Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-3339 | 3.064 | SV-28589r1_rule | ECCD-1 ECCD-2 | High |
Description |
---|
This is a Category 1 finding because it could give unauthorized individuals access to the Registry. It controls which registry paths are accessible from a remote computer. |
STIG | Date |
---|---|
Windows 2008 Member Server Security Technical Implementation Guide | 2015-09-02 |
Check Text ( C-32798r1_chk ) |
---|
Analyze the system using the Security Configuration and Analysis snap-in. Expand the Security Configuration and Analysis tree view. Navigate to Local Policies -> Security Options. If the value for “Network access: Remotely accessible registry paths” contains entries besides the following, then this is a finding: System\CurrentControlSet\Control\ProductOptions System\CurrentControlSet\Control\Server Applications Software\Microsoft\Windows NT\CurrentVersion The policy referenced configures the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \System\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedExactPaths\ Value Name: Machine Value Type: REG_MULTI_SZ Value: As defined in policy above Note: Legitimate applications may add entries to this registry value. If an application requires these entries to function properly and is documented with the IAO, this would not be a finding. Documentation should contain supporting information from the vendor's instructions. |
Fix Text (F-28869r1_fix) |
---|
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> “Network access: Remotely accessible registry paths” as defined in the Check section. |