WA000-WI6092 - The PercentUAllowed registry entry is not set properly.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Vulnerability Key: V0013720
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
If PercentUAllowed is non-zero, Http.sys accepts the %uNNNN notation in request URLs. Allowing this type of notation opens
the web server to encoding attacks.

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-10

Plugin: Windows

Control ID: cfdd716caeb2ae2621692fcac8e6b6059f6614c15b77864e4cb81172c8e91fa0