[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-47753-9

Platform: cpe:/o:microsoft:windows_server_2016Date: (C)2022-09-02   (M)2023-07-04



This policy setting changes the operational behavior of the Responder network protocol driver.The Responder allows a computer to participate in Link Layer Topology Discovery requests so that it can be discovered and located on the network. It also allows a computer to participate in Quality-of-Service activities such as bandwidth estimation and network health analysis.If you enable this policy setting, additional options are available to fine-tune your selection. You may choose the "Allow operation while in domain" option to allow the Responder to operate on a network interface that's connected to a managed network. On the other hand, if a network interface is connected to an unmanaged network, you may choose the "Allow operation while in public network" and "Prohibit operation while in private network" options instead.If you disable or do not configure this policy setting, the default behavior for the Responder will apply.Fix:(1) GPO: Computer ConfigurationAdministrative TemplatesNetworkLink-Layer Topology DiscoveryTurn on Responder (RSPNDR) driver(2) REG: HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindowsLLTD!EnableRspndr(2) REG: HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindowsLLTD!AllowRspndrOnDomain(2) REG: HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindowsLLTD!AllowRspndrOnPublicNet


Parameter:

[enabled/disabled, enabled/disabled, enabled/disabled]


Technical Mechanism:

(1) GPO: Computer Configuration\Administrative Templates\Network\Link-Layer Topology Discovery\Turn on Responder (RSPNDR) driver (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\LLTD!EnableRspndr (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\LLTD!AllowRspndrOnDomain (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\LLTD!AllowRspndrOnPublicNet

CCSS Severity:CCSS Metrics:
CCSS Score : 3.7Attack Vector: NETWORK
Exploit Score: 2.2Attack Complexity: HIGH
Impact Score: 1.4Privileges Required: NONE
Severity: LOWUser Interaction: NONE
Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NScope: UNCHANGED
 Confidentiality: LOW
 Integrity: NONE
 Availability: NONE
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:83687


OVAL    1
oval:org.secpod.oval:def:83687
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_Server_2016

© SecPod Technologies