DCOM can be enabled by non-administrators

Risk Level: Low risk vulnerability  Low

Check or Attack Name: DCOM - permissions

Platforms: Windows NT
Description:

Permissions were found improperly set for the DCOM registry key. If enabled, DCOM may be used to remotely execute programs.

Remedy:

Avoid granting non-administrators write access to the Ole key in the Windows NT registry.

To restrict access, follow these steps:

  1. Open Registry Editor. From the Windows NT Start menu, select Run, type regedt32, and click OK.
  2. Go to the HKEY_LOCAL_MACHINE\Software\Microsoft\Ole key.
  3. From the Security menu, select Permissions to display the Registry Key Permissions dialog box.
  4. Remove write access from all non-Administrators.
References:

X-Force Logo
Know Your Risks