| Vuln ID | Severity | Asset | STIG | Title | Status | Doc Status | Assigned To | Actions |
|---|---|---|---|---|---|---|---|---|
| V-218797 | CAT II | MONT-MB-002 | Microsoft IIS 10.0 Server Security Techn... | The IIS 10.0 web server must be reviewed on a regu... | - | |||
Check TextConsult with the System Administrator and review all of the IIS 10.0 and Operating System features installed. Determine if any features installed are no longer necessary for operation. If any utility programs, features, or modules are installed which are not necessary for operation, this is a finding. If any unnecessary Operating System features are installed, this is a finding. Fix TextRemove all utility programs, Operating System features, or modules installed that are not necessary for web server operation. Finding DetailsEvaluate-STIG 1.2507.5 (Scan-IIS10_0_Server_Checks) was unable to determine a Status but found the below configuration on 10/23/2025: ResultHash: 64C688BC1C9B1982AFFD18FC23E02FDD4F322D99 ~~~~~ The following Windows features are installed: FileAndStorage-Services File-Services FS-FileServer MSMQ MSMQ-Server MSMQ-Services NET-Framework-45-ASPNET NET-Framework-45-Core NET-Framework-45-Features NET-WCF-HTTP-Activation45 NET-WCF-MSMQ-Activation45 NET-WCF-Pipe-Activation45 NET-WCF-Services45 NET-WCF-TCP-Activation45 NET-WCF-TCP-PortSharing45 PowerShell PowerShell-ISE PowerShellRoot RPC-over-HTTP-Proxy RSAT RSAT-ADDS RSAT-ADDS-Tools RSAT-AD-Tools RSAT-Clustering RSAT-Clustering-CmdInterface RSAT-Clustering-Mgmt RSAT-Clustering-PowerShell RSAT-Feature-Tools RSAT-Role-Tools Server-Media-Foundation Storage-Services WAS WAS-Config-APIs WAS-Process-Model Web-App-Dev Web-Asp-Net45 Web-Basic-Auth Web-Client-Auth Web-Common-Http Web-Default-Doc Web-Digest-Auth Web-Dir-Browsing Web-Dyn-Compression Web-Filtering Web-Health Web-Http-Errors Web-Http-Logging Web-Http-Redirect Web-Http-Tracing Web-ISAPI-Ext Web-ISAPI-Filter Web-Lgcy-Mgmt-Console Web-Log-Libraries Web-Metabase Web-Mgmt-Compat Web-Mgmt-Console Web-Mgmt-Service Web-Mgmt-Tools Web-Net-Ext45 Web-Performance Web-Request-Monitor Web-Security Web-Server Web-Stat-Compression Web-Static-Content Web-WebServer Web-Windows-Auth Web-WMI Windows-Identity-Foundation WoW64-Support CommentsDocumentation
Source: _Reviewed/MONT-MB-002/Checklist/MONT-MB-002_IIS10Server_V3R4_20251023-152431.ckl
Scan Date: 2026-01-14T12:57:32.874734
Technology Area: Web Review
|
||||||||
| V-218797 | CAT II | MONT-DP-001 | Microsoft IIS 10.0 Server Security Techn... | The IIS 10.0 web server must be reviewed on a regu... | - | |||
Check TextConsult with the System Administrator and review all of the IIS 10.0 and Operating System features installed. Determine if any features installed are no longer necessary for operation. If any utility programs, features, or modules are installed which are not necessary for operation, this is a finding. If any unnecessary Operating System features are installed, this is a finding. Fix TextRemove all utility programs, Operating System features, or modules installed that are not necessary for web server operation. Finding DetailsEvaluate-STIG 1.2507.5 (Scan-IIS10_0_Server_Checks) was unable to determine a Status but found the below configuration on 10/23/2025: ResultHash: 774CC3055B80C5163C0500736DC8B27D15DDBC89 ~~~~~ The following Windows features are installed: BITS BITS-IIS-Ext FileAndStorage-Services File-Services FS-FileServer NET-Framework-45-Core NET-Framework-45-Features NET-WCF-Services45 NET-WCF-TCP-PortSharing45 PowerShell PowerShell-ISE PowerShellRoot RDC RSAT RSAT-Bits-Server RSAT-Feature-Tools Storage-Services Web-App-Dev Web-Common-Http Web-Default-Doc Web-Dir-Browsing Web-Filtering Web-Health Web-Http-Errors Web-Http-Logging Web-Http-Redirect Web-Http-Tracing Web-ISAPI-Ext Web-Log-Libraries Web-Metabase Web-Mgmt-Compat Web-Mgmt-Console Web-Mgmt-Tools Web-Performance Web-Request-Monitor Web-Security Web-Server Web-Stat-Compression Web-Static-Content Web-WebServer WoW64-Support Commentsdocumentation
Source: _Reviewed/MONT-DP-001/Checklist/MONT-DP-001_IIS10Server_V3R4_20251023-143809.ckl
Scan Date: 2026-01-14T12:57:35.201603
Technology Area: Web Review
|
||||||||