Check: WINER-000001
Windows Vista STIG:
WINER-000001
(in versions v6 r42 through v6 r41)
Title
The Windows Error Reporting Service must be running and configured to start automatically. (Cat II impact)
Discussion
Windows Error Reporting information can be used to help diagnose day-to-day software issues, as well as help discover malicious code and possibly zero-day attacks on systems.
Check Content
Verify the Start Type and Status of the Windows Error Reporting Service. Run "Services.msc". If the Windows Error Reporting Service does not have a Status of "Started" and a Start Type of "Automatic", this is a finding.
Fix Text
Configure the Start Type of the Windows Error Reporting Service to "Automatic" and ensure the service has a status of "Started".
Additional Identifiers
Rule ID: SV-71657r1_rule
Vulnerability ID: V-56511
Group Title: WINER-000001
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001312 |
The information system generates error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |