Check: 5.048
Win2k3 Audit:
5.048
(in version v6 r1.29)
Title
Terminal Services is not configured to allow only the original client to reconnect. (Cat II impact)
Discussion
This setting, which is located under the Sessions section of the Terminal Services configuration option, controls whether a different client may be used to resume a disconnected session. Only the original client should be able to resume a session to help prevent session hijacking.
Check Content
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Terminal Services -> Sessions “Allow Reconnection from Original Client Only” to “Enabled”.
Additional Identifiers
Rule ID: SV-29712r1_rule
Vulnerability ID: V-3459
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |