WN10-EP-000310 - Windows 10 Kernel (Direct Memory Access) DMA Protection must be enabled.

Information

Kernel DMA Protection to protect PCs against drive-by Direct Memory Access (DMA) attacks using PCI hot plug devices connected to Thunderbolt(TM) 3 ports. Drive-by DMA attacks can lead to disclosure of sensitive information residing on a PC, or even injection of malware that allows attackers to bypass the lock screen or control PCs remotely.

Solution

Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Kernel DMA Protection >> 'Enumeration policy for external devices incompatible with Kernel DMA Protection' to 'Enabled' with 'Enumeration Policy' set to 'Block All'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_10_V3R2_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-4, CAT|II, CCI|CCI-001090, Rule-ID|SV-220902r958524_rule, STIG-ID|WN10-EP-000310, STIG-Legacy|SV-108661, STIG-Legacy|V-99557, Vuln-ID|V-220902

Plugin: Windows

Control ID: 2f9963f7db011fa9d5707078e2921429a1407c182ae93b44cc6249c0233a3b43