[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-47766-1

Platform: cpe:/o:microsoft:windows_server_2016Date: (C)2022-09-02   (M)2023-07-04



Specifies that link local multicast name resolution (LLMNR) is disabled on client computers.LLMNR is a secondary name resolution protocol. With LLMNR, queries are sent using multicast over a local network link on a single subnet from a client computer to another client computer on the same subnet that also has LLMNR enabled. LLMNR does not require a DNS server or DNS client configuration, and provides name resolution in scenarios in which conventional DNS name resolution is not possible.If you enable this policy setting, LLMNR will be disabled on all available network adapters on the client computer.If you disable this policy setting, or you do not configure this policy setting, LLMNR will be enabled on all available network adapters.Fix:(1) GPO: Computer ConfigurationAdministrative TemplatesNetworkDNS ClientTurn off multicast name resolution(2) REG: HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindows NTDNSClient!EnableMulticast


Parameter:

[enabled/disabled]


Technical Mechanism:

(1) GPO: Computer Configuration\Administrative Templates\Network\DNS Client\Turn off multicast name resolution (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DNSClient!EnableMulticast

CCSS Severity:CCSS Metrics:
CCSS Score : 6.5Attack Vector: NETWORK
Exploit Score: 2.2Attack Complexity: HIGH
Impact Score: 4.2Privileges Required: NONE
Severity: MEDIUMUser Interaction: NONE
Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:HScope: UNCHANGED
 Confidentiality: LOW
 Integrity: NONE
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:83700


OVAL    1
oval:org.secpod.oval:def:83700
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_Server_2016

© SecPod Technologies