Check: 5.048
Windows 2003 DC STIG:
5.048
(in version v6 r40)
Title
Terminal Services is not configured to allow only the original client to reconnect. (Cat II impact)
Discussion
This setting, which is located under the Sessions section of the Terminal Services configuration option, controls whether a different client may be used to resume a disconnected session. Only the original client should be able to resume a session to help prevent session hijacking.
Check Content
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Terminal Services -> Sessions “Allow Reconnection from Original Client Only” to “Enabled”.
Additional Identifiers
Rule ID: SV-29712r1_rule
Vulnerability ID: V-3459
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
CM-6 |
Configuration Settings |