[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-99666-0

Platform: cpe:/o:microsoft:windows_server_2019Date: (C)2022-11-22   (M)2023-07-04



The Maximum lifetime for user ticket policy setting determines the maximum amount of time (in hours) that a user's ticket-granting ticket can be used. When a user's ticket-granting ticket expires, a new one must be requested or the existing one must be renewed. The possible values for this Group Policy setting are: * A user-defined number of hours from 0 through 99,999 * Not defined. If the value for this policy setting is too high, users might be able to access network resources outside of their logon hours, or users whose accounts have been disabled might be able to continue to access network services by using valid service tickets that were issued before their account was disabled. If the value is set to 0, ticket-granting tickets never expire.


Parameter:

[Hours]


Technical Mechanism:

Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy\Maximum lifetime for user ticket

CCSS Severity:CCSS Metrics:
CCSS Score : 8.1Attack Vector: NETWORK
Exploit Score: 2.2Attack Complexity: HIGH
Impact Score: 5.9Privileges Required: NONE
Severity: HIGHUser Interaction: NONE
Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:85622


OVAL    1
oval:org.secpod.oval:def:85622
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_2019

© SecPod Technologies