5.5 Ensure 'GameInput Service (GameInputSvc)' is set to 'Disabled'

Information

This service enables the use of keyboards, mice, gamepads, and other input devices to be used with the GameInput API.

The recommended state for this setting is: Disabled.

Note: GameInput service runs as LocalSystem in its own process of GameInputSvc.exe and doesn't share its process with other services.

GameInput API pipes input from keyboards, mice, gamepads, and other game controllers via Direct Memory Access (DMA) to decrease latency for gaming performance. This DMA use increases the risk of input data (especially keystrokes) being captured by a threat actor.

Solution

To establish the recommended configuration via GP, set the following UI path to: Disabled.

Computer Configuration\Policies\Windows Settings\Security Settings\System Services\GameInput Service

Impact:

Input devices will not be able to utilize the GameInput API.

See Also

https://workbench.cisecurity.org/benchmarks/26296

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 9a0a81b6b3efb3d860b44d2394d00593ee367e351b3c381fd5370c2509da38f8