CCE-93075-0Platform: cpe:/o:microsoft:windows_server_2019 | Date: (C)2020-09-22 (M)2023-07-04 |
All Removable Storage: Allow direct access in remote sessions
This policy setting grants normal users direct access to removable storage devices in remote sessions.
If you enable this policy setting, remote users will be able to open direct handles to removable storage devices in remote sessions.
If you disable or do not configure this policy setting, remote users will not be able to open direct handles to removable storage devices in remote sessions.
Parameter:
[enable/disable]
Technical Mechanism:
(1) GPO: Computer ConfigurationAdministrative TemplatesSystemRemovable Storage Access!All Removable Storage: Allow direct access in remote sessions
(2) REG: HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindowsRemovableStorageDevices!AllowRemoteDASD
CCSS Severity: | CCSS Metrics: |
CCSS Score : 8.8 | Attack Vector: NETWORK |
Exploit Score: 2.8 | Attack Complexity: LOW |
Impact Score: 5.9 | Privileges Required: LOW |
Severity: HIGH | User Interaction: NONE |
Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | Scope: UNCHANGED |
| Confidentiality: HIGH |
| Integrity: HIGH |
| Availability: HIGH |
| |
References: Resource Id | Reference |
---|
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:56095 |