CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.5

Windows 11 MSS (Legacy): 12 Checks

Wartiva runs 12 checks for section 18.5, MSS (Legacy), of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 12 checks on this page

Ensure Automatic Logon Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: Automatic logon is enabled.

Checks whether automatic logon at startup is disabled.

This rule fails when autoAdminLogon is not false.

Rationale: Automatic logon lets anyone with physical access reach everything on the host and connected networks, and it stores the password in the registry in plaintext where it is remotely readable by Authenticated Users.

Impact: None; this is the default behavior.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (AutoAdminLogon) Enable Automatic Logon and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v AutoAdminLogon /t REG_SZ /d 0 /f
Framework mappings
  • CIS Controls v8: 3.11 Encrypt Sensitive Data at Rest
  • NIST SP 800-53 Rev. 5: AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
  • CMMC 2.0 Level 2: MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
  • PCI DSS v4.0.1: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Computer Ignores NetBIOS Name Release Requests Except From WINS Servers

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: Computer honors NetBIOS name release requests from any host.

Checks whether the host ignores NetBIOS name-release requests except those from WINS servers.

This rule fails when noNameReleaseOnDemand is not true.

Rationale: The unauthenticated NetBT protocol is easily spoofed; an attacker can send a name-conflict datagram to make a host relinquish its name, causing connectivity or logon failures.

Impact: None; this is the default behavior.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers and set it to Enabled.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters" /v NoNameReleaseOnDemand /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • NIST SP 800-53 Rev. 5: AC-18 Wireless Access; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan
  • NIST SP 800-171 Rev. 2: 3.4.4 Analyze the security impact of changes prior to implementation
  • CMMC 2.0 Level 2: CM.L2-3.4.4 Analyze the security impact of changes prior to implementation
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.4.2 Permit untrusted-to-trusted inbound traffic only to authorized public services; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
Risk
External Attack Surface
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure ICMP Redirects Cannot Override OSPF Generated Routes

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: ICMP redirects can override OSPF-generated routes.

Checks whether ICMP redirects are prevented from overriding OSPF-generated routes.

This rule fails when enableICMPRedirect is not false.

Rationale: ICMP-redirect-plumbed host routes temporarily override proper routing; ignoring such redirects limits exposure to attacks that disrupt the host's network participation.

Impact: Windows will not plumb host routes from received ICMP redirects.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes and set it to Disabled.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v EnableICMPRedirect /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
  • NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure IPv4 IP Source Routing Is Set To Highest Protection

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: IPv4 IP source routing is not set to highest protection.

Checks whether IPv4 source routing is completely disabled so all incoming source-routed packets are dropped.

This rule fails when disableIpSourceRouting is not ENABLED_HIGHEST_SOURCE_ROUTING_COMPLETELY_DISABLED.

Rationale: Source routing lets a sender dictate a packet's path, which an attacker can use to obscure their identity and location; completely disabling it drops such packets.

Impact: All incoming source-routed packets are dropped.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (DisableIPSourceRouting) IP source routing protection level and set it to Enabled: Highest protection, source routing is completely disabled.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v DisableIPSourceRouting /t REG_DWORD /d 2 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure IPv4 TCP Maximum Data Retransmissions Is Set To Three

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: IPv4 TCP maximum data retransmissions is not set to three.

Checks whether IPv4 TCP aborts a connection after three retransmissions of an unacknowledged data segment.

This rule fails when tcpMaxDataRetransmissionsIpv4 is not 3.

Rationale: Limiting retransmissions reduces the resources an attacker can tie up by never acknowledging data the host has sent.

Impact: An unacknowledged segment is retransmitted at most three times before the connection is aborted.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted and set it to Enabled: 3.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v TcpMaxDataRetransmissions /t REG_DWORD /d 3 /f
Framework mappings
  • CIS Controls v8: 4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • NIST SP 800-53 Rev. 5: AC-18 Wireless Access; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan
  • NIST SP 800-171 Rev. 2: 3.4.4 Analyze the security impact of changes prior to implementation
  • CMMC 2.0 Level 2: CM.L2-3.4.4 Analyze the security impact of changes prior to implementation
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.4.2 Permit untrusted-to-trusted inbound traffic only to authorized public services; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Ensure IPv6 IP Source Routing Is Set To Highest Protection

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: IPv6 IP source routing is not set to highest protection.

Checks whether IPv6 source routing is completely disabled so all incoming source-routed packets are dropped.

This rule fails when disableAutoSourceRouting is not ENABLED_HIGHEST_SOURCE_ROUTING_COMPLETELY_DISABLED.

Rationale: Source routing lets a sender dictate a packet's path, which an attacker can use to obscure their identity and location; completely disabling it drops such packets.

Impact: All incoming source-routed packets are dropped.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (DisableIPSourceRouting IPv6) IP source routing protection level and set it to Enabled: Highest protection, source routing is completely disabled.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v DisableIPSourceRouting /t REG_DWORD /d 2 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure IPv6 TCP Maximum Data Retransmissions Is Set To Three

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: IPv6 TCP maximum data retransmissions is not set to three.

Checks whether IPv6 TCP aborts a connection after three retransmissions of an unacknowledged data segment.

This rule fails when tcpMaxDataRetransmissionsIpv6 is not 3.

Rationale: Limiting retransmissions reduces the resources an attacker can tie up by never acknowledging data the host has sent.

Impact: An unacknowledged segment is retransmitted at most three times before the connection is aborted.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted and set it to Enabled: 3.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\TCPIP6\Parameters" /v TcpMaxDataRetransmissions /t REG_DWORD /d 3 /f
Framework mappings
  • CIS Controls v8: 4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • NIST SP 800-53 Rev. 5: AC-18 Wireless Access; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan
  • NIST SP 800-171 Rev. 2: 3.4.4 Analyze the security impact of changes prior to implementation
  • CMMC 2.0 Level 2: CM.L2-3.4.4 Analyze the security impact of changes prior to implementation
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.4.2 Permit untrusted-to-trusted inbound traffic only to authorized public services; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Ensure IRDP Router Discovery Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: IRDP router discovery is enabled.

Checks whether the Internet Router Discovery Protocol (IRDP) is disabled.

This rule fails when performRouterDiscovery is not false.

Rationale: An attacker on the same segment could impersonate a router via IRDP so that other hosts route traffic through the compromised machine.

Impact: Windows will not automatically detect and configure default gateway addresses.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses and set it to Disabled.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v PerformRouterDiscovery /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Safe DLL Search Mode Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: Safe DLL search mode is disabled.

Checks whether the DLL search order searches system paths before the current working directory.

This rule fails when safeDllSearchMode is not true.

Rationale: If the current directory is searched first, hostile code packaged with modified system DLLs can be loaded in place of the genuine libraries.

Impact: None; this is the default behavior.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (SafeDllSearchMode) Enable Safe DLL search mode and set it to Enabled.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" /v SafeDllSearchMode /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Saving Of Dial-up And VPN Passwords Is Prevented

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: Dial-up and VPN passwords can be saved.

Checks whether caching of dial-up and VPN connection passwords is prevented.

This rule fails when disableSavePassword is not true.

Rationale: A stolen device with a saved dial-up or VPN password could automatically connect to the organization's network.

Impact: Users cannot automatically store logon credentials for dial-up and VPN connections.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (DisableSavePassword) Prevent the dial-up password from being saved and set it to Enabled.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\RasMan\Parameters" /v DisableSavePassword /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
  • NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
  • NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Security Event Log Warning Threshold Is 90 Percent Or Less

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: Security event log warning threshold is unset or above 90 percent.

Checks whether a warning audit is generated when the Security event log reaches a threshold of 90 percent or less of its capacity.

This rule fails when eventLogWarningLevel is 0 (the non-compliant default, no warning) or greater than 90.

Rationale: Without a warning threshold, a full Security log can silently stop recording recent events, letting an attacker's activity go unlogged.

Impact: An audit event is generated when the Security log reaches the configured percentage full.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning and set it to Enabled: 90% or less.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security" /v WarningLevel /t REG_DWORD /d 90 /f
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure TCP Keep-Alive Time Is Set To Five Minutes

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.5

Finding: TCP keep-alive time is not set to five minutes.

Checks whether TCP verifies idle connections every 300,000 milliseconds (5 minutes) instead of the two-hour default.

This rule fails when keepAliveTime is not 300000000000 ns (300,000 ms / 5 minutes).

Rationale: A shorter keep-alive interval disconnects idle sessions more quickly, reducing the window in which an attacker could hold many connections open to cause a denial of service.

Impact: Applications that request TCP keep-alives will have idle sessions verified every five minutes.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MSS (Legacy) > MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds and set it to Enabled: 300,000 or 5 minutes.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v KeepAliveTime /t REG_DWORD /d 300000 /f
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)