UCF STIG Viewer Logo

Windows XP Security Technical Implementation Guide


Overview

Date Finding Count (147)
2014-04-07 CAT I (High): 17 CAT II (Med): 89 CAT III (Low): 41
STIG Description
The Windows XP Security Technical Implementation Guide (STIG) is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements were developed from Federal and DoD consensus, as well as the Windows XP Security Guide and security templates published by Microsoft Corporation. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.letterkenny.FSO.mbx.stig-customer-support-mailbox@mail.mil.

Available Profiles



Findings (MAC III - Administrative Classified)

Finding ID Severity Title
V-1073 High Systems must be at supported service packs (SP) or releases levels.
V-1159 High The Recovery Console option is set to permit automatic logon to the system.
V-1153 High The Send download LanMan compatible password option is not set to Send NTLMv2 response only\refuse LM.
V-2374 High The system is configured to autoplay removable media.
V-1093 High Anonymous shares are not restricted.
V-1145 High Administrator automatic logon is enabled.
V-3338 High Unauthorized named pipes are accessible with anonymous credentials.
V-3339 High Unauthorized registry paths are remotely accessible.
V-4107 High Windows operating systems that are no longer supported by the vendor for security updates must not be installed on a system.
V-18010 High Unapproved Users have access to Debug programs.
V-3343 High Solicited Remote Assistance is allowed.
V-3341 High Remote control of a Terminal Service session is allowed.
V-3340 High Unauthorized shares can be accessed anonymously.
V-3344 High The use of local accounts with blank passwords is not restricted to console logons only.
V-1102 High Unauthorized users are granted right to Act as part of the operating system.
V-17900 High Disallow AutoPlay/Autorun from Autorun.inf
V-3379 High The system is configured to store the LAN Manager hash of the password in the SAM.
V-3384 Medium The system is not configured to make the object creator the owner of objects created by administrators.
V-3383 Medium The system is not configured to use FIPS compliant Algorithms for Encryption, Hashing, and Signing.
V-3381 Medium The system is not configured to recommended LDAP client signing requirements.
V-3380 Medium The system is not configured to force users to log off when their allowed logon hours expire.
V-3460 Medium Terminal Services is not configured to disconnect clients when time limits are exceeded.
V-3469 Medium The system is configured to prevent background refresh of Group Policy.
V-15823 Medium Remove Software Certificate Installation Files
V-1139 Medium The option to prevent the password in dial-up networking from being saved is not enabled.
V-1164 Medium Outgoing secure channel traffic is not signed when possible.
V-1166 Medium The Windows SMB client is not enabled to perform SMB packet signing when possible.
V-1163 Medium Outgoing secure channel traffic is not encrypted when possible.
V-1162 Medium The Windows SMB server is not enabled to perform SMB packet signing when possible.
V-3471 Medium The system is configured to automatically forward error information.
V-3470 Medium The system is configured to allow unsolicited remote assistance offers.
V-1089 Medium The required legal notice must be configured to display before console logon.
V-3479 Medium The system is not configured to use Safe DLL Search Mode.
V-1083 Medium POSIX subsystem registry key exists.
V-1080 Medium File-auditing configuration does not meet minimum requirements.
V-3478 Medium The system is configured to allow installation of printers using kernel-mode drivers.
V-6850 Medium Auditing records are configured as required.
V-6836 Medium For systems utilizing a logon ID as the individual identifier, passwords are not at a minimum of 14-characters.
V-6832 Medium The Windows Server SMB client is not enabled to always perform SMB packet signing.
V-6833 Medium The Windows Server SMB server is not enabled to always perform SMB packet signing.
V-6831 Medium Outgoing secure channel traffic is not encrypted or signed.
V-14262 Medium IPv6 will be disabled until a deliberate transition strategy has been implemented.
V-14261 Medium Windows is prevented from using Windows Update to search for drivers.
V-14260 Medium Computer prevented from downloading print driver packages over HTTP.
V-1154 Medium Ctrl+Alt+Del security attention sequence is Disabled.
V-3385 Medium The system is configured to allow case insensitivity.
V-1157 Medium The Smart Card removal option is set to take no action.
V-1099 Medium Lockout duration does not meet minimum requirements.
V-1098 Medium Time before bad-logon counter is reset does not meet minimum requirements.
V-2372 Medium Reversible password encryption is not disabled.
V-1097 Medium Number of allowed bad-logon attempts does not meet minimum requirements.
V-3382 Medium The system is not configured to meet the minimum requirement for session security for NTLM SSP based Clients.
V-3376 Medium The system is configured to permit storage of credentials or .NET Passports.
V-3377 Medium The system is configured to give anonymous users Everyone rights.
V-3374 Medium The system is not configured to require a strong session key.
V-3378 Medium The system is not configured to use the Classic security model.
V-1171 Medium Ejection of removable NTFS media is not restricted to Administrators.
V-15682 Medium RSS Attachment Downloads
V-15683 Medium Windows Explorer – Shell Protocol Protected Mode
V-1141 Medium Unencrypted password is sent to 3rd party SMB Server.
V-15685 Medium Windows Installer – User Control
V-3459 Medium Terminal Services is not configured to allow only the original client to reconnect.
V-3458 Medium Terminal Services idle session time limit does not meet the requirement.
V-3453 Medium Terminal Services is not configured to always prompt a client for passwords upon connection.
V-3457 Medium Terminal Services is not configured to set a time limit for disconnected sessions.
V-3456 Medium Terminal Services is not configured to delete temporary folders.
V-3455 Medium Terminal Services is configured to use a common temporary folder for all sessions.
V-3454 Medium Terminal Services is not configured with the client connection encryption set to the required level.
V-3369 Medium Restricted accounts are not disabled.
V-1130 Medium ACLs for system files and directories do not conform to minimum requirements.
V-15679 Medium Windows Movie Maker Online Hosting
V-15678 Medium Windows Movie Maker Web Links
V-15677 Medium Windows Movie Maker Codec Downloads
V-15674 Medium Disable Internet File Association Service
V-14247 Medium Terminal Services - Prevent password saving in the Remote Desktop Client
V-1114 Medium The built-in guest account has not been renamed.
V-1115 Medium The built-in administrator account has not been renamed.
V-3426 Medium The system is configured to allow remote desktop sharing through NetMeeting.
V-3480 Medium Media Player must be configured to prevent automatic checking for updates.
V-15666 Medium Windows Peer to Peer Networking
V-14258 Medium Search Companion will be prevented from automatically downloading content updates.
V-14259 Medium Prevent printing over HTTP.
V-14256 Medium Web Publishing and online ordering wizards prevented from downloading list of providers.
V-14257 Medium Windows Messenger prevented from collecting anonymous information.
V-14254 Medium Client computers required to authenticate for RPC communication.
V-14255 Medium File and Folder Publish to Web option unavailable.
V-14253 Medium Restrict unauthenticated RPC clients.
V-15684 Medium Windows Installer – IE Security Prompt
V-3349 Medium Windows Messenger (MSN Messenger, .NET messenger) is run at system startup.
V-3348 Medium The user is allowed to launch Windows Messenger (MSN Messenger, .NET Messenger).
V-1118 Medium Event log sizes do not meet minimum requirements.
V-4448 Medium Group Policy objects are not reprocessed if they have not changed.
V-4447 Medium The Terminal Server does not require secure RPC communication.
V-14229 Medium Audit of Backup and Restore Privileges is not turned off.
V-14228 Medium Auditing Access of Global System Objects must be turned off.
V-15669 Medium Prohibit Internet Connection Sharing
V-15667 Medium Prohibit Network Bridge in Windows
V-3666 Medium The system is not configured to meet the minimum requirement for session security for NTLM SSP based Servers.
V-1103 Medium User rights and advanced user rights settings do not meet minimum requirements.
V-1107 Medium Password uniqueness does not meet minimum requirements.
V-1105 Medium Minimum password age does not meet minimum requirements.
V-1104 Medium Maximum password age does not meet minimum requirements.
V-26483 Medium The Deny logon as a batch job user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems.
V-1113 Medium The built-in guest account is not disabled.
V-26484 Medium The Deny logon as a service user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems. No other groups or accounts must be assigned this right.
V-26485 Medium The Deny logon locally user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems.
V-1075 Low The system allows shutdown from the logon dialog box.
V-1174 Low Amount of idle time required before suspending a session is improperly set.
V-1173 Low The default permissions of Global system objects are not increased.
V-3375 Low Domain Controller authentication is not required to unlock the workstation.
V-1165 Low The computer account password is prevented from being reset.
V-1160 Low The unsigned driver installation behavior is improperly set.
V-1084 Low System pagefile is cleared upon shutdown.
V-1085 Low Floppy media devices are not allocated upon user logon.
V-11806 Low The system is configured to allow the display of the last user name on the logon screen.
V-1158 Low The Recovery Console SET command is enabled.
V-1150 Low The built-in Microsoft password filter is not enabled.
V-1151 Low Print driver installation privilege is not restricted to administrators.
V-1091 Low System halts once an event log has reached its maximum size.
V-1090 Low Caching of logon credentials is not limited.
V-3373 Low The maximum age for machine account passwords is not set to requirements.
V-26359 Low The Windows dialog box title for the legal banner must be configured.
V-15686 Low Windows Installer – Vendor Signed Updates
V-15687 Low Media Player – First Use Dialog Boxes
V-1148 Low Local users exist on a workstation in a domain.
V-1136 Low Users are not forcibly disconnected when logon hours expire.
V-15676 Low Order Prints Online
V-15675 Low Windows Registration Wizard
V-15673 Low Internet Connection Wizard ISP Downloads
V-15672 Low Event Viewer Events.asp Links
V-15671 Low Root Certificates Update
V-15670 Low Error Reporting - Display Error Notification
V-15680 Low Classic Logon
V-4438 Low TCP data retransmissions are not controlled.
V-4437 Low TCP connection response retransmissions are not controlled.
V-4111 Low The system is configured to redirect ICMP.
V-4108 Low The system does not generate an audit event when the audit log reaches a percent full threshold.
V-4109 Low The system is configured to allow dead gateway detection.
V-4113 Low The system is configured for a greater keep-alive time than recommended.
V-4112 Low The system is configured to detect and configure default gateway addresses.
V-4110 Low The system is configured to allow IP source routing.
V-4117 Low The system is configured to allow SYN attacks.
V-4116 Low The system is configured to allow name-release attacks.
V-4442 Low This check verifies that Windows is configured to have password protection take effect within a limited time frame when the screen saver becomes active.
V-16047 Low Built-in Admin Account Status
V-17373 Low Secure Removable Media – CD-ROM
V-1172 Low Users are not warned in advance that their passwords will expire.