nsacyber / Windows-Secure-Host-Baseline

Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings. #nsacyber
Other
1.55k stars 287 forks source link

SEHOP not enforced #50

Open mlosapio opened 6 years ago

mlosapio commented 6 years ago

This STIG doesn't appear to be applied anywhere.

https://www.stigviewer.com/stig/windows_10/2016-11-03/finding/V-68849

It does flag on the compliance report:

FAILED WN10-00-000150: Structured Exception Handling Overwrite Protection (SEHOP) must be turned on.

cryps1s commented 6 years ago

Clarifying on this issue:

When attempting to use the SHB and subsequent compliance checks on a v1709 host, it returns a finding as listed above. This is due to the deprecation of EMET on v1709 and higher builds of W10.

The correct COA here would be to port over the EMET ruleset into exploit guard as a separate lgpo pack that can be applied to more modern versions of W10.

iadgovuser1 commented 6 years ago

Ultimately this will be resolved once we post materials for when the next SHB is out (soon).