Check: 3.040
Windows XP STIG:
3.040
(in versions v6 r1.32 through v1 r0)
Title
Administrator automatic logon is enabled. (Cat I impact)
Discussion
This is a category 1 finding because it will directly log on to the system with administrator privileges when the machine is rebooted. This would give full access to any unauthorized individual who reboots the computer. By default this setting is not enabled. If this setting exists, it should be disabled. If this capability exists, the password may also be present in the registry, and must be removed.
Check Content
Analyze the system using the Security Configuration and Analysis snap-in. Expand the Security Configuration and Analysis tree view. Navigate to Local Policies -> Security Options. If the value for “MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)” is not set to “Disabled”, then this is a finding. The policy referenced configures the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ Value Name: AutoAdminLogon Type: REG_SZ Value: 0 Note: The Gold Disk will also check for the existence of the HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\defaultpassword value. If it exists this will also make this a finding.
Fix Text
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> “MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)” to “Disabled”.
Additional Identifiers
Rule ID: SV-1145r1_rule
Vulnerability ID: V-1145
Group Title: Disable Automatic Logon
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |