Check: WN11-00-000150
Microsoft Windows 11 STIG:
WN11-00-000150
(in versions v2 r2 through v1 r1)
Title
Structured Exception Handling Overwrite Protection (SEHOP) must be enabled. (Cat I impact)
Discussion
Attackers are constantly looking for vulnerabilities in systems and applications. Structured Exception Handling Overwrite Protection (SEHOP) blocks exploits that use the Structured Exception Handling overwrite technique, a common buffer overflow attack.
Check Content
Verify SEHOP is turned on. If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SYSTEM\CurrentControlSet\Control\Session Manager\kernel\ Value Name: DisableExceptionChainValidation Value Type: REG_DWORD Value: 0x00000000 (0)
Fix Text
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "Enable Structured Exception Handling Overwrite Protection (SEHOP)" to "Enabled". This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
Additional Identifiers
Rule ID: SV-253284r958928_rule
Vulnerability ID: V-253284
Group Title: SRG-OS-000433-GPOS-00192
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002794 |
Develop an incident response plan. |
CCI-002824 |
Implement organization-defined controls to protect the system memory from unauthorized code execution. |