WA000-WI6082 - The EnableNonUTF8 registry entry is not set properly.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Vulnerability Key: V0013715
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
UTF8 lets you represent characters of many languages in an encoded form. A period and a space are ASCII characters, but UTF8 also can
represent non-ASCII characters. Hackers can use this capability to submit content in a URL that can execute in the CPU by means of a
buffer overflow. The IIS 6.0 registry entry EnableNonUTF8 permits or denies UTF8.

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-10

Plugin: Windows

Control ID: e395a6fbbef359679ed29e01e6eebb829c1cb2f793b47d415d7d789322cb268a