1.2 Remote Data Services (RDS) - 'HKLM\System\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\VbBusObj.VbBusObjCls'

Information

2. Remove the registry key located in HKLM\System\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\V bBusObj.VbBusObjCls. A vulnerability in this feature led to the development of the virii and worms such as Code Red and Nimda.

Solution

Make sure the registry item located in 'HKLM\System\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch' does not exist (delete the key VbBusObj.VbBusObjCls)

See Also

https://workbench.cisecurity.org/files/657

Item Details

Audit Name: CIS IIS 6.0 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CCE|CCE-19384-7, CSCv6|9.1

Plugin: Windows

Control ID: c2f4cd005f98dd66fe8c9ba163791e82be3cde805d48d21d439e0d3164176247