[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

User Account Control: Only elevate UIAccess applications that are installed in secure locations

ID: oval:org.secpod.oval:def:80841Date: (C)2022-06-06   (M)2023-12-12
Class: COMPLIANCEFamily: windows




This policy setting controls whether applications that request to run with a User Interface Accessibility (UIAccess) integrity level must reside in a secure location in the file system. Secure locations are limited to the following: - ...\Program Files\, including subfolders - ...\Windows\system32\ - ...\Program Files (x86)\, including subfolders for 64-bit versions of Windows Note: Windows enforces a public key infrastructure (PKI) signature check on any interactive application that requests to run with a UIAccess integrity level regardless of the state of this security setting. The options are: * Enabled: (Default) If an application resides in a secure location in the file system, it runs only with UIAccess integrity. * Disabled: An application runs with UIAccess integrity even if it does not reside in a secure location in the file system. Counter Measure: Enable the User Account Control: Only elevate UIAccess applications that are installed in secure locations setting. Potential Impact: If the application that requests UIAccess meets the UIAccess setting requirements, Windows Vista starts the application with the ability to bypass most of the UIPI restrictions. If the application does not meet the security restrictions, the application will be started without UIAccess rights and can interact only with applications at the same or lower privilege level. Fix: (1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Only elevate UIAccess applications that are installed in secure locations (2) REG: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System!EnableSecureUIAPaths

Platform:
Microsoft Windows Server 2022
Reference:
CCE-97568-0
CPE    1
cpe:/o:microsoft:windows_server_2022:::x64
CCE    1
CCE-97568-0
XCCDF    2
xccdf_org.secpod_benchmark_general_Windows_Server_2022
xccdf_org.secpod_benchmark_SecPod_Windows_Server_2022

© SecPod Technologies