[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-98043-3

Platform: cpe:/o:microsoft:windows_server_2022:::x64Date: (C)2022-06-07   (M)2023-07-04



Exclude files and paths from Attack Surface Reduction (ASR) rules. Enabled: Specify the folders or files and resources that should be excluded from ASR rules in the Options section. Enter each rule on a new line as a name-value pair: - Name column: Enter a folder path or a fully qualified resource name. For example, ""C:Windows"" will exclude all files in that directory. ""C:WindowsApp.exe"" will exclude only that specific file in that specific folder - Value column: Enter ""0"" for each item Disabled: No exclusions will be applied to the ASR rules. Not configured: Same as Disabled. You can configure ASR rules in the Configure Attack Surface Reduction rules GP setting. Fix: (1) GPO: Computer ConfigurationAdministrative TemplatesWindows ComponentsMicrosoft Defender AntivirusMicrosoft Defender Exploit GuardAttack Surface ReductionExclude files and paths from Attack Surface Reduction Rules (2) REG: HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindows DefenderWindows Defender Exploit GuardASR!ExploitGuard_ASR_ASROnlyExclusions


Parameter:

[enabled/disabled]


Technical Mechanism:

(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Microsoft Defender Exploit Guard\Attack Surface Reduction\Exclude files and paths from Attack Surface Reduction Rules (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR!ExploitGuard_ASR_ASROnlyExclusions

CCSS Severity:CCSS Metrics:
CCSS Score : 6.3Attack Vector: LOCAL
Exploit Score: 1.0Attack Complexity: HIGH
Impact Score: 5.2Privileges Required: LOW
Severity: MEDIUMUser Interaction: NONE
Vector: AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:HScope: UNCHANGED
 Confidentiality: NONE
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:81273


OVAL    1
oval:org.secpod.oval:def:81273
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_Server_2022

© SecPod Technologies