Windows NT registry opened remotely |
---|
Risk Level: | Low | Check or Attack Name: registry |
---|---|---|
Platforms: | Windows NT | |
Description: | The Windows NT registry may be opened by a remote user. This may indicate that permissions are not set properly, or that possibly the Guest account is enabled with network access rights. An attacker could alter file associations, permitting the introduction of a Trojan horse, or otherwise seriously compromise the machine. If the host running the scan is a trusted host, this may not indicate a vulnerability. Under Windows NT 4.0, registry access from the network can be denied completely. |
|
Remedy: | Restrict registry access or reset permissions (or both). To restrict registry access, follow these steps:
|
|
References: |
Know Your Risks |