WN10-EP-000310 - Windows 10 Kernel (Direct Memory Access) DMA Protection must be enabled.

Information

Kernel DMA Protection to protect PCs against drive-by Direct Memory Access (DMA) attacks using PCI hot plug devices connected to Thunderbolt(TM) 3 ports. Drive-by DMA attacks can lead to disclosure of sensitive information residing on a PC, or even injection of malware that allows attackers to bypass the lock screen or control PCs remotely.

Solution

Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Kernel DMA Protection >> 'Enumeration policy for external devices incompatible with Kernel DMA Protection' to 'Enabled' with 'Enumeration Policy' set to 'Block All'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_10_V3R4_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-4, CAT|II, CCI|CCI-001090, Rule-ID|SV-220902r958524_rule, STIG-ID|WN10-EP-000310, STIG-Legacy|SV-108661, STIG-Legacy|V-99557, Vuln-ID|V-220902

Plugin: Windows

Control ID: 5e764d48bb7461b7a7eb2051b4cd6932d1338630dc0b643a00d3580360579a74