[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Ensure Turn On Virtualization Based Security: Kernel-mode Hardware-enforced Stack Protection is set to Enabled: Enabled in enforcement mode

ID: oval:org.secpod.oval:def:94689Date: (C)2023-11-22   (M)2023-11-22
Class: COMPLIANCEFamily: windows




This policy setting enables Hardware-enforced Stack Protection for kernel-mode code. Kernel-mode data stacks are hardened with hardware-based shadow stacks, which store intended return address targets to ensure that program control flow is not tampered. The recommended state for this setting is: Enabled: Enabled in enforcement mode.Fix:(1) GPO: Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Kernel-mode Hardware-enforced Stack Protection(2) REG: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard!ConfigureKernelShadowStacksLaunch

Platform:
Microsoft Windows 11
Reference:
CCE-97213-3
CCE    1
CCE-97213-3
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_11

© SecPod Technologies