UCF STIG Viewer Logo

Terminal Services is not configured to allow only the original client to reconnect.


Overview

Finding ID Version Rule ID IA Controls Severity
V-3459 5.048 SV-29712r1_rule ECSC-1 Medium
Description
This setting, which is located under the Sessions section of the Terminal Services configuration option, controls whether a different client may be used to resume a disconnected session. Only the original client should be able to resume a session to help prevent session hijacking.
STIG Date
Windows 2003 Member Server Security Technical Implementation Guide 2014-01-07

Details

Check Text ( C-1925r1_chk )
If the following registry value doesn’t exist or its value is not set to 1, then this is a finding:

Registry Hive: HKEY_LOCAL_MACHINE
Subkey: \Software\Policies\Microsoft\Windows NT\Terminal Services\
Value Name: fReconnectSame
Type: REG_DWORD
Value: 1
Fix Text (F-5933r1_fix)
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Terminal Services -> Sessions “Allow Reconnection from Original Client Only” to “Enabled”.