavePassword) Prevent the dial-up password from being saved (recommended)” to “Enabled”. |