[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-99668-6

Platform: cpe:/o:microsoft:windows_server_2019Date: (C)2022-11-22   (M)2023-07-04



Determines whether the Kerberos Key Distribution Center (KDC) validates every request for a session ticket against the user rights policy of the target computer. Validation of each request for a session ticket is optional because the extra step takes time and may slow network access to services. By default, this setting is enabled in the Default Domain Group Policy object (GPO). When this policy is enabled, the user requesting the session ticket must have the right to Log on locally (if the requested service is running on the same machine) or the right to Access this computer from the network (if the requested service is on a remote machine) in order to receive a session ticket. If the policy is disabled, this check is not performed.


Parameter:

[enable/disable]


Technical Mechanism:

Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy\Enforce user logon restrictions

CCSS Severity:CCSS Metrics:
CCSS Score : 7.5Attack Vector: NETWORK
Exploit Score: 1.6Attack Complexity: HIGH
Impact Score: 5.9Privileges Required: LOW
Severity: HIGHUser Interaction: NONE
Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:85623


OVAL    1
oval:org.secpod.oval:def:85623
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_2019

© SecPod Technologies