Vulnerability ID Severity Description
V-254247 Medium Windows Server 2022 must be maintained at a supported servicing level
V-253263 High Windows 11 systems must be maintained at a supported servicing level
V-220911 Medium The built-in administrator account must be renamed
V-254448 Medium Windows Server 2022 built-in guest account must be renamed
V-205910 Medium Windows Server 2019 built-in guest account must be renamed
V-220912 Medium The built-in guest account must be renamed
V-253436 Medium The built-in guest account must be renamed
V-205908 High Windows Server 2019 must prevent local accounts with blank passwords from being used from the net...
V-254446 High Windows Server 2022 must prevent local accounts with blank passwords from being used from the net...
V-220910 Medium Local accounts with blank passwords must be restricted to prevent access from the network
V-253434 Medium Local accounts with blank passwords must be restricted to prevent access from the network
V-254342 Medium Windows Server 2022 must be configured to enable Remote host allows delegation of nonexportable c...
V-205863 Medium Windows Server 2019 must be configured to enable Remote host allows delegation of non-exportable ...
V-253368 Medium Windows 11 must be configured to enable Remote host allows delegation of non-exportable credentials
V-220810 Medium Windows 10 must be configured to enable Remote host allows delegation of non-exportable credentials
V-254376 Medium Windows Server 2022 must disable automatically signing in the last interactive user after a syste...
V-205925 Medium Windows Server 2019 must disable automatically signing in the last interactive user after a syste...
V-253413 Medium Automatically signing in the last interactive user after a system-initiated restart must be disabled
V-220859 Medium Automatically signing in the last interactive user after a system-initiated restart must be disabled
V-260469 High Ubuntu 22.04 LTS must disable the x86 Ctrl-Alt-Delete key sequence
V-253441 Low The computer account password must not be prevented from being reset
V-220917 Low The computer account password must not be prevented from being reset
V-254349 Medium Windows Server 2022 users must be prompted to authenticate when the system wakes from sleep (on b...
V-205867 Medium Windows Server 2019 users must be prompted to authenticate when the system wakes from sleep (on b...
V-254350 Medium Windows Server 2022 users must be prompted to authenticate when the system wakes from sleep (plug...
V-205868 Medium Windows Server 2019 users must be prompted to authenticate when the system wakes from sleep (plug...
V-254417 Medium Windows Server 2022 domain controllers must be configured to allow reset of machine account passw...
V-205876 Medium Windows Server 2019 domain controllers must be configured to allow reset of machine account passw...
V-254427 Medium The password for the krbtgt account on a domain must be reset at least every 180 days
V-205877 Medium The password for the krbtgt account on a domain must be reset at least every 180 days
V-254441 High Windows Server 2022 must be running Credential Guard on domain-joined member servers
V-205907 High Windows Server 2019 must be running Credential Guard on domain-joined member servers
V-253370 High Credential Guard must be running on Windows 11 domain-joined systems
V-220812 High Credential Guard must be running on Windows 10 domain-joined systems
V-253447 Low Caching of logon credentials must be limited
V-220923 Low Caching of logon credentials must be limited
V-254432 Medium Windows Server 2022 must limit the caching of logon credentials to four or less on domain-joined ...
V-205906 Medium Windows Server 2019 must limit the caching of logon credentials to four or less on domain-joined ...
V-254345 Medium Windows Server 2022 group policy objects must be reprocessed even if they have not changed
V-205866 Medium Windows Server 2019 group policy objects must be reprocessed even if they have not changed
V-253373 Medium Group Policy objects must be reprocessed even if they have not changed
V-220814 Medium Group Policy objects must be reprocessed even if they have not changed
V-254340 Medium Windows Server 2022 hardened Universal Naming Convention (UNC) paths must be defined to require m...
V-205862 Medium Windows Server 2019 hardened Universal Naming Convention (UNC) paths must be defined to require m...
V-253362 Medium Hardened UNC Paths must be defined to require mutual authentication and integrity for at least th...
V-250319 Medium Hardened UNC paths must be defined to require mutual authentication and integrity for at least th...
V-254454 Medium Windows Server 2022 maximum age for machine account passwords must be configured to 30 days or less
V-205911 Medium Windows Server 2019 maximum age for machine account passwords must be configured to 30 days or less
V-253442 Low The maximum age for machine account passwords must be configured to 30 days or less
V-220918 Low The maximum age for machine account passwords must be configured to 30 days or less
V-254476 Medium Windows Server 2022 must be configured to at least negotiate signing for LDAP client signing
V-205920 Medium Windows Server 2019 must be configured to at least negotiate signing for LDAP client signing
V-253463 Medium The system must be configured to the required LDAP client signing level
V-220939 Medium The system must be configured to the required LDAP client signing level
V-254364 Medium Windows Server 2022 File Explorer shell protocol must run in protected mode
V-205872 Medium Windows Server 2019 File Explorer shell protocol must run in protected mode
V-253398 Medium File Explorer shell protocol must run in protected mode
V-220839 Medium File Explorer shell protocol must run in protected mode
V-254248 Medium Windows Server 2022 must use an antivirus program
V-205850 High Windows Server 2019 must use an anti-virus program
V-253264 High The Windows 11 system must use an antivirus program
V-220707 High The Windows 10 system must use an anti-virus program
V-254344 Medium Windows Server 2022 Early Launch Antimalware, Boot-Start Driver Initialization Policy must preven...
V-205865 Medium Windows Server 2019 Early Launch Antimalware, Boot-Start Driver Initialization Policy must preven...
V-253372 Medium Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers
V-220813 Medium Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers
V-253281 Medium A host-based firewall must be installed and enabled on the system
V-220724 Medium A host-based firewall must be installed and enabled on the system
V-254370 Medium Windows Server 2022 must prevent attachments from being downloaded from RSS feeds
V-205873 Medium Windows Server 2019 must prevent attachments from being downloaded from RSS feeds
V-253407 Medium Attachments must be prevented from being downloaded from RSS feeds
V-220853 Medium Attachments must be prevented from being downloaded from RSS feeds
V-220844 Medium The Windows Defender SmartScreen filter for Microsoft Edge must be enabled
V-220841 Medium Users must not be allowed to ignore Windows Defender SmartScreen filter warnings for unverified f...
V-220840 Medium Users must not be allowed to ignore Windows Defender SmartScreen filter warnings for malicious we...
V-254466 High Windows Server 2022 must not allow anonymous enumeration of Security Account Manager (SAM) accounts
V-205914 High Windows Server 2019 must not allow anonymous enumeration of Security Account Manager (SAM) accounts
V-253453 High Anonymous enumeration of SAM accounts must not be allowed
V-220929 High Anonymous enumeration of SAM accounts must not be allowed
V-254339 Medium Windows Server 2022 insecure logons to an SMB server must be disabled
V-205861 Medium Windows Server 2019 insecure logons to an SMB server must be disabled
V-253360 Medium Insecure logons to an SMB server must be disabled
V-220802 Medium Insecure logons to an SMB server must be disabled
V-254475 High Windows Server 2022 LAN Manager authentication level must be configured to send NTLMv2 response o...
V-205919 High Windows Server 2019 LAN Manager authentication level must be configured to send NTLMv2 response o...
V-253462 High The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM
V-220938 High The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM
V-254468 Medium Windows Server 2022 must be configured to prevent anonymous users from having the same permission...
V-205915 Medium Windows Server 2019 must be configured to prevent anonymous users from having the same permission...
V-253455 Medium The system must be configured to prevent anonymous users from having the same rights as the Every...
V-254471 Medium Windows Server 2022 must prevent NTLM from falling back to a Null session
V-205917 Medium Windows Server 2019 must prevent NTLM from falling back to a Null session
V-253458 Medium NTLM must be prevented from falling back to a Null session
V-220934 Medium NTLM must be prevented from falling back to a Null session
V-254470 Medium Windows Server 2022 services using Local System that use Negotiate when reverting to NTLM authent...
V-205916 Medium Windows Server 2019 services using Local System that use Negotiate when reverting to NTLM authent...
V-254477 Medium Windows Server 2022 session security for NTLM SSP-based clients must be configured to require NTL...
V-205921 Medium Windows Server 2019 session security for NTLM SSP-based clients must be configured to require NTL...
V-254478 Medium Windows Server 2022 session security for NTLM SSP-based servers must be configured to require NTL...
V-205922 Medium Windows Server 2019 session security for NTLM SSP-based servers must be configured to require NTL...
V-254335 Low Windows Server 2022 Internet Protocol version 6 (IPv6) source routing must be configured to the h...
V-205858 Low Windows Server 2019 Internet Protocol version 6 (IPv6) source routing must be configured to the h...
V-253353 Medium IPv6 source routing must be configured to highest protection
V-220795 Medium IPv6 source routing must be configured to highest protection
V-254336 Low Windows Server 2022 source routing must be configured to the highest protection level to prevent ...
V-205859 Low Windows Server 2019 source routing must be configured to the highest protection level to prevent ...
V-205869 Medium Windows Server 2019 Telemetry must be configured to Security or Basic
V-220834 Medium Windows Telemetry must not be configured to Full