Nessus Report

Report generated by Tenable Nessus™

Server 2

Mon, 12 Jan 2026 19:02:59 India Standard Time

TABLE OF CONTENTS
Vulnerabilities by HostExpand All | Collapse All
172.17.100.112
49
186
53
2
1916
Critical
High
Medium
Low
Info
Scan Information
Start time: Mon Jan 12 17:57:56 2026
End time: Mon Jan 12 18:36:08 2026
Host Information
Netbios Name: MIDDLEWAREAPI
IP: 172.17.100.112
MAC Address: 00:50:56:BC:7D:2B
OS: Microsoft Windows Server 2019 Datacenter Build 17763
Vulnerabilities

172177 - .NET Core SDK SEoL
-
Synopsis
An unsupported version of .NET Core SDK is installed on the remote host.
Description
According to its version, the .NET Core SDK installed on the remote host is no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of .NET Core SDK that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/03/07, Modified: 2023/03/07
Plugin Output

tcp/0


Path : C:\\program files\dotnet\\sdk\1.1.0
Installed version : 1.1.0
Security End of Life : June 26, 2019
Time since Security End of Life (Est.) : >= 6 years

tcp/0


Path : C:\\program files\dotnet\\sdk\7.0.400
Installed version : 7.0.400
Security End of Life : May 13, 2024
Time since Security End of Life (Est.) : >= 1 year
172178 - ASP.NET Core SEoL
-
Synopsis
An unsupported version of ASP.NET Core is installed on the remote host.
Description
According to its version, the ASP.NET Core installed on the remote host is no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of ASP.NET Core that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/03/07, Modified: 2023/03/07
Plugin Output

tcp/0


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\6.0.25
Installed version : 6.0.25
Security End of Life : November 12, 2024
Time since Security End of Life (Est.) : >= 1 year

tcp/0


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\7.0.10
Installed version : 7.0.10
Security End of Life : May 13, 2024
Time since Security End of Life (Est.) : >= 1 year

tcp/0


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\6.0.25
Installed version : 6.0.25
Security End of Life : November 12, 2024
Time since Security End of Life (Est.) : >= 1 year

tcp/0


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\7.0.10
Installed version : 7.0.10
Security End of Life : May 13, 2024
Time since Security End of Life (Est.) : >= 1 year

156860 - Apache Log4j 1.x Multiple Vulnerabilities
-
Synopsis
A logging library running on the remote host has multiple vulnerabilities.
Description
According to its self-reported version number, the installation of Apache Log4j on the remote host is 1.x and is no longer supported. Log4j reached its end of life prior to 2016. Additionally, Log4j 1.x is affected by multiple vulnerabilities, including :

- Log4j includes a SocketServer that accepts serialized log events and deserializes them without verifying whether the objects are allowed or not. This can provide an attack vector that can be exploited. (CVE-2019-17571)

- Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. (CVE-2020-9488)

- JMSSink uses JNDI in an unprotected manner allowing any application using the JMSSink to be vulnerable if it is configured to reference an untrusted site or if the site referenced can be accesseed by the attacker.
(CVE-2022-23302)

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Apache Log4j that is currently supported.

Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4904
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2019-17571
CVE CVE-2020-9488
CVE CVE-2022-23302
CVE CVE-2022-23305
CVE CVE-2022-23307
CVE CVE-2023-26464
XREF CEA-ID:CEA-2021-0004
XREF CEA-ID:CEA-2021-0025
XREF IAVA:2021-A-0573
Plugin Information
Published: 2022/01/19, Modified: 2024/06/13
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17

tcp/445/cifs


Path : C:\Program Files\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17

182252 - Apache Log4j SEoL (<= 1.x)
-
Synopsis
An unsupported version of Apache Log4j is installed on the remote host.
Description
According to its version, Apache Log4j is less than or equal to 1.x. It is, therefore, no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Apache Log4j that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/09/29, Modified: 2023/11/02
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17
Security End of Life : August 4, 2015
Time since Security End of Life (Est.) : >= 10 years

tcp/0


Path : C:\Program Files\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17
Security End of Life : August 4, 2015
Time since Security End of Life (Est.) : >= 10 years

182865 - KB5031361: Windows 10 version 1809 / Windows Server 2019 Security Update (October 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5031361. It is, therefore, affected by multiple vulnerabilities

- The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. (CVE-2023-44487)
- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2023-36577)

- Windows IIS Server Elevation of Privilege Vulnerability (CVE-2023-36434)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5031361
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.9443
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-29348
CVE CVE-2023-35349
CVE CVE-2023-36431
CVE CVE-2023-36434
CVE CVE-2023-36436
CVE CVE-2023-36438
CVE CVE-2023-36557
CVE CVE-2023-36563
CVE CVE-2023-36564
CVE CVE-2023-36567
CVE CVE-2023-36570
CVE CVE-2023-36571
CVE CVE-2023-36572
CVE CVE-2023-36573
CVE CVE-2023-36574
CVE CVE-2023-36575
CVE CVE-2023-36576
CVE CVE-2023-36577
CVE CVE-2023-36578
CVE CVE-2023-36579
CVE CVE-2023-36581
CVE CVE-2023-36582
CVE CVE-2023-36583
CVE CVE-2023-36584
CVE CVE-2023-36585
CVE CVE-2023-36589
CVE CVE-2023-36590
CVE CVE-2023-36591
CVE CVE-2023-36592
CVE CVE-2023-36593
CVE CVE-2023-36594
CVE CVE-2023-36596
CVE CVE-2023-36598
CVE CVE-2023-36602
CVE CVE-2023-36603
CVE CVE-2023-36605
CVE CVE-2023-36606
CVE CVE-2023-36697
CVE CVE-2023-36698
CVE CVE-2023-36701
CVE CVE-2023-36702
CVE CVE-2023-36703
CVE CVE-2023-36704
CVE CVE-2023-36706
CVE CVE-2023-36707
CVE CVE-2023-36709
CVE CVE-2023-36710
CVE CVE-2023-36711
CVE CVE-2023-36712
CVE CVE-2023-36713
CVE CVE-2023-36717
CVE CVE-2023-36718
CVE CVE-2023-36720
CVE CVE-2023-36721
CVE CVE-2023-36722
CVE CVE-2023-36723
CVE CVE-2023-36724
CVE CVE-2023-36725
CVE CVE-2023-36726
CVE CVE-2023-36729
CVE CVE-2023-36731
CVE CVE-2023-36732
CVE CVE-2023-36743
CVE CVE-2023-36776
CVE CVE-2023-36902
CVE CVE-2023-38159
CVE CVE-2023-38166
CVE CVE-2023-41765
CVE CVE-2023-41766
CVE CVE-2023-41767
CVE CVE-2023-41768
CVE CVE-2023-41769
CVE CVE-2023-41770
CVE CVE-2023-41771
CVE CVE-2023-41772
CVE CVE-2023-41773
CVE CVE-2023-41774
CVE CVE-2023-44487
MSKB 5031361
XREF MSFT:MS23-5031361
XREF IAVA:2023-A-0552-S
XREF IAVA:2023-A-0553-S
XREF CISA-KNOWN-EXPLOITED:2023/12/07
XREF CISA-KNOWN-EXPLOITED:2023/10/31
XREF CEA-ID:CEA-2024-0004
XREF IAVB:2023-B-0083-S
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/10/10, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5031361

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.4974
185579 - KB5032196: Windows 10 version 1809 / Windows Server 2019 Security Update (November 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5032196. It is, therefore, affected by multiple vulnerabilities

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2023-36402)

- Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability (CVE-2023-36397)

- Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability (CVE-2023-36028)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5032196
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.9021
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-24023
CVE CVE-2023-36017
CVE CVE-2023-36025
CVE CVE-2023-36028
CVE CVE-2023-36033
CVE CVE-2023-36036
CVE CVE-2023-36047
CVE CVE-2023-36392
CVE CVE-2023-36393
CVE CVE-2023-36394
CVE CVE-2023-36395
CVE CVE-2023-36397
CVE CVE-2023-36398
CVE CVE-2023-36400
CVE CVE-2023-36401
CVE CVE-2023-36402
CVE CVE-2023-36403
CVE CVE-2023-36404
CVE CVE-2023-36405
CVE CVE-2023-36408
CVE CVE-2023-36423
CVE CVE-2023-36424
CVE CVE-2023-36425
CVE CVE-2023-36427
CVE CVE-2023-36428
CVE CVE-2023-36705
CVE CVE-2023-36719
CVE CVE-2023-38039
CVE CVE-2023-38545
CVE CVE-2024-21315
MSKB 5032196
XREF MSFT:MS23-5032196
XREF CISA-KNOWN-EXPLOITED:2023/12/05
XREF CEA-ID:CEA-2023-0052
XREF IAVA:2023-A-0638-S
XREF IAVA:2023-A-0636-S
XREF IAVA:2024-A-0105
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/11/14, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5032196

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.5122
202028 - KB5040430: Windows 10 version 1809 / Windows Server 2019 Security Update (July 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5040430. It is, therefore, affected by multiple vulnerabilities

- RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen- prefix collision attack against MD5 Response Authenticator signature. (CVE-2024-3596)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5040430
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.9286
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-3596
CVE CVE-2024-21417
CVE CVE-2024-28899
CVE CVE-2024-30013
CVE CVE-2024-30071
CVE CVE-2024-30079
CVE CVE-2024-30081
CVE CVE-2024-30098
CVE CVE-2024-35270
CVE CVE-2024-37969
CVE CVE-2024-37970
CVE CVE-2024-37971
CVE CVE-2024-37972
CVE CVE-2024-37973
CVE CVE-2024-37974
CVE CVE-2024-37975
CVE CVE-2024-37981
CVE CVE-2024-37984
CVE CVE-2024-37986
CVE CVE-2024-37987
CVE CVE-2024-37988
CVE CVE-2024-37989
CVE CVE-2024-38010
CVE CVE-2024-38011
CVE CVE-2024-38013
CVE CVE-2024-38015
CVE CVE-2024-38017
CVE CVE-2024-38019
CVE CVE-2024-38022
CVE CVE-2024-38025
CVE CVE-2024-38027
CVE CVE-2024-38028
CVE CVE-2024-38030
CVE CVE-2024-38031
CVE CVE-2024-38033
CVE CVE-2024-38034
CVE CVE-2024-38041
CVE CVE-2024-38043
CVE CVE-2024-38044
CVE CVE-2024-38047
CVE CVE-2024-38048
CVE CVE-2024-38049
CVE CVE-2024-38050
CVE CVE-2024-38051
CVE CVE-2024-38052
CVE CVE-2024-38053
CVE CVE-2024-38054
CVE CVE-2024-38055
CVE CVE-2024-38056
CVE CVE-2024-38057
CVE CVE-2024-38058
CVE CVE-2024-38060
CVE CVE-2024-38061
CVE CVE-2024-38062
CVE CVE-2024-38064
CVE CVE-2024-38065
CVE CVE-2024-38066
CVE CVE-2024-38067
CVE CVE-2024-38068
CVE CVE-2024-38069
CVE CVE-2024-38070
CVE CVE-2024-38071
CVE CVE-2024-38072
CVE CVE-2024-38073
CVE CVE-2024-38074
CVE CVE-2024-38076
CVE CVE-2024-38077
CVE CVE-2024-38079
CVE CVE-2024-38085
CVE CVE-2024-38091
CVE CVE-2024-38099
CVE CVE-2024-38100
CVE CVE-2024-38101
CVE CVE-2024-38102
CVE CVE-2024-38104
CVE CVE-2024-38105
CVE CVE-2024-38112
CVE CVE-2024-38517
CVE CVE-2024-39684
MSKB 5040430
XREF MSFT:MS24-5040430
XREF CISA-KNOWN-EXPLOITED:2024/07/30
XREF IAVA:2024-A-0408-S
XREF IAVA:2024-A-0407-S
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/07/09, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5040430

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.6054
205461 - KB5041578: Windows 10 version 1809 / Windows Server 2019 Security Update (August 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5041578. It is, therefore, affected by multiple vulnerabilities

- An elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS) including a subset of Azure Virtual Machine SKUS. This can allow an attacker with administrator privileges to replace current versions of Windows system files with outdated versions. By exploiting this vulnerability, an attacker could reintroduce previously mitigated vulnerabilities, circumvent some features of VBS, and exfiltrate data protected by VBS. (CVE-2024-21302)

- A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism. (CVE-2022-2601)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5041578
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.9006
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/08/13, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5041578

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.6189
206898 - KB5043050: Windows 10 version 1809 / Windows Server 2019 Security Update (September 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5043050. It is, therefore, affected by multiple vulnerabilities

- Windows MSHTML Platform Spoofing Vulnerability (CVE-2024-43461)

- Windows Remote Desktop Licensing Service Spoofing Vulnerability (CVE-2024-43455)

- Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability (CVE-2024-38260, CVE-2024-38263, CVE-2024-43454, CVE-2024-43467)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5043050
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.2639
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/09/10, Modified: 2025/10/22
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5043050

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.6292
208285 - KB5044277: Windows 10 version 1809 / Windows Server 2019 Security Update (October 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5044277. It is, therefore, affected by multiple vulnerabilities

- libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances. (CVE-2024-6197)
- Remote Desktop Client Remote Code Execution Vulnerability (CVE-2024-43599)

- An unauthenticated attacker could send a specially crafted protocol message to a Routing and Remote Access Service (RRAS) server, which could lead to remote code execution (RCE) on the RAS server machine.
(CVE-2024-43607)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5044277
Risk Factor
Critical
CVSS v3.0 Base Score
9.0 (CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.6 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.5847
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-6197
CVE CVE-2024-20659
CVE CVE-2024-30092
CVE CVE-2024-37976
CVE CVE-2024-37979
CVE CVE-2024-37982
CVE CVE-2024-37983
CVE CVE-2024-38124
CVE CVE-2024-38149
CVE CVE-2024-38202
CVE CVE-2024-38212
CVE CVE-2024-38261
CVE CVE-2024-38262
CVE CVE-2024-38265
CVE CVE-2024-43453
CVE CVE-2024-43456
CVE CVE-2024-43501
CVE CVE-2024-43502
CVE CVE-2024-43506
CVE CVE-2024-43509
CVE CVE-2024-43511
CVE CVE-2024-43512
CVE CVE-2024-43513
CVE CVE-2024-43514
CVE CVE-2024-43515
CVE CVE-2024-43516
CVE CVE-2024-43517
CVE CVE-2024-43518
CVE CVE-2024-43519
CVE CVE-2024-43520
CVE CVE-2024-43521
CVE CVE-2024-43523
CVE CVE-2024-43524
CVE CVE-2024-43525
CVE CVE-2024-43526
CVE CVE-2024-43528
CVE CVE-2024-43532
CVE CVE-2024-43534
CVE CVE-2024-43535
CVE CVE-2024-43536
CVE CVE-2024-43537
CVE CVE-2024-43538
CVE CVE-2024-43540
CVE CVE-2024-43541
CVE CVE-2024-43542
CVE CVE-2024-43543
CVE CVE-2024-43544
CVE CVE-2024-43545
CVE CVE-2024-43547
CVE CVE-2024-43549
CVE CVE-2024-43550
CVE CVE-2024-43551
CVE CVE-2024-43553
CVE CVE-2024-43554
CVE CVE-2024-43555
CVE CVE-2024-43556
CVE CVE-2024-43557
CVE CVE-2024-43558
CVE CVE-2024-43559
CVE CVE-2024-43560
CVE CVE-2024-43561
CVE CVE-2024-43562
CVE CVE-2024-43563
CVE CVE-2024-43564
CVE CVE-2024-43565
CVE CVE-2024-43567
CVE CVE-2024-43570
CVE CVE-2024-43572
CVE CVE-2024-43573
CVE CVE-2024-43575
CVE CVE-2024-43581
CVE CVE-2024-43582
CVE CVE-2024-43583
CVE CVE-2024-43585
CVE CVE-2024-43589
CVE CVE-2024-43592
CVE CVE-2024-43593
CVE CVE-2024-43599
CVE CVE-2024-43607
CVE CVE-2024-43608
CVE CVE-2024-43611
CVE CVE-2024-43615
MSKB 5044277
XREF MSFT:MS24-5044277
XREF CISA-KNOWN-EXPLOITED:2024/10/29
XREF IAVA:2024-A-0628
XREF IAVA:2024-A-0631-S
XREF IAVA:2024-A-0630-S
Plugin Information
Published: 2024/10/08, Modified: 2024/11/18
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5044277

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.6414
210860 - KB5046615: Windows 10 version 1809 / Windows Server 2019 Security Update (November 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5046615. It is, therefore, affected by multiple vulnerabilities

- Windows Kerberos Remote Code Execution Vulnerability (CVE-2024-43639)

- Windows NT OS Kernel Elevation of Privilege Vulnerability (CVE-2024-43623)

- Windows Telephony Service Elevation of Privilege Vulnerability (CVE-2024-43626)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5046615
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
10.0
EPSS Score
0.9039
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/11/12, Modified: 2025/01/23
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5046615

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.6530
249130 - KB5063877: Windows 10 version 1809 / Windows Server 2019 Security Update (August 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5063877. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
(CVE-2025-53766)

- Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. (CVE-2025-49751)

- Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. (CVE-2025-49743)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5063877
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.017
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5063877

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.7671
270378 - KB5066586: Windows 10 version 1809 / Windows Server 2019 Security Update (October 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5066586. It is, therefore, affected by multiple vulnerabilities

- tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka Predictor heap-buffer-overflow. (CVE-2016-9535)

- In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. (CVE-2025-47827)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5066586
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0824
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
6.2 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2016-9535
CVE CVE-2025-24052
CVE CVE-2025-24990
CVE CVE-2025-25004
CVE CVE-2025-47827
CVE CVE-2025-48813
CVE CVE-2025-49708
CVE CVE-2025-50152
CVE CVE-2025-50175
CVE CVE-2025-53150
CVE CVE-2025-53768
CVE CVE-2025-54957
CVE CVE-2025-55325
CVE CVE-2025-55326
CVE CVE-2025-55328
CVE CVE-2025-55332
CVE CVE-2025-55333
CVE CVE-2025-55335
CVE CVE-2025-55336
CVE CVE-2025-55338
CVE CVE-2025-55678
CVE CVE-2025-55679
CVE CVE-2025-55680
CVE CVE-2025-55681
CVE CVE-2025-55683
CVE CVE-2025-55687
CVE CVE-2025-55692
CVE CVE-2025-55695
CVE CVE-2025-55696
CVE CVE-2025-55699
CVE CVE-2025-55700
CVE CVE-2025-55701
CVE CVE-2025-58714
CVE CVE-2025-58715
CVE CVE-2025-58716
CVE CVE-2025-58717
CVE CVE-2025-58718
CVE CVE-2025-58719
CVE CVE-2025-58720
CVE CVE-2025-58722
CVE CVE-2025-58725
CVE CVE-2025-58726
CVE CVE-2025-58728
CVE CVE-2025-58729
CVE CVE-2025-58730
CVE CVE-2025-58732
CVE CVE-2025-58733
CVE CVE-2025-58734
CVE CVE-2025-58735
CVE CVE-2025-58736
CVE CVE-2025-58737
CVE CVE-2025-58738
CVE CVE-2025-58739
CVE CVE-2025-59184
CVE CVE-2025-59185
CVE CVE-2025-59186
CVE CVE-2025-59187
CVE CVE-2025-59188
CVE CVE-2025-59190
CVE CVE-2025-59191
CVE CVE-2025-59192
CVE CVE-2025-59193
CVE CVE-2025-59195
CVE CVE-2025-59196
CVE CVE-2025-59197
CVE CVE-2025-59198
CVE CVE-2025-59199
CVE CVE-2025-59200
CVE CVE-2025-59201
CVE CVE-2025-59202
CVE CVE-2025-59203
CVE CVE-2025-59204
CVE CVE-2025-59205
CVE CVE-2025-59207
CVE CVE-2025-59208
CVE CVE-2025-59209
CVE CVE-2025-59211
CVE CVE-2025-59214
CVE CVE-2025-59230
CVE CVE-2025-59242
CVE CVE-2025-59244
CVE CVE-2025-59253
CVE CVE-2025-59254
CVE CVE-2025-59255
CVE CVE-2025-59258
CVE CVE-2025-59259
CVE CVE-2025-59260
CVE CVE-2025-59275
CVE CVE-2025-59277
CVE CVE-2025-59278
CVE CVE-2025-59280
CVE CVE-2025-59282
CVE CVE-2025-59294
CVE CVE-2025-59295
MSKB 5066586
XREF MSFT:MS25-5066586
XREF CISA-KNOWN-EXPLOITED:2025/11/04
XREF IAVA:2025-A-0775-S
XREF IAVA:2025-A-0776-S
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5066586

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.7919

172179 - Microsoft .NET Core SEoL
-
Synopsis
An unsupported version of Microsoft .NET Core is installed on the remote host.
Description
According to its version, the Microsoft .NET Core installed on the remote host is no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Microsoft .NET Core that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/03/07, Modified: 2023/03/07
Plugin Output

tcp/0


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Security End of Life : November 12, 2024
Time since Security End of Life (Est.) : >= 1 year

tcp/0


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NetCore.App\7.0.10\
Installed version : 7.0.10.32713
Security End of Life : May 13, 2024
Time since Security End of Life (Est.) : >= 1 year

tcp/0


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\1.0.5\
Installed version : 1.0.5
Security End of Life : June 26, 2019
Time since Security End of Life (Est.) : >= 6 years

tcp/0


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\1.1.2\
Installed version : 1.1.2
Security End of Life : June 26, 2019
Time since Security End of Life (Est.) : >= 6 years

tcp/0


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Security End of Life : November 12, 2024
Time since Security End of Life (Est.) : >= 1 year

tcp/0


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.10\
Installed version : 7.0.10.32713
Security End of Life : May 13, 2024
Time since Security End of Life (Est.) : >= 1 year

270707 - Microsoft ASP.NET Core Security Feature Bypass (October 2025)
-
Synopsis
The remote Windows host is affected by a security feature bypass vulnerability.
Description
The version of ASP.NET Core installed on the remote Windows host is 8.0.x prior to 8.0.21, 9.0.x prior to 9.0.10, or 10.0.0-rc.1.25451.107. It is, therefore, affected by a security feature bypass vulnerability.
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core to version 8.0.21, 9.0.10, 10.0.0-rc.2.25502.107 or later.
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L)
VPR Score
10.0
EPSS Score
0.0004
CVSS v2.0 Base Score
8.7 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:P)
STIG Severity
I
References
CVE CVE-2025-55315
XREF IAVA:2025-A-0753
Plugin Information
Published: 2025/10/17, Modified: 2025/10/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\8.0.0
Installed version : 8.0.0
Fixed version : 8.0.21

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\8.0.0
Installed version : 8.0.0
Fixed version : 8.0.21

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\8.0.7
Installed version : 8.0.7
Fixed version : 8.0.21
56998 - Microsoft Office Unsupported Version Detection
-
Synopsis
The remote host contains an unsupported version of Microsoft Office.
Description
According to its version, the installation of Microsoft Office on the remote Windows host is no longer supported.
Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Microsoft Office that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
References
XREF IAVA:0001-A-0503
Plugin Information
Published: 2011/12/02, Modified: 2024/03/22
Plugin Output

tcp/445/cifs


Installed product : Office 2010
End of support date : October 13, 2020
Supported versions : Office 2016, 2019, 2021 or Office 365
64784 - Microsoft SQL Server Unsupported Version Detection
-
Synopsis
An unsupported version of a database server is running on the remote host.
Description
According to its self-reported version number, the installation of Microsoft SQL Server on the remote host is no longer supported.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Microsoft SQL Server that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
References
XREF IAVA:0001-A-0560
Plugin Information
Published: 2013/02/21, Modified: 2025/10/30
Plugin Output

tcp/445/cifs


The following unsupported installations of Microsoft SQL Server were
detected :

Installed version : 13.0.4001.0 Express Edition
Install path : C:\Program Files\Microsoft SQL Server\130\LocalDB\Binn\
Instance : MSSQL13E.LOCALDB
Minimum supported version : 13.0.6300.2 (2016 SP3)
179692 - Node.js 16.x < 16.20.2 / 18.x < 18.17.1 / 20.x < 20.5.1 Multiple Vulnerabilities (Wednesday August 09 2023 Security Releases).
-
Synopsis
Node.js - JavaScript run-time environment is affected by multiple vulnerabilities.
Description
The version of Node.js installed on the remote host is prior to 16.20.2, 18.17.1, 20.5.1. It is, therefore, affected by multiple vulnerabilities as referenced in the Wednesday August 09 2023 Security Releases advisory:

- Permissions policies can be bypassed via Module._load (CVE-2023-32002)

- Permission model bypass by specifying a path traversal sequence in a Buffer (CVE-2023-32004)

- process.binding() can bypass the permission model through path traversal (CVE-2023-32558)

- Permissions policies can impersonate other modules in using module.constructor.createRequire() (CVE-2023-32006)

- Permissions policies can be bypassed via process.binding (CVE-2023-32559)

- fs.statfs can retrive stats from files restricted by the Permission Model (CVE-2023-32005)

- fs.mkdtemp() and fs.mkdtempSync() are missing getValidatedPath() checks (CVE-2023-32003)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Node.js version 16.20.22 / 18.17.1 / 20.5.1 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0103
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2023/08/11, Modified: 2024/01/09
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\nodejs\
Installed version : 18.16.1
Fixed version : 18.17.1
183390 - Node.js 18.x < 18.18.2 / 20.x < 20.8.1 Multiple Vulnerabilities (Friday October 13 2023 Security Releases).
-
Synopsis
Node.js - JavaScript run-time environment is affected by multiple vulnerabilities.
Description
The version of Node.js installed on the remote host is prior to 18.18.2, 20.8.1. It is, therefore, affected by multiple vulnerabilities as referenced in the Friday October 13 2023 Security Releases advisory.

- Undici did not always clear Cookie headers on cross-origin redirects. By design, cookie headers are forbidden request headers, disallowing them to be set in RequestInit.headers in browser environments.
Since undici handles headers more liberally than the spec, there was a disconnect from the assumptions the spec made, and undici's implementation of fetch. As such this may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd party site. More details area available in GHSA-wqq4-5wpv-mx2g (CVE-2023-45143)

- Rapidly creating and cancelling streams (HEADERS frame immediately followed by RST_STREAM) without bound causes denial of service. See https://www.cve.org/CVERecord?id=CVE-2023-44487 for details. Impacts:
(CVE-2023-44487)

- A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations. Impacts: Please note that at the time this CVE is issued, the permission model is an experimental feature of Node.js. Thanks to Tobias Nieen who reported and created the security patch. (CVE-2023-39331)

- Various node:fs functions allow specifying paths as either strings or Uint8Array objects. In Node.js environments, the Buffer class extends the Uint8Array class. Node.js prevents path traversal through strings (see CVE-2023-30584) and Buffer objects (see CVE-2023-32004), but not through non-Buffer Uint8Array objects. This is distinct from CVE-2023-32004 (report 2038134), which only referred to Buffer objects. However, the vulnerability follows the same pattern using Uint8Array instead of Buffer. Impacts:
Please note that at the time this CVE is issued, the permission model is an experimental feature of Node.js. Thanks to Tobias Nieen who reported and created the security patch. (CVE-2023-39332)

- When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to node's policy implementation, thus effectively disabling the integrity check. Impacts: Please note that at the time this CVE is issued, the policy mechanism is an experimental feature of Node.js. Thanks to Tobias Nieen who reported and created the security patch. (CVE-2023-38552)

- Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebAssembly module was a JavaScript module. Impacts: Thanks to dittyroma for reporting the issue and to Tobias Nieen for fixing it. (CVE-2023-39333)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Node.js version 18.18.2 / 20.8.1 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.9
EPSS Score
0.9443
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-38552
CVE CVE-2023-39331
CVE CVE-2023-39332
CVE CVE-2023-39333
CVE CVE-2023-44487
CVE CVE-2023-45143
XREF CISA-KNOWN-EXPLOITED:2023/10/31
XREF CEA-ID:CEA-2024-0004
XREF IAVB:2023-B-0083-S
Plugin Information
Published: 2023/10/19, Modified: 2024/02/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\nodejs\
Installed version : 18.16.1
Fixed version : 18.18.2
190856 - Node.js 18.x < 18.19.1 / 20.x < 20.11.1 / 21.x < 21.6.2 Multiple Vulnerabilities (Wednesday February 14 2024 Security Releases).
-
Synopsis
Node.js - JavaScript run-time environment is affected by multiple vulnerabilities.
Description
The version of Node.js installed on the remote host is prior to 18.19.1, 20.11.1, 21.6.2. It is, therefore, affected by multiple vulnerabilities as referenced in the Wednesday February 14 2024 Security Releases advisory.

- On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges with the only exception of CAP_NET_BIND_SERVICE. Due to a bug in the implementation of this exception, Node.js incorrectly applies this exception even when certain other capabilities have been set. This allows unprivileged users to inject code that inherits the process's elevated privileges. Impacts: Thank you, to Tobias Nieen for reporting this vulnerability and for fixing it. (CVE-2024-21892)

- A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits. Impacts: Thank you, to Bartek Nowotarski for reporting this vulnerability and thank you Paolo Insogna for fixing it. (CVE-2024-22019)

- The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer, the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals, namely, Buffer.prototype.utf8Write, the application can modify the result of path.resolve(), which leads to a path traversal vulnerability. Impacts: Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js. Thank you, to Tobias Nieen for reporting this vulnerability and for fixing it. (CVE-2024-21896)

- setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid().
This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). Impacts: Thank you, to valette for reporting this vulnerability and thank you Tobias Nieen for fixing it. (CVE-2024-22017)

- A vulnerability in the privateDecrypt() API of the crypto library, allowed a covert timing side-channel during PKCS#1 v1.5 padding error handling. The vulnerability revealed significant timing differences in decryption for valid and invalid ciphertexts. This poses a serious threat as attackers could remotely exploit the vulnerability to decrypt captured RSA ciphertexts or forge signatures, especially in scenarios involving API endpoints processing Json Web Encryption messages. Impacts: Thank you, to hkario for reporting this vulnerability and thank you Michael Dawson for fixing it. (CVE-2023-46809)

- Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission model bypass through path traversal attack. Impacts: Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js. Thank you, to xion for reporting this vulnerability and thank you Rafael Gonzaga for fixing it. (CVE-2024-21891)

- The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. For example: --allow-fs-read=/home/node/.ssh/*.pub will ignore pub and give access to everything after .ssh/. Impacts: Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js. Thank you, to Tobias Nieen for reporting this vulnerability and thank you Rafael Gonzaga for fixing it. (CVE-2024-21890)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Node.js version 18.19.1 / 20.11.1 / 21.6.2 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.1041
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/02/21, Modified: 2025/04/03
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\nodejs\
Installed version : 18.16.1
Fixed version : 18.19.1
234624 - Oracle Java SE Multiple Vulnerabilities (April 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the April 2025 CPU advisory.

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX (gstreamer)). Supported versions that are affected are Oracle Java SE: 8u441, 8u441-perf; Oracle GraalVM Enterprise Edition: 20.3.17 and 21.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2024-47606)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u441; Oracle GraalVM Enterprise Edition: 20.3.17 and 21.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2024-54534)

- Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.14 and 21.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GraalVM for JDK executes to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GraalVM for JDK accessible data as well as unauthorized access to critical data or complete access to all Oracle GraalVM for JDK accessible data. (CVE-2025-23083)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the April 2025 Oracle Critical Patch Update advisory.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0067
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/04/18, Modified: 2025/08/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jdk-17\
Installed version : 17.0.12 / build 17.0.12
Fixed version : Upgrade to version 17.0.15 or greater
242293 - Oracle Java SE Multiple Vulnerabilities (July 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the July 2025 CPU advisory.

- Vulnerability in Oracle Java SE (component: JavaFX (libxml2)). Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. (CVE-2024-40896)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and 24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. (CVE-2025-30749)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and 24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2025-50059)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the July 2025 Oracle Critical Patch Update advisory.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0023
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/07/18, Modified: 2025/10/30
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jdk-17\
Installed version : 17.0.12 / build 17.0.12
Fixed version : Upgrade to version 17.0.16 or greater
187859 - Security Update for Microsoft .NET Core (January 2024)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the 2024_Jan_09 advisory.

- NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability (CVE-2024-0057)

- .NET Denial of Service Vulnerability (CVE-2024-20672)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0864
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-0057
CVE CVE-2024-20672
XREF IAVA:2024-A-0017-S
Plugin Information
Published: 2024/01/10, Modified: 2024/02/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Fixed version : 6.0.26

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.1

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NetCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.15

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Fixed version : 6.0.26

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.15

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.1
187901 - Security Updates for Microsoft .NET Framework (January 2024)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by multiple vulnerabilities, as follows:

- Denial of service vulnerability in Microsoft .NET Framework. (CVE-2023-36042, CVE-2024-21312)

- Security feature bypass in System.Data.SqlClient SQL data provider. An attacker can perform a man-in-the-middle attack on the connection between the client and server in order to read and modify the TLS traffic. (CVE-2024-0056)

- Security feature bypass in applications that use the X.509 chain building APIs. When processing an untrusted certificate with malformed signatures, the framework returns an incorrect reason code.
Applications which make use of this reason code may treat this scenario as a successful chain build, potentially bypassing the application's typical authentication logic. (CVE-2024-0057)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.0864
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36042
CVE CVE-2024-0056
CVE CVE-2024-0057
CVE CVE-2024-21312
MSKB 5033898
MSKB 5033899
MSKB 5033904
MSKB 5033907
MSKB 5033909
MSKB 5033910
MSKB 5033911
MSKB 5033912
MSKB 5033914
MSKB 5033916
MSKB 5033917
MSKB 5033918
MSKB 5033919
MSKB 5033920
MSKB 5033922
MSKB 5033945
MSKB 5033946
MSKB 5033947
MSKB 5033948
XREF MSFT:MS24-5033898
XREF MSFT:MS24-5033899
XREF MSFT:MS24-5033904
XREF MSFT:MS24-5033907
XREF MSFT:MS24-5033909
XREF MSFT:MS24-5033910
XREF MSFT:MS24-5033911
XREF MSFT:MS24-5033912
XREF MSFT:MS24-5033914
XREF MSFT:MS24-5033916
XREF MSFT:MS24-5033917
XREF MSFT:MS24-5033918
XREF MSFT:MS24-5033919
XREF MSFT:MS24-5033920
XREF MSFT:MS24-5033922
XREF MSFT:MS24-5033945
XREF MSFT:MS24-5033946
XREF MSFT:MS24-5033947
XREF MSFT:MS24-5033948
XREF IAVA:2024-A-0011-S
Plugin Information
Published: 2024/01/10, Modified: 2024/03/29
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5033911

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.web.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4690.0

185887 - Security Updates for Microsoft .NET Framework (November 2023)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by multiple vulnerabilities, as follows:

- Security feature bypass in ASP.NET. An attacker can bypass the security checks that prevents an attacker from accessing internal applications in a website. (CVE-2023-36560)

- Privilege escalation vulnerability in FTP component of .NET Framework. An attacker can inject arbitrary commands to the FTP server. (CVE-2023-36049)

- Information disclosure vulnerability in .NET Framework. An attacker can obtain the ObjRef URI which could lead to remote code execution. (CVE-2024-29059
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.9385
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36049
CVE CVE-2023-36560
CVE CVE-2024-29059
MSKB 5031984
MSKB 5031987
MSKB 5031988
MSKB 5031989
MSKB 5031990
MSKB 5031991
MSKB 5031993
MSKB 5031995
MSKB 5031999
MSKB 5032000
MSKB 5032004
MSKB 5032005
MSKB 5032006
MSKB 5032007
MSKB 5032008
MSKB 5032009
MSKB 5032010
MSKB 5032011
MSKB 5032012
XREF MSFT:MS23-5031984
XREF MSFT:MS23-5031987
XREF MSFT:MS23-5031988
XREF MSFT:MS23-5031989
XREF MSFT:MS23-5031990
XREF MSFT:MS23-5031991
XREF MSFT:MS23-5031993
XREF MSFT:MS23-5031995
XREF MSFT:MS23-5031999
XREF MSFT:MS23-5032000
XREF MSFT:MS23-5032004
XREF MSFT:MS23-5032005
XREF MSFT:MS23-5032006
XREF MSFT:MS23-5032007
XREF MSFT:MS23-5032008
XREF MSFT:MS23-5032009
XREF MSFT:MS23-5032010
XREF MSFT:MS23-5032011
XREF MSFT:MS23-5032012
XREF IAVA:2023-A-0618-S
XREF IAVA:2024-A-0178-S
XREF CISA-KNOWN-EXPLOITED:2025/02/25
Plugin Information
Published: 2023/11/16, Modified: 2025/02/04
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5031990

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.web.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4682.0

207065 - Security Updates for Microsoft SQL Server Elevation of Privilege (September 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is affected by the following vulnerabilities:

- An elevation of privilege vulnerability. An authenticated, remote attacker can exploit this issue, to gain elevated privileges. (CVE-2024-37341, CVE-2024-37965, CVE-2024-37980)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.076
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-37341
CVE CVE-2024-37965
CVE CVE-2024-37980
MSKB 5042207
MSKB 5042209
MSKB 5042578
MSKB 5042749
MSKB 5042211
MSKB 5042215
MSKB 5042214
MSKB 5042217
XREF MSFT:MS24-5042207
XREF MSFT:MS24-5042209
XREF MSFT:MS24-5042578
XREF MSFT:MS24-5042749
XREF MSFT:MS24-5042211
XREF MSFT:MS24-5042215
XREF MSFT:MS24-5042214
XREF MSFT:MS24-5042217
XREF IAVA:2024-A-0565-S
Plugin Information
Published: 2024/09/12, Modified: 2025/01/08
Plugin Output

tcp/445/cifs



KB : 5042214
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2120.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
187806 - Security Updates for Microsoft Visual Studio Products (January 2024)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability (CVE-2023-29356, CVE-2023-32025, CVE-2023-32026, CVE-2023-32027)

- NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability (CVE-2024-0057)

- Visual Studio Elevation of Privilege Vulnerability (CVE-2024-20656)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.59 for Visual Studio 2017
- Update 16.11.33 for Visual Studio 2019
- Update 17.2.23 for Visual Studio 2022
- Update 17.4.15 for Visual Studio 2022
- Update 17.6.11 for Visual Studio 2022
- Update 17.8.4 for Visual Studio 2022
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.5702
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/01/09, Modified: 2025/11/24
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.34407.156 (15.9.59)

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.34408.163 (17.8.4)
197296 - Security Updates for Microsoft Visual Studio Products (May 2024)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- Recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution. (CVE-2024-32002)

- Remote Code Execution while cloning special-crafted local repositories. (CVE-2024-32004)

- A Remote Code Execution vulnerability exists in .NET 7.0 and .NET 8.0 where a stack buffer overrun occurs in .NET Double Parse routine. (CVE-2024-30045)

- A Vulnerability exists in Microsoft.AspNetCore.Server.Kestrel.Core.dll where a dead-lock can occur resulting in Denial of Service. (CVE-2024-30046)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.62 for Visual Studio 2017
- Update 16.11.36 for Visual Studio 2019
- Update 17.4.19 for Visual Studio 2022
- Update 17.6.15 for Visual Studio 2022
- Update 17.8.10 for Visual Studio 2022
- Update 17.9.7 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
9.0 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.1 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.7959
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-30045
CVE CVE-2024-30046
CVE CVE-2024-32002
CVE CVE-2024-32004
XREF IAVA:2024-A-0287-S
Plugin Information
Published: 2024/05/17, Modified: 2024/06/14
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.34830.200 (15.9.62)

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.34902.127 (17.8.10)
210895 - Security Updates for Microsoft Visual Studio Products (November 2024)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- A remote unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to a .NET vulnerable webapp or loading a specially crafted file into a vulnerable application. (CVE-2024-43498)
- The NrbfDecoder component in .NET 9 contains a denial of service vulnerability due to incorrect input validation. (CVE-2024-43499)

- Elevation of Privilege Vulnerability in Visual Studio C++ Redistributable Installer (CVE-2024-43590)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.6.20 for Visual Studio 2022
- Update 17.8.15 for Visual Studio 2022
- Update 17.10.8 for Visual Studio 2022
- Update 17.11.5 for Visual Studio 2022
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0548
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-43498
CVE CVE-2024-43499
CVE CVE-2024-49044
CVE CVE-2024-49050
CVE CVE-2024-49049
XREF IAVA:2024-A-0734-S
XREF IAVA:2024-A-0726-S
Plugin Information
Published: 2024/11/13, Modified: 2025/01/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.35430.204 (17.8.16)

156103 - Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104)
-
Synopsis
A package installed on the remote host is affected by a remote code execution vulnerability.
Description
The version of Apache Log4j on the remote host is 1.2. It is, therefore, affected by a remote code execution vulnerability when specifically configured to use JMSAppender.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life.

Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.722
CVSS v2.0 Base Score
6.0 (CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-4104
XREF IAVA:2021-A-0573
XREF IAVA:0001-A-0650
Plugin Information
Published: 2021/12/15, Modified: 2024/06/13
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17
Fixed version : 2.16.0

tcp/0


Path : C:\Program Files\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17
Fixed version : 2.16.0

181409 - Curl 7.84 <= 8.2.1 Header DoS (CVE-2023-38039)
-
Synopsis
The remote Windows host has a program that is affected by a denial of service vulnerability.
Description
The version of Curl installed on the remote host is affected by a denial of service vulnerability due to accepting and storing unlimited large headers.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade Curl to version 8.3.0 or later
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.7 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1447
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
6.1 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-38039
XREF IAVA:2023-A-0485-S
Plugin Information
Published: 2023/09/14, Modified: 2024/10/07
Plugin Output

tcp/445/cifs


Path : c:\windows\system32\curl.exe
Installed version : 8.0.1.0
Fixed version : 8.3.0

tcp/445/cifs


Path : c:\windows\syswow64\curl.exe
Installed version : 8.0.1.0
Fixed version : 8.3.0
181303 - KB5030214: Windows 10 version 1809 / Windows Server 2019 Security Update (September 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5030214. It is, therefore, affected by multiple vulnerabilities

- Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability (CVE-2023-35355)

- DHCP Server Service Denial of Service Vulnerability (CVE-2023-38162)

- Windows GDI Elevation of Privilege Vulnerability (CVE-2023-36804, CVE-2023-38161)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5030214
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.7891
CVSS v2.0 Base Score
8.3 (CVSS2#AV:A/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.2 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-35355
CVE CVE-2023-36801
CVE CVE-2023-36802
CVE CVE-2023-36803
CVE CVE-2023-36804
CVE CVE-2023-36805
CVE CVE-2023-38139
CVE CVE-2023-38140
CVE CVE-2023-38141
CVE CVE-2023-38142
CVE CVE-2023-38143
CVE CVE-2023-38144
CVE CVE-2023-38147
CVE CVE-2023-38149
CVE CVE-2023-38152
CVE CVE-2023-38160
CVE CVE-2023-38161
CVE CVE-2023-38162
MSKB 5030214
XREF MSFT:MS23-5030214
XREF CISA-KNOWN-EXPLOITED:2023/10/03
XREF IAVA:2023-A-0472-S
XREF IAVA:2023-A-0471-S
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/09/12, Modified: 2024/10/23
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5030214

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.4851
186789 - KB5033371: Windows 10 version 1809 / Windows Server 2019 Security Update (December 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5033371. It is, therefore, affected by multiple vulnerabilities

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2023-36006)

- Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability (CVE-2023-36696)

- Win32k Elevation of Privilege Vulnerability (CVE-2023-36011)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5033371
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.3857
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/12/12, Modified: 2025/10/31
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5033371

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.5202
187803 - KB5034127: Windows 10 version 1809 / Windows Server 2019 Security Update (January 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5034127. It is, therefore, affected by multiple vulnerabilities

- Microsoft ODBC Driver Remote Code Execution Vulnerability (CVE-2024-20654)

- BitLocker Security Feature Bypass Vulnerability (CVE-2024-20666)

- Windows Kerberos Security Feature Bypass Vulnerability (CVE-2024-20674)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5034127
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.5194
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/01/09, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5034127

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.5328
190482 - KB5034768: Windows 10 version 1809 / Windows Server 2019 Security Update (February 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5034768. It is, therefore, affected by multiple vulnerabilities

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2024-21350, CVE-2024-21352, CVE-2024-21358, CVE-2024-21359, CVE-2024-21360, CVE-2024-21361, CVE-2024-21365, CVE-2024-21366, CVE-2024-21367, CVE-2024-21368, CVE-2024-21369, CVE-2024-21370, CVE-2024-21375, CVE-2024-21391, CVE-2024-21420)

- Windows Kernel Elevation of Privilege Vulnerability (CVE-2024-21338, CVE-2024-21371)

- Windows Kernel Information Disclosure Vulnerability (CVE-2024-21340)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5034768
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.9377
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/02/13, Modified: 2025/10/09
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5034768

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.5458
191938 - KB5035849: Windows 10 version 1809 / Windows Server 2019 Security Update (March 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5035849. It is, therefore, affected by multiple vulnerabilities

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2024-21441, CVE-2024-21444, CVE-2024-21450, CVE-2024-26161, CVE-2024-26166)

- Windows USB Hub Driver Remote Code Execution Vulnerability (CVE-2024-21429)

- Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability (CVE-2024-21430)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5035849
Risk Factor
Critical
CVSS v3.0 Base Score
8.1 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.3458
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/03/12, Modified: 2025/10/22
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5035849

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.5576
193091 - KB5036896: Windows 10 version 1809 / Windows Server 2019 Security Update (April 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5036896. It is, therefore, affected by multiple vulnerabilities

- SmartScreen Prompt Security Feature Bypass Vulnerability (CVE-2024-29988)

- Secure Boot Security Feature Bypass Vulnerability (CVE-2024-20669, CVE-2024-26168, CVE-2024-26171, CVE-2024-26175, CVE-2024-26180, CVE-2024-26189, CVE-2024-26194, CVE-2024-26240, CVE-2024-26250, CVE-2024-28896, CVE-2024-28897, CVE-2024-28898, CVE-2024-28903, CVE-2024-28919, CVE-2024-28920, CVE-2024-28921, CVE-2024-28922, CVE-2024-28923, CVE-2024-28924, CVE-2024-28925, CVE-2024-29061, CVE-2024-29062)

- Windows rndismp6.sys Remote Code Execution Vulnerability (CVE-2024-26252, CVE-2024-26253)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5036896
Risk Factor
Critical
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.8317
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-20665
CVE CVE-2024-20669
CVE CVE-2024-20678
CVE CVE-2024-20693
CVE CVE-2024-23593
CVE CVE-2024-23594
CVE CVE-2024-26158
CVE CVE-2024-26168
CVE CVE-2024-26171
CVE CVE-2024-26172
CVE CVE-2024-26175
CVE CVE-2024-26179
CVE CVE-2024-26180
CVE CVE-2024-26183
CVE CVE-2024-26189
CVE CVE-2024-26194
CVE CVE-2024-26195
CVE CVE-2024-26200
CVE CVE-2024-26202
CVE CVE-2024-26205
CVE CVE-2024-26207
CVE CVE-2024-26208
CVE CVE-2024-26209
CVE CVE-2024-26210
CVE CVE-2024-26211
CVE CVE-2024-26212
CVE CVE-2024-26214
CVE CVE-2024-26215
CVE CVE-2024-26216
CVE CVE-2024-26217
CVE CVE-2024-26218
CVE CVE-2024-26219
CVE CVE-2024-26220
CVE CVE-2024-26221
CVE CVE-2024-26222
CVE CVE-2024-26223
CVE CVE-2024-26224
CVE CVE-2024-26226
CVE CVE-2024-26227
CVE CVE-2024-26228
CVE CVE-2024-26229
CVE CVE-2024-26230
CVE CVE-2024-26231
CVE CVE-2024-26232
CVE CVE-2024-26233
CVE CVE-2024-26234
CVE CVE-2024-26237
CVE CVE-2024-26239
CVE CVE-2024-26240
CVE CVE-2024-26241
CVE CVE-2024-26242
CVE CVE-2024-26244
CVE CVE-2024-26248
CVE CVE-2024-26250
CVE CVE-2024-26252
CVE CVE-2024-26253
CVE CVE-2024-26254
CVE CVE-2024-26255
CVE CVE-2024-28896
CVE CVE-2024-28897
CVE CVE-2024-28898
CVE CVE-2024-28900
CVE CVE-2024-28901
CVE CVE-2024-28902
CVE CVE-2024-28903
CVE CVE-2024-28919
CVE CVE-2024-28920
CVE CVE-2024-28921
CVE CVE-2024-28922
CVE CVE-2024-28923
CVE CVE-2024-28924
CVE CVE-2024-28925
CVE CVE-2024-29050
CVE CVE-2024-29056
CVE CVE-2024-29061
CVE CVE-2024-29062
CVE CVE-2024-29064
CVE CVE-2024-29066
CVE CVE-2024-29988
MSKB 5036896
XREF MSFT:MS24-5036896
XREF CISA-KNOWN-EXPLOITED:2024/05/21
XREF IAVA:2024-A-0227-S
XREF IAVA:2024-A-0228-S
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/04/09, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5036896

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.5696
197006 - KB5037765: Windows 10 version 1809 / Windows Server 2019 Security Update (May 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5037765 or 5039705. It is, therefore, affected by multiple vulnerabilities

- Windows MSHTML Platform Security Feature Bypass Vulnerability (CVE-2024-30040)

- Windows Common Log File System Driver Elevation of Privilege Vulnerability (CVE-2024-29996, CVE-2024-30025, CVE-2024-30037)

- Windows Mobile Broadband Driver Remote Code Execution Vulnerability (CVE-2024-29997, CVE-2024-29998, CVE-2024-29999, CVE-2024-30000, CVE-2024-30001, CVE-2024-30002, CVE-2024-30003, CVE-2024-30004, CVE-2024-30005, CVE-2024-30012, CVE-2024-30021)

Due to issues with the originally published patch (KB5037765), Microsoft has released KB5039705 as an Out-of-Bounds (OOB) patch.
While the OOB patch does not include any new security fixes relative to KB5037765, it may be required if KB5037765 fails to install.
Please review the links provided in the See Also section for additional guidance.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5037765 or 5039705
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.5191
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2024/05/14, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5037765
- 5039705

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.5820
200349 - KB5039217: Windows 10 version 1809 / Windows Server 2019 Security Update (June 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5039217. It is, therefore, affected by multiple vulnerabilities

- Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability (CVE-2024-30097)

- Windows Remote Access Connection Manager Information Disclosure Vulnerability (CVE-2024-30069)

- DHCP Server Service Denial of Service Vulnerability (CVE-2024-30070)

- Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability (CVE-2024-30080)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5039217
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.8897
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-50868
CVE CVE-2024-30062
CVE CVE-2024-30063
CVE CVE-2024-30065
CVE CVE-2024-30066
CVE CVE-2024-30067
CVE CVE-2024-30068
CVE CVE-2024-30069
CVE CVE-2024-30070
CVE CVE-2024-30076
CVE CVE-2024-30077
CVE CVE-2024-30078
CVE CVE-2024-30080
CVE CVE-2024-30082
CVE CVE-2024-30083
CVE CVE-2024-30084
CVE CVE-2024-30085
CVE CVE-2024-30086
CVE CVE-2024-30087
CVE CVE-2024-30088
CVE CVE-2024-30089
CVE CVE-2024-30090
CVE CVE-2024-30091
CVE CVE-2024-30093
CVE CVE-2024-30094
CVE CVE-2024-30095
CVE CVE-2024-30096
CVE CVE-2024-30097
CVE CVE-2024-30099
CVE CVE-2024-35250
CVE CVE-2024-35265
CVE CVE-2024-38213
MSKB 5039217
XREF MSFT:MS24-5039217
XREF IAVA:2024-A-0343-S
XREF IAVA:2024-A-0345-S
XREF CISA-KNOWN-EXPLOITED:2025/01/06
XREF CISA-KNOWN-EXPLOITED:2024/11/05
XREF CISA-KNOWN-EXPLOITED:2024/09/03
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2024/06/11, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5039217

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.5933
212239 - KB5048661: Windows 10 version 1809 / Windows Server 2019 Security Update (December 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5048661. It is, therefore, affected by multiple vulnerabilities

- Windows Kernel-Mode Driver Elevation of Privilege Vulnerability (CVE-2024-49074)

- Input Method Editor (IME) Remote Code Execution Vulnerability (CVE-2024-49079)

- Windows Common Log File System Driver Elevation of Privilege Vulnerability (CVE-2024-49090)

- Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability (CVE-2024-49112)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5048661
Risk Factor
Critical
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.0 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.8871
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/12/10, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5048661

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.6640
214115 - KB5050008: Windows 10 version 1809 / Windows Server 2019 Security Update (January 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5050008. It is, therefore, affected by multiple vulnerabilities

- Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability (CVE-2025-21307)

- Windows Telephony Service Remote Code Execution Vulnerability (CVE-2025-21223, CVE-2025-21233, CVE-2025-21236, CVE-2025-21237, CVE-2025-21238, CVE-2025-21239, CVE-2025-21240, CVE-2025-21241, CVE-2025-21243, CVE-2025-21244, CVE-2025-21245, CVE-2025-21246, CVE-2025-21248, CVE-2025-21250, CVE-2025-21252, CVE-2025-21266, CVE-2025-21273, CVE-2025-21282, CVE-2025-21286, CVE-2025-21302, CVE-2025-21303, CVE-2025-21305, CVE-2025-21306, CVE-2025-21339, CVE-2025-21409, CVE-2025-21411, CVE-2025-21413, CVE-2025-21417)

- Windows BitLocker Information Disclosure Vulnerability (CVE-2025-21210, CVE-2025-21214)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5050008
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.7811
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-7344
CVE CVE-2025-21189
CVE CVE-2025-21193
CVE CVE-2025-21202
CVE CVE-2025-21207
CVE CVE-2025-21210
CVE CVE-2025-21211
CVE CVE-2025-21213
CVE CVE-2025-21214
CVE CVE-2025-21215
CVE CVE-2025-21217
CVE CVE-2025-21218
CVE CVE-2025-21219
CVE CVE-2025-21220
CVE CVE-2025-21223
CVE CVE-2025-21225
CVE CVE-2025-21226
CVE CVE-2025-21227
CVE CVE-2025-21228
CVE CVE-2025-21229
CVE CVE-2025-21230
CVE CVE-2025-21231
CVE CVE-2025-21232
CVE CVE-2025-21233
CVE CVE-2025-21236
CVE CVE-2025-21237
CVE CVE-2025-21238
CVE CVE-2025-21239
CVE CVE-2025-21240
CVE CVE-2025-21241
CVE CVE-2025-21242
CVE CVE-2025-21243
CVE CVE-2025-21244
CVE CVE-2025-21245
CVE CVE-2025-21246
CVE CVE-2025-21248
CVE CVE-2025-21249
CVE CVE-2025-21250
CVE CVE-2025-21251
CVE CVE-2025-21252
CVE CVE-2025-21255
CVE CVE-2025-21256
CVE CVE-2025-21257
CVE CVE-2025-21258
CVE CVE-2025-21260
CVE CVE-2025-21261
CVE CVE-2025-21263
CVE CVE-2025-21265
CVE CVE-2025-21266
CVE CVE-2025-21268
CVE CVE-2025-21269
CVE CVE-2025-21270
CVE CVE-2025-21271
CVE CVE-2025-21272
CVE CVE-2025-21273
CVE CVE-2025-21274
CVE CVE-2025-21276
CVE CVE-2025-21277
CVE CVE-2025-21278
CVE CVE-2025-21280
CVE CVE-2025-21281
CVE CVE-2025-21282
CVE CVE-2025-21284
CVE CVE-2025-21285
CVE CVE-2025-21286
CVE CVE-2025-21287
CVE CVE-2025-21288
CVE CVE-2025-21289
CVE CVE-2025-21290
CVE CVE-2025-21291
CVE CVE-2025-21292
CVE CVE-2025-21293
CVE CVE-2025-21294
CVE CVE-2025-21295
CVE CVE-2025-21296
CVE CVE-2025-21297
CVE CVE-2025-21298
CVE CVE-2025-21299
CVE CVE-2025-21300
CVE CVE-2025-21301
CVE CVE-2025-21302
CVE CVE-2025-21303
CVE CVE-2025-21304
CVE CVE-2025-21305
CVE CVE-2025-21306
CVE CVE-2025-21307
CVE CVE-2025-21308
CVE CVE-2025-21309
CVE CVE-2025-21310
CVE CVE-2025-21312
CVE CVE-2025-21314
CVE CVE-2025-21316
CVE CVE-2025-21318
CVE CVE-2025-21319
CVE CVE-2025-21320
CVE CVE-2025-21321
CVE CVE-2025-21323
CVE CVE-2025-21324
CVE CVE-2025-21327
CVE CVE-2025-21328
CVE CVE-2025-21329
CVE CVE-2025-21330
CVE CVE-2025-21331
CVE CVE-2025-21332
CVE CVE-2025-21336
CVE CVE-2025-21338
CVE CVE-2025-21339
CVE CVE-2025-21340
CVE CVE-2025-21341
CVE CVE-2025-21374
CVE CVE-2025-21378
CVE CVE-2025-21382
CVE CVE-2025-21389
CVE CVE-2025-21409
CVE CVE-2025-21411
CVE CVE-2025-21413
CVE CVE-2025-21417
MSKB 5050008
XREF MSFT:MS25-5050008
XREF IAVA:2025-A-0034-S
XREF IAVA:2025-A-0033-S
XREF CWE:20
XREF CWE:41
XREF CWE:59
XREF CWE:94
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:191
XREF CWE:200
XREF CWE:203
XREF CWE:269
XREF CWE:284
XREF CWE:347
XREF CWE:352
XREF CWE:362
XREF CWE:400
XREF CWE:415
XREF CWE:416
XREF CWE:451
XREF CWE:476
XREF CWE:532
XREF CWE:591
XREF CWE:636
XREF CWE:693
XREF CWE:843
XREF CWE:908
XREF CWE:922
Exploitable With
Metasploit (true)
Plugin Information
Published: 2025/01/14, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5050008

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.6766
216131 - KB5052000: Windows 10 version 1809 / Windows Server 2019 Security Update (February 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5052000. It is, therefore, affected by multiple vulnerabilities

- Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVE-2025-21208, CVE-2025-21410)

- Windows Telephony Service Remote Code Execution Vulnerability (CVE-2025-21190, CVE-2025-21200, CVE-2025-21371, CVE-2025-21406, CVE-2025-21407)

- Microsoft Digest Authentication Remote Code Execution Vulnerability (CVE-2025-21368, CVE-2025-21369)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5052000
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.2857
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2025/02/11, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5052000

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.6893
232617 - KB5053596: Windows 10 version 1809 / Windows Server 2019 Security Update (March 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5053596. It is, therefore, affected by multiple vulnerabilities

- Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. (CVE-2025-26645)

- Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. (CVE-2025-24035, CVE-2025-24045)

- ** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process. Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is End-of-Life and should be removed. For more information on this, refer to the CVE Record's reference information. (CVE-2024-9157)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5053596
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.5654
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-9157
CVE CVE-2025-21180
CVE CVE-2025-21247
CVE CVE-2025-24035
CVE CVE-2025-24044
CVE CVE-2025-24045
CVE CVE-2025-24046
CVE CVE-2025-24048
CVE CVE-2025-24050
CVE CVE-2025-24051
CVE CVE-2025-24054
CVE CVE-2025-24055
CVE CVE-2025-24056
CVE CVE-2025-24059
CVE CVE-2025-24061
CVE CVE-2025-24064
CVE CVE-2025-24066
CVE CVE-2025-24067
CVE CVE-2025-24071
CVE CVE-2025-24072
CVE CVE-2025-24984
CVE CVE-2025-24985
CVE CVE-2025-24987
CVE CVE-2025-24988
CVE CVE-2025-24991
CVE CVE-2025-24992
CVE CVE-2025-24993
CVE CVE-2025-24995
CVE CVE-2025-24996
CVE CVE-2025-25008
CVE CVE-2025-26633
CVE CVE-2025-26645
MSKB 5053596
XREF MSFT:MS25-5053596
XREF IAVA:2025-A-0181-S
XREF IAVA:2025-A-0182-S
XREF CISA-KNOWN-EXPLOITED:2025/05/08
XREF CISA-KNOWN-EXPLOITED:2025/04/01
XREF CWE:23
XREF CWE:41
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:200
XREF CWE:284
XREF CWE:416
XREF CWE:532
XREF CWE:591
XREF CWE:681
XREF CWE:693
XREF CWE:707
Plugin Information
Published: 2025/03/11, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5053596

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.7009
234046 - KB5055519: Windows 10 version 1809 / Windows Server 2019 Security Update (April 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5055519. It is, therefore, affected by multiple vulnerabilities

- Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. (CVE-2025-26687)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-27481)
- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges. (CVE-2025-27740)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5055519
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.2827
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21174
CVE CVE-2025-21191
CVE CVE-2025-21197
CVE CVE-2025-21203
CVE CVE-2025-21204
CVE CVE-2025-21205
CVE CVE-2025-21221
CVE CVE-2025-21222
CVE CVE-2025-24058
CVE CVE-2025-24060
CVE CVE-2025-24073
CVE CVE-2025-24074
CVE CVE-2025-26635
CVE CVE-2025-26637
CVE CVE-2025-26640
CVE CVE-2025-26641
CVE CVE-2025-26644
CVE CVE-2025-26647
CVE CVE-2025-26648
CVE CVE-2025-26652
CVE CVE-2025-26663
CVE CVE-2025-26664
CVE CVE-2025-26665
CVE CVE-2025-26666
CVE CVE-2025-26667
CVE CVE-2025-26668
CVE CVE-2025-26669
CVE CVE-2025-26670
CVE CVE-2025-26671
CVE CVE-2025-26672
CVE CVE-2025-26673
CVE CVE-2025-26674
CVE CVE-2025-26676
CVE CVE-2025-26678
CVE CVE-2025-26679
CVE CVE-2025-26680
CVE CVE-2025-26686
CVE CVE-2025-26687
CVE CVE-2025-26688
CVE CVE-2025-27467
CVE CVE-2025-27469
CVE CVE-2025-27470
CVE CVE-2025-27471
CVE CVE-2025-27473
CVE CVE-2025-27474
CVE CVE-2025-27476
CVE CVE-2025-27477
CVE CVE-2025-27478
CVE CVE-2025-27479
CVE CVE-2025-27480
CVE CVE-2025-27481
CVE CVE-2025-27482
CVE CVE-2025-27483
CVE CVE-2025-27484
CVE CVE-2025-27485
CVE CVE-2025-27486
CVE CVE-2025-27487
CVE CVE-2025-27491
CVE CVE-2025-27727
CVE CVE-2025-27730
CVE CVE-2025-27731
CVE CVE-2025-27732
CVE CVE-2025-27733
CVE CVE-2025-27735
CVE CVE-2025-27736
CVE CVE-2025-27737
CVE CVE-2025-27738
CVE CVE-2025-27739
CVE CVE-2025-27740
CVE CVE-2025-27741
CVE CVE-2025-27742
CVE CVE-2025-29809
CVE CVE-2025-29810
CVE CVE-2025-29824
MSKB 5055519
XREF CISA-KNOWN-EXPLOITED:2025/04/29
XREF MSFT:MS25-5055519
XREF IAVA:2025-A-0256-S
XREF IAVA:2025-A-0255-S
XREF CWE:20
XREF CWE:59
XREF CWE:121
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:200
XREF CWE:284
XREF CWE:345
XREF CWE:367
XREF CWE:400
XREF CWE:410
XREF CWE:415
XREF CWE:416
XREF CWE:591
XREF CWE:667
XREF CWE:693
XREF CWE:787
XREF CWE:822
XREF CWE:908
XREF CWE:922
XREF CWE:1039
XREF CWE:1390
Plugin Information
Published: 2025/04/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5055519

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.7131
235845 - KB5058392: Windows 10 version 1809 / Windows Server 2019 Security Update (May 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5058392. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. (CVE-2025-29967)

- Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-29830, CVE-2025-29958, CVE-2025-29959)

- Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-29832, CVE-2025-29835, CVE-2025-29836, CVE-2025-29960, CVE-2025-29961)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5058392
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.2127
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/05/13, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5058392

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.7309
238080 - KB5060531: Windows 10 version 1809 / Windows Server 2019 Security Update (June 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5060531. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-33066)

- Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
(CVE-2025-33073)

- Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
(CVE-2025-32712)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5060531
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.5119
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-3052
CVE CVE-2025-24065
CVE CVE-2025-24068
CVE CVE-2025-24069
CVE CVE-2025-32712
CVE CVE-2025-32713
CVE CVE-2025-32714
CVE CVE-2025-32715
CVE CVE-2025-32716
CVE CVE-2025-32718
CVE CVE-2025-32719
CVE CVE-2025-32720
CVE CVE-2025-32721
CVE CVE-2025-32722
CVE CVE-2025-32724
CVE CVE-2025-32725
CVE CVE-2025-33050
CVE CVE-2025-33052
CVE CVE-2025-33053
CVE CVE-2025-33055
CVE CVE-2025-33056
CVE CVE-2025-33057
CVE CVE-2025-33058
CVE CVE-2025-33059
CVE CVE-2025-33060
CVE CVE-2025-33061
CVE CVE-2025-33062
CVE CVE-2025-33063
CVE CVE-2025-33064
CVE CVE-2025-33065
CVE CVE-2025-33066
CVE CVE-2025-33067
CVE CVE-2025-33068
CVE CVE-2025-33070
CVE CVE-2025-33071
CVE CVE-2025-33073
CVE CVE-2025-33075
CVE CVE-2025-47160
MSKB 5060531
XREF MSFT:MS25-5060531
XREF IAVA:2025-A-0428-S
XREF IAVA:2025-A-0417-S
XREF CISA-KNOWN-EXPLOITED:2025/11/10
XREF CISA-KNOWN-EXPLOITED:2025/07/01
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:269
XREF CWE:284
XREF CWE:400
XREF CWE:416
XREF CWE:476
XREF CWE:693
XREF CWE:908
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2025/06/10, Modified: 2025/10/21
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5060531

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.7434
241548 - KB5062557: Windows 10 version 1809 / Windows Server 2019 Security Update (July 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5062557. It is, therefore, affected by multiple vulnerabilities

- Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
(CVE-2025-49659)

- Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48799)

- Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48820)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5062557
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0055
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-36350
CVE CVE-2025-36357
CVE CVE-2025-47159
CVE CVE-2025-47971
CVE CVE-2025-47972
CVE CVE-2025-47973
CVE CVE-2025-47975
CVE CVE-2025-47976
CVE CVE-2025-47980
CVE CVE-2025-47981
CVE CVE-2025-47982
CVE CVE-2025-47984
CVE CVE-2025-47985
CVE CVE-2025-47986
CVE CVE-2025-47987
CVE CVE-2025-47991
CVE CVE-2025-47996
CVE CVE-2025-47998
CVE CVE-2025-47999
CVE CVE-2025-48000
CVE CVE-2025-48001
CVE CVE-2025-48003
CVE CVE-2025-48799
CVE CVE-2025-48800
CVE CVE-2025-48803
CVE CVE-2025-48804
CVE CVE-2025-48805
CVE CVE-2025-48806
CVE CVE-2025-48808
CVE CVE-2025-48811
CVE CVE-2025-48814
CVE CVE-2025-48815
CVE CVE-2025-48816
CVE CVE-2025-48817
CVE CVE-2025-48818
CVE CVE-2025-48819
CVE CVE-2025-48820
CVE CVE-2025-48821
CVE CVE-2025-48822
CVE CVE-2025-48823
CVE CVE-2025-48824
CVE CVE-2025-49657
CVE CVE-2025-49658
CVE CVE-2025-49659
CVE CVE-2025-49660
CVE CVE-2025-49661
CVE CVE-2025-49663
CVE CVE-2025-49664
CVE CVE-2025-49665
CVE CVE-2025-49666
CVE CVE-2025-49667
CVE CVE-2025-49668
CVE CVE-2025-49669
CVE CVE-2025-49670
CVE CVE-2025-49671
CVE CVE-2025-49672
CVE CVE-2025-49673
CVE CVE-2025-49674
CVE CVE-2025-49675
CVE CVE-2025-49676
CVE CVE-2025-49678
CVE CVE-2025-49679
CVE CVE-2025-49680
CVE CVE-2025-49681
CVE CVE-2025-49683
CVE CVE-2025-49684
CVE CVE-2025-49685
CVE CVE-2025-49686
CVE CVE-2025-49687
CVE CVE-2025-49688
CVE CVE-2025-49689
CVE CVE-2025-49690
CVE CVE-2025-49691
CVE CVE-2025-49716
CVE CVE-2025-49721
CVE CVE-2025-49722
CVE CVE-2025-49723
CVE CVE-2025-49724
CVE CVE-2025-49725
CVE CVE-2025-49726
CVE CVE-2025-49727
CVE CVE-2025-49729
CVE CVE-2025-49730
CVE CVE-2025-49732
CVE CVE-2025-49733
CVE CVE-2025-49740
CVE CVE-2025-49742
CVE CVE-2025-49744
CVE CVE-2025-49753
CVE CVE-2025-49760
CVE CVE-2025-55230
CVE CVE-2025-55231
MSKB 5062557
XREF MSFT:MS25-5062557
XREF IAVA:2025-A-0507-S
XREF IAVA:2025-A-0506-S
XREF IAVA:2025-A-0631-S
XREF CWE:20
XREF CWE:23
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:191
XREF CWE:197
XREF CWE:200
XREF CWE:284
XREF CWE:306
XREF CWE:326
XREF CWE:349
XREF CWE:353
XREF CWE:362
XREF CWE:367
XREF CWE:400
XREF CWE:415
XREF CWE:416
XREF CWE:476
XREF CWE:591
XREF CWE:693
XREF CWE:787
XREF CWE:820
XREF CWE:822
XREF CWE:843
XREF CWE:862
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5062557

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.7558
261799 - KB5065428: Windows 10 version 1809 / Windows Server 2019 Security Update (September 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5065428. It is, therefore, affected by multiple vulnerabilities

- SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for hardening against relay attacks: SMB Server signing SMB Server Extended Protection for Authentication (EPA) Microsoft is releasing this CVE to provide customers with audit capabilities to help them to assess their environment and to identify any potential device or software incompatibility issues before deploying SMB Server hardening measures that protect against relay attacks. If you have not already enabled SMB Server hardening measures, we advise customers to take the following actions to be protected from these relay attacks:
Assess your environment by utilizing the audit capabilities that we are exposing in the September 2025 security updates. See Support for Audit Events to deploy SMB Server HardeningSMB Server Signing & SMB Server EPA. Adopt appropriate SMB Server hardening measures. (CVE-2025-55234)

- Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. (CVE-2025-49734)

- Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-53796, CVE-2025-53797, CVE-2025-53798, CVE-2025-53806)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5065428
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0073
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5065428

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.7786
274782 - KB5068791: Windows 10 version 1809 / Windows Server 2019 Security Update (November 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5068791. It is, therefore, affected by multiple vulnerabilities

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-60724, CVE-2025-60714, CVE-2025-60715, CVE-2025-62452)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information.
(CVE-2025-59509, CVE-2025-59513, CVE-2025-60706, CVE-2025-62208, CVE-2025-62209)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2025-59505, CVE-2025-59506, CVE-2025-59507, CVE-2025-59508, CVE-2025-59511, CVE-2025-59512, CVE-2025-59514, CVE-2025-59515, CVE-2025-60703, CVE-2025-60704, CVE-2025-60705, CVE-2025-60707, CVE-2025-60709, CVE-2025-60713, CVE-2025-60716, CVE-2025-60717, CVE-2025-60719, CVE-2025-60720, CVE-2025-62213, CVE-2025-62215, CVE-2025-62217)


Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5068791
Risk Factor
Critical
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0009
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/11/11, Modified: 2025/11/14
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5068791

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.8024
277987 - KB5071544: Windows 10 version 1809 / Windows Server 2019 Security Update (December 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5071544. It is, therefore, affected by multiple vulnerabilities

- Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-62549)

- Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. (CVE-2025-62457)

- Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. (CVE-2025-62458)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5071544
Risk Factor
Critical
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0821
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/12/09, Modified: 2025/12/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5071544

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.4737
Should be : 10.0.17763.8146
56176 - MS11-073: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2587634)
-
Synopsis
Arbitrary code can be executed on the remote host through Microsoft Office.
Description
The remote Windows host is running a version of Microsoft Office that is potentially affected by two vulnerabilities :

- The application insecurely restricts the path used for loading external libraries when opening documents that use the .doc, .xls, or .ppt Office binary format and when the Office File Validation Add-in is not installed. This could lead to arbitrary code execution.
(CVE-2011-1980)

- The application may use an uninitialized object pointer when opening a Word document, which could lead to arbitrary code execution. (CVE-2011-1982)
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, and 2010.
Risk Factor
High
VPR Score
8.9
EPSS Score
0.5972
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 49513
BID 49519
CVE CVE-2011-1980
CVE CVE-2011-1982
MSKB 2584052
MSKB 2584063
MSKB 2584066
XREF CERT:909022
XREF MSFT:MS11-073
Exploitable With
Core Impact (true) (true) (true)
Plugin Information
Published: 2011/09/14, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



KB : 2584066
- C:\Program Files (x86)\Common Files\Microsoft Shared\Office14\Mso.dll has not been patched.
Remote version : 14.0.6023.1000
Should be : 14.0.6106.5005
57275 - MS11-089: Vulnerability in Microsoft Office Could Allow Remote Code Execution (2590602)
-
Synopsis
Arbitrary code can be executed on the remote host through Microsoft Office.
Description
The version of Microsoft Office installed on the remote host has a use-after-free vulnerability. A remote attacker could exploit this by tricking a user into opening a specially crafted Word file, resulting in arbitrary code execution.
See Also
Solution
Microsoft has released a set of patches for Office 2007 SP2, 2007 SP3, 2010, and 2010 SP1.
Risk Factor
High
VPR Score
8.9
EPSS Score
0.5475
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 50956
CVE CVE-2011-1983
MSKB 2589320
MSKB 2596785
XREF MSFT:MS11-089
Plugin Information
Published: 2011/12/13, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



KB : 2589320
- C:\Program Files (x86)\Common Files\Microsoft Shared\Office14\Msptls.dll has not been patched.
Remote version : 14.0.4730.1010
Should be : 14.0.6112.5000
58659 - MS12-027: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2664258)
-
Synopsis
The remote Windows host is affected by a remote code execution vulnerability.
Description
A memory corruption issue exists in Windows common controls, specifically within the MSCOMCTL.TreeView, MSCOMCTL.ListView2, MSCOMCTL.TreeView2, and MSCOMCTL.ListView controls component of MSCOMCTL.OCX, due to improper sanitization of user-supplied input. An unauthenticated, remote attacker can exploit this issue by convincing a user to view a specially crafted web page, resulting in the execution of arbitrary code.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007 and 2010; Office 2003 Web Components; SQL Server 2000, 2005, 2005 Express Edition, 2008, and 2008 R2; BizTalk Server 2002; Commerce Server 2002, 2007, 2009, and 2009 R2; Microsoft Visual FoxPro 8.0 and 9.0; and Visual Basic 6.0 Runtime.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9429
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 52911
CVE CVE-2012-0158
MSKB 983807
MSKB 983808
MSKB 983809
MSKB 2597112
MSKB 2598039
MSKB 2598041
MSKB 2641426
MSKB 2645025
MSKB 2647488
MSKB 2647490
MSKB 2655547
MSKB 2658674
MSKB 2658676
MSKB 2658677
XREF EDB-ID:18780
XREF MSFT:MS12-027
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Exploitable With
CANVAS (true) Core Impact (true) Metasploit (true)
Plugin Information
Published: 2012/04/11, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable controls do not have the kill bit set :

Class identifier : {996BF5E0-8044-4650-ADEB-0B013914E99C}
Filename : C:\Windows\SysWOW64\MSCOMCTL.OCX
Installed version : 6.1.98.18

Class identifier : {9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}
Filename : C:\Windows\SysWOW64\MSCOMCTL.OCX
Installed version : 6.1.98.18

Nessus determined these controls are being used by the following applications :

Product : Office 2010
Missing update : KB2598039
61532 - MS12-057: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2731879)
-
Synopsis
Arbitrary code can be executed on the remote host through Microsoft Office.
Description
The remote Windows host has a version of Microsoft Office that is potentially affected by a remote code execution vulnerability.
Specially crafted Computer Graphics Metafile (CGM) graphics files can be used to exploit this vulnerability and allow an attacker to take control of an affected system.
See Also
Solution
Microsoft has released a set of patches for Office 2007 and 2010.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.5323
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 54876
CVE CVE-2012-2524
MSKB 2553260
MSKB 2589322
MSKB 2596615
MSKB 2596754
MSKB 2687501
MSKB 2687510
XREF MSFT:MS12-057
XREF IAVB:2012-B-0075
Plugin Information
Published: 2012/08/15, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



KB : 2687501
- C:\Program Files (x86)\Common Files\Microsoft Shared\Office14\Mso.dll has not been patched.
Remote version : 14.0.6023.1000
Should be : 14.0.6123.5001
61535 - MS12-060: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573)
-
Synopsis
The remote Windows host has a code execution vulnerability.
Description
There is an unspecified remote code execution vulnerability in Windows common controls, which is included in several Microsoft products. An attacker could exploit this by tricking a user into viewing a maliciously crafted web page, resulting in arbitrary code execution.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2003, 2007, and 2010, Office 2003 Web Components, Microsoft SQL Server 2000, Microsoft SQL Analysis Services 2000, Microsoft Commerce Server 2002, 2007, and 2009, Microsoft Host Integration Server 2004, Microsoft Visual Fox Pro 8.0 and 9.0, and Visual Basic 6.0 Runtime.
Risk Factor
High
VPR Score
9.8
EPSS Score
0.9195
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 54948
CVE CVE-2012-1856
MSKB 983811
MSKB 983812
MSKB 983813
MSKB 2597986
MSKB 2687441
MSKB 2726929
MSKB 2708437
MSKB 2708940
MSKB 2708941
MSKB 2711207
MSKB 2716389
MSKB 2716390
MSKB 2716392
MSKB 2716393
XREF MSFT:MS12-060
XREF CISA-KNOWN-EXPLOITED:2022/03/24
Exploitable With
Core Impact (true)
Plugin Information
Published: 2012/08/15, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable controls do not have the kill bit set :

Class identifier : {24B224E0-9545-4A2F-ABD5-86AA8A849385}
Filename : C:\Windows\SysWOW64\MSCOMCTL.OCX
Installed version : 6.1.98.18

Nessus determined these controls are being used by the following applications :

Product : Office 2010
Missing Update : KB2597986
62459 - MS12-064: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2742319)
-
Synopsis
A Microsoft Office component installed on the remote host is affected by multiple remote code execution vulnerabilities.
Description
The version of Office, Office Compatibility Pack, Microsoft Word Viewer, Microsoft Office Web Apps, and/or Microsoft Share Point Server installed on the remote host is affected by multiple remote code execution vulnerabilities :

- A flaw in the way Microsoft Word handles Word files can allow an attacker to execute arbitrary code by tricking a user into opening a specially crafted Word file.
(CVE-2012-0182)

- A flaw in the way Microsoft Office handles RTF files can be exploited to execute arbitrary code by tricking a user into opening a specially crafted RTF document.
(CVE-2012-2528)
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, Office Compatibility Pack, Microsoft Word Viewer, Microsoft Office Web Apps and Microsoft SharePoint Server.
Risk Factor
High
VPR Score
9.7
EPSS Score
0.5685
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 55780
BID 55781
CVE CVE-2012-0182
CVE CVE-2012-2528
MSKB 2553488
MSKB 2598237
MSKB 2687314
MSKB 2687315
MSKB 2687401
MSKB 2687483
MSKB 2687485
XREF MSFT:MS12-064
Plugin Information
Published: 2012/10/10, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.6123.5005
63226 - MS12-079: Vulnerability in Microsoft Word Could Allow Remote Code Execution (2780642)
-
Synopsis
A Microsoft Office component installed on the remote host is affected by a remote code execution vulnerability.
Description
The version of Office, Office Compatibility Pack, Microsoft Word Viewer, Microsoft Office Web Apps, and/or Microsoft Share Point Server installed on the remote host has a remote code execution vulnerability. This is due to the way that Microsoft Office software parses RTF data and could allow an attacker to execute arbitrary code by tricking a user into opening a specially crafted RTF file.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, Office Compatibility Pack, Microsoft Word Viewer, Microsoft Office Web Apps and Microsoft SharePoint Server.
Risk Factor
High
VPR Score
9.4
EPSS Score
0.8553
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 56834
CVE CVE-2012-2539
MSKB 2760405
MSKB 2760410
MSKB 2687412
MSKB 2760416
MSKB 2760421
MSKB 2760497
MSKB 2760498
XREF MSFT:MS12-079
XREF CISA-KNOWN-EXPLOITED:2022/04/18
Plugin Information
Published: 2012/12/11, Modified: 2022/03/29
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.6129.5000
69832 - MS13-072: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2845537)
-
Synopsis
The Microsoft Office component installed on the remote host is affected by multiple remote code execution vulnerabilities.
Description
The remote Windows host is running a version of Microsoft Office, Microsoft Word, Office Compatibility Pack, or Microsoft Word Viewer that is affected by the following remote code execution vulnerabilities :

- A remote code execution vulnerability exists due to the way the XML parser used by Word resolves external entities. (CVE-2013-3160)

- Remote code execution vulnerabilities exist due to memory corruption issues in the way that Microsoft Office parses files.
(CVE-2013-3847, CVE-2013-3848, CVE-2013-3849, CVE-2013-3850, CVE-2013-3851, CVE-2013-3852, CVE-2013-3853, CVE-2013-3854, CVE-2013-3855, CVE-2013-3856, CVE-2013-3857, CVE-2013-3858)

If an attacker can trick a user on the affected host into opening a specially crafted file, it may be possible to leverage these issues to read arbitrary files on the target system or execute arbitrary code, subject to the user's privileges.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, Office Compatibility Pack, and Microsoft Word Viewer.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.6689
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 62162
BID 62165
BID 62168
BID 62169
BID 62170
BID 62171
BID 62216
BID 62217
BID 62220
BID 62222
BID 62223
BID 62224
BID 62226
CVE CVE-2013-3160
CVE CVE-2013-3847
CVE CVE-2013-3848
CVE CVE-2013-3849
CVE CVE-2013-3850
CVE CVE-2013-3851
CVE CVE-2013-3852
CVE CVE-2013-3853
CVE CVE-2013-3854
CVE CVE-2013-3855
CVE CVE-2013-3856
CVE CVE-2013-3857
CVE CVE-2013-3858
MSKB 2597973
MSKB 2760411
MSKB 2760769
MSKB 2760823
MSKB 2767773
MSKB 2767913
MSKB 2817474
MSKB 2817682
MSKB 2817683
MSKB 2845537
XREF MSFT:MS13-072
XREF IAVA:2013-A-0178-S
Plugin Information
Published: 2013/09/11, Modified: 2023/02/16
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.7106.5001

Product : Microsoft Office 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\\Wwlib.dll
Installed version :
Fixed version : 14.0.7106.5001
69834 - MS13-074: Vulnerabilities in Microsoft Access Could Allow Remote Code Execution (2848637)
-
Synopsis
It is possible to execute arbitrary code on the remote host through Microsoft Access.
Description
The remote Windows host is running a version of Microsoft Access that is affected by multiple remote code execution vulnerabilities. These vulnerabilities are due to the way that Microsoft Access parses content in Access files.

If an attacker can trick a user on the affected host into opening a specially crafted Access file, it may be possible to leverage these issues to read arbitrary files on the target system or execute arbitrary code, subject to the user's privileges.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, and 2013.
Risk Factor
High
VPR Score
7.4
EPSS Score
0.5802
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.7 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
BID 62229
BID 62230
BID 62231
CVE CVE-2013-3155
CVE CVE-2013-3156
CVE CVE-2013-3157
MSKB 2596825
MSKB 2687423
MSKB 2810009
MSKB 2848637
XREF MSFT:MS13-074
XREF IAVB:2013-B-0099-S
Exploitable With
Core Impact (true)
Plugin Information
Published: 2013/09/11, Modified: 2025/03/13
Plugin Output

tcp/445/cifs



KB : 2687423
- C:\Program Files (x86)\Common Files\Microsoft Shared\Office14\Acecore.dll has not been patched.
Remote version : 14.0.6023.1000
Should be : 14.0.7102.1000
71941 - MS14-001: Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2916605)
-
Synopsis
The remote host is affected by multiple memory corruption vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Microsoft Word, Office Compatibility Pack, Microsoft Word Viewer, SharePoint Server, or Microsoft Office Web Apps that is affected by one or more unspecified memory corruption vulnerabilities. By tricking a user into opening a specially crafted file, it may be possible for a remote attacker to take complete control of the system or execute arbitrary code.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, Office Compatibility Pack, Microsoft Word Viewer, SharePoint Server, and Office Web Apps.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.3724
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 64726
BID 64727
BID 64728
CVE CVE-2014-0258
CVE CVE-2014-0259
CVE CVE-2014-0260
MSKB 2827224
MSKB 2837577
MSKB 2837596
MSKB 2837615
MSKB 2837617
MSKB 2837625
MSKB 2863834
MSKB 2863866
MSKB 2863867
MSKB 2863879
MSKB 2863901
MSKB 2863902
XREF MSFT:MS14-001
XREF IAVA:2014-A-0006-S
Plugin Information
Published: 2014/01/14, Modified: 2023/02/16
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.7113.5001

Product : Microsoft Office 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\\Wwlib.dll
Installed version :
Fixed version : 14.0.7113.5001
73413 - MS14-017: Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2949660)
-
Synopsis
The remote host is affected by multiple memory corruption vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Microsoft Word, Office Compatibility Pack, Microsoft Word Viewer, SharePoint Server, or Microsoft Office Web Apps that is affected by one or more unspecified memory corruption vulnerabilities. By tricking a user into opening a specially crafted file, it may be possible for a remote attacker to take complete control of the system or execute arbitrary code.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, 2013, Office Compatibility Pack, Microsoft Word Viewer, SharePoint Server, and Office Web Apps.
Risk Factor
High
VPR Score
9.6
EPSS Score
0.9313
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 66385
BID 66614
BID 66629
CVE CVE-2014-1757
CVE CVE-2014-1758
CVE CVE-2014-1761
MSKB 2863910
MSKB 2878220
MSKB 2878221
MSKB 2878236
MSKB 2878237
MSKB 2863907
MSKB 2878303
MSKB 2878304
MSKB 2878219
MSKB 2863919
MSKB 2863926
XREF CERT:882841
XREF IAVA:2014-A-0049-S
XREF MSFT:MS14-017
XREF CISA-KNOWN-EXPLOITED:2022/08/15
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2014/04/08, Modified: 2023/02/16
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.7121.5004

Product : Microsoft Office 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\\Wwlib.dll
Installed version :
Fixed version : 14.0.7121.5004
78437 - MS14-061: Vulnerability in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3000434)
-
Synopsis
The remote host is affected by a remote code execution vulnerability.
Description
The remote Windows host has a version of Microsoft Office, Microsoft Word, Office Compatibility Pack, SharePoint Server, or Microsoft Office Web Apps that is affected by remote code execution vulnerability due to a flaw in parsing Word documents. This vulnerability can be triggered by tricking a user into opening a specially crafted Word document.
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, Office Compatibility Pack, SharePoint Server, and Office Web Apps.
Risk Factor
High
VPR Score
6.7
EPSS Score
0.3203
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 70360
CVE CVE-2014-4117
MSKB 2883031
MSKB 2883032
MSKB 2883008
MSKB 2883013
MSKB 2883098
MSKB 2889827
XREF MSFT:MS14-061
Plugin Information
Published: 2014/10/15, Modified: 2018/07/30
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.7134.5000

Product : Microsoft Office 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\\Wwlib.dll
Installed version : 14.0.6024.1000
Fixed version : 14.0.7134.5000
192147 - Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203)
-
Synopsis
An application installed on the remote Windows host is affected by an elevation of privilege vulnerability.
Description
The version of Microsoft Azure Data Studio installed on the remote Windows host is prior to 1.48.0. It is, therefore, affected by an unspecified elevation of privilege vulnerability.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Microsoft Azure Data Studio version 1.48.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0214
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-26203
XREF IAVA:2024-A-0157
Plugin Information
Published: 2024/03/15, Modified: 2024/03/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Azure Data Studio\
Installed version : 1.44.0.0
Fixed version : 1.48.0
27525 - Microsoft Office Service Pack Out of Date
-
Synopsis
The remote office suite is not up to date.
Description
The remote version of Microsoft Office has no service pack or the one installed is no longer supported.
See Also
Solution
Install the latest service pack.
Risk Factor
High
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2007/10/23, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The remote Microsoft Office 2010 system has Service Pack 1 applied.
The system should have Office 2010 Service Pack 2 installed.
192945 - Node.js 18.x < 18.20.1 / 20.x < 20.12.1 / 21.x < 21.7.2 Multiple Vulnerabilities (Wednesday, April 3, 2024 Security Releases).
-
Synopsis
Node.js - JavaScript run-time environment is affected by multiple vulnerabilities.
Description
The version of Node.js installed on the remote host is prior to 18.20.1, 20.12.1, 21.7.2. It is, therefore, affected by multiple vulnerabilities as referenced in the Wednesday, April 3, 2024 Security Releases advisory.

- An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition. Impacts: Thank you, to bart for reporting this vulnerability and Anna Henningsen for fixing it. (CVE-2024-27983)

- The team has identified a vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content- length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first. Impacts: Thank you, to bpingel for reporting this vulnerability and Paolo Insogna for fixing it. Summary The Node.js project will release new versions of the 18.x, 20.x, 21.x releases lines on or shortly after, Wednesday, April 3, 2024 in order to address: (CVE-2024-27982)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Node.js version 18.20.1 / 20.12.1 / 21.7.2 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
8.2 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
CVSS v3.0 Temporal Score
7.1 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.0
EPSS Score
0.7267
CVSS v2.0 Base Score
5.4 (CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
4.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-27982
CVE CVE-2024-27983
XREF IAVB:2024-B-0033-S
Plugin Information
Published: 2024/04/05, Modified: 2024/04/19
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\nodejs\
Installed version : 18.16.1
Fixed version : 18.20.1
193573 - Node.js 18.x < 18.20.2 / 20.x < 20.12.2 / 21.x < 21.7.3 Command Injection Vulnerability (Wednesday, April 10, 2024 Security Releases).
-
Synopsis
Node.js - JavaScript run-time environment is affected by command Injection vulnerability.
Description
The version of Node.js installed on the remote host is prior to 18.20.2, 20.12.2, 21.7.3. It is, therefore, affected by a command injection vulnerability as referenced in the Wednesday, April 10, 2024 Security Releases advisory. This is due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Node.js version 18.20.2 / 20.12.2 / 21.7.3 or later.
Risk Factor
High
CVSS v3.0 Base Score
8.1 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.1 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0039
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-27980
XREF IAVB:2024-B-0039-S
Plugin Information
Published: 2024/04/19, Modified: 2025/01/09
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\nodejs\
Installed version : 18.16.1
Fixed version : 18.20.2
201969 - Node.js 18.x < 18.20.4 / 20.x < 20.15.1 / 22.x < 22.4.1 Multiple Vulnerabilities (Monday, July 8, 2024 Security Releases).
-
Synopsis
Node.js - JavaScript run-time environment is affected by multiple vulnerabilities.
Description
The version of Node.js installed on the remote host is prior to 18.20.4, 20.15.1, 22.4.1. It is, therefore, affected by multiple vulnerabilities as referenced in the Monday, July 8, 2024 Security Releases advisory.

- The CVE-2024-27980 was identified as an incomplete fix for the BatBadBut vulnerability. This vulnerability arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled. This vulnerability affects all users of child_process.spawn and child_process.spawnSync on Windows in all active release lines.
Impact: Thank you, to tianst for reporting this vulnerability and thank you RafaelGSS for fixing it.
(CVE-2024-27980)

- A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers. Impact: Thank you, to dittyroma for reporting this vulnerability and thank you RafaelGSS for fixing it. (CVE-2024-22020)

- A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a read-only file descriptor to change the owner and permissions of a file. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 22. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js. Impact: Thank you, to 4xpl0r3r for reporting this vulnerability and thank you RafaelGSS for fixing it. (CVE-2024-36137)

- A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 22. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js. Impact: Thank you, to haxatron1 for reporting this vulnerability and thank you RafaelGSS for fixing it. (CVE-2024-22018)

- The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases. This vulnerability affects Windows users of the Node.js Permission Model in version v22.x and v20.x Impact:
Thank you, to tniessen for reporting this vulnerability and thank you RafaelGSS for fixing it.
(CVE-2024-37372)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Node.js version 18.20.4 / 20.15.1 / 22.4.1 or later.
Risk Factor
High
CVSS v3.0 Base Score
8.1 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.1 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0074
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C)
CVSS v2.0 Temporal Score
6.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-22018
CVE CVE-2024-22020
CVE CVE-2024-27980
CVE CVE-2024-36137
CVE CVE-2024-37372
XREF IAVB:2024-B-0039-S
XREF IAVB:2024-B-0083-S
Plugin Information
Published: 2024/07/08, Modified: 2025/01/24
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\nodejs\
Installed version : 18.16.1
Fixed version : 18.20.4
214404 - Node.js 18.x < 18.20.6 / 20.x < 20.18.2 / 22.x < 22.13.1 / 23.x < 23.6.1 Multiple Vulnerabilities (Tuesday, January 21, 2025 Security Releases).
-
Synopsis
Node.js - JavaScript run-time environment is affected by multiple vulnerabilities.
Description
The version of Node.js installed on the remote host is prior to 18.20.6, 20.18.2, 22.13.1, 23.6.1. It is, therefore, affected by multiple vulnerabilities as referenced in the Tuesday, January 21, 2025 Security Releases advisory.

- A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x. Impact: Thank you, to newtmitch for reporting this vulnerability and thank you RafaelGSS for fixing it. (CVE-2025-23085)

- With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23. Impact: Thank you, to leodog896 for reporting this vulnerability and thank you RafaelGSS for fixing it. (CVE-2025-23083)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Node.js version 18.20.6 / 20.18.2 / 22.13.1 / 23.6.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.7 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
CVSS v3.0 Temporal Score
6.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.2
EPSS Score
0.0006
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-23083
CVE CVE-2025-23085
XREF IAVB:2025-B-0012-S
Plugin Information
Published: 2025/01/21, Modified: 2025/08/05
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\nodejs\
Installed version : 18.16.1
Fixed version : 18.20.6
209282 - Oracle Java SE Multiple Vulnerabilities (October 2024 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the October 2024 CPU advisory.

- Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.12, 21.0.4 and 23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM for JDK. (CVE-2024-36138)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u421; Oracle GraalVM Enterprise Edition: 20.3.15 and 21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2023-42950)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
JavaFX (libxml2)). Supported versions that are affected are Oracle Java SE: 8u421; Oracle GraalVM Enterprise Edition: 20.3.15 and 21.3.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2024-25062)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2024 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.7 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0074
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
6.1 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/10/18, Modified: 2025/11/05
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jdk-17\
Installed version : 17.0.12 / build 17.0.12
Fixed version : Upgrade to version 17.0.13 or greater
271249 - Oracle Java SE Multiple Vulnerabilities (October 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The 8u461, 11.0.28, 17.0.16, 21.0.8, 25, versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the October 2025 CPU advisory.

- Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. (CVE-2025-31257)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2025-53057)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2025-53066)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
9.2
EPSS Score
0.0009
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
Plugin Information
Published: 2025/10/23, Modified: 2025/12/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jdk-17\
Installed version : 17.0.12 / build 17.0.12
Fixed version : Upgrade to version 17.0.17 or greater
242073 - RARLAB WinRAR < 7.12 Beta 1 Directory Traversal Remote Code Execution (CVE-2025-6218)
-
Synopsis
The remote Windows host has an application installed which is affected by a directory traversal remote code execution vulnerability.
Description
The remote host is running RARLAB WinRAR, an archive manager for Windows, whose reported version is prior to 7.12 Beta 1. It is, therefore, affected by a vulnerability:

- RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198. (CVE-2025-6218)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to RARLAB WinRAR version 7.12 Beta 1 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.0029
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-6218
XREF IAVA:2025-A-0227
XREF ZDI:ZDI-25-409
XREF CISA-KNOWN-EXPLOITED:2025/12/30
Plugin Information
Published: 2025/07/14, Modified: 2025/12/09
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.12 Beta 1
248462 - RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088)
-
Synopsis
The remote Windows host has an application installed which is affected by a directory traversal vulnerability.
Description
The remote host is running RARLAB WinRAR, an archive manager for Windows, whose reported version is prior to 7.13. It is, therefore, affected by a vulnerability:

- A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. (CVE-2025-8088)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to RARLAB WinRAR version 7.13 or later.
Risk Factor
Critical
CVSS v4.0 Base Score
8.4 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.0562
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-8088
XREF CISA-KNOWN-EXPLOITED:2025/09/02
XREF IAVA:2025-A-0608
Plugin Information
Published: 2025/08/11, Modified: 2025/08/21
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.13
125217 - Security Update for .NET Core (May 2019)
-
Synopsis
The remote Windows host is affected by a .NET Core denial of service vulnerabilities.
Description
The Microsoft .NET Core installation on the remote host is version 1.0.x < 1.0.16, 1.1.x < 1.1.13, 2.1.x < 2.1.11, 2.2.x < 2.2.5.
It is, therefore, affected by a denial of service (DoS) vulnerability when .NET Core improperly handles web requests. An unauthenticated, remote attacker could exploit this issue, via sending a specially crafted requests to the .NET Core application, to cause the application to stop responding.
See Also
Solution
Refer to vendor documentation.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.1
EPSS Score
0.0451
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
BID 108207
BID 108208
BID 108245
CVE CVE-2019-0820
CVE CVE-2019-0980
CVE CVE-2019-0981
CVE CVE-2019-0982
XREF IAVA:2019-A-0149-S
XREF CEA-ID:CEA-2019-0326
Plugin Information
Published: 2019/05/16, Modified: 2024/05/22
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\1.0.5\
Installed version : 1.0.5
Fixed version : 1.0.16 (1.0.16.5115)

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\1.1.2\
Installed version : 1.1.2
Fixed version : 1.1.13 (1.1.13.1809)
183024 - Security Update for Microsoft .NET 7 Core (October 2023)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of Microsoft .NET 7 Core installed on the remote host is prior to 7.0.12. It is, therefore, affected by multiple vulnerabilities as referenced in the 2023_Oct_10 advisory.

- A vulnerability exists in the ASP.NET Core Kestrel web server where a malicious client may flood the server with specially crafted HTTP/2 requests, causing denial of service. (CVE-2023-44487)

- A null pointer vulnerability exists in MsQuic.dll which may lead to Denial of Service. This issue only affects Windows systems. (CVE-2023-38171)

- A memory leak vulnerability exists in MsQuic.dll which may lead to Denial of Service. This issue only affects Windows systems. (CVE-2023-36435)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.9
EPSS Score
0.9443
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
6.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36435
CVE CVE-2023-38171
CVE CVE-2023-44487
XREF CISA-KNOWN-EXPLOITED:2023/10/31
XREF IAVA:2023-A-0543-S
XREF CEA-ID:CEA-2024-0004
XREF IAVB:2023-B-0083-S
Plugin Information
Published: 2023/10/13, Modified: 2024/02/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NetCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.12

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.12
232847 - Security Update for Microsoft .NET 8 Core (January 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of Microsoft .NET 8 Core installed on the remote host is prior to 8.0.12. It is, therefore, affected by multiple vulnerabilities as referenced in the vendor advisory.

- .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)

- .NET Elevation of Privilege Vulnerability (CVE-2025-21173)

- .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0035
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
References
Plugin Information
Published: 2025/03/19, Modified: 2025/03/19
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.12

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.12

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.7\
Installed version : 8.0.7
Fixed version : 8.0.12
193142 - Security Update for Microsoft .NET Core (April 2024)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the 2024_Apr_09 advisory.

- .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (CVE-2024-21409)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.547
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-21409
XREF IAVA:2024-A-0218-S
Plugin Information
Published: 2024/04/10, Modified: 2024/05/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Fixed version : 6.0.29

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.4

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NetCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.18

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Fixed version : 6.0.29

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.18

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.4
234051 - Security Update for Microsoft .NET Core (April 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the vendor advisory.

- Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. (CVE-2025-26682)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.3085
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-26682
XREF IAVA:2025-A-0238-S
Plugin Information
Published: 2025/04/08, Modified: 2025/05/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.15

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.15

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.7\
Installed version : 8.0.7
Fixed version : 8.0.15
190535 - Security Update for Microsoft .NET Core (February 2024)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the 2024_Feb_13 advisory.

- .NET Denial of Service Vulnerability (CVE-2024-21404)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0216
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-21404
XREF IAVA:2024-A-0089-S
Plugin Information
Published: 2024/02/14, Modified: 2024/03/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Fixed version : 6.0.27

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.2

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NetCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.16

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Fixed version : 6.0.27

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.16

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.2
202031 - Security Update for Microsoft .NET Core (July 2024)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the vendor advisory.

- .NET Core and Visual Studio Denial of Service Vulnerability (CVE-2024-30105)

- .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2024-35264)

- .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability (CVE-2024-38081)

- .NET and Visual Studio Denial of Service Vulnerability (CVE-2024-38095)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0529
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-30105
CVE CVE-2024-35264
CVE CVE-2024-38081
CVE CVE-2024-38095
XREF IAVA:2024-A-0398-S
XREF IAVA:2024-A-0406-S
Plugin Information
Published: 2024/07/09, Modified: 2025/05/07
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.7

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.7
209021 - Security Update for Microsoft .NET Core (July 2024)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the vendor advisory.

- .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability (CVE-2024-38081)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0035
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2024/10/15, Modified: 2024/10/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Fixed version : 6.0.32

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Fixed version : 6.0.32
238082 - Security Update for Microsoft .NET Core (June 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the vendor advisory.

- .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-30399)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-30399
XREF IAVA:2025-A-0410-S
Plugin Information
Published: 2025/06/10, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.17

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.17

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.7\
Installed version : 8.0.7
Fixed version : 8.0.17
192012 - Security Update for Microsoft .NET Core (March 2024)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the 2024_Mar_12 advisory.

- .NET and Visual Studio Denial of Service Vulnerability (CVE-2024-21392)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1026
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-21392
XREF IAVA:2024-A-0151-S
Plugin Information
Published: 2024/03/13, Modified: 2024/04/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.3

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NetCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.17

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.17

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.3
232619 - Security Update for Microsoft .NET Core (March 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of Microsoft .NET Core installed on the remote host is 8.0.x < 8.0.14 or 9.0.x < 9.0.3.
It is, therefore, affected by a vulnerability as referenced in the vendor advisory.

- Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. (CVE-2025-24070)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H)
CVSS v3.0 Temporal Score
6.1 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.5
EPSS Score
0.0015
CVSS v2.0 Base Score
6.6 (CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:C)
CVSS v2.0 Temporal Score
4.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-24070
XREF IAVA:2025-A-0175-S
Plugin Information
Published: 2025/03/11, Modified: 2025/04/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.14

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.14

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.7\
Installed version : 8.0.7
Fixed version : 8.0.14
235852 - Security Update for Microsoft .NET Core (May 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the vendor advisory.

- External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. (CVE-2025-26646)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
8.0 (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0004
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-26646
XREF IAVA:2025-A-0330-S
Plugin Information
Published: 2025/05/13, Modified: 2025/06/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.16

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.16

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.7\
Installed version : 8.0.7
Fixed version : 8.0.16
208286 - Security Update for Microsoft .NET Core (October 2024)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the vendor advisory.

- .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2024-38229)

- .NET and Visual Studio Denial of Service Vulnerability (CVE-2024-43483,CVE-2024-43484,CVE-2024-43485)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0338
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38229
CVE CVE-2024-43483
CVE CVE-2024-43484
CVE CVE-2024-43485
XREF IAVA:2024-A-0625-S
XREF IAVA:2024-A-0632-S
Plugin Information
Published: 2024/10/08, Modified: 2025/05/07
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Fixed version : 6.0.35

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.10

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Installed version : 6.0.25
Fixed version : 6.0.35

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.10

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.7\
Installed version : 8.0.7
Fixed version : 8.0.10
181277 - Security Update for Microsoft .NET Core (September 2023)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the 2023_Sep_12 advisory.

- Visual Studio Remote Code Execution Vulnerability (CVE-2023-36792, CVE-2023-36793, CVE-2023-36794, CVE-2023-36796)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0156
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36792
CVE CVE-2023-36793
CVE CVE-2023-36794
CVE CVE-2023-36796
XREF IAVA:2023-A-0475-S
Plugin Information
Published: 2023/09/12, Modified: 2023/10/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NetCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.11

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.11
190545 - Security Update for Microsoft ASP.NET Core (February 2024) (CVE-2024-21386)
-
Synopsis
The remote Windows host is affected by a ASP.NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a denial of service as referenced in the vendor advisory.

- ASP.NET Core Denial of Service Vulnerability

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1026
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-21386
XREF IAVA:2024-A-0093
Plugin Information
Published: 2024/02/14, Modified: 2024/03/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\6.0.25
Installed version : 6.0.25
Fixed version : 6.0.27

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\7.0.10
Installed version : 7.0.10
Fixed version : 7.0.16

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\8.0.0
Installed version : 8.0.0
Fixed version : 8.0.2

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\6.0.25
Installed version : 6.0.25
Fixed version : 6.0.27

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\7.0.10
Installed version : 7.0.10
Fixed version : 7.0.16

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\8.0.0
Installed version : 8.0.0
Fixed version : 8.0.2
241523 - Security Update for Microsoft Visual Studio Code (April 2025)
-
Synopsis
The remote host has an application installed that is missing a security update.
Description
The version of Microsoft Visual Studio Code installed on the remote host is prior to 1.100.1. It is, therefore, affected by a vulnerability where files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Microsoft Visual Studio Code 1.100.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.1 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N)
VPR Score
5.1
EPSS Score
0.0006
CVSS v2.0 Base Score
5.6 (CVSS2#AV:L/AC:L/Au:N/C:C/I:P/A:N)
STIG Severity
I
References
CVE CVE-2025-21264
XREF IAVA:2025-A-0333-S
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Installed version : 1.81.1
Fixed version : 1.100.1
216141 - Security Update for Microsoft Visual Studio Code (February 2025)
-
Synopsis
The remote host has an application installed that is missing a security update.
Description
The version of Microsoft Visual Studio Code installed on the remote host is prior to 1.97.1. It is, therefore, affected by multiple vulnerabilities:

- An elevation of privilege vulnerability exists in VS Code 1.97.0 and earlier versions for users of the code serve-web command on Windows. An attacker can place an evil version of the node module that is optionally required by one of the dependencies for the Visual Studio Code remote server in a world writable directory like C:
ode_modules to get it executed under the privileges of the current user. (CVE-2025-24039)

- A vulnerability exists in VS Code 1.97.0 and earlier versions where an attacker with write permissions on certain common directories can place a binary that would be executed automatically by the JavaScript debugger. This requires an attacker to be able to create and modify files on the user's machine. (CVE-2025-24042)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Microsoft Visual Studio Code 1.97.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0008
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-24039
CVE CVE-2025-24042
XREF IAVA:2025-A-0108-S
Plugin Information
Published: 2025/02/11, Modified: 2025/06/23
Plugin Output

tcp/445/cifs


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Installed version : 1.81.1
Fixed version : 1.97.1
191929 - Security Update for Microsoft Visual Studio Code (March 2024)
-
Synopsis
The remote host has an application installed that is missing a security update.
Description
The version of Microsoft Visual Studio Code installed on the remote Windows host is prior to 1.87.2. It is, therefore, affected by an unspecified elevation of privilege vulnerability.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update to Microsoft Visual Studio Code 1.87.2 or later.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.107
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-26165
XREF IAVA:2024-A-0156-S
Plugin Information
Published: 2024/03/12, Modified: 2025/06/23
Plugin Output

tcp/445/cifs


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Installed version : 1.81.1
Fixed version : 1.87.2
232737 - Security Update for Microsoft Visual Studio Code (March 2025)
-
Synopsis
The remote host has an application installed that is missing a security update.
Description
The version of Microsoft Visual Studio Code installed on the remote host is prior to 1.98.0. It is, therefore, affected by multiple vulnerabilities:

- Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. (CVE-2025-26631)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Microsoft Visual Studio Code 1.98.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0012
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-26631
XREF IAVA:2025-A-0179-S
Plugin Information
Published: 2025/03/14, Modified: 2025/04/10
Plugin Output

tcp/445/cifs


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Installed version : 1.81.1
Fixed version : 1.98.0
235854 - Security Update for Microsoft Visual Studio Code (May 2025)
-
Synopsis
The remote host has an application installed that is missing a security update.
Description
The version of Microsoft Visual Studio Code installed on the remote Windows host is prior to 1.100.1. It is, therefore, affected by an unspecified security feature bypass vulnerability.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update to Microsoft Visual Studio Code 1.100.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.1 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N)
VPR Score
5.1
EPSS Score
0.0006
CVSS v2.0 Base Score
5.6 (CVSS2#AV:L/AC:L/Au:N/C:C/I:P/A:N)
STIG Severity
I
References
CVE CVE-2025-21264
XREF IAVA:2025-A-0333-S
XREF CWE:552
Plugin Information
Published: 2025/05/13, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Installed version : 1.81.1
Fixed version : 1.100.1
181339 - Security Update for Microsoft Visual Studio Code (September 2023)
-
Synopsis
The remote host has an application installed that is missing a security update.
Description
The version of Microsoft Visual Studio Code installed on the remote host is prior to 1.82.1. It is, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version
See Also
Solution
Upgrade to Microsoft Visual Studio Code 1.82.1 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0128
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36742
CVE CVE-2023-39956
XREF IAVA:2023-A-0482-S
Plugin Information
Published: 2023/09/13, Modified: 2024/10/23
Plugin Output

tcp/445/cifs


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Installed version : 1.81.1
Fixed version : 1.82.1
265431 - Security Update for Microsoft Visual Studio Code (September 2025)
-
Synopsis
The remote host has an application installed that is missing a security update.
Description
The version of Microsoft Visual Studio Code installed on the remote host is prior to 1.104.0. It is, therefore, affected by multiple vulnerabilities:

- Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. (CVE-2025-55319)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Microsoft Visual Studio Code 1.104.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0008
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-55319
XREF IAVA:2025-A-0689
Plugin Information
Published: 2025/09/19, Modified: 2025/09/19
Plugin Output

tcp/445/cifs


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Installed version : 1.81.1
Fixed version : 1.104.0
168395 - Security Updates for Microsoft .NET Framework (April 2022)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by a denial of service vulnerability.
See Also
http://www.nessus.org/u?496ec3f1
http://www.nessus.org/u?eff833d3
https://support.microsoft.com/en-us/help/5012117
https://support.microsoft.com/en-us/help/5012118
https://support.microsoft.com/en-us/help/5012119
https://support.microsoft.com/en-us/help/5012120
https://support.microsoft.com/en-us/help/5012121
https://support.microsoft.com/en-us/help/5012122
https://support.microsoft.com/en-us/help/5012123
https://support.microsoft.com/en-us/help/5012124
https://support.microsoft.com/en-us/help/5012125
https://support.microsoft.com/en-us/help/5012128
https://support.microsoft.com/en-us/help/5012129
https://support.microsoft.com/en-us/help/5012130
https://support.microsoft.com/en-us/help/5012131
https://support.microsoft.com/en-us/help/5012136
https://support.microsoft.com/en-us/help/5012137
https://support.microsoft.com/en-us/help/5012138
https://support.microsoft.com/en-us/help/5012139
https://support.microsoft.com/en-us/help/5012140
https://support.microsoft.com/en-us/help/5012141
https://support.microsoft.com/en-us/help/5012142
https://support.microsoft.com/en-us/help/5012143
https://support.microsoft.com/en-us/help/5012144
https://support.microsoft.com/en-us/help/5012145
https://support.microsoft.com/en-us/help/5012146
https://support.microsoft.com/en-us/help/5012147
https://support.microsoft.com/en-us/help/5012148
https://support.microsoft.com/en-us/help/5012149
https://support.microsoft.com/en-us/help/5012150
https://support.microsoft.com/en-us/help/5012151
https://support.microsoft.com/en-us/help/5012152
https://support.microsoft.com/en-us/help/5012153
https://support.microsoft.com/en-us/help/5012154
https://support.microsoft.com/en-us/help/5012155
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0433
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
4.1 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-26832
MSKB 5012117
MSKB 5012118
MSKB 5012119
MSKB 5012120
MSKB 5012121
MSKB 5012122
MSKB 5012123
MSKB 5012124
MSKB 5012125
MSKB 5012128
MSKB 5012129
MSKB 5012130
MSKB 5012131
MSKB 5012136
MSKB 5012137
MSKB 5012138
MSKB 5012139
MSKB 5012140
MSKB 5012141
MSKB 5012142
MSKB 5012143
MSKB 5012144
MSKB 5012145
MSKB 5012146
MSKB 5012147
MSKB 5012148
MSKB 5012149
MSKB 5012150
MSKB 5012151
MSKB 5012152
MSKB 5012153
MSKB 5012154
MSKB 5012155
XREF MSFT:MS22-5012117
XREF MSFT:MS22-5012118
XREF MSFT:MS22-5012119
XREF MSFT:MS22-5012120
XREF MSFT:MS22-5012121
XREF MSFT:MS22-5012122
XREF MSFT:MS22-5012123
XREF MSFT:MS22-5012124
XREF MSFT:MS22-5012125
XREF MSFT:MS22-5012128
XREF MSFT:MS22-5012129
XREF MSFT:MS22-5012130
XREF MSFT:MS22-5012131
XREF MSFT:MS22-5012136
XREF MSFT:MS22-5012137
XREF MSFT:MS22-5012138
XREF MSFT:MS22-5012139
XREF MSFT:MS22-5012140
XREF MSFT:MS22-5012141
XREF MSFT:MS22-5012142
XREF MSFT:MS22-5012143
XREF MSFT:MS22-5012144
XREF MSFT:MS22-5012145
XREF MSFT:MS22-5012146
XREF MSFT:MS22-5012147
XREF MSFT:MS22-5012148
XREF MSFT:MS22-5012149
XREF MSFT:MS22-5012150
XREF MSFT:MS22-5012151
XREF MSFT:MS22-5012152
XREF MSFT:MS22-5012153
XREF MSFT:MS22-5012154
XREF MSFT:MS22-5012155
XREF IAVA:2022-A-0143-S
Plugin Information
Published: 2022/12/05, Modified: 2023/09/20
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5012119

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.web.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4494.0

193217 - Security Updates for Microsoft .NET Framework (April 2024)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by remote code execution vulnerability.
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.547
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-21409
MSKB 5036604
MSKB 5036605
MSKB 5036606
MSKB 5036607
MSKB 5036608
MSKB 5036609
MSKB 5036610
MSKB 5036611
MSKB 5036612
MSKB 5036613
MSKB 5036614
MSKB 5036615
MSKB 5036618
MSKB 5036619
MSKB 5036620
MSKB 5036621
MSKB 5036624
MSKB 5036625
MSKB 5036626
MSKB 5036627
MSKB 5036631
MSKB 5036632
MSKB 5036633
MSKB 5036634
MSKB 5036636
MSKB 5036637
XREF MSFT:MS24-5036604
XREF MSFT:MS24-5036605
XREF MSFT:MS24-5036606
XREF MSFT:MS24-5036607
XREF MSFT:MS24-5036608
XREF MSFT:MS24-5036609
XREF MSFT:MS24-5036610
XREF MSFT:MS24-5036611
XREF MSFT:MS24-5036612
XREF MSFT:MS24-5036613
XREF MSFT:MS24-5036614
XREF MSFT:MS24-5036615
XREF MSFT:MS24-5036618
XREF MSFT:MS24-5036619
XREF MSFT:MS24-5036620
XREF MSFT:MS24-5036621
XREF MSFT:MS24-5036624
XREF MSFT:MS24-5036625
XREF MSFT:MS24-5036626
XREF MSFT:MS24-5036627
XREF MSFT:MS24-5036631
XREF MSFT:MS24-5036632
XREF MSFT:MS24-5036633
XREF MSFT:MS24-5036634
XREF MSFT:MS24-5036636
XREF MSFT:MS24-5036637
XREF IAVA:2024-A-0219-S
Plugin Information
Published: 2024/04/11, Modified: 2024/07/12
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5036610

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.runtime.serialization.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4718.0

139598 - Security Updates for Microsoft .NET Framework (August 2020)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. (CVE-2020-1476)

- A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. (CVE-2020-1046)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.068
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-1046
CVE CVE-2020-1476
MSKB 4569751
MSKB 4571709
MSKB 4569748
MSKB 4569749
MSKB 4569746
MSKB 4571692
MSKB 4569745
MSKB 4571741
MSKB 4570506
MSKB 4570507
MSKB 4571694
MSKB 4570505
MSKB 4570502
MSKB 4570503
MSKB 4570500
MSKB 4570501
MSKB 4570508
MSKB 4570509
XREF MSFT:MS20-4569751
XREF MSFT:MS20-4571709
XREF MSFT:MS20-4569748
XREF MSFT:MS20-4569749
XREF MSFT:MS20-4569746
XREF MSFT:MS20-4571692
XREF MSFT:MS20-4569745
XREF MSFT:MS20-4571741
XREF MSFT:MS20-4570506
XREF MSFT:MS20-4570507
XREF MSFT:MS20-4571694
XREF MSFT:MS20-4570505
XREF MSFT:MS20-4570502
XREF MSFT:MS20-4570503
XREF MSFT:MS20-4570500
XREF MSFT:MS20-4570501
XREF MSFT:MS20-4570508
XREF MSFT:MS20-4570509
XREF IAVA:2020-A-0368-S
XREF CEA-ID:CEA-2020-0101
Plugin Information
Published: 2020/08/14, Modified: 2022/12/06
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 4569750

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.web.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4210.0

179664 - Security Updates for Microsoft .NET Framework (August 2023)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by multiple vulnerabilities, as follows:

- A remote code execution vulnerability in applications running on IIS using their parent application's Application Pool which can lead to privilege escalation and other security bypasses. (CVE-2023-36899)

- A spoofing vulnerability where an unauthenticated remote attacker can sign ClickOnce deployments without a valid code signing certificate. (CVE-2023-36873)
See Also
http://www.nessus.org/u?31a7e1cb
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36873
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36899
https://support.microsoft.com/en-us/help/5028946
https://support.microsoft.com/en-us/help/5028947
https://support.microsoft.com/en-us/help/5028948
https://support.microsoft.com/en-us/help/5028950
https://support.microsoft.com/en-us/help/5028951
https://support.microsoft.com/en-us/help/5028952
https://support.microsoft.com/en-us/help/5028953
https://support.microsoft.com/en-us/help/5028954
https://support.microsoft.com/en-us/help/5028955
https://support.microsoft.com/en-us/help/5028956
https://support.microsoft.com/en-us/help/5028957
https://support.microsoft.com/en-us/help/5028958
https://support.microsoft.com/en-us/help/5028960
https://support.microsoft.com/en-us/help/5028961
https://support.microsoft.com/en-us/help/5028962
https://support.microsoft.com/en-us/help/5028963
https://support.microsoft.com/en-us/help/5028967
https://support.microsoft.com/en-us/help/5028968
https://support.microsoft.com/en-us/help/5028969
https://support.microsoft.com/en-us/help/5028970
https://support.microsoft.com/en-us/help/5028973
https://support.microsoft.com/en-us/help/5028974
https://support.microsoft.com/en-us/help/5028975
https://support.microsoft.com/en-us/help/5028976
https://support.microsoft.com/en-us/help/5028977
https://support.microsoft.com/en-us/help/5028978
https://support.microsoft.com/en-us/help/5028979
https://support.microsoft.com/en-us/help/5028980
https://support.microsoft.com/en-us/help/5028981
https://support.microsoft.com/en-us/help/5028982
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.6966
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.0 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36873
CVE CVE-2023-36899
MSKB 5028946
MSKB 5028947
MSKB 5028948
MSKB 5028950
MSKB 5028951
MSKB 5028952
MSKB 5028953
MSKB 5028954
MSKB 5028955
MSKB 5028956
MSKB 5028957
MSKB 5028958
MSKB 5028960
MSKB 5028961
MSKB 5028962
MSKB 5028963
MSKB 5028967
MSKB 5028968
MSKB 5028969
MSKB 5028970
MSKB 5028973
MSKB 5028974
MSKB 5028975
MSKB 5028976
MSKB 5028977
MSKB 5028978
MSKB 5028979
MSKB 5028980
MSKB 5028981
MSKB 5028982
XREF MSFT:MS23-5028946
XREF MSFT:MS23-5028947
XREF MSFT:MS23-5028948
XREF MSFT:MS23-5028950
XREF MSFT:MS23-5028951
XREF MSFT:MS23-5028952
XREF MSFT:MS23-5028953
XREF MSFT:MS23-5028954
XREF MSFT:MS23-5028955
XREF MSFT:MS23-5028956
XREF MSFT:MS23-5028957
XREF MSFT:MS23-5028958
XREF MSFT:MS23-5028960
XREF MSFT:MS23-5028961
XREF MSFT:MS23-5028962
XREF MSFT:MS23-5028963
XREF MSFT:MS23-5028967
XREF MSFT:MS23-5028968
XREF MSFT:MS23-5028969
XREF MSFT:MS23-5028970
XREF MSFT:MS23-5028973
XREF MSFT:MS23-5028974
XREF MSFT:MS23-5028975
XREF MSFT:MS23-5028976
XREF MSFT:MS23-5028977
XREF MSFT:MS23-5028978
XREF MSFT:MS23-5028979
XREF MSFT:MS23-5028980
XREF MSFT:MS23-5028981
XREF MSFT:MS23-5028982
XREF IAVA:2023-A-0406-S
Plugin Information
Published: 2023/08/10, Modified: 2023/09/15
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5028953

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.windows.forms.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4654.0

168745 - Security Updates for Microsoft .NET Framework (December 2022)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability in the handling of XPS files.
See Also
http://www.nessus.org/u?0d29de7c
http://www.nessus.org/u?e40dadbd
https://support.microsoft.com/en-us/help/5020859
https://support.microsoft.com/en-us/help/5020860
https://support.microsoft.com/en-us/help/5020861
https://support.microsoft.com/en-us/help/5020862
https://support.microsoft.com/en-us/help/5020866
https://support.microsoft.com/en-us/help/5020867
https://support.microsoft.com/en-us/help/5020868
https://support.microsoft.com/en-us/help/5020869
https://support.microsoft.com/en-us/help/5020872
https://support.microsoft.com/en-us/help/5020873
https://support.microsoft.com/en-us/help/5020874
https://support.microsoft.com/en-us/help/5020875
https://support.microsoft.com/en-us/help/5020876
https://support.microsoft.com/en-us/help/5020877
https://support.microsoft.com/en-us/help/5020878
https://support.microsoft.com/en-us/help/5020879
https://support.microsoft.com/en-us/help/5020880
https://support.microsoft.com/en-us/help/5020881
https://support.microsoft.com/en-us/help/5020882
https://support.microsoft.com/en-us/help/5020883
https://support.microsoft.com/en-us/help/5020894
https://support.microsoft.com/en-us/help/5020895
https://support.microsoft.com/en-us/help/5020896
https://support.microsoft.com/en-us/help/5020897
https://support.microsoft.com/en-us/help/5020898
https://support.microsoft.com/en-us/help/5020899
https://support.microsoft.com/en-us/help/5020900
https://support.microsoft.com/en-us/help/5020901
https://support.microsoft.com/en-us/help/5020902
https://support.microsoft.com/en-us/help/5020903
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0893
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-41089
MSKB 5020859
MSKB 5020860
MSKB 5020861
MSKB 5020862
MSKB 5020866
MSKB 5020867
MSKB 5020868
MSKB 5020869
MSKB 5020872
MSKB 5020873
MSKB 5020874
MSKB 5020875
MSKB 5020876
MSKB 5020877
MSKB 5020878
MSKB 5020879
MSKB 5020880
MSKB 5020881
MSKB 5020882
MSKB 5020883
MSKB 5020894
MSKB 5020895
MSKB 5020896
MSKB 5020897
MSKB 5020898
MSKB 5020899
MSKB 5020900
MSKB 5020901
MSKB 5020902
MSKB 5020903
XREF MSFT:MS22-5020859
XREF MSFT:MS22-5020860
XREF MSFT:MS22-5020861
XREF MSFT:MS22-5020862
XREF MSFT:MS22-5020866
XREF MSFT:MS22-5020867
XREF MSFT:MS22-5020868
XREF MSFT:MS22-5020869
XREF MSFT:MS22-5020872
XREF MSFT:MS22-5020873
XREF MSFT:MS22-5020874
XREF MSFT:MS22-5020875
XREF MSFT:MS22-5020876
XREF MSFT:MS22-5020877
XREF MSFT:MS22-5020878
XREF MSFT:MS22-5020879
XREF MSFT:MS22-5020880
XREF MSFT:MS22-5020881
XREF MSFT:MS22-5020882
XREF MSFT:MS22-5020883
XREF MSFT:MS22-5020894
XREF MSFT:MS22-5020895
XREF MSFT:MS22-5020896
XREF MSFT:MS22-5020897
XREF MSFT:MS22-5020898
XREF MSFT:MS22-5020899
XREF MSFT:MS22-5020900
XREF MSFT:MS22-5020901
XREF MSFT:MS22-5020902
XREF MSFT:MS22-5020903
XREF IAVA:2022-A-0534-S
Plugin Information
Published: 2022/12/15, Modified: 2023/11/20
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5020874

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.core.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4590.0

168396 - Security Updates for Microsoft .NET Framework (February 2021)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by a denial of service vulnerability.
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.1799
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-24111
MSKB 4578950
MSKB 4578951
MSKB 4578952
MSKB 4578953
MSKB 4600944
MSKB 4600945
MSKB 4600957
MSKB 4601048
MSKB 4601050
MSKB 4601051
MSKB 4601052
MSKB 4601054
MSKB 4601055
MSKB 4601056
MSKB 4601057
MSKB 4601058
MSKB 4601060
MSKB 4601089
MSKB 4601090
MSKB 4601091
MSKB 4601092
MSKB 4601093
MSKB 4601094
XREF MSFT:MS21-4578950
XREF MSFT:MS21-4578951
XREF MSFT:MS21-4578952
XREF MSFT:MS21-4578953
XREF MSFT:MS21-4600944
XREF MSFT:MS21-4600945
XREF MSFT:MS21-4600957
XREF MSFT:MS21-4601048
XREF MSFT:MS21-4601050
XREF MSFT:MS21-4601051
XREF MSFT:MS21-4601052
XREF MSFT:MS21-4601054
XREF MSFT:MS21-4601055
XREF MSFT:MS21-4601056
XREF MSFT:MS21-4601057
XREF MSFT:MS21-4601058
XREF MSFT:MS21-4601060
XREF MSFT:MS21-4601089
XREF MSFT:MS21-4601090
XREF MSFT:MS21-4601091
XREF MSFT:MS21-4601092
XREF MSFT:MS21-4601093
XREF MSFT:MS21-4601094
XREF IAVA:2021-A-0079-S
Plugin Information
Published: 2022/12/05, Modified: 2022/12/06
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 4601055

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.web.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4330.0

171598 - Security Updates for Microsoft .NET Framework (February 2023)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by multiple vulnerabilities, as follows:

- A denial of service (DoS) vulnerability. (CVE-2023-21722)

- A remote code execution vulnerability. (CVE-2023-21808)
See Also
http://www.nessus.org/u?5bd7d30c
http://www.nessus.org/u?42dae88f
http://www.nessus.org/u?db0b1765
https://support.microsoft.com/en-us/help/5022497
https://support.microsoft.com/en-us/help/5022498
https://support.microsoft.com/en-us/help/5022499
https://support.microsoft.com/en-us/help/5022501
https://support.microsoft.com/en-us/help/5022502
https://support.microsoft.com/en-us/help/5022503
https://support.microsoft.com/en-us/help/5022504
https://support.microsoft.com/en-us/help/5022505
https://support.microsoft.com/en-us/help/5022506
https://support.microsoft.com/en-us/help/5022507
https://support.microsoft.com/en-us/help/5022508
https://support.microsoft.com/en-us/help/5022509
https://support.microsoft.com/en-us/help/5022511
https://support.microsoft.com/en-us/help/5022512
https://support.microsoft.com/en-us/help/5022513
https://support.microsoft.com/en-us/help/5022514
https://support.microsoft.com/en-us/help/5022515
https://support.microsoft.com/en-us/help/5022516
https://support.microsoft.com/en-us/help/5022520
https://support.microsoft.com/en-us/help/5022521
https://support.microsoft.com/en-us/help/5022522
https://support.microsoft.com/en-us/help/5022523
https://support.microsoft.com/en-us/help/5022524
https://support.microsoft.com/en-us/help/5022525
https://support.microsoft.com/en-us/help/5022526
https://support.microsoft.com/en-us/help/5022529
https://support.microsoft.com/en-us/help/5022530
https://support.microsoft.com/en-us/help/5022531
https://support.microsoft.com/en-us/help/5022574
https://support.microsoft.com/en-us/help/5022575
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0118
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-21722
CVE CVE-2023-21808
MSKB 5022497
MSKB 5022498
MSKB 5022499
MSKB 5022501
MSKB 5022502
MSKB 5022503
MSKB 5022504
MSKB 5022505
MSKB 5022506
MSKB 5022507
MSKB 5022508
MSKB 5022509
MSKB 5022511
MSKB 5022512
MSKB 5022513
MSKB 5022514
MSKB 5022515
MSKB 5022516
MSKB 5022520
MSKB 5022521
MSKB 5022522
MSKB 5022523
MSKB 5022524
MSKB 5022525
MSKB 5022526
MSKB 5022529
MSKB 5022530
MSKB 5022531
MSKB 5022574
MSKB 5022575
XREF MSFT:MS23-5022497
XREF MSFT:MS23-5022498
XREF MSFT:MS23-5022499
XREF MSFT:MS23-5022501
XREF MSFT:MS23-5022502
XREF MSFT:MS23-5022503
XREF MSFT:MS23-5022504
XREF MSFT:MS23-5022505
XREF MSFT:MS23-5022506
XREF MSFT:MS23-5022507
XREF MSFT:MS23-5022508
XREF MSFT:MS23-5022509
XREF MSFT:MS23-5022511
XREF MSFT:MS23-5022512
XREF MSFT:MS23-5022513
XREF MSFT:MS23-5022514
XREF MSFT:MS23-5022515
XREF MSFT:MS23-5022516
XREF MSFT:MS23-5022520
XREF MSFT:MS23-5022521
XREF MSFT:MS23-5022522
XREF MSFT:MS23-5022523
XREF MSFT:MS23-5022524
XREF MSFT:MS23-5022525
XREF MSFT:MS23-5022526
XREF MSFT:MS23-5022529
XREF MSFT:MS23-5022530
XREF MSFT:MS23-5022531
XREF MSFT:MS23-5022574
XREF MSFT:MS23-5022575
XREF IAVA:2023-A-0087-S
Plugin Information
Published: 2023/02/17, Modified: 2023/09/04
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5022504

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.core.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4614.0

168397 - Security Updates for Microsoft .NET Framework (January 2022)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by a denial of service vulnerability.
See Also
http://www.nessus.org/u?a191b934
http://www.nessus.org/u?0717522a
https://support.microsoft.com/en-us/help/5008858
https://support.microsoft.com/en-us/help/5008859
https://support.microsoft.com/en-us/help/5008860
https://support.microsoft.com/en-us/help/5008865
https://support.microsoft.com/en-us/help/5008866
https://support.microsoft.com/en-us/help/5008867
https://support.microsoft.com/en-us/help/5008868
https://support.microsoft.com/en-us/help/5008869
https://support.microsoft.com/en-us/help/5008870
https://support.microsoft.com/en-us/help/5008873
https://support.microsoft.com/en-us/help/5008874
https://support.microsoft.com/en-us/help/5008875
https://support.microsoft.com/en-us/help/5008876
https://support.microsoft.com/en-us/help/5008877
https://support.microsoft.com/en-us/help/5008878
https://support.microsoft.com/en-us/help/5008879
https://support.microsoft.com/en-us/help/5008880
https://support.microsoft.com/en-us/help/5008881
https://support.microsoft.com/en-us/help/5008882
https://support.microsoft.com/en-us/help/5008883
https://support.microsoft.com/en-us/help/5008885
https://support.microsoft.com/en-us/help/5008886
https://support.microsoft.com/en-us/help/5008887
https://support.microsoft.com/en-us/help/5008888
https://support.microsoft.com/en-us/help/5008889
https://support.microsoft.com/en-us/help/5008890
https://support.microsoft.com/en-us/help/5008891
https://support.microsoft.com/en-us/help/5008892
https://support.microsoft.com/en-us/help/5008893
https://support.microsoft.com/en-us/help/5008894
https://support.microsoft.com/en-us/help/5008895
https://support.microsoft.com/en-us/help/5008896
https://support.microsoft.com/en-us/help/5008897
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.155
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2022-21911
MSKB 5008858
MSKB 5008859
MSKB 5008860
MSKB 5008865
MSKB 5008866
MSKB 5008867
MSKB 5008868
MSKB 5008869
MSKB 5008870
MSKB 5008873
MSKB 5008874
MSKB 5008875
MSKB 5008876
MSKB 5008877
MSKB 5008878
MSKB 5008879
MSKB 5008880
MSKB 5008881
MSKB 5008882
MSKB 5008883
MSKB 5008885
MSKB 5008886
MSKB 5008887
MSKB 5008888
MSKB 5008889
MSKB 5008890
MSKB 5008891
MSKB 5008892
MSKB 5008893
MSKB 5008894
MSKB 5008895
MSKB 5008896
MSKB 5008897
XREF MSFT:MS22-5008858
XREF MSFT:MS22-5008859
XREF MSFT:MS22-5008860
XREF MSFT:MS22-5008865
XREF MSFT:MS22-5008866
XREF MSFT:MS22-5008867
XREF MSFT:MS22-5008868
XREF MSFT:MS22-5008869
XREF MSFT:MS22-5008870
XREF MSFT:MS22-5008873
XREF MSFT:MS22-5008874
XREF MSFT:MS22-5008875
XREF MSFT:MS22-5008876
XREF MSFT:MS22-5008877
XREF MSFT:MS22-5008878
XREF MSFT:MS22-5008879
XREF MSFT:MS22-5008880
XREF MSFT:MS22-5008881
XREF MSFT:MS22-5008882
XREF MSFT:MS22-5008883
XREF MSFT:MS22-5008885
XREF MSFT:MS22-5008886
XREF MSFT:MS22-5008887
XREF MSFT:MS22-5008888
XREF MSFT:MS22-5008889
XREF MSFT:MS22-5008890
XREF MSFT:MS22-5008891
XREF MSFT:MS22-5008892
XREF MSFT:MS22-5008893
XREF MSFT:MS22-5008894
XREF MSFT:MS22-5008895
XREF MSFT:MS22-5008896
XREF MSFT:MS22-5008897
Plugin Information
Published: 2022/12/05, Modified: 2022/12/06
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5008878

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.web.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4465.0

214274 - Security Updates for Microsoft .NET Framework (January 2025)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by multiple denial of service vulnerabilities, as follows:

- A remote code execution vulnerability. An attacker can exploit this issue to cause the affected component to execute unauthorized code. (CVE-2025-21176)

Note that Nessus has relied upon on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0035
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21176
MSKB 5049614
MSKB 5049618
MSKB 5049620
MSKB 5049622
MSKB 5049624
MSKB 5049993
MSKB 5050013
MSKB 5050180
MSKB 5050181
MSKB 5050182
MSKB 5050183
MSKB 5050184
MSKB 5050185
MSKB 5050186
MSKB 5050187
MSKB 5050188
MSKB 5050416
XREF MSFT:MS25-5049614
XREF MSFT:MS25-5049618
XREF MSFT:MS25-5049620
XREF MSFT:MS25-5049622
XREF MSFT:MS25-5049624
XREF MSFT:MS25-5049993
XREF MSFT:MS25-5050013
XREF MSFT:MS25-5050180
XREF MSFT:MS25-5050181
XREF MSFT:MS25-5050182
XREF MSFT:MS25-5050183
XREF MSFT:MS25-5050184
XREF MSFT:MS25-5050185
XREF MSFT:MS25-5050186
XREF MSFT:MS25-5050187
XREF MSFT:MS25-5050188
XREF MSFT:MS25-5050416
XREF IAVA:2025-A-0028-S
XREF CWE:126
Plugin Information
Published: 2025/01/16, Modified: 2025/04/09
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5049615

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4775.0

138464 - Security Updates for Microsoft .NET Framework (July 2020)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the process responsible for deserialization of the XML content. (CVE-2020-1147)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.9343
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1147
MSKB 4565489
MSKB 4565508
MSKB 4565511
MSKB 4565513
MSKB 4565627
MSKB 4565628
MSKB 4565630
MSKB 4565631
MSKB 4565633
MSKB 4566466
MSKB 4566467
MSKB 4566468
MSKB 4566469
MSKB 4566516
MSKB 4566517
MSKB 4566518
MSKB 4566519
MSKB 4566520
XREF IAVA:2020-A-0305-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
XREF MSFT:MS20-4565489
XREF MSFT:MS20-4565508
XREF MSFT:MS20-4565511
XREF MSFT:MS20-4565513
XREF MSFT:MS20-4565627
XREF MSFT:MS20-4565628
XREF MSFT:MS20-4565630
XREF MSFT:MS20-4565631
XREF MSFT:MS20-4565633
XREF MSFT:MS20-4566466
XREF MSFT:MS20-4566467
XREF MSFT:MS20-4566468
XREF MSFT:MS20-4566469
XREF MSFT:MS20-4566516
XREF MSFT:MS20-4566517
XREF MSFT:MS20-4566518
XREF MSFT:MS20-4566519
XREF MSFT:MS20-4566520
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2020/07/14, Modified: 2023/04/25
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 4565632

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.configuration.dll has not been patched.
Remote version : 4.8.3761.0
Should be : 4.8.4190.0

202304 - Security Updates for Microsoft .NET Framework (July 2024)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by remote code execution vulnerability.
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0035
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38081
MSKB 5041017
MSKB 5041020
MSKB 5041016
MSKB 5041023
MSKB 5041022
MSKB 5041021
MSKB 5041026
MSKB 5039885
MSKB 5041024
MSKB 5041027
MSKB 5039895
MSKB 5041019
MSKB 5041018
XREF MSFT:MS24-5041017
XREF MSFT:MS24-5041020
XREF MSFT:MS24-5041016
XREF MSFT:MS24-5041023
XREF MSFT:MS24-5041022
XREF MSFT:MS24-5041021
XREF MSFT:MS24-5041026
XREF MSFT:MS24-5039885
XREF MSFT:MS24-5041024
XREF MSFT:MS24-5041027
XREF MSFT:MS24-5039895
XREF MSFT:MS24-5041019
XREF MSFT:MS24-5041018
XREF IAVA:2024-A-0399-S
Plugin Information
Published: 2024/07/12, Modified: 2024/10/11
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5039886

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.windows.forms.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4739.0

177393 - Security Updates for Microsoft .NET Framework (June 2023)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by multiple vulnerabilities, as follows:

- A remote code execution vulnerability in the MSDIA SDK where corrupted PDBs can cause a heap overflow.
(CVE-2023-24897)

- A remote code execution vulnerability in WPF where the BAML offers other ways to instantiate types.
(CVE-2023-21808)

- A remote code execution vulnerability in the WPF XAML parser (CVE-2023-24895)
See Also
http://www.nessus.org/u?283f4db9
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24895
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24897
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24936
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29326
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29331
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32030
https://support.microsoft.com/en-us/help/5027107
https://support.microsoft.com/en-us/help/5027108
https://support.microsoft.com/en-us/help/5027109
https://support.microsoft.com/en-us/help/5027110
https://support.microsoft.com/en-us/help/5027111
https://support.microsoft.com/en-us/help/5027112
https://support.microsoft.com/en-us/help/5027113
https://support.microsoft.com/en-us/help/5027114
https://support.microsoft.com/en-us/help/5027115
https://support.microsoft.com/en-us/help/5027116
https://support.microsoft.com/en-us/help/5027117
https://support.microsoft.com/en-us/help/5027118
https://support.microsoft.com/en-us/help/5027119
https://support.microsoft.com/en-us/help/5027121
https://support.microsoft.com/en-us/help/5027122
https://support.microsoft.com/en-us/help/5027123
https://support.microsoft.com/en-us/help/5027124
https://support.microsoft.com/en-us/help/5027125
https://support.microsoft.com/en-us/help/5027126
https://support.microsoft.com/en-us/help/5027127
https://support.microsoft.com/en-us/help/5027128
https://support.microsoft.com/en-us/help/5027129
https://support.microsoft.com/en-us/help/5027131
https://support.microsoft.com/en-us/help/5027132
https://support.microsoft.com/en-us/help/5027133
https://support.microsoft.com/en-us/help/5027134
https://support.microsoft.com/en-us/help/5027138
https://support.microsoft.com/en-us/help/5027139
https://support.microsoft.com/en-us/help/5027140
https://support.microsoft.com/en-us/help/5027141
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.1026
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-24895
CVE CVE-2023-24897
CVE CVE-2023-24936
CVE CVE-2023-29326
CVE CVE-2023-29330
CVE CVE-2023-29331
CVE CVE-2023-32030
MSKB 5027107
MSKB 5027108
MSKB 5027109
MSKB 5027110
MSKB 5027111
MSKB 5027112
MSKB 5027113
MSKB 5027114
MSKB 5027115
MSKB 5027116
MSKB 5027117
MSKB 5027118
MSKB 5027119
MSKB 5027121
MSKB 5027122
MSKB 5027123
MSKB 5027124
MSKB 5027125
MSKB 5027126
MSKB 5027127
MSKB 5027128
MSKB 5027129
MSKB 5027131
MSKB 5027132
MSKB 5027133
MSKB 5027134
MSKB 5027138
MSKB 5027139
MSKB 5027140
MSKB 5027141
XREF MSFT:MS23-5027107
XREF MSFT:MS23-5027108
XREF MSFT:MS23-5027109
XREF MSFT:MS23-5027110
XREF MSFT:MS23-5027111
XREF MSFT:MS23-5027112
XREF MSFT:MS23-5027113
XREF MSFT:MS23-5027114
XREF MSFT:MS23-5027115
XREF MSFT:MS23-5027116
XREF MSFT:MS23-5027117
XREF MSFT:MS23-5027118
XREF MSFT:MS23-5027119
XREF MSFT:MS23-5027121
XREF MSFT:MS23-5027122
XREF MSFT:MS23-5027123
XREF MSFT:MS23-5027124
XREF MSFT:MS23-5027125
XREF MSFT:MS23-5027126
XREF MSFT:MS23-5027127
XREF MSFT:MS23-5027128
XREF MSFT:MS23-5027129
XREF MSFT:MS23-5027131
XREF MSFT:MS23-5027132
XREF MSFT:MS23-5027133
XREF MSFT:MS23-5027134
XREF MSFT:MS23-5027138
XREF MSFT:MS23-5027139
XREF MSFT:MS23-5027140
XREF MSFT:MS23-5027141
XREF IAVA:2023-A-0291-S
Plugin Information
Published: 2023/06/16, Modified: 2023/08/11
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5027124

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.core.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4644.0

136564 - Security Updates for Microsoft .NET Framework (May 2020)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. (CVE-2020-1108)

- An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. (CVE-2020-1066)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.2954
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
4.0 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-1066
CVE CVE-2020-1108
MSKB 4556812
MSKB 4556826
MSKB 4556807
MSKB 4556813
MSKB 4556406
MSKB 4556405
MSKB 4556404
MSKB 4556403
MSKB 4556402
MSKB 4556401
MSKB 4556400
MSKB 4556441
MSKB 4552926
MSKB 4552931
MSKB 4556399
MSKB 4552928
MSKB 4552929
XREF MSFT:MS20-4556812
XREF MSFT:MS20-4556826
XREF MSFT:MS20-4556807
XREF MSFT:MS20-4556813
XREF MSFT:MS20-4556406
XREF MSFT:MS20-4556405
XREF MSFT:MS20-4556404
XREF MSFT:MS20-4556403
XREF MSFT:MS20-4556402
XREF MSFT:MS20-4556401
XREF MSFT:MS20-4556400
XREF MSFT:MS20-4556441
XREF MSFT:MS20-4552926
XREF MSFT:MS20-4552931
XREF MSFT:MS20-4556399
XREF MSFT:MS20-4552928
XREF MSFT:MS20-4552929
XREF IAVA:2020-A-0207-S
Exploitable With
Core Impact (true)
Plugin Information
Published: 2020/05/13, Modified: 2023/01/30
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 4552930

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.runtime.serialization.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4180.0

208757 - Security Updates for Microsoft .NET Framework (October 2024)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by multiple denial of service vulnerabilities, as follows:

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2024-43483, CVE-2024-43484)

Note that Nessus has relied upon on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0338
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-43483
CVE CVE-2024-43484
MSKB 5044009
MSKB 5044010
MSKB 5044011
MSKB 5044012
MSKB 5044016
MSKB 5044017
MSKB 5044018
MSKB 5044019
MSKB 5044021
MSKB 5044022
MSKB 5044023
MSKB 5044024
MSKB 5044025
MSKB 5044026
MSKB 5044028
MSKB 5044029
MSKB 5044030
MSKB 5044033
MSKB 5044035
XREF MSFT:MS24-5044009
XREF MSFT:MS24-5044010
XREF MSFT:MS24-5044011
XREF MSFT:MS24-5044012
XREF MSFT:MS24-5044016
XREF MSFT:MS24-5044017
XREF MSFT:MS24-5044018
XREF MSFT:MS24-5044019
XREF MSFT:MS24-5044021
XREF MSFT:MS24-5044022
XREF MSFT:MS24-5044023
XREF MSFT:MS24-5044024
XREF MSFT:MS24-5044025
XREF MSFT:MS24-5044026
XREF MSFT:MS24-5044028
XREF MSFT:MS24-5044029
XREF MSFT:MS24-5044030
XREF MSFT:MS24-5044033
XREF MSFT:MS24-5044035
XREF IAVA:2024-A-0632-S
Plugin Information
Published: 2024/10/11, Modified: 2025/03/31
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5044022

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.web.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4762.0

181375 - Security Updates for Microsoft .NET Framework (September 2023)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by multiple vulnerabilities, as follows:

- Multiple vulnerabilities in DiaSymReader.dll where parsing an corrupted PDB can result in remote code execution. (CVE-2023-36792, CVE-2023-36793, CVE-2023-36794 CVE-2023-36796)

- A vulnerability in the WPF XML parser where an unsandboxed parser can lead to remote code execution.
(CVE-2023-36788)
See Also
http://www.nessus.org/u?3bbdfd35
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36788
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36792
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36793
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36794
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36796
https://support.microsoft.com/en-us/help/5029915
https://support.microsoft.com/en-us/help/5029916
https://support.microsoft.com/en-us/help/5029917
https://support.microsoft.com/en-us/help/5029919
https://support.microsoft.com/en-us/help/5029920
https://support.microsoft.com/en-us/help/5029921
https://support.microsoft.com/en-us/help/5029922
https://support.microsoft.com/en-us/help/5029923
https://support.microsoft.com/en-us/help/5029924
https://support.microsoft.com/en-us/help/5029925
https://support.microsoft.com/en-us/help/5029926
https://support.microsoft.com/en-us/help/5029927
https://support.microsoft.com/en-us/help/5029928
https://support.microsoft.com/en-us/help/5029929
https://support.microsoft.com/en-us/help/5029931
https://support.microsoft.com/en-us/help/5029932
https://support.microsoft.com/en-us/help/5029933
https://support.microsoft.com/en-us/help/5029937
https://support.microsoft.com/en-us/help/5029938
https://support.microsoft.com/en-us/help/5029940
https://support.microsoft.com/en-us/help/5029941
https://support.microsoft.com/en-us/help/5029942
https://support.microsoft.com/en-us/help/5029943
https://support.microsoft.com/en-us/help/5029944
https://support.microsoft.com/en-us/help/5029945
https://support.microsoft.com/en-us/help/5029946
https://support.microsoft.com/en-us/help/5029947
https://support.microsoft.com/en-us/help/5029948
https://support.microsoft.com/en-us/help/5030030
https://support.microsoft.com/en-us/help/5030160
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0156
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36788
CVE CVE-2023-36792
CVE CVE-2023-36793
CVE CVE-2023-36794
CVE CVE-2023-36796
MSKB 5029915
MSKB 5029916
MSKB 5029917
MSKB 5029919
MSKB 5029920
MSKB 5029921
MSKB 5029922
MSKB 5029923
MSKB 5029924
MSKB 5029925
MSKB 5029926
MSKB 5029927
MSKB 5029928
MSKB 5029929
MSKB 5029931
MSKB 5029932
MSKB 5029933
MSKB 5029937
MSKB 5029938
MSKB 5029940
MSKB 5029941
MSKB 5029942
MSKB 5029943
MSKB 5029944
MSKB 5029945
MSKB 5029946
MSKB 5029947
MSKB 5029948
MSKB 5030030
MSKB 5030160
XREF MSFT:MS23-5029916
XREF MSFT:MS23-5029917
XREF MSFT:MS23-5029919
XREF MSFT:MS23-5029920
XREF MSFT:MS23-5029921
XREF MSFT:MS23-5029922
XREF MSFT:MS23-5029923
XREF MSFT:MS23-5029924
XREF MSFT:MS23-5029925
XREF MSFT:MS23-5029926
XREF MSFT:MS23-5029927
XREF MSFT:MS23-5029928
XREF MSFT:MS23-5029929
XREF MSFT:MS23-5029931
XREF MSFT:MS23-5029932
XREF MSFT:MS23-5029933
XREF MSFT:MS23-5029937
XREF MSFT:MS23-5029938
XREF MSFT:MS23-5029940
XREF MSFT:MS23-5029941
XREF MSFT:MS23-5029942
XREF MSFT:MS23-5029943
XREF MSFT:MS23-5029944
XREF MSFT:MS23-5029945
XREF MSFT:MS23-5029946
XREF MSFT:MS23-5029947
XREF MSFT:MS23-5029948
XREF MSFT:MS23-5030030
XREF MSFT:MS23-5030160
XREF IAVA:2023-A-0470-S
Plugin Information
Published: 2023/09/13, Modified: 2023/11/16
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5029925

C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll has not been patched.
Remote version : 14.8.3761.0
Should be : 14.8.4667.0

182957 - Security Updates for Microsoft ASP.NET Core (October 2023)
-
Synopsis
The Microsoft ASP.NET core installations on the remote host are affected by a denial of service vulnerability.
Description
The version of ASP.NET core installed on the remote host is affected by a denial of service (DoS) vulnerability. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update ASP.NET Core Runtime to version 6.0.23, 7.0.12, 8.0.0-rc2 or later
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.9
EPSS Score
0.9443
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
6.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-44487
XREF CISA-KNOWN-EXPLOITED:2023/10/31
XREF IAVA:2023-A-0545-S
XREF CEA-ID:CEA-2024-0004
XREF IAVB:2023-B-0083-S
Plugin Information
Published: 2023/10/12, Modified: 2024/02/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\7.0.10
Installed version : 7.0.10
Fixed version : 7.0.12

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\7.0.10
Installed version : 7.0.10
Fixed version : 7.0.12
175450 - Security Updates for Microsoft SQL Server (April 2023)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-23384) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.4
EPSS Score
0.0079
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.5 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-23384
MSKB 5020863
MSKB 5021037
MSKB 5021045
MSKB 5021112
MSKB 5021123
MSKB 5021124
MSKB 5021125
MSKB 5021126
MSKB 5021127
MSKB 5021128
MSKB 5021129
MSKB 5021522
XREF MSFT:MS23-5020863
XREF MSFT:MS23-5021037
XREF MSFT:MS23-5021045
XREF MSFT:MS23-5021112
XREF MSFT:MS23-5021123
XREF MSFT:MS23-5021124
XREF MSFT:MS23-5021125
XREF MSFT:MS23-5021126
XREF MSFT:MS23-5021127
XREF MSFT:MS23-5021128
XREF MSFT:MS23-5021129
XREF MSFT:MS23-5021522
XREF IAVA:2023-A-0189-S
Plugin Information
Published: 2023/05/12, Modified: 2023/08/11
Plugin Output

tcp/445/cifs



KB : 5021125
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2101.7

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
249129 - Security Updates for Microsoft SQL Server (August 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- An elevation of privilege vulnerability. (CVE-2025-53727)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53727
MSKB 5063814
MSKB 5063756
MSKB 5063757
MSKB 5063758
MSKB 5063759
MSKB 5063760
MSKB 5063761
MSKB 5063762
XREF MSFT:MS25-5063814
XREF MSFT:MS25-5063756
XREF MSFT:MS25-5063757
XREF MSFT:MS25-5063758
XREF MSFT:MS25-5063759
XREF MSFT:MS25-5063760
XREF MSFT:MS25-5063761
XREF MSFT:MS25-5063762
XREF IAVA:2025-A-0599-S
XREF CWE:89
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



KB : 5063758
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2140.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
207070 - Security Updates for Microsoft SQL Server (CVE-2024-43474) (September 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- An information disclosure vulnerability. An authenticated, remote attacker can exploit this to disclose sensitive database and file information. (CVE-2024-43474)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.051
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-43474
MSKB 5042215
MSKB 5042214
MSKB 5042217
XREF MSFT:MS24-5042215
XREF MSFT:MS24-5042214
XREF MSFT:MS24-5042217
XREF IAVA:2024-A-0565-S
Plugin Information
Published: 2024/09/12, Modified: 2025/01/08
Plugin Output

tcp/445/cifs



KB : 5042214
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2120.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
171604 - Security Updates for Microsoft SQL Server (February 2023)
-
Synopsis
The Microsoft SQL Server installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft SQL Server installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-21528, CVE-2023-21568, CVE-2023-21704, CVE-2023-21705, CVE-2023-21713, CVE-2023-21718)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5021126
-KB5021129
-KB5021522
-KB5021127
-KB5021045
-KB5021037
-KB5021128
-KB5021124
-KB5021125
-KB5020863
-KB5021112
-KB5021123
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0056
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-21528
CVE CVE-2023-21568
CVE CVE-2023-21704
CVE CVE-2023-21705
CVE CVE-2023-21713
CVE CVE-2023-21718
MSKB 5020863
MSKB 5021112
MSKB 5021126
MSKB 5021129
MSKB 5021522
MSKB 5021127
MSKB 5021045
MSKB 5021037
MSKB 5021128
MSKB 5021123
MSKB 5021124
MSKB 5021125
XREF MSFT:MS23-5020863
XREF MSFT:MS23-5021112
XREF MSFT:MS23-5021126
XREF MSFT:MS23-5021129
XREF MSFT:MS23-5021522
XREF MSFT:MS23-5021127
XREF MSFT:MS23-5021045
XREF MSFT:MS23-5021037
XREF MSFT:MS23-5021128
XREF MSFT:MS23-5021124
XREF MSFT:MS23-5021125
XREF IAVA:2023-A-0086
Plugin Information
Published: 2023/02/17, Modified: 2023/09/04
Plugin Output

tcp/445/cifs



KB : 5021125
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2101.7

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
145033 - Security Updates for Microsoft SQL Server (January 2021)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by an elevation of privilege vulnerability. An authenticated, remote attacker can exploit this issue, to gain elevated privileges.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4583456
-KB4583457
-KB4583458
-KB4583459
-KB4583460
-KB4583461
-KB4583462
-KB4583463
-KB4583465
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0159
CVSS v2.0 Base Score
6.5 (CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
4.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-1636
MSKB 4583456
MSKB 4583457
MSKB 4583458
MSKB 4583459
MSKB 4583460
MSKB 4583461
MSKB 4583462
MSKB 4583463
MSKB 4583465
XREF IAVA:2021-A-0018-S
XREF MSFT:MS21-4583456
XREF MSFT:MS21-4583457
XREF MSFT:MS21-4583458
XREF MSFT:MS21-4583459
XREF MSFT:MS21-4583460
XREF MSFT:MS21-4583461
XREF MSFT:MS21-4583462
XREF MSFT:MS21-4583463
XREF MSFT:MS21-4583465
XREF CEA-ID:CEA-2021-0001
Plugin Information
Published: 2021/01/15, Modified: 2023/06/29
Plugin Output

tcp/445/cifs



KB : 4583458
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2080.9

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
216604 - Security Updates for Microsoft SQL Server (July 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft SQL Server installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-20701, CVE-2024-21303, CVE-2024-21308, CVE-2024-21317, CVE-2024-21331, CVE-2024-21332, CVE-2024-21333, CVE-2024-21335, CVE-2024-21373, CVE-2024-21398, CVE-2024-21414, CVE-2024-21415, CVE-2024-21425, CVE-2024-21428, CVE-2024-21449, CVE-2024-28928, CVE-2024-35256, CVE-2024-35271, CVE-2024-35272, CVE-2024-37318, CVE-2024-37319, CVE-2024-37320, CVE-2024-37321, CVE-2024-37322, CVE-2024-37323, CVE-2024-37324, CVE-2024-37326, CVE-2024-37327, CVE-2024-37328, CVE-2024-37329, CVE-2024-37330, CVE-2024-37331, CVE-2024-37332, CVE-2024-37333, CVE-2024-37334, CVE-2024-37336, CVE-2024-38087, CVE-2024-38088)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5040942
-KB5040939
-KB5040936
-KB5040986
-KB5040944
-KB5040948
-KB5040940
-KB5040946
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0692
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2024-20701
CVE CVE-2024-21303
CVE CVE-2024-21308
CVE CVE-2024-21317
CVE CVE-2024-21331
CVE CVE-2024-21332
CVE CVE-2024-21333
CVE CVE-2024-21335
CVE CVE-2024-21373
CVE CVE-2024-21398
CVE CVE-2024-21414
CVE CVE-2024-21415
CVE CVE-2024-21425
CVE CVE-2024-21428
CVE CVE-2024-21449
CVE CVE-2024-28928
CVE CVE-2024-35256
CVE CVE-2024-35271
CVE CVE-2024-35272
CVE CVE-2024-37318
CVE CVE-2024-37319
CVE CVE-2024-37320
CVE CVE-2024-37321
CVE CVE-2024-37322
CVE CVE-2024-37323
CVE CVE-2024-37324
CVE CVE-2024-37326
CVE CVE-2024-37327
CVE CVE-2024-37328
CVE CVE-2024-37329
CVE CVE-2024-37330
CVE CVE-2024-37331
CVE CVE-2024-37332
CVE CVE-2024-37333
CVE CVE-2024-37334
CVE CVE-2024-37336
CVE CVE-2024-38087
CVE CVE-2024-38088
MSKB 5040942
MSKB 5040939
MSKB 5040936
MSKB 5040986
MSKB 5040944
MSKB 5040948
MSKB 5040940
MSKB 5040946
XREF MSFT:MS24-5040942
XREF MSFT:MS24-5040939
XREF MSFT:MS24-5040936
XREF MSFT:MS24-5040986
XREF MSFT:MS24-5040944
XREF MSFT:MS24-5040948
XREF MSFT:MS24-5040940
XREF MSFT:MS24-5040946
XREF CWE:121
XREF CWE:122
XREF CWE:190
XREF CWE:415
XREF CWE:416
Plugin Information
Published: 2025/02/21, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



KB : 5040986
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2116.2

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
241544 - Security Updates for Microsoft SQL Server (July 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-49717)

- Information disclosure vulnerabilities. An authenticated, remote attacker can exploit this to disclose sensitive database and file information. (CVE-2025-49718, CVE-2025-49719)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
VPR Score
8.1
EPSS Score
0.003
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49717
CVE CVE-2025-49718
CVE CVE-2025-49719
MSKB 5058712
MSKB 5058713
MSKB 5058714
MSKB 5058716
MSKB 5058717
MSKB 5058718
MSKB 5058721
MSKB 5058722
XREF MSFT:MS25-5058712
XREF MSFT:MS25-5058713
XREF MSFT:MS25-5058714
XREF MSFT:MS25-5058716
XREF MSFT:MS25-5058717
XREF MSFT:MS25-5058718
XREF MSFT:MS25-5058721
XREF MSFT:MS25-5058722
XREF IAVA:2025-A-0492-S
XREF CWE:20
XREF CWE:122
XREF CWE:908
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



KB : 5058713
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2135.5

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
162393 - Security Updates for Microsoft SQL Server (June 2022)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-29143)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5015371
-KB5014553
-KB5014351
-KB5014353
-KB5014354
-KB5014356
-KB5014365
-KB5014355
-KB5014165
-KB5014164
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0048
CVSS v2.0 Base Score
6.0 (CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-29143
MSKB 5015371
MSKB 5014553
MSKB 5014351
MSKB 5014353
MSKB 5014354
MSKB 5014356
MSKB 5014365
MSKB 5014355
MSKB 5014165
MSKB 5014164
XREF IAVA:2022-A-0244-S
XREF MSFT:MS22-5015371
XREF MSFT:MS22-5014553
XREF MSFT:MS22-5014351
XREF MSFT:MS22-5014353
XREF MSFT:MS22-5014354
XREF MSFT:MS22-5014356
XREF MSFT:MS22-5014365
XREF MSFT:MS22-5014355
XREF MSFT:MS22-5014165
XREF MSFT:MS22-5014164
Plugin Information
Published: 2022/06/17, Modified: 2024/10/23
Plugin Output

tcp/445/cifs



KB : 5014356
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2095.3

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
211472 - Security Updates for Microsoft SQL Server (November 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-38255, CVE-2024-43459, CVE-2024-43462, CVE-2024-48993, CVE-2024-48994, CVE-2024-48995, CVE-2024-48996, CVE-2024-48997, CVE-2024-48998, CVE-2024-48999, CVE-2024-49000, CVE-2024-49001, CVE-2024-49002, CVE-2024-49003, CVE-2024-49004, CVE-2024-49005, CVE-2024-49006, CVE-2024-49007, CVE-2024-49008, CVE-2024-49009, CVE-2024-49010, CVE-2024-49011, CVE-2024-49012, CVE-2024-49013, CVE-2024-49014, CVE-2024-49015, CVE-2024-49016, CVE-2024-49017, CVE-2024-49018, CVE-2024-49021, CVE-2024-49043)
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0596
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38255
CVE CVE-2024-43459
CVE CVE-2024-43462
CVE CVE-2024-48993
CVE CVE-2024-48994
CVE CVE-2024-48995
CVE CVE-2024-48996
CVE CVE-2024-48997
CVE CVE-2024-48998
CVE CVE-2024-48999
CVE CVE-2024-49000
CVE CVE-2024-49001
CVE CVE-2024-49002
CVE CVE-2024-49003
CVE CVE-2024-49004
CVE CVE-2024-49005
CVE CVE-2024-49006
CVE CVE-2024-49007
CVE CVE-2024-49008
CVE CVE-2024-49009
CVE CVE-2024-49010
CVE CVE-2024-49011
CVE CVE-2024-49012
CVE CVE-2024-49013
CVE CVE-2024-49014
CVE CVE-2024-49015
CVE CVE-2024-49016
CVE CVE-2024-49017
CVE CVE-2024-49018
CVE CVE-2024-49021
CVE CVE-2024-49043
MSKB 5046855
MSKB 5046856
MSKB 5046857
MSKB 5046858
MSKB 5046859
MSKB 5046860
MSKB 5046861
MSKB 5046862
XREF MSFT:MS24-5046855
XREF MSFT:MS24-5046856
XREF MSFT:MS24-5046857
XREF MSFT:MS24-5046858
XREF MSFT:MS24-5046859
XREF MSFT:MS24-5046860
XREF MSFT:MS24-5046861
XREF MSFT:MS24-5046862
XREF IAVA:2024-A-0731
Plugin Information
Published: 2024/11/15, Modified: 2024/11/18
Plugin Output

tcp/445/cifs



KB : 5046859
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2130.3

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
275459 - Security Updates for Microsoft SQL Server (November 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected a vulnerability:

- Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. (CVE-2025-59499)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59499
MSKB 5068400
MSKB 5068401
MSKB 5068402
MSKB 5068403
MSKB 5068404
MSKB 5068405
MSKB 5068406
MSKB 5068407
XREF MSFT:MS25-5068400
XREF MSFT:MS25-5068401
XREF MSFT:MS25-5068402
XREF MSFT:MS25-5068403
XREF MSFT:MS25-5068404
XREF MSFT:MS25-5068405
XREF MSFT:MS25-5068406
XREF MSFT:MS25-5068407
XREF IAVA:2025-A-0848
Plugin Information
Published: 2025/11/14, Modified: 2025/11/14
Plugin Output

tcp/445/cifs



KB : 5068405
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2155.2

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
207067 - Security Updates for Microsoft SQL Server (September 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-26186, CVE-2024-26191, CVE-2024-37335, CVE-2024-37338, CVE-2024-37339, CVE-2024-37340)

- An information disclosure vulnerability. An authenticated, remote attacker can exploit this to disclose sensitive database and file information. (CVE-2024-37337, CVE-2024-37342, CVE-2024-37966)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0464
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-26186
CVE CVE-2024-26191
CVE CVE-2024-37335
CVE CVE-2024-37337
CVE CVE-2024-37338
CVE CVE-2024-37339
CVE CVE-2024-37340
CVE CVE-2024-37342
CVE CVE-2024-37966
MSKB 5042578
MSKB 5042749
MSKB 5042211
MSKB 5042215
MSKB 5042214
MSKB 5042217
XREF MSFT:MS24-5042578
XREF MSFT:MS24-5042749
XREF MSFT:MS24-5042211
XREF MSFT:MS24-5042215
XREF MSFT:MS24-5042214
XREF MSFT:MS24-5042217
XREF IAVA:2024-A-0565-S
Plugin Information
Published: 2024/09/12, Modified: 2024/11/15
Plugin Output

tcp/445/cifs



KB : 5042214
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2120.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
261809 - Security Updates for Microsoft SQL Server (September 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerabilities:

- Improper Handling of Exceptional Conditions in Newtonsoft.Json (CVE-2024-21907)

- An information disclosure vulnerability (CVE-2025-47997)

- A privilege escalation vulnerability (CVE-2025-55227)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0252
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2024-21907
CVE CVE-2025-47997
CVE CVE-2025-55227
MSKB 5065220
MSKB 5065221
MSKB 5065222
MSKB 5065223
MSKB 5065224
MSKB 5065225
MSKB 5065226
MSKB 5065227
XREF MSFT:MS25-5065220
XREF MSFT:MS25-5065221
XREF MSFT:MS25-5065222
XREF MSFT:MS25-5065223
XREF MSFT:MS25-5065224
XREF MSFT:MS25-5065225
XREF MSFT:MS25-5065226
XREF MSFT:MS25-5065227
XREF IAVA:2025-A-0669
XREF CWE:77
XREF CWE:200
XREF CWE:362
XREF CWE:755
Plugin Information
Published: 2025/09/09, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



KB : 5065223
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2145.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER

193160 - Security Updates for Microsoft SQL Server ODBC Driver (April 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server driver installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-28929)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-28930)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-28931)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for the Microsoft SQL Driver.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0893
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/04/10, Modified: 2025/01/22
Plugin Output

tcp/0


Path : C:\Windows\System32\msodbcsql17.dll
Installed version : 17.10.3.1
Fixed version : 17.10.6

178851 - Security Updates for Microsoft SQL Server ODBC Driver (June 2023)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server driver installation on the remote host is missing a security update. It is, therefore, affected by remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for the Microsoft SQL Driver.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0374
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2023/07/26, Modified: 2023/07/27
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msodbcsql17.dll
Installed version : 17.10.3.1
Fixed version : 17.10.4.1

183036 - Security Updates for Microsoft SQL Server ODBC Driver (October 2023)
-
Synopsis
The Microsoft SQL Server ODBC Driver installed on the remote host is missing a security update.
Description
The Microsoft SQL Server ODBC Driver installed on the remote host is missing a security update. It is, therefore, affected by multiple vulnerabilities.

- An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-36417, CVE-2023-36420, CVE-2023-36730, CVE-2023-36785)

- An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2023-36728)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for the Microsoft SQL ODBC Driver.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0164
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2023/10/13, Modified: 2023/10/16
Plugin Output

tcp/0


Path : C:\Windows\System32\msodbcsql17.dll
Installed version : 17.10.3.1
Fixed version : 17.10.5.1

193161 - Security Updates for Microsoft SQL Server OLE DB Driver (April 2024)
-
Synopsis
The Microsoft SQL Server OLE DB Driver installed on the remote host is missing a security update.
Description
The Microsoft SQL Server OLE DB Driver installed on the remote host is missing a security update. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-28906)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-28908)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-28909)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for the Microsoft SQL OLE DB Driver.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0906
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/04/10, Modified: 2025/08/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msoledbsql.dll
Installed version : 18.6.5.0
Fixed version : 18.7.2
205300 - Security Updates for Microsoft SQL Server OLE DB Driver (July 2024)
-
Synopsis
The Microsoft SQL Server OLE DB Driver installed on the remote host is missing a security update.
Description
The Microsoft SQL Server OLE DB Driver installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker could exploit the vulnerability by tricking an authenticated user (UI:R) into attempting to connect to a malicious SQL server database via a connection driver. This could result in the database returning malicious data that could cause arbitrary code execution on the client.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for the Microsoft SQL OLE DB Driver.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0243
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2024/08/09, Modified: 2025/08/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msoledbsql.dll
Installed version : 18.6.5.0
Fixed version : 18.7.4
178852 - Security Updates for Microsoft SQL Server OLE DB Driver (June 2023)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server driver installation on the remote host is missing a security update. It is, therefore, affected by remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for the Microsoft SQL Driver.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0463
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-29349
CVE CVE-2023-32028
CVE CVE-2023-38169
XREF IAVA:2023-A-0410-S
Plugin Information
Published: 2023/07/26, Modified: 2025/08/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msoledbsql.dll
Installed version : 18.6.5.0
Fixed version : 18.6.6
182968 - Security Updates for Microsoft SQL Server OLE DB Driver (October 2023)
-
Synopsis
The Microsoft SQL Server OLE DB Driver installed on the remote host is missing a security update.
Description
The Microsoft SQL Server OLE DB Driver installed on the remote host is missing a security update. It is, therefore, affected by multiple vulnerabilities.

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-36417)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2023-36728) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for the Microsoft SQL OLE DB Driver.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0155
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36417
CVE CVE-2023-36728
XREF IAVA:2023-A-0541-S
Plugin Information
Published: 2023/10/12, Modified: 2025/08/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msoledbsql.dll
Installed version : 18.6.5.0
Fixed version : 18.6.7
214126 - Security Updates for Microsoft Visual Studio 2022 17.6 / 17.8 / 17.10 Products (January 2025)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- An undisclosed .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)

- An undisclosed Visual Studio Remote Code Execution Vulnerability (CVE-2025-21178)

- An undisclosed .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.10.10 for Visual Studio 2022
- Update 17.8.17 for Visual Studio 2022
- Update 17.6.22 for Visual Studio 2022
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0106
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-50338
CVE CVE-2025-21171
CVE CVE-2025-21172
CVE CVE-2025-21173
CVE CVE-2025-21176
CVE CVE-2025-21178
XREF IAVA:2025-A-0035-S
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:200
XREF CWE:379
Plugin Information
Published: 2025/01/14, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.35707.121 (17.8.17)
232738 - Security Updates for Microsoft Visual Studio 2022 17.8 / 17.10 / 17.12 / 17.13 Products (March 2025)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- An undisclosed ASP.NET Core and xVisual Studio Elevation of Privilege Vulnerability (CVE-2025-24070)

- An undisclosed Visual Studio Elevation of Privilege Vulnerability (CVE-2025-24998)

- An undisclosed Visual Studio Elevation of Privilege Vulnerability (CVE-2025-25003)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.8.19 for Visual Studio 2022
- Update 17.10.12 for Visual Studio 2022
- Update 17.12.6 for Visual Studio 2022
- Update 17.13.3 for Visual Studio 2022
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0015
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-24070
CVE CVE-2025-24998
CVE CVE-2025-25003
XREF IAVA:2025-A-0178
XREF CWE:427
XREF CWE:1390
Plugin Information
Published: 2025/03/14, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.35827.206 (17.8.19)
234217 - Security Updates for Microsoft Visual Studio 2022 17.8 / 17.10 / 17.12 Products (April 2025)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- Improper access control in Visual Studio allows an authorized attacker to eleveate priveleges locally (CVE-2025-29802)

- Improper access control in Visual Studio allows an authorized attacker to eleveate priveleges locally (CVE-2025-29804)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.8.20 for Visual Studio 2022
- Update 17.10.13 for Visual Studio 2022
- Update 17.12.7 for Visual Studio 2022
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-29802
CVE CVE-2025-29804
XREF IAVA:2025-A-0243-S
XREF CWE:284
XREF CWE:427
Plugin Information
Published: 2025/04/11, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.35931.193 (17.8.20)
238333 - Security Updates for Microsoft Visual Studio 2022 Products (June 2025)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. (CVE-2025-30399)

- Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.. (CVE-2025-47959)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.8.22 for Visual Studio 2022
- Update 17.10.16 for Visual Studio 2022
- Update 17.12.9 for Visual Studio 2022
- Update 17.14.5 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-30399
CVE CVE-2025-47959
XREF IAVA:2025-A-0419
XREF CWE:77
XREF CWE:426
Plugin Information
Published: 2025/06/12, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.36129.11 (17.8.22)
236780 - Security Updates for Microsoft Visual Studio 2022/2019 Products (May 2025)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. (CVE-2025-32702)

- Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. (CVE-2025-32703)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 16.11.47 for Visual Studio 2019
- Update 17.8.21 for Visual Studio 2022
- Update 17.10.14 for Visual Studio 2022
- Update 17.12.8 for Visual Studio 2022
- Update 17.13.7 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-32702
CVE CVE-2025-32703
XREF IAVA:2025-A-0336-S
XREF CWE:77
XREF CWE:200
XREF CWE:1220
Plugin Information
Published: 2025/05/15, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.36105.29 (17.8.21)
238332 - Security Updates for Microsoft Visual Studio 2022/2019 Products (May 2025)
-
Synopsis
The Microsoft Visual Studio Products are affected by a Network Spoofing Vulnerability
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by network spoofing vulnerability where External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.8.21 for Visual Studio 2022
- Update 17.10.15 for Visual Studio 2022
- Update 17.12.8 for Visual Studio 2022
- Update 17.13.7 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
8.0 (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0004
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
References
Plugin Information
Published: 2025/06/12, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.36105.29 (17.8.21)
148552 - Security Updates for Microsoft Visual Studio Products (April 2021)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by the multiple vulnerabilities, including the following:

- A privilege escalation vulnerability exists in Microsoft Visual Studio's installer component. An authenticated, local attacker can exploit this, to escalate privileges on an affected system (CVE-2021-27064).

- Several privilege escalation vulnerabilities exist in Microsoft Visual Studio's diagnostic hub standard collector service component. An authenticated, local attacker can exploit these, to escalate privileges on an affected system (CVE-2021-28313, CVE-2021-28321, CVE-2021-28322).

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- KB5001292 (for Visual Studio 2015)
- Update 15.9.35 for Visual Studio 2017
- Update 16.4.21 for Visual Studio 2019
- Update 16.7.14 for Visual Studio 2019
- Update 16.9.4 for Visual Studio 2019
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0111
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-27064
CVE CVE-2021-28313
CVE CVE-2021-28321
CVE CVE-2021-28322
MSKB 5001292
XREF MSFT:MS21-5001292
XREF IAVA:2021-A-0169-S
Plugin Information
Published: 2021/04/14, Modified: 2023/07/25
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1500
174163 - Security Updates for Microsoft Visual Studio Products (April 2023)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- .NET DLL Hijacking Remote Code Execution Vulnerability. (CVE-2023-28260)

- Visual Studio Elevation of Privilege Vulnerability. (CVE-2023-28262)

- Visual Studio Information Disclosure Vulnerability. (CVE-2023-28263)

- Visual Studio Remote Code Execution Vulnerability. (CVE-2023-28296)

- Visual Studio Spoofing Vulnerability. (CVE-2023-28299)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.54 for Visual Studio 2017
- Update 16.11.26 for Visual Studio 2019
- Update 17.0.21 for Visual Studio 2022
- Update 17.2.15 for Visual Studio 2022
- Update 17.4.7 for Visual Studio 2022
- Update 17.5.4 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0463
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-28260
CVE CVE-2023-28262
CVE CVE-2023-28263
CVE CVE-2023-28296
CVE CVE-2023-28299
XREF IAVA:2023-A-0184-S
Plugin Information
Published: 2023/04/12, Modified: 2024/04/08
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.33529.398 (15.9.54)
193088 - Security Updates for Microsoft Visual Studio Products (April 2024)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- A remote code execution vulnerability exists in .NET, .NET Framework, and Visual Studio. An unauthenticated, remote attacker can exploit this to bypass authentication and execute arbitrary code.
(CVE-2024-21409)

- A remote code execution vulnerability exists in the Microsoft ODBC Driver for SQL Server. An unauthenticated, remote attacker can exploit this to bypass authentication and execute arbitrary code.
(CVE-2024-28929, CVE-2024-28930, CVE-2024-28931, CVE-2024-28932, CVE-2024-28933, CVE-2024-28934, CVE-2024-28935, CVE-2024-28936, CVE-2024-28937, CVE-2024-28938)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 16.11.35 for Visual Studio 2019
- Update 17.4.18 for Visual Studio 2022
- Update 17.6.14 for Visual Studio 2022
- Update 17.8.9 for Visual Studio 2022
- Update 17.9.6 for Visual Studio 2022
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.547
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/04/09, Modified: 2024/05/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.34728.176 (17.8.9)
127855 - Security Updates for Microsoft Visual Studio Products (August 2019)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by the following vulnerability :

- An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user. (CVE-2019-1211)
See Also
Solution
Microsoft has released security updates to address this issue.
Risk Factor
Low
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0064
CVSS v2.0 Base Score
3.7 (CVSS2#AV:L/AC:H/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
2.7 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2019/08/13, Modified: 2022/06/27
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.812
139506 - Security Updates for Microsoft Visual Studio Products (August 2020)
-
Synopsis
The Microsoft Visual Studio Products are affected by a denial-of-service vulnerability.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by a denial-of-service vulnerability:

- A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests. (CVE-2020-1597)
Solution
Microsoft has released 15.9.26, 16.0.17, 16.4.12, and 16.7.1 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0644
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1597
XREF IAVA:2020-A-0377-S
XREF CEA-ID:CEA-2020-0101
Plugin Information
Published: 2020/08/11, Modified: 2022/12/05
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1234
119611 - Security Updates for Microsoft Visual Studio Products (December 2018)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by the following vulnerability :

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability. The security update addresses the vulnerability by ensuring the Diagnostics Hub Standard Collector Service properly impersonates file operations.
(CVE-2018-8599)
See Also
Solution
Microsoft has released KB4469516 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0037
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
3.4 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8599
MSKB 4469516
XREF MSFT:MS18-4469516
Plugin Information
Published: 2018/12/13, Modified: 2022/06/27
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.222
131939 - Security Updates for Microsoft Visual Studio Products (December 2019)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. (CVE-2019-1351)

- A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
(CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387)

- A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host. An attacker who successfully exploited this vulnerability could cause a connected guest's computer to open a browser and navigate to a URL without consent from the guest. (CVE-2019-1486)
See Also
Solution
Microsoft has released Visual Studio 2017 15.9.18, Visual Studio 2019 16.0.19, and Visual Studio 2019 16.4.1 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3913
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2019/12/10, Modified: 2024/04/04
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.960
143573 - Security Updates for Microsoft Visual Studio Products (December 2020)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by the following vulnerability:

- An unspecified remote code execution vulnerability exists in Visual Studio. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2020-17156)
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.30 for Visual Studio 2017
- Update 16.0.21 for Visual Studio 2019
- Update 16.4.16 for Visual Studio 2019
- Update 16.7.9 for Visual Studio 2019
- Update 16.8.3 for Visual Studio 2019
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0475
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-17156
XREF IAVA:2020-A-0553-S
Plugin Information
Published: 2020/12/08, Modified: 2025/02/14
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1321
122133 - Security Updates for Microsoft Visual Studio Products (February 2019)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Visual Studio software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2019-0613)

- A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's. An attacker who successfully exploited this vulnerability could use it to bypass security logic intended to ensure that a user-provided URL belonged to a specific hostname or a subdomain of that hostname. This could be used to cause privileged communication to be made to an untrusted service as if it was a trusted service. To exploit the vulnerability, an attacker must provide a URL string to an application that attempts to verify that the URL belongs to a specific hostname or to a subdomain of that hostname. The application must then make an HTTP request to the attacker-provided URL either directly or by sending a processed version of the attacker-provided URL to a web browser.
(CVE-2019-0657)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.0 (26228.73) for Visual Studio 2017
- Update 15.9.7 for Visual Studio 2017 15.9
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.1904
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 106872
BID 106890
CVE CVE-2019-0613
CVE CVE-2019-0657
Plugin Information
Published: 2019/02/12, Modified: 2022/06/27
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.423
146426 - Security Updates for Microsoft Visual Studio Products (February 2021)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-1639)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2021-1721)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.32 for Visual Studio 2017
- Update 16.4.18 for Visual Studio 2019
- Update 16.7.11 for Visual Studio 2019
- Update 16.8.5 for Visual Studio 2019
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0477
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2021-1639
CVE CVE-2021-1721
XREF IAVA:2021-A-0074-S
Plugin Information
Published: 2021/02/11, Modified: 2024/11/29
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1382
190548 - Security Updates for Microsoft Visual Studio Products (February 2024)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2024-21386, CVE-2024-21404)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.4.16 for Visual Studio 2022
- Update 17.6.12 for Visual Studio 2022
- Update 17.8.7 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1026
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-21386
CVE CVE-2024-21404
XREF IAVA:2024-A-0090-S
Plugin Information
Published: 2024/02/14, Modified: 2024/03/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.34601.278 (17.8.7)
216241 - Security Updates for Microsoft Visual Studio Products (February 2025)
-
Synopsis
The Microsoft Visual Studio Products are affected by a privelige elevation vulnerability
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by a privilege elevation vulnerability.
- An attacker could exploit the flaw to gain higher-level access privileges than they are normally allowed. Specifically, in this case, the weakness lies within the Visual Studio Installer. When exploited, it could allow a malicious user or process to bypass certain security controls, potentially resulting in unauthorized system access. This kind of vulnerability is particularly dangerous because it may empower an attacker with administrative rights, granting them the ability to install software, delete files, or even take over system functions. (CVE-2025-21206)
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.12.5 for Visual Studio 2022
- Update 17.10.11 for Visual Studio 2022
- Update 17.8.18 for Visual Studio 2022
- Update 16.11.44 for Visual Studio 2019
- Update 15.9.70 for Visual Studio 2017
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.001
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21206
XREF IAVA:2025-A-0107-S
XREF CWE:427
Plugin Information
Published: 2025/02/13, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.35727.129 (15.9.70)

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.35728.64 (17.8.18)
121065 - Security Updates for Microsoft Visual Studio Products (January 2019)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists when Visual Studio improperly discloses arbitrary file contents if the victim opens a malicious .vscontent file. An attacker who took advantage of this information disclosure could view arbitrary file contents from the computer where the victim launched Visual Studio. To take advantage of the vulnerability, an attacker would need to trick a user into opening a malicious .vscontent file using a vulnerable version of Visual Studio. An attacker would have no way to force a developer to produce this information disclosure. The security update addresses the vulnerability by correcting how Visual Studio loads .vscontent files. (CVE-2019-0537)

- A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ constructs. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted file which was compiled with an affected version of Visual Studio. In an email attack scenario, an attacker could exploit the vulnerability by sending a specially crafted project, or resource file, to the user and convince the user to open the file. (CVE-2019-0546)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- KB4476698
- KB4476755
- Update 15.9.4 for Visual Studio 2017
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.2692
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2019-0537
CVE CVE-2019-0546
MSKB 4476698
MSKB 4476755
XREF MSFT:MS19-4476698
XREF MSFT:MS19-4476755
XREF IAVA:2019-A-0011-S
Plugin Information
Published: 2019/01/10, Modified: 2025/02/14
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.280
126604 - Security Updates for Microsoft Visual Studio Products (July 2019)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files. An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external entity (XXE) declaration. (CVE-2019-1079)

- A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1113)

- An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permissions. An attacker who successfully exploited this vulnerability overwrite arbitrary files with XML content in the security context of the local system. (CVE-2019-1077)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4506161
-KB4506162
-KB4506163
-KB4506164
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3372
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
BID 108931
BID 108977
CVE CVE-2019-1077
CVE CVE-2019-1079
CVE CVE-2019-1113
MSKB 4506161
MSKB 4506162
MSKB 4506163
MSKB 4506164
XREF MSFT:MS19-4506161
XREF MSFT:MS19-4506162
XREF MSFT:MS19-4506163
XREF MSFT:MS19-4506164
XREF IAVA:2019-A-0225-S
Plugin Information
Published: 2019/07/11, Modified: 2025/02/14
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.770
138473 - Security Updates for Microsoft Visual Studio Products (July 2020)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Visual Studio when the software fails to check the source markup of XML file input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the process responsible for deserialization of the XML content. (CVE-2020-1147)

- An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
(CVE-2020-1393)

- An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies. A local attacker who successfully exploited the vulnerability could inject arbitrary code to run in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, a local attacker would need to plant malicious content on an affected computer and wait for another user to launch Visual Studio or Visual Studio Code. (CVE-2020-1416)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- KB4567703
- Update 15.9.25 for Visual Studio 2017
- Update 16.0.16 for Visual Studio 2019
- Update 16.4.11 for Visual Studio 2019
- Update 16.6.4 for Visual Studio 2019
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.9343
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.7 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1147
CVE CVE-2020-1393
CVE CVE-2020-1416
MSKB 4567703
XREF MSFT:MS20-4567703
XREF IAVA:2020-A-0309-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2020/07/14, Modified: 2023/07/25
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1216
202032 - Security Updates for Microsoft Visual Studio Products (July 2024)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- .NET Core and Visual Studio Denial of Service Vulnerability. (CVE-2024-30105, CVE-2024-38095)

- .NET and Visual Studio Remote Code Execution Vulnerability. (CVE-2024-35264)

- .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability. (CVE-2024-38081)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.4.21 for Visual Studio 2022
- Update 17.6.17 for Visual Studio 2022
- Update 17.8.12 for Visual Studio 2022
- Update 17.10.4 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0529
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-30105
CVE CVE-2024-35264
CVE CVE-2024-38081
CVE CVE-2024-38095
XREF IAVA:2024-A-0398-S
XREF IAVA:2024-A-0406-S
Plugin Information
Published: 2024/07/09, Modified: 2025/05/07
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.35027.43 (17.8.12)
241959 - Security Updates for Microsoft Visual Studio Products (July 2025)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities.

- Vulnerability in Gitk where when a user clones an untrusted repository and runs Gitk without additional command arguments, any writable file can be created and truncated. The option 'Support per-file encoding' must have been enabled. (CVE-2025-27613)

- Vulnerability in Gitk where a Git repository can be crafted in such a way that a user who has cloned the repository can be tricked into running any script supplied by the attacker by invoking gitk filename, where filename has a particular structure. (CVE-2025-27614)

- Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. (CVE-2025-49739)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.14.8 for Visual Studio 2022
- Update 17.12.10 for Visual Studio 2022
- Update 17.10.17 for Visual Studio 2022
- Update 17.8.23 for Visual Studio 2022
- Update 16.11.49 for Visual Studio 2019
- Update 15.9.75 for Visual Studio 2017
Risk Factor
Critical
CVSS v4.0 Base Score
8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0008
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-46334
CVE CVE-2025-27613
CVE CVE-2025-27614
CVE CVE-2025-46334
CVE CVE-2025-46835
CVE CVE-2025-48384
CVE CVE-2025-48385
CVE CVE-2025-48386
CVE CVE-2025-49739
XREF IAVA:2025-A-0494
XREF CISA-KNOWN-EXPLOITED:2025/09/15
XREF CWE:59
XREF CWE:73
XREF CWE:78
XREF CWE:88
XREF CWE:120
XREF CWE:436
Plugin Information
Published: 2025/07/11, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.36227.7 (15.9.75)

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.36227.8 (17.8.23)
137271 - Security Updates for Microsoft Visual Studio Products (June 2020)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-1202, CVE-2020-1203)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability. The security update addresses the vulnerability by ensuring the Diagnostics Hub Standard Collector Service properly handles file operations. (CVE-2020-1257, CVE-2020-1278, CVE-2020-1293)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- KB4562053 (for Visual Studio 2015)
- Update 15.9.24 for Visual Studio 2017
- Update 16.0.15 for Visual Studio 2019
- Update 16.4.10 for Visual Studio 2019
- Update 16.6.2 for Visual Studio 2019
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0074
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1202
CVE CVE-2020-1203
CVE CVE-2020-1257
CVE CVE-2020-1278
CVE CVE-2020-1293
MSKB 4562053
XREF MSFT:MS20-4562053
XREF IAVA:2020-A-0257-S
Plugin Information
Published: 2020/06/09, Modified: 2024/03/07
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1177
177249 - Security Updates for Microsoft Visual Studio Products (June 2023)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability in the MSDIA SDK where corrupted PDBs can cause heap overflow, leading to a crash or remote code execution. (CVE-2023-24897)

- A remote code execution vulnerability where specially crafted input to git apply -reject can lead to controlled content writes at arbitrary locations. (CVE-2023-25652)

- A spoofing vulnerability where Github localization messages refer to a hard-coded path instead of respecting the runtime prefix that leads to out-of-bound memory writes and crashes. (CVE-2023-25815)

- An Out-Of-Bounds Write Vulnerability in Autodesk FBX SDK version 2020 or prior may lead to code execution through maliciously crafted FBX files or information disclosure. (CVE-2023-27909)

- An information disclosure vulnerability where a user may be tricked into opening a malicious FBX file. This may exploit a stack buffer overflow (CVE-2023-27910) or heap buffer overflow (CVE-2023-27911) vulnerability in Autodesk FBX SDK 2020 or prior which may lead to remote code execution.

- A remote code execution vulnerability where a configuration file containing a logic error results in arbitrary configuration injection. (CVE-2023-29007)

- A remote code execution vulnerability where the Git for Windows executable responsible for implementing a SOCKS5 proxy is susceptible to picking up an untrusted configuration on multi-user machines. (CVE-2023-29011)

- A remote code execution vulnerability where the Git for Windows Git CMD program incorrectly searches for a program upon startup, leading to silent arbitrary code execution. (CVE-2023-29012)

- A remote code execution vulnerability in the .NET SDK during tool restore which can lead to an elevation of privilege. (CVE-2023-33135)

- An information disclosure vulnerability by the obj file parser in Visual Studio. (CVE-2023-33139)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Patch for the Update 5 for Visual Studio 2013
- Patch for the Update 3 for Visual Studio 2015
- Update 15.9.55 for Visual Studio 2017
- Update 16.11.27 for Visual Studio 2019
- Update 17.0.22 for Visual Studio 2022
- Update 17.2.16 for Visual Studio 2022
- Update 17.4.8 for Visual Studio 2022
- Update 17.6.3 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.1026
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N)
CVSS v2.0 Temporal Score
6.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-21808
CVE CVE-2023-21815
CVE CVE-2023-23381
CVE CVE-2023-24895
CVE CVE-2023-24897
CVE CVE-2023-24936
CVE CVE-2023-25652
CVE CVE-2023-25815
CVE CVE-2023-27909
CVE CVE-2023-27910
CVE CVE-2023-27911
CVE CVE-2023-29007
CVE CVE-2023-29011
CVE CVE-2023-29012
CVE CVE-2023-29331
CVE CVE-2023-33032
CVE CVE-2023-33126
CVE CVE-2023-33128
CVE CVE-2023-33135
CVE CVE-2023-33139
MSKB 5025792
MSKB 5026454
MSKB 5026455
MSKB 5026610
XREF MSFT:MS23-5025792
XREF MSFT:MS23-5026454
XREF MSFT:MS23-5026455
XREF MSFT:MS23-5026610
XREF IAVA:2023-A-0293-S
Plugin Information
Published: 2023/06/13, Modified: 2024/01/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.33801.237 (15.9.55)
122792 - Security Updates for Microsoft Visual Studio Products (March 2019)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited the vulnerability could execute arbitrary code in the context of the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2019-0809)
Solution
Microsoft has released a patch to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0636
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2019-0809
XREF IAVA:2019-A-0079-S
Plugin Information
Published: 2019/03/12, Modified: 2025/02/14
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.518
134381 - Security Updates for Microsoft Visual Studio Products (March 2020)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL. An attacker who successfully exploited this vulnerability could compromise the access tokens, exposing security and privacy risks. (CVE-2020-0884)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations. (CVE-2020-0810)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability. The security update addresses the vulnerability by ensuring the Diagnostics Hub Standard Collector Service properly handles file operations. (CVE-2020-0793)

- A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2020-0789)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- KB4538032
- Update 15.9.21 for Visual Studio 2017
- Update 16.0.12 for Visual Studio 2019
- Update 16.4.6 for Visual Studio 2019
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0163
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2020-0789
CVE CVE-2020-0793
CVE CVE-2020-0810
CVE CVE-2020-0884
MSKB 4538032
XREF MSFT:MS20-4538032
Plugin Information
Published: 2020/03/10, Modified: 2024/03/22
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1064
147749 - Security Updates for Microsoft Visual Studio Products (March 2021)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-21300)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.34 for Visual Studio 2017
- Update 16.7.13 for Visual Studio 2019
- Update 16.8.7 for Visual Studio 2019
- Update 16.9.1 for Visual Studio 2019
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.6009
CVSS v2.0 Base Score
5.1 (CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
4.2 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-21300
XREF IAVA:2021-A-0133-S
Exploitable With
Metasploit (true)
Plugin Information
Published: 2021/03/12, Modified: 2022/06/27
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1440
172528 - Security Updates for Microsoft Visual Studio Products (March 2023)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8 can be tricked into using its local clone optimization even when using a non-local transport.
As a workaround, avoid cloning repositories from untrusted sources with --recurse-submodules. Instead, consider cloning repositories without recursively cloning their submodules, and instead run git submodule update at each layer. Before doing so, inspect each new .gitmodules file to ensure that it does not contain suspicious module URLs. (CVE-2023-22490)

- Prior to Git for Windows version 2.39.2, by carefully crafting DLL and putting into a subdirectory of a specific name living next to the Git for Windows installer, Windows can be tricked into side-loading said DLL. This potentially allows users with local write access to place malicious payloads in a location where automated upgrades might run the Git for Windows installer with elevation. If upgrading is impractical, never leave untrusted files in the Downloads folder or its sub-folders before executing the Git for Windows installer, or move the installer into a different directory before executing it.
(CVE-2023-22743)

- Prior to Git for Windows version 2.39.2, when gitk is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick users into running untrusted code. As a workaround, avoid using gitk (or Git Visualize History functionality) in clones of untrusted repositories. (CVE-2023-23618)

- Git is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to git apply, a path outside the working tree can be overwritten as the user who is running git apply. As a workaround, use git apply --stat to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link. (CVE-2023-23946)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.53 for Visual Studio 2017
- Update 16.11.25 for Visual Studio 2019
- Update 17.0.20 for Visual Studio 2022
- Update 17.2.14 for Visual Studio 2022
- Update 17.4.6 for Visual Studio 2022
- Update 17.5.2 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0084
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N)
CVSS v2.0 Temporal Score
6.1 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-22490
CVE CVE-2023-22743
CVE CVE-2023-23618
CVE CVE-2023-23946
XREF IAVA:2023-A-0138-S
Plugin Information
Published: 2023/03/14, Modified: 2024/04/08
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.33423.255 (15.9.53)
191932 - Security Updates for Microsoft Visual Studio Products (March 2024)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple denial of service vulnerabilities. An attacker can exploit these issues to cause the affected component to deny system or application services.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.4.17 for Visual Studio 2022
- Update 17.6.13 for Visual Studio 2022
- Update 17.8.8 for Visual Studio 2022
- Update 17.9.3 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1026
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-21392
CVE CVE-2024-26190
XREF IAVA:2024-A-0153-S
Plugin Information
Published: 2024/03/12, Modified: 2024/04/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.34701.33 (17.8.8)
125255 - Security Updates for Microsoft Visual Studio Products (May 2019)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by an elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file deletion in arbitrary locations. (CVE-2019-0727)
See Also
Solution
Microsoft has released KB4489639 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0029
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
References
BID 108225
CVE CVE-2019-0727
MSKB 4489639
XREF MSFT:MS19-4489639
XREF CEA-ID:CEA-2019-0326
Plugin Information
Published: 2019/05/17, Modified: 2022/12/05
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.665
136515 - Security Updates for Microsoft Visual Studio Products (May 2020)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication.
(CVE-2020-1108)

- A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. (CVE-2020-1161)
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.23 for Visual Studio 2017
- Update 16.0.14 for Visual Studio 2019
- Update 16.4.8 for Visual Studio 2019
- Update 16.5.5 for Visual Studio 2019
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0206
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2020/05/12, Modified: 2024/03/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1146
149436 - Security Updates for Microsoft Visual Studio Products (May 2021)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by the multiple vulnerabilities, including the following:

- A remote code execution vulnerability exists in Visual Studio. An unauthenticated, remote attacker can exploit this to bypass authentication and execute arbitrary commands (CVE-2021-27068).

- A privilege escalation vulnerability exists in Visual Studio. An authenticated, local attacker can exploit this to escalate their privileges of an affected system (CVE-2021-31204)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.36 for Visual Studio 2017
- Update 16.4.22 for Visual Studio 2019
- Update 16.7.15 for Visual Studio 2019
- Update 16.9.5 for Visual Studio 2019
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0769
CVSS v2.0 Base Score
6.5 (CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-27068
CVE CVE-2021-31204
XREF IAVA:2021-A-0220-S
Plugin Information
Published: 2021/05/12, Modified: 2024/01/02
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1525
154051 - Security Updates for Microsoft Visual Studio Products (October 2021)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- Multiple denial of service (DoS) vulnerabilities exist in Visual Studio. An unauthenticated, remote attacker can exploit these issues to impose a DoS condition on the application. (CVE-2021-1971, CVE-2021-3449, CVE-2021-3450)

- An information disclosure vulnerability exists in Visual Studio. An unauthenticated, remote attacker can exploit this to disclose potentially sensitive information. (CVE-2021-41355)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.40 for Visual Studio 2017
- Update 16.4.27 for Visual Studio 2019
- Update 16.7.20 for Visual Studio 2019
- Update 16.9.12 for Visual Studio 2019
- Update 16.11.5 for Visual Studio 2019
Risk Factor
Medium
CVSS v3.0 Base Score
7.4 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
CVSS v3.0 Temporal Score
6.9 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.0
EPSS Score
0.1126
CVSS v2.0 Base Score
5.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N)
CVSS v2.0 Temporal Score
4.8 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-1971
CVE CVE-2021-3449
CVE CVE-2021-3450
CVE CVE-2021-41355
XREF IAVA:2021-A-0471-S
XREF CEA-ID:CEA-2021-0025
Plugin Information
Published: 2021/10/13, Modified: 2023/11/28
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1705
208750 - Security Updates for Microsoft Visual Studio Products (October 2024)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- .NET Denial of Service Vulnerability in System.Security.Cryptography.Cose, System.IO.Packaging, System.Runtime.Caching (CVE-2024-43483)
- .NET Denial of Service Vulnerability in System.IO.Packaging (CVE-2024-43484)

- Elevation of Privilege Vulnerability in Visual Studio C++ Redistributable Installer (CVE-2024-43590)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.6.20 for Visual Studio 2022
- Update 17.8.15 for Visual Studio 2022
- Update 17.11.5 for Visual Studio 2022
- Update 17.10.8 for Visual Studio 2022
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0338
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-43483
CVE CVE-2024-43484
CVE CVE-2024-43485
CVE CVE-2024-43590
CVE CVE-2024-43603
XREF IAVA:2024-A-0626-S
Plugin Information
Published: 2024/10/11, Modified: 2024/11/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.35326.199 (17.8.15)
128708 - Security Updates for Microsoft Visual Studio Products (September 2019)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability.
The security update addresses the vulnerability by ensuring the Diagnostics Hub Standard Collector Service properly impersonates file operations. (CVE-2019-1232)

- A denial of service vulnerability exists when .NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core web application.
The vulnerability can be exploited remotely, without authentication. The update addresses the vulnerability by correcting how the .NET Core web application handles web requests. (CVE-2019-1301)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- KB4513696
- Update 15.9.16 for Visual Studio 2017
- Update 16.0.8 for Visual Studio 2019
- Update 15.0 (26228.98) for Visual Studio 2017
- Update 16.2.5 for Visual Studio 2019
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0275
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
3.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2019-1232
CVE CVE-2019-1301
MSKB 4513696
XREF MSFT:MS19-4513696
XREF IAVA:2019-A-0332-S
Plugin Information
Published: 2019/09/11, Modified: 2025/02/14
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.858
140465 - Security Updates for Microsoft Visual Studio Products (September 2020)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles file operations. (CVE-2020-1133)

- A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2020-16856, CVE-2020-16874)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles data operations. (CVE-2020-1130)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4571480
-KB4571479
-KB4571481
-KB4576950
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0587
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1130
CVE CVE-2020-1133
CVE CVE-2020-16856
CVE CVE-2020-16874
MSKB 4571480
MSKB 4571479
MSKB 4571481
MSKB 4576950
XREF MSFT:MS20-4571480
XREF MSFT:MS20-4571479
XREF MSFT:MS20-4571481
XREF MSFT:MS20-4576950
XREF IAVA:2020-A-0414-S
XREF CEA-ID:CEA-2020-0118
Plugin Information
Published: 2020/09/10, Modified: 2022/12/05
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1259
153428 - Security Updates for Microsoft Visual Studio Products (September 2021)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A permission assignment vulnerability exists in Visual Studio after installing the Game development with C++ and selecting the Unreal Engine Installer workload. The system is vulnerable to LPE during the installation it creates a directory with write access to all users. (CVE-2021-26434)

- A code execution vulnerability exists in Visual Studio due to incorrect memory handling. An unauthenticated, local attacker can exploit this to bypass authentication and execute arbitrary commands. (CVE-2021-36952)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.39 for Visual Studio 2017
- Update 16.4.26 for Visual Studio 2019
- Update 16.7.19 for Visual Studio 2019
- Update 16.9.11 for Visual Studio 2019
- Update 16.11.3 for Visual Studio 2019
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.2011
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-26434
CVE CVE-2021-36952
XREF IAVA:2021-A-0430-S
Plugin Information
Published: 2021/09/16, Modified: 2023/11/30
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1684
233416 - VMware Tools 11.x / 12.x < 12.5.1 Authentication Bypass (VMSA-2025-0005)
-
Synopsis
The virtualization tool suite is installed on the remote Windows host is affected by an authentication bypass vulnerability.
Description
The version of VMware Tools installed on the remote Windows host is 11.x or 12.x prior to 12.5.1. It is, therefore, affected by an authentication bypass vulnerability:

- VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious actor with non-administrative privileges on a guest VM may gain ability to perform certain high privilege operations within that VM. (CVE-2025-22230)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0003
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-22230
XREF VMSA:2025-0005
XREF IAVA:2025-A-0199-S
Plugin Information
Published: 2025/03/27, Modified: 2025/05/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.1
266420 - VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015)
-
Synopsis
The virtualization tool suite installed on the remote host is affected by multiple vulnerabilities.
Description
The version of VMware Tools installed on the remote host is 11.x or 12.x prior to 12.5.4, or 13.x prior to 13.0.5.
It is, therefore, affected by multiple vulnerabilities as disclosed in the VMSA-2025-0015 advisory:

- VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. (CVE-2025-41244)

- VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX. (CVE-2025-41246)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.4, 13.0.5 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0002
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-41244
CVE CVE-2025-41246
XREF VMSA:2025-0015
XREF IAVA:2025-A-0712
XREF CISA-KNOWN-EXPLOITED:2025/11/20
Plugin Information
Published: 2025/10/02, Modified: 2025/10/30
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.4
CVE(s) : CVE-2025-41244 CVE-2025-41246
276819 - Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803)
-
Synopsis
A Microsoft development toolset on the remote Windows host is affected by privilege escalation.
Description
In VSTA 2019 (prior 16.0.35907.0) and VSTA 2022 (prior to 17.0.35906.0), the software contains a vulnerability (CVE-2025-29803) that could allow remote or local attackers to execute arbitrary code or escalate privileges within the host application, potentially compromising systems that rely on VSTA for automation or extensibility.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-29803
XREF IAVA:2025-A-0247
Plugin Information
Published: 2025/11/25, Modified: 2025/11/25
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\16.0\Bin\VstaCore.dll
Installed version : 16.0.31110
Fixed version : 16.0.35907.0
180174 - WinRAR < 6.23 RCE
-
Synopsis
The remote Windows host has an application installed which is affected by a remote code execution vulnerability.
Description
The remote host is running WinRAR, an archive manager for Windows.

The version of WinRAR installed on the remote host is affected by a an improper validation of user-supplied data, which can result in memory access past the end of an allocated buffer which can be exploited remotely and may allow attackers to execute code in the context of the current process.
See Also
Solution
Upgrade to WinRAR version 6.23 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.9385
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2023-38831
CVE CVE-2023-40477
XREF CISA-KNOWN-EXPLOITED:2023/09/14
XREF IAVA:2023-A-0436-S
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2023/08/24, Modified: 2024/05/03
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 6.23
192940 - WinRAR < 7.00 Multiple Vulnerabilities
-
Synopsis
The remote Windows host has an application installed which is affected by multiple vulnerabilities.
Description
The remote host is running WinRAR, an archive manager for Windows, whose reported version is prior to 7.00. It is, therefore, affected by multiple vulnerabilties:

- The vulnerability exists due to an error within the archive extraction functionality. A remote attacker can use a specially crafted archive to bypass the Mark-Of-The-Web protection mechanism and potentially compromise the affected system. (CVE-2024-30370)

- RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899. (CVE-2024-36052)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to WinRAR version 7.00 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
6.7 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0042
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.9 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2024-30370
CVE CVE-2024-36052
XREF IAVA:2024-A-0194-S
XREF IAVA:2024-A-0303-S
Plugin Information
Published: 2024/04/05, Modified: 2025/06/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.0
166555 - WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
-
Synopsis
The remote Windows host is potentially missing a mitigation for a remote code execution vulnerability.
Description
The remote system may be in a vulnerable state to CVE-2013-3900 due to a missing or misconfigured registry keys:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck An unauthenticated, remote attacker could exploit this, by sending specially crafted requests, to execute arbitrary code on an affected host.
See Also
Solution
Add and enable registry value EnableCertPaddingCheck:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck

Additionally, on 64 Bit OS systems, Add and enable registry value EnableCertPaddingCheck:

- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.7941
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.6 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2013-3900
XREF CISA-KNOWN-EXPLOITED:2022/07/10
XREF IAVA:2013-A-0227
Plugin Information
Published: 2022/10/26, Modified: 2025/12/17
Plugin Output

tcp/445/cifs



Nessus detected the following potentially insecure registry key configuration:
- Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.
- Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.
71321 - MS13-106: Vulnerability in a Microsoft Office Shared Component Could Allow Security Feature Bypass (2905238)
-
Synopsis
The remote Windows host is affected by a security feature bypass vulnerability.
Description
The remote Windows host is running a version of Microsoft Office that contains a shared component that is affected by a security feature bypass. Successful exploitation of the issue can allow an attacker to bypass the Address Space Layout Randomization (ASLR) security feature.
An attacker would need to entice a victim to visit a specially crafted web page with a browser capable of instantiating COM components in order to trigger the issue.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007 and 2010.
Risk Factor
Medium
VPR Score
4.2
EPSS Score
0.148
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
BID 64095
CVE CVE-2013-5057
MSKB 2850016
MSKB 2850022
XREF MSFT:MS13-106
XREF IAVB:2013-B-0135
Exploitable With
Core Impact (true)
Plugin Information
Published: 2013/12/11, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



KB : 2850016
- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll has not been patched.
Remote version : 2.5.50727.4039
Should be : 5.70.51021.0
73983 - MS14-024: Vulnerability in a Microsoft Common Control Could Allow Security Feature Bypass (2961033)
-
Synopsis
The remote Windows host is affected by a security feature bypass vulnerability.
Description
The remote Windows host is running a version of Microsoft Office that contains a shared component (MSCOMCTL common controls library) that is affected by a security feature bypass. Successful exploitation of the issue could allow an attacker to bypass the Address Space Layout Randomization (ASLR) security feature. An attacker would need to entice a victim to visit a specially crafted web page with a browser capable of instantiating COM components in order to exploit the issue.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, and 2013.
Risk Factor
Medium
VPR Score
5.9
EPSS Score
0.1293
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 67273
CVE CVE-2014-1809
MSKB 2961033
MSKB 2880508
MSKB 2880507
MSKB 2880502
MSKB 2817330
MSKB 2760272
MSKB 2880971
MSKB 2810073
MSKB 2596804
MSKB 2589288
XREF MSFT:MS14-024
XREF IAVB:2014-B-0057
Plugin Information
Published: 2014/05/14, Modified: 2019/11/26
Plugin Output

tcp/445/cifs



KB : 2810073
- C:\Windows\SysWOW64\mscomctl.ocx has not been patched.
Remote version : 6.1.98.18
Should be : 6.1.98.39
243568 - Node.js 18.x < 18.20.6 / 20.x < 20.18.2 / 22.x < 22.13.1 / 23.x < 23.6.1 Multiple Vulnerabilities (Tuesday, January 21, 2025 Security Releases).
-
Synopsis
Node.js - JavaScript run-time environment is affected by multiple vulnerabilities.
Description
The version of Node.js installed on the remote host is prior to 18.20.6, 20.18.2, 22.13.1, 23.6.1. It is, therefore, affected by multiple vulnerabilities as referenced in the Tuesday, January 21, 2025 Security Releases advisory.

- A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of path.join API. Impact: Thank you, to taise for reporting this vulnerability and thank you tniessen for fixing it. (CVE-2025-23084)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Node.js version 18.20.6 / 20.18.2 / 22.13.1 / 23.6.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
5.6 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N)
VPR Score
4.4
EPSS Score
0.0002
CVSS v2.0 Base Score
5.2 (CVSS2#AV:L/AC:L/Au:S/C:C/I:P/A:N)
STIG Severity
I
References
CVE CVE-2025-23084
XREF IAVB:2025-B-0012-S
Plugin Information
Published: 2025/08/05, Modified: 2025/08/05
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\nodejs\
Installed version : 18.16.1
Fixed version : 18.20.6
192685 - Node.js Module node-tar < 6.2.1 DoS
-
Synopsis
A module in the Node.js JavaScript run-time environment is affected by a denial of service vulnerability.
Description
In the nodejs module node-tar prior to version 6.2.1, there is no validation of the number of folders created while unpacking a file. As a result, an attacker can use a malicious file to exhaust the CPU and memory on the host and crash the nodejs client.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to node-tar version 6.2.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
5.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.003
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.4 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2024-28863
XREF IAVB:2024-B-0027
Plugin Information
Published: 2024/03/29, Modified: 2025/12/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\tar\package.json
Installed version : 6.1.13
Fixed version : 6.2.1
214532 - Oracle Java SE Multiple Vulnerabilities (January 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The 8u431, 11.0.26, 17.0.14, 20.3.16, 21.0.5, 21.3.12, 23.0.2, and perf versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the January 2025 CPU advisory.

- Vulnerability in Oracle Java SE (component: Install (Sparkle)). The supported version that is affected is Oracle Java SE: 8u431. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: Only applies to the macOS autoupdater. (CVE-2025-0509)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.26, 17.0.14, 21.0.5, 23.0.2; Oracle GraalVM for JDK: 17.0.14, 21.0.5, 23.0.2; Oracle GraalVM Enterprise Edition: 20.3.16 and 21.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. (CVE-2025-21502)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the January 2025 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
6.8 (CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
5.9 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0003
CVSS v2.0 Base Score
7.2 (CVSS2#AV:A/AC:L/Au:M/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-0509
CVE CVE-2025-21502
XREF IAVA:2025-A-0049-S
Plugin Information
Published: 2025/01/23, Modified: 2025/08/06
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jdk-17\
Installed version : 17.0.12 / build 17.0.12
Fixed version : Upgrade to version 17.0.14 or greater
57608 - SMB Signing not required
-
Synopsis
Signing is not required on the remote SMB server.
Description
Signing is not required on the remote SMB server. An unauthenticated, remote attacker can exploit this to conduct man-in-the-middle attacks against the SMB server.
See Also
Solution
Enforce message signing in the host's configuration. On Windows, this is found in the policy setting 'Microsoft network server: Digitally sign communications (always)'. On Samba, the setting is called 'server signing'. See the 'see also' links for further details.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v3.0 Temporal Score
4.6 (CVSS:3.0/E:U/RL:O/RC:C)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
Plugin Information
Published: 2012/01/19, Modified: 2022/10/05
Plugin Output

tcp/445/cifs

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/1433/mssql


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : CN=SSL_Self_Signed_Fallback
|-Issuer : CN=SSL_Self_Signed_Fallback

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : CN=MiddlewareAPI
|-Issuer : CN=MiddlewareAPI

45411 - SSL Certificate with Wrong Hostname
-
Synopsis
The SSL certificate for this service is for a different host.
Description
The 'commonName' (CN) attribute of the SSL certificate presented for this service is for a different machine.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
Plugin Information
Published: 2010/04/03, Modified: 2020/04/27
Plugin Output

tcp/443/www


The identities known by Nessus are :

172.17.100.112
middlewareapi
172.17.100.112

The Common Name in the certificate is :

www.lkp.net.in

The Subject Alternate Names in the certificate are :

admin.pennypal.in
aims.lkp.net.in
allocation.lkp.net.in
api.lkp.net.in
backoffice.lkp.net.in
bo.lkp.net.in
demo.pennypal.in
devtrade.lkp.net.in
devtradekyc.lkp.net.in
druat.pennypal.in
ekyc.lkp.net.in
ekyc.lkponline.com
ekyc.pennypal.in
ekycuat.lkp.net.in
getsetgrow.lkponline.com
hrms.lkp.net.in
ia.lkp.net.in
ipo.lkp.net.in
lkp.net.in
lkpconnect.net.in
lkpsec.com
lms.lkp.net.in
middleware.lkp.net.in
middlewareapi.lkp.net.in
notification.lkponline.com
notification.pennypal.in
pay.lkp.net.in
pennypal.in
ra.lkp.net.in
referral.pennypal.in
rekyc.pennypal.in
spip.lkp.net.in
spip.lkponline.com
trading.lkponline.com
trading.pennypal.in
trilogy.lkp.net.in
uat.lkp.net.in
uat.lkpsec.com
uat.pennypal.in
uatbackoffice.lkp.net.in
uatekyc.lkponline.com
uatgetsetgrow.lkponline.com
uatspip.lkponline.com
uattrading.lkponline.com
uatweb.pennypal.in
wealth.lkp.net.in
welcome.lkp.net.in
www.lkp.net.in
www.lkpfinance.com
www.lkpsec.com

45411 - SSL Certificate with Wrong Hostname
-
Synopsis
The SSL certificate for this service is for a different host.
Description
The 'commonName' (CN) attribute of the SSL certificate presented for this service is for a different machine.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
Plugin Information
Published: 2010/04/03, Modified: 2020/04/27
Plugin Output

tcp/1433/mssql


The identities known by Nessus are :

172.17.100.112
middlewareapi
172.17.100.112

The Common Name in the certificate is :

SSL_Self_Signed_Fallback
57582 - SSL Self-Signed Certificate
-
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host.

Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output

tcp/1433/mssql


The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :

|-Subject : CN=SSL_Self_Signed_Fallback

57582 - SSL Self-Signed Certificate
-
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host.

Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output

tcp/3389/msrdp


The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :

|-Subject : CN=MiddlewareAPI

122154 - Security Update for .NET Core (February 2019)
-
Synopsis
The remote Windows host is affected by a .NET Core domain spoofing vulnerability.
Description
The remote Windows host has an installation of .NET Core with a version of 1.0.x < 1.0.14, 1.1.x < 1.1.11, 2.1.x < 2.1.8 or 2.2x < 2.2.2. Therefore, the host is affected by the following:

- A Domain spoofing vulnerability which causes the meaning of a URI to change when International Domain Name encoding is applied.
An attacker who successfully exploited the vulnerability could redirect a URI. (CVE-2019-0657)
See Also
Solution
Refer to vendor documentation.
Risk Factor
Medium
CVSS v3.0 Base Score
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.2 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0284
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2019-0657
XREF IAVA:2019-A-0044-S
Plugin Information
Published: 2019/02/13, Modified: 2025/03/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\1.0.5\
Installed version : 1.0.5
Fixed version : 1.0.14 (1.0.14.5101)

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\1.1.2\
Installed version : 1.1.2
Fixed version : 1.1.11 (1.1.11.1791)
122778 - Security Update for .NET Core SDK (March 2019)
-
Synopsis
The remote Windows host is affected by a tampering vulnerability.
Description
The remote Windows host has an installation of .NET Core SDK with a version of 1.x < 1.1.13 or 2.1.x < 2.1.505. Therefore, the host is affected by a tampering vulnerability with in the NuGet Package Manager. An authenticated, attacker can exploit this, via manipulating the folder contents prior to building or installing a application, to modify files and folders after unpacking.
See Also
Solution
Refer to vendor documentation.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.1
EPSS Score
0.0489
CVSS v2.0 Base Score
4.0 (CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.0 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2019/03/12, Modified: 2020/01/17
Plugin Output

tcp/445/cifs


Path : C:\\program files\dotnet\\sdk\1.1.0
Installed version : 1.1.0
Fixed version : 1.1.13
205451 - Security Update for Microsoft .NET Core (August 2024)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the vendor advisory.

- .NET and Visual Studio Information Disclosure Vulnerability (CVE-2024-38167)

- .NET and Visual Studio Denial of Service Vulnerability (CVE-2024-38168)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0362
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38167
CVE CVE-2024-38168
XREF IAVA:2024-A-0490-S
Plugin Information
Published: 2024/08/13, Modified: 2024/10/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.8

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.8

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.7\
Installed version : 8.0.7
Fixed version : 8.0.8
196990 - Security Update for Microsoft .NET Core (May 2024)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the vendor advisory.

- .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2024-30045)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
6.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
CVSS v3.0 Temporal Score
5.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.2
EPSS Score
0.0153
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.5 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-30045
XREF IAVA:2024-A-0280
Plugin Information
Published: 2024/05/14, Modified: 2024/05/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.5

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NetCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.19

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.19

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.5
185886 - Security Update for Microsoft .NET Core (November 2023) (CVE-2023-36558)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by security feature bypass vulnerability as referenced in the vendor advisory.

- ASP.NET Core - Security Feature Bypass Vulnerability (CVE-2023-36558)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0062
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
3.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36558
XREF IAVA:2023-A-0615-S
Plugin Information
Published: 2023/11/16, Modified: 2024/01/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NetCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.14

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.10\
Installed version : 7.0.10.32713
Fixed version : 7.0.14
270711 - Security Update for Microsoft .NET Core (October 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by information disclosure vulnerability as referenced in the vendor advisory.

- Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. (CVE-2025-55248)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
4.8 (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N)
VPR Score
3.6
EPSS Score
0.0003
CVSS v2.0 Base Score
4.9 (CVSS2#AV:N/AC:H/Au:S/C:C/I:N/A:N)
STIG Severity
I
References
CVE CVE-2025-55248
XREF IAVA:2025-A-0752
Plugin Information
Published: 2025/10/17, Modified: 2025/11/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.21

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Installed version : 8.0.0
Fixed version : 8.0.21

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.7\
Installed version : 8.0.7
Fixed version : 8.0.21
185884 - Security Update for Microsoft ASP.NET Core (November 2023) (CVE-2023-36558)
-
Synopsis
The remote Windows host is affected by a ASP.NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by security feature bypass vulnerability as referenced in the vendor advisory.

- ASP.NET Core - Security Feature Bypass Vulnerability (CVE-2023-36558)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0062
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
3.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36558
XREF IAVA:2023-A-0617-S
Plugin Information
Published: 2023/11/16, Modified: 2024/02/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\7.0.10
Installed version : 7.0.10
Fixed version : 7.0.14

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\7.0.10
Installed version : 7.0.10
Fixed version : 7.0.14
236781 - Security Update for Microsoft Visual 2017 15.9 (May 2025)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by a information disclosure vulnerability where Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. (CVE-2025-32703)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9 for Visual Studio 2017
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
VPR Score
3.6
EPSS Score
0.0005
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:N)
STIG Severity
I
References
CVE CVE-2025-32703
XREF IAVA:2025-A-0336-S
XREF CWE:200
XREF CWE:1220
Plugin Information
Published: 2025/05/15, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.36101.55 (15.9.73)
234038 - Security Update for Microsoft Visual Studio Code (April 2025)
-
Synopsis
The remote host has an application installed that is missing a security update.
Description
The version of Microsoft Visual Studio Code installed on the remote Windows host is prior to 1.99.1. It is, therefore, affected by an unspecified elevation of privilege vulnerability.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update to Microsoft Visual Studio Code 1.99.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L)
VPR Score
6.3
CVSS v2.0 Base Score
6.4 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:P)
STIG Severity
I
References
CVE CVE-2025-20570
XREF IAVA:2025-A-0241-S
Plugin Information
Published: 2025/04/08, Modified: 2025/05/16
Plugin Output

tcp/445/cifs


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Installed version : 1.81.1
Fixed version : 1.99.1
177353 - Security Update for Microsoft Visual Studio Code (June 2023)
-
Synopsis
The remote host has an application installed that is missing a security update.
Description
The version of Microsoft Visual Studio Code installed on the remote Windows host is prior to 1.79.1. It is, therefore, affected by a session spoofing vulnerability. An attacker can exploit this to perform actions with the privileges of another user.
See Also
Solution
Upgrade to Microsoft Visual Studio Code 1.79.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.6 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N)
CVSS v3.0 Temporal Score
5.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.7
EPSS Score
0.0173
CVSS v2.0 Base Score
6.2 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:N)
CVSS v2.0 Temporal Score
4.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-33144
XREF IAVA:2023-A-0299-S
Plugin Information
Published: 2023/06/15, Modified: 2023/09/25
Plugin Output

tcp/445/cifs


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Installed version : 1.81.1
Fixed version : 1.82.2
275467 - Security Update for Microsoft Visual Studio Code (November 2025)
-
Synopsis
The remote host has an application installed that is missing a security update.
Description
The version of Microsoft Visual Studio Code installed on the remote Windows host is prior to 1.105.1. It is, therefore, affected by security feature bypass vulnerability. Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update to Microsoft Visual Studio Code 1.105.1 or later.
Risk Factor
Low
CVSS v3.0 Base Score
5.0 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N)
VPR Score
4.4
EPSS Score
0.0005
CVSS v2.0 Base Score
1.9 (CVSS2#AV:L/AC:M/Au:N/C:N/I:P/A:N)
STIG Severity
I
References
CVE CVE-2025-62453
XREF IAVA:2025-A-0849
Plugin Information
Published: 2025/11/14, Modified: 2025/11/14
Plugin Output

tcp/445/cifs


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Installed version : 1.81.1
Fixed version : 1.105.1
167885 - Security Updates for Microsoft .NET Framework (May 2022)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by a denial of service vulnerability that is caused by a local user opening a specially crafted file.
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
5.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0088
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-30130
MSKB 5013612
MSKB 5013615
MSKB 5013616
MSKB 5013617
MSKB 5013618
MSKB 5013619
MSKB 5013620
MSKB 5013621
MSKB 5013622
MSKB 5013623
MSKB 5013624
MSKB 5013625
MSKB 5013626
MSKB 5013627
MSKB 5013628
MSKB 5013629
MSKB 5013630
MSKB 5013631
MSKB 5013632
MSKB 5013635
MSKB 5013636
MSKB 5013637
MSKB 5013638
MSKB 5013641
MSKB 5013642
MSKB 5013643
MSKB 5013644
XREF MSFT:MS22-5013612
XREF MSFT:MS22-5013615
XREF MSFT:MS22-5013616
XREF MSFT:MS22-5013617
XREF MSFT:MS22-5013618
XREF MSFT:MS22-5013619
XREF MSFT:MS22-5013620
XREF MSFT:MS22-5013621
XREF MSFT:MS22-5013622
XREF MSFT:MS22-5013623
XREF MSFT:MS22-5013624
XREF MSFT:MS22-5013625
XREF MSFT:MS22-5013626
XREF MSFT:MS22-5013627
XREF MSFT:MS22-5013628
XREF MSFT:MS22-5013629
XREF MSFT:MS22-5013630
XREF MSFT:MS22-5013631
XREF MSFT:MS22-5013632
XREF MSFT:MS22-5013635
XREF MSFT:MS22-5013636
XREF MSFT:MS22-5013637
XREF MSFT:MS22-5013638
XREF MSFT:MS22-5013641
XREF MSFT:MS22-5013642
XREF MSFT:MS22-5013643
XREF MSFT:MS22-5013644
XREF IAVA:2022-A-0202-S
Plugin Information
Published: 2022/11/18, Modified: 2024/11/26
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5013626

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.directoryservices.dll has not been patched.
Remote version : 4.8.3761.0
Should be : 4.8.4501.0

167254 - Security Updates for Microsoft .NET Framework (November 2022)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by an information disclosure vulnerability in the System.Data.SqlClient and Microsoft.Data.SqlClient packages. A timeout occurring under high load can cause incorrect data to be returned as the result of an asynchronously executed query.
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
5.8 (CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.4 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0008
CVSS v2.0 Base Score
4.3 (CVSS2#AV:A/AC:H/Au:S/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-41064
MSKB 5020606
MSKB 5020608
MSKB 5020609
MSKB 5020610
MSKB 5020611
MSKB 5020612
MSKB 5020613
MSKB 5020614
MSKB 5020615
MSKB 5020617
MSKB 5020618
MSKB 5020619
MSKB 5020620
MSKB 5020621
MSKB 5020622
MSKB 5020623
MSKB 5020624
MSKB 5020627
MSKB 5020628
MSKB 5020629
MSKB 5020630
MSKB 5020632
XREF MSFT:MS22-5020606
XREF MSFT:MS22-5020608
XREF MSFT:MS22-5020609
XREF MSFT:MS22-5020610
XREF MSFT:MS22-5020611
XREF MSFT:MS22-5020612
XREF MSFT:MS22-5020613
XREF MSFT:MS22-5020614
XREF MSFT:MS22-5020615
XREF MSFT:MS22-5020617
XREF MSFT:MS22-5020618
XREF MSFT:MS22-5020619
XREF MSFT:MS22-5020620
XREF MSFT:MS22-5020621
XREF MSFT:MS22-5020622
XREF MSFT:MS22-5020623
XREF MSFT:MS22-5020624
XREF MSFT:MS22-5020627
XREF MSFT:MS22-5020628
XREF MSFT:MS22-5020629
XREF MSFT:MS22-5020630
XREF MSFT:MS22-5020632
XREF IAVA:2022-A-0477-S
Plugin Information
Published: 2022/11/10, Modified: 2023/10/05
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 5020615

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.core.dll has not been patched.
Remote version : 4.8.4110.0
Should be : 4.8.4585.0

141503 - Security Updates for Microsoft .NET Framework (October 2020)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.
(CVE-2020-16937)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
4.7 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.1 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0389
CVSS v2.0 Base Score
4.0 (CVSS2#AV:L/AC:H/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
3.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-16937
MSKB 4578968
MSKB 4578969
MSKB 4578971
MSKB 4578972
MSKB 4578974
MSKB 4579976
MSKB 4579977
MSKB 4579978
MSKB 4579979
MSKB 4579980
MSKB 4580327
MSKB 4580328
MSKB 4580330
MSKB 4580346
MSKB 4580467
MSKB 4580468
MSKB 4580469
MSKB 4580470
XREF MSFT:MS20-4578968
XREF MSFT:MS20-4578969
XREF MSFT:MS20-4578971
XREF MSFT:MS20-4578972
XREF MSFT:MS20-4578974
XREF MSFT:MS20-4579976
XREF MSFT:MS20-4579977
XREF MSFT:MS20-4579978
XREF MSFT:MS20-4579979
XREF MSFT:MS20-4579980
XREF MSFT:MS20-4580327
XREF MSFT:MS20-4580328
XREF MSFT:MS20-4580330
XREF MSFT:MS20-4580346
XREF MSFT:MS20-4580467
XREF MSFT:MS20-4580468
XREF MSFT:MS20-4580469
XREF MSFT:MS20-4580470
XREF IAVA:2020-A-0456-S
XREF CEA-ID:CEA-2020-0126
Plugin Information
Published: 2020/10/19, Modified: 2022/12/05
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 4578973

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.security.dll has not been patched.
Remote version : 4.8.3761.0
Should be : 4.8.4261.0

147218 - Security Updates for Microsoft Office Products (March 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
They are affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-24108, CVE-2021-27054, CVE-2021-27057, CVE-2021-27059)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4493228
-KB4493203
-KB4504703
-KB4493225
-KB4493200
-KB4493214
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0487
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-24108
CVE CVE-2021-27054
CVE CVE-2021-27057
CVE CVE-2021-27059
MSKB 4493228
MSKB 4493203
MSKB 4504703
MSKB 4493225
MSKB 4493200
MSKB 4493214
XREF MSFT:MS21-4493228
XREF MSFT:MS21-4493203
XREF MSFT:MS21-4504703
XREF MSFT:MS21-4493225
XREF MSFT:MS21-4493200
XREF MSFT:MS21-4493214
XREF IAVA:2021-A-0132-S
XREF CISA-KNOWN-EXPLOITED:2021/11/17
Plugin Information
Published: 2021/03/09, Modified: 2025/10/31
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2010 SP2
KB : 4504703
- C:\Program Files (x86)\Common Files\Microsoft Shared\Office14\mso.dll has not been patched.
Remote version : 14.0.6023.1000
Should be : 14.0.7266.5000

Product : Microsoft Office 2010 SP2
KB : 4493214
- C:\Program Files (x86)\Microsoft Office\Office14\graph.exe has not been patched.
Remote version : 14.0.6024.1000
Should be : 14.0.7266.5000
182956 - Security Updates for Microsoft SQL Server (October 2023)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A Denial of Service vulnerability. An attacker could impact availability of the service resulting in Denial of Service (DoS) (CVE-2023-36728) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0029
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
3.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36728
MSKB 5029184
MSKB 5029185
MSKB 5029186
MSKB 5029187
MSKB 5029375
MSKB 5029376
MSKB 5029377
MSKB 5029378
MSKB 5029379
MSKB 5029503
XREF MSFT:MS23-5029184
XREF MSFT:MS23-5029185
XREF MSFT:MS23-5029186
XREF MSFT:MS23-5029187
XREF MSFT:MS23-5029375
XREF MSFT:MS23-5029376
XREF MSFT:MS23-5029377
XREF MSFT:MS23-5029378
XREF MSFT:MS23-5029379
XREF MSFT:MS23-5029503
XREF IAVA:2023-A-0541-S
Plugin Information
Published: 2023/10/12, Modified: 2024/01/12
Plugin Output

tcp/445/cifs



KB : 5029377
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2104.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
179644 - Security Updates for Microsoft Visual Studio Office Tools (August 2023)
-
Synopsis
The Microsoft Visual Studio Products are affected by a spoofing vulnerability.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by
- Visual Studio Tools for Office Runtime Spoofing Vulnerability. (CVE-2023-36897) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.56 for Visual Studio 2017
- Update 16.11.29 for Visual Studio 2019
- Update 17.2.18 for Visual Studio 2022
- Update 17.4.10 for Visual Studio 2022
- Update 17.6.6 for Visual Studio 2022
- Update 17.7 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.1
EPSS Score
0.0106
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36897
XREF IAVA:2023-A-0415-S
XREF IAVA:2023-A-0419-S
Plugin Information
Published: 2023/08/10, Modified: 2023/09/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.33529.398 (15.9.56)
135481 - Security Updates for Microsoft Visual Studio Products (April 2020)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions. An attacker who successfully exploited this vulnerability could overwrite arbitrary file content in the security context of the local system. (CVE-2020-0899)

- An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operations. An attacker who successfully exploited the vulnerability could delete files in arbitrary locations with elevated permissions. (CVE-2020-0900)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- KB4540102 (for Visual Studio 2015)
- Update 15.9.22 for Visual Studio 2017
- Update 16.0.13 for Visual Studio 2019
- Update 16.4.7 for Visual Studio 2019
- Update 16.5.4 for Visual Studio 2019
Risk Factor
Low
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0045
CVSS v2.0 Base Score
3.6 (CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:P)
CVSS v2.0 Temporal Score
2.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-0899
CVE CVE-2020-0900
MSKB 4540102
XREF MSFT:MS20-4540102
XREF IAVA:2020-A-0148-S
Plugin Information
Published: 2020/04/14, Modified: 2022/06/27
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1093
152423 - Security Updates for Microsoft Visual Studio Products (August 2021)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2021-26423)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-34485, CVE-2021-34532)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.38 for Visual Studio 2017
- Update 16.4.25 for Visual Studio 2019
- Update 16.7.18 for Visual Studio 2019
- Update 16.9.10 for Visual Studio 2019
- Update 16.11.0 for Visual Studio 2019
Risk Factor
Low
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.024
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
1.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-26423
CVE CVE-2021-34485
CVE CVE-2021-34532
XREF IAVA:2021-A-0380-S
Plugin Information
Published: 2021/08/10, Modified: 2021/09/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1622
205591 - Security Updates for Microsoft Visual Studio Products (August 2024)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- .NET and Visual Studio Information Disclosure Vulnerability. (CVE-2024-38167)
- .NET Core and Visual Studio Denial of Service Vulnerability. (CVE-2024-38168)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 17.6.18 for Visual Studio 2022
- Update 17.8.13 for Visual Studio 2022
- Update 17.10.6 for Visual Studio 2022
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0362
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38167
CVE CVE-2024-38168
XREF IAVA:2024-A-0498-S
Plugin Information
Published: 2024/08/15, Modified: 2024/10/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.35201.163 (17.8.13)
144977 - Security Updates for Microsoft Visual Studio Products (January 2021)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2021-1651, CVE-2021-1680)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2021-1723)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2020-26870)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Install KB4584787 for Visual Studio 2015
- Update 15.9.31 for Visual Studio 2017
- Update 16.0.22 for Visual Studio 2019
- Update 16.4.17 for Visual Studio 2019
- Update 16.7.10 for Visual Studio 2019
- Update 16.8.4 for Visual Studio 2019
Risk Factor
High
CVSS v3.0 Base Score
6.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
CVSS v3.0 Temporal Score
5.5 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.025
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-26870
CVE CVE-2021-1651
CVE CVE-2021-1680
CVE CVE-2021-1723
MSKB 4584787
XREF MSFT:MS21-4584787
XREF CEA-ID:CEA-2021-0001
XREF IAVA:2021-A-0021-S
Plugin Information
Published: 2021/01/14, Modified: 2025/02/14
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1342
200353 - Security Updates for Microsoft Visual Studio Products (June 2024)
-
Synopsis
The Microsoft Visual Studio Products are affected by multiple vulnerabilities.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by multiple vulnerabilities, including:

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2024-29060, CVE-2024-29187)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-30052)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.63 for Visual Studio 2017
- Update 16.11.37 for Visual Studio 2019
- Update 17.4.20 for Visual Studio 2022
- Update 17.6.16 for Visual Studio 2022
- Update 17.8.11 for Visual Studio 2022
- Update 17.10.2 for Visual Studio 2022
Risk Factor
Medium
CVSS v3.0 Base Score
6.7 (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L)
CVSS v3.0 Temporal Score
6.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
7.0
EPSS Score
0.0095
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:P)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-29060
CVE CVE-2024-29187
CVE CVE-2024-30052
XREF IAVA:2024-A-0346-S
Plugin Information
Published: 2024/06/11, Modified: 2024/10/07
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.34930.103 (15.9.63)

tcp/445/cifs


Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Installed version : 17.8.34330.188
Fixed version : 17.8.34931.61 (17.8.11)
130969 - Security Updates for Microsoft Visual Studio Products (November 2019)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by the following vulnerability :

- An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files. An attacker who successfully exploited this vulnerability could overwrite arbitrary files in the security context of the local system.
(CVE-2019-1425)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.17 for Visual Studio 2017
- Update 16.0.9 for Visual Studio 2019
- Update 16.3.9 for Visual Studio 2019
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0751
CVSS v2.0 Base Score
5.8 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:P)
CVSS v2.0 Temporal Score
4.3 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2019/11/13, Modified: 2022/06/27
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.905
142694 - Security Updates for Microsoft Visual Studio Products (November 2020)
-
Synopsis
The Microsoft Visual Studio Products are affected by a tampering vulnerability.
Description
The Microsoft Visual Studio Products are missing security updates. They are, therefore, affected by a tampering vulnerability. The vulnerability exists when the Python Tools for Visual Studio creates the python27 folder. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
See Also
Solution
Update the Visual Studio installation to one of the following versions, or later:
- VS 2017 15.9.29
- VS 2019 16.0.20
- VS 2019 16.4.15
- VS 2019 16.8.0
Risk Factor
Low
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.1
EPSS Score
0.0045
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
1.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-17100
XREF IAVA:2020-A-0519-S
Plugin Information
Published: 2020/11/10, Modified: 2022/06/27
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1300
155018 - Security Updates for Microsoft Visual Studio Products (November 2021)
-
Synopsis
The Microsoft Visual Studio Products are missing a security update.
Description
The Microsoft Visual Studio Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A denial of service (DoS) vulnerability exists in the OpenSSL component of Visual Studio. An unauthenticated, remote attacker can exploit this issue to cause the application to stop responding. (CVE-2020-1971)

- Multiple A privilege escalation vulnerabilities exist in Visual Studio. An unauthenticated, local attacker can exploit thees to gain privileged access to the system. (CVE-2021-42277, CVE-2021-42319)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- Update 15.9.41 for Visual Studio 2017
- Update 16.7.21 for Visual Studio 2019
- Update 16.9.13 for Visual Studio 2019
- Update 16.11.6 for Visual Studio 2019
Risk Factor
Medium
CVSS v3.0 Base Score
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
5.5 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.003
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
3.8 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1971
CVE CVE-2021-42277
CVE CVE-2021-42319
XREF IAVA:2021-A-0542-S
XREF CEA-ID:CEA-2021-0004
XREF CEA-ID:CEA-2021-0025
Plugin Information
Published: 2021/11/10, Modified: 2023/12/29
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Installed version : 15.3.26730.8
Fixed version : 15.9.28307.1745

58453 - Terminal Services Doesn't Use Network Level Authentication (NLA) Only
-
Synopsis
The remote Terminal Services doesn't use Network Level Authentication only.
Description
The remote Terminal Services is not configured to use Network Level Authentication (NLA) only. NLA uses the Credential Security Support Provider (CredSSP) protocol to perform strong server authentication either through TLS/SSL or Kerberos mechanisms, which protect against man-in-the-middle attacks. In addition to improving authentication, NLA also helps protect the remote computer from malicious users and software by completing user authentication before a full RDP connection is established.
See Also
Solution
Enable Network Level Authentication (NLA) on the remote RDP server. This is generally done on the 'Remote' tab of the 'System' settings on Windows.
Risk Factor
Medium
CVSS v3.0 Base Score
4.0 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N)
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
Plugin Information
Published: 2012/03/23, Modified: 2025/09/29
Plugin Output

tcp/3389/msrdp

Nessus was able to negotiate non-NLA (Network Level Authentication) security.

236832 - VMware Tools 11.x / 12.x < 12.5.2 Insecure File Handling (VMSA-2025-0007)
-
Synopsis
The virtualization tool suite is installed on the remote host is affected by an insecure file handling vulnerability.
Description
The version of VMware Tools installed on the remote host is 11.x or 12.x prior to 12.5.2. It is, therefore, affected by an insecure file handling vulnerability:

- VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM. (CVE-2025-22247)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.2 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.1 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N)
VPR Score
5.0
EPSS Score
0.0001
CVSS v2.0 Base Score
5.2 (CVSS2#AV:L/AC:L/Au:S/C:P/I:C/A:N)
STIG Severity
I
References
CVE CVE-2025-22247
XREF VMSA:2025-0007
XREF IAVA:2025-A-0324-S
Plugin Information
Published: 2025/05/16, Modified: 2025/10/02
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.2
247827 - VMware Tools 11.x / 12.x < 12.5.3 / 13.x < 13.0.1.0 vSockets Information Disclosure (VMSA-2025-0013)
-
Synopsis
The virtualization tool suite is installed on the remote Windows host is affected by an information disclosure vulnerability.
Description
The version of VMware Tools installed on the remote Windows host is 11.x, 12.x prior to 12.5.3, or 13.x prior to 13.0.1.0. It is, therefore, affected by an information disclosure vulnerbility:

- VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets. (CVE-2025-41239)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.3 or 13.0.1.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.2 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
4.4
EPSS Score
0.0001
CVSS v2.0 Base Score
4.9 (CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N)
References
CVE CVE-2025-41239
XREF VMSA:2025-0013
Plugin Information
Published: 2025/08/11, Modified: 2025/08/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.3
234002 - WinRAR < 7.11 Mark of the Web Bypass (CVE-2025-31334)
-
Synopsis
The remote Windows host has an application installed which is affected by a mark of the web bypass vulnerability.
Description
The remote host is running WinRAR, an archive manager for Windows, whose reported version is prior to 7.11. It is, therefore, affected by a vulnerability:

- Issue that bypasses the 'Mark of the Web' security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed. (CVE-2025-31334)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to WinRAR version 7.11 or later.
Risk Factor
High
CVSS v3.0 Base Score
6.8 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
STIG Severity
II
References
CVE CVE-2025-31334
XREF IAVA:2025-A-0227
Plugin Information
Published: 2025/04/08, Modified: 2025/04/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.11
132101 - Windows Speculative Execution Configuration Check
-
Synopsis
The remote host has not properly mitigated a series of speculative execution vulnerabilities.
Description
The remote host has not properly mitigated a series of known speculative execution vulnerabilities. It, therefore, may be affected by :
- Branch Target Injection (BTI) (CVE-2017-5715)
- Bounds Check Bypass (BCB) (CVE-2017-5753)
- Rogue Data Cache Load (RDCL) (CVE-2017-5754)
- Rogue System Register Read (RSRE) (CVE-2018-3640)
- Speculative Store Bypass (SSB) (CVE-2018-3639)
- L1 Terminal Fault (L1TF) (CVE-2018-3615, CVE-2018-3620, CVE-2018-3646)
- Microarchitectural Data Sampling Uncacheable Memory (MDSUM) (CVE-2019-11091)
- Microarchitectural Store Buffer Data Sampling (MSBDS) (CVE-2018-12126)
- Microarchitectural Load Port Data Sampling (MLPDS) (CVE-2018-12127)
- Microarchitectural Fill Buffer Data Sampling (MFBDS) (CVE-2018-12130)
- TSX Asynchronous Abort (TAA) (CVE-2019-11135)
- Intel Branch History Injection (BHI) (CVE-2022-0001)
See Also
Solution
Apply vendor recommended settings.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.2 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
7.9
EPSS Score
0.9433
CVSS v2.0 Base Score
5.4 (CVSS2#AV:L/AC:M/Au:N/C:C/I:P/A:N)
CVSS v2.0 Temporal Score
4.7 (CVSS2#E:H/RL:OF/RC:C)
References
BID 102371
BID 102378
BID 104232
BID 105080
BID 108330
CVE CVE-2017-5715
CVE CVE-2017-5753
CVE CVE-2017-5754
CVE CVE-2018-3615
CVE CVE-2018-3620
CVE CVE-2018-3639
CVE CVE-2018-3646
CVE CVE-2018-12126
CVE CVE-2018-12127
CVE CVE-2018-12130
CVE CVE-2019-11135
CVE CVE-2022-0001
XREF CEA-ID:CEA-2019-0547
XREF CEA-ID:CEA-2019-0324
Exploitable With
CANVAS (true)
Plugin Information
Published: 2019/12/18, Modified: 2025/08/27
Plugin Output

tcp/445/cifs

Current Settings:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: Not Set
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: Not Set

-----------------------------------

Recommended Settings 1:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00000048 (72)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135
Note: Hyper-Threading enabled.

-----------------------------------

Recommended Settings 2:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00002048 (8264)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135
Note: Hyper-Threading disabled.

-----------------------------------

Recommended Settings 3:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00802048 (8396872)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135, CVE-2022-0001
Note: Hyper-Threading disabled.

-----------------------------------

Recommended Settings 4:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00800048 (8388680)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135, CVE-2022-0001
Note: Hyper-Threading enabled.

10114 - ICMP Timestamp Request Remote Date Disclosure
-
Synopsis
It is possible to determine the exact time set on the remote host.
Description
The remote host answers to an ICMP timestamp request. This allows an attacker to know the date that is set on the targeted machine, which may assist an unauthenticated, remote attacker in defeating time-based authentication protocols.

Timestamps returned from machines running Windows Vista / 7 / 2008 / 2008 R2 are deliberately incorrect, but usually within 1000 seconds of the actual system time.
Solution
Filter out the ICMP timestamp requests (13), and the outgoing ICMP timestamp replies (14).
Risk Factor
Low
VPR Score
2.2
EPSS Score
0.0037
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 1999/08/01, Modified: 2024/10/07
Plugin Output

icmp/0

The ICMP timestamps seem to be in little endian format (not in network format)
The remote clock is synchronized with the local clock.

140501 - Security Updates for Microsoft .NET Framework (September 2020)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. The security update addresses a potential abuse of ClickOnce to download applications from untrusted servers using NTLM authentication.
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Low
CVSS v3.0 Base Score
3.3 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
CVSS v2.0 Base Score
1.9 (CVSS2#AV:L/AC:M/Au:N/C:N/I:P/A:N)
References
MSKB 4576478
MSKB 4576479
MSKB 4576480
MSKB 4576481
MSKB 4576482
MSKB 4576483
MSKB 4576484
MSKB 4576485
MSKB 4576486
MSKB 4576487
MSKB 4576488
MSKB 4576489
MSKB 4576490
XREF MSFT:MS20-4576478
XREF MSFT:MS20-4576479
XREF MSFT:MS20-4576480
XREF MSFT:MS20-4576481
XREF MSFT:MS20-4576482
XREF MSFT:MS20-4576483
XREF MSFT:MS20-4576484
XREF MSFT:MS20-4576485
XREF MSFT:MS20-4576486
XREF MSFT:MS20-4576487
XREF MSFT:MS20-4576488
XREF MSFT:MS20-4576489
XREF MSFT:MS20-4576490
Plugin Information
Published: 2020/09/11, Modified: 2020/09/11
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.8
The remote host is missing one of the following rollup KBs :

Cumulative
- 4576483

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.deployment.dll has not been patched.
Remote version : 4.8.3761.0
Should be : 4.8.4240.0

46180 - Additional DNS Hostnames
-
Synopsis
Nessus has detected potential virtual hosts.
Description
Hostnames different from the current hostname have been collected by miscellaneous plugins. Nessus has generated a list of hostnames that point to the remote host. Note that these are only the alternate hostnames for vhosts discovered on a web server.

Different web servers may be hosted on name-based virtual hosts.
See Also
Solution
If you want to test them, re-scan using the special vhost syntax, such as :

www.example.com[192.0.32.10]
Risk Factor
None
Plugin Information
Published: 2010/04/29, Modified: 2022/08/15
Plugin Output

tcp/0

The following hostnames point to the remote host :
- middlewareapi

16193 - Antivirus Software Check
-
Synopsis
An antivirus application is installed on the remote host.
Description
An antivirus application is installed on the remote host, and its engine and virus definitions are up to date.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/01/18, Modified: 2025/05/27
Plugin Output

tcp/445/cifs


Kaspersky :
Kaspersky Anti-Virus is installed on the remote host :

Product name : Kaspersky Endpoint Security for Windows
Version : 21.15.8.493
Installation path : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0
Virus signatures : 01/11/2026

156001 - Apache Log4j JAR Detection (Windows)
-
Synopsis
Apache Log4j is installed on the remote Windows host.
Description
One or more instances of Apache Log4j, a logging API, are installed on the remote Windows Host.

- Powershell version 5 or greater is required for this plugin.

- If the 'Perform thorough tests' setting is enabled, this plugin will inspect the manifest and properties files of the detected Java archive files.

- The plugin timeout can be set to a custom value other than the plugin's default of 60 minutes via the 'timeout.156001' scanner setting in Nessus 8.15.1 or later.

Please see https://docs.tenable.com/nessus/Content/SettingsAdvanced.htm#Custom for more information.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVA:0001-A-0650
XREF IAVT:0001-T-0941
Plugin Information
Published: 2021/12/10, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus detected 2 installs of Apache Log4j:

Path : C:\Program Files\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Version : 1.2.17
JMSAppender.class association : Found
JdbcAppender.class association : Found
JndiLookup.class association : Not Found
Method : log4j-core file search

Path : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Version : 1.2.17
JMSAppender.class association : Found
JdbcAppender.class association : Found
JndiLookup.class association : Not Found
Method : log4j-core file search

43 Jar files successfully inspected.
92415 - Application Compatibility Cache
-
Synopsis
Nessus was able to gather application compatibility settings on the remote host.
Description
Nessus was able to generate a report on the application compatibility cache on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Application compatibility cache report attached.
34097 - BIOS Info (SMB)
-
Synopsis
BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's SMB interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/08, Modified: 2024/06/11
Plugin Output

tcp/0


Version : 6.00
Release date : 20201112000000.000000+000
Secure boot : disabled
34096 - BIOS Info (WMI)
-
Synopsis
The BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's WMI interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/05, Modified: 2025/12/15
Plugin Output

tcp/0


Vendor : Phoenix Technologies LTD
Version : 6.00
Release date : 20201112000000.000000+000
UUID : AE784D56-06FF-FE22-1EAB-F64374CCB000
Secure boot : disabled
92416 - BagMRU Folder History
-
Synopsis
Nessus was able to enumerate folders that were opened in Windows Explorer.
Description
Nessus was able to enumerate folders that were opened in Windows Explorer. Microsoft Windows maintains folder settings using a registry key known as shellbags or BagMRU. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

BagMRU report attached.

42799 - Broken Web Servers
-
Synopsis
Tests on this web server have been disabled.
Description
The remote web server seems password protected or misconfigured. Further tests on it were disabled so that the whole scan is not slowed down.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/13, Modified: 2011/08/17
Plugin Output

tcp/5357/www


This web server was declared broken by :
zkteco_zkbio_time_detect.nbin
for the following reason :
The server answered with a 503 code (overloaded).

96533 - Chrome Browser Extension Enumeration
-
Synopsis
One or more Chrome browser extensions are installed on the remote host.
Description
Nessus was able to enumerate Chrome browser extensions installed on the remote host.
See Also
Solution
Make sure that the use and configuration of these extensions comply with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0511
Plugin Information
Published: 2017/01/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


User : Administrator
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.99.1
Update Date : Jan. 9, 2026 at 19:32:30 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.99.1_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Jan. 9, 2026 at 19:32:30 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

45590 - Common Platform Enumeration (CPE)
-
Synopsis
It was possible to enumerate CPE names that matched on the remote system.
Description
By using information obtained from a Nessus scan, this plugin reports CPE (Common Platform Enumeration) matches for various hardware and software products found on a host.

Note that if an official CPE is not available for the product, this plugin computes the best possible CPE based on the information available from the scan.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/04/21, Modified: 2025/09/29
Plugin Output

tcp/0


The remote operating system matched the following CPE :

cpe:/o:microsoft:windows_server_2019:10.0.17763.4737:-:~~datacenter~~x64~ -> Microsoft Windows Server 2019

Following application CPE's matched on the remote system :

cpe:/a:apache:log4j:1.2.17 -> Apache Software Foundation log4j
cpe:/a:google:chrome:143.0.7499.193 -> Google Chrome
cpe:/a:haxx:curl:8.0.1.0 -> Haxx Curl
cpe:/a:kaspersky:kaspersky_anti-virus:21.15.8.493 -> Kaspersky Anti-virus
cpe:/a:microsoft:.net_core:1.0.5 -> Microsoft .NET Core
cpe:/a:microsoft:.net_core:1.1.0 -> Microsoft .NET Core
cpe:/a:microsoft:.net_core:1.1.2 -> Microsoft .NET Core
cpe:/a:microsoft:.net_core:6.0.25 -> Microsoft .NET Core
cpe:/a:microsoft:.net_core:7.0.10.32713 -> Microsoft .NET Core
cpe:/a:microsoft:.net_core:7.0.400 -> Microsoft .NET Core
cpe:/a:microsoft:.net_core:8.0.0 -> Microsoft .NET Core
cpe:/a:microsoft:.net_core:8.0.303 -> Microsoft .NET Core
cpe:/a:microsoft:.net_core:8.0.7 -> Microsoft .NET Core
cpe:/a:microsoft:.net_framework:4.8 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:4.8.4110.0 -> Microsoft .NET Framework
cpe:/a:microsoft:asp.net_core:6.0.25 -> Microsoft ASP.NET Core
cpe:/a:microsoft:asp.net_core:7.0.10 -> Microsoft ASP.NET Core
cpe:/a:microsoft:asp.net_core:8.0.0 -> Microsoft ASP.NET Core
cpe:/a:microsoft:asp.net_core:8.0.7 -> Microsoft ASP.NET Core
cpe:/a:microsoft:excelcnv:14.0.6024.1000:1
cpe:/a:microsoft:ie:11.1790.17763.0 -> Microsoft Internet Explorer
cpe:/a:microsoft:iis:10.0 -> Microsoft IIS
cpe:/a:microsoft:internet_explorer:11.0.17763.4720 -> Microsoft Internet Explorer
cpe:/a:microsoft:internet_information_services:10.0.17763.4492 -> Microsoft Internet Information Server (IIS) -
cpe:/a:microsoft:office:2010:1 -> Microsoft Office
cpe:/a:microsoft:office_compatibility_pack -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:office_compatibility_pack:14.0.4762.1000 -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:office_compatibility_pack:14.0.6024.1000 -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:remote_desktop_connection:10.0.17763.2867 -> Microsoft Remote Desktop Connection
cpe:/a:microsoft:sql_server:13.0.4001.0 -> Microsoft SQLServer
cpe:/a:microsoft:sql_server:15.0.2000.0 -> Microsoft SQLServer
cpe:/a:microsoft:sql_server:15.0.2000.5 -> Microsoft SQLServer
cpe:/a:microsoft:sql_server:15.0.4153.1 -> Microsoft SQLServer
cpe:/a:microsoft:visual_studio:15.3.26730.8 -> Microsoft Visual Studio
cpe:/a:microsoft:visual_studio:17.8.34330.188 -> Microsoft Visual Studio
cpe:/a:microsoft:visual_studio_code:1.81.1 -> Microsoft Visual Studio Code
cpe:/a:microsoft:visual_studio_tools_for_applications:15.0.27520
cpe:/a:microsoft:visual_studio_tools_for_applications:16.0.31110
cpe:/a:microsoft:word:14.0.6024.1000:1 -> Microsoft Word
cpe:/a:microsoft:wordcnv:14.0.4762.1000:0
cpe:/a:nodejs:node.js:18.16.1 -> Nodejs Node.js
cpe:/a:oracle:jre:17.0.12 -> Oracle JRE
cpe:/a:postman:postman:9.22.2 -> Postman
cpe:/a:rarlab:winrar:5.90.0.0 -> RARLAB WinRAR
cpe:/a:smartbedded:meteobridge_firmware
cpe:/a:vmware:tools:12.3.5.46049 -> VMWare Tools
x-cpe:/a:microsoft:azure_data_studio:1.44.0.0
x-cpe:/a:microsoft:odbc_driver_for_sql_server:17.10.3.1
x-cpe:/a:microsoft:ole_db_driver_for_sql_server:18.6.5.0
x-cpe:/a:microsoft:visual_studio_code:14.5.2
x-cpe:/a:microsoft:web_deploy:10.0.7421
24270 - Computer Manufacturer Information (WMI)
-
Synopsis
It is possible to obtain the name of the remote computer manufacturer.
Description
By making certain WMI queries, it is possible to obtain the model of the remote computer as well as the name of its manufacturer and its serial number.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/02, Modified: 2025/12/15
Plugin Output

tcp/0


Computer Manufacturer : VMware, Inc.
Computer Model : VMware Virtual Platform
Computer SerialNumber : VMware-56 4d 78 ae ff 06 22 fe-1e ab f6 43 74 cc b0 00
Computer Type : Other

Computer Physical CPU's : 12
Computer Logical CPU's : 24
CPU0
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU1
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU2
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU3
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU4
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU5
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU6
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU7
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU8
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU9
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU10
Architecture : x64
Physical Cores: 2
Logical Cores : 2
CPU11
Architecture : x64
Physical Cores: 2
Logical Cores : 2

Computer Memory : 32767 MB
RAM slot #0
Form Factor: DIMM
Type : DRAM
Capacity : 16384 MB
RAM slot #1
Form Factor: DIMM
Type : DRAM
Capacity : 16384 MB
171860 - Curl Installed (Windows)
-
Synopsis
Curl is installed on the remote Windows host.
Description
Curl, a command line tool for transferring data with URLs, was detected on the remote Windows host.

Please note, if the installation is located in either the Windows\System32 or Windows\SysWOW64 directory, it will be considered as managed by the OS. In this case, paranoid scanning is require to trigger downstream vulnerabilty checks. Paranoid scanning has no affect on this plugin itself.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/23, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus detected 2 installs of Curl:

Path : c:\windows\system32\curl.exe
Version : 8.0.1.0
Managed by OS : True

Path : c:\windows\syswow64\curl.exe
Version : 8.0.1.0
Managed by OS : True

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/135/epmap


The following DCERPC services are available locally :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc0D84F0

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc0D84F0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : dabrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-077da4832557502cd1

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000002
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9b37709f7460135fca

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000047
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f1db1192a3ecf41945

Object UUID : 00000047-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE975470C6D7C80AF083F7FD89B10F

Object UUID : 00000047-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-db33ed41365805d012

Object UUID : 00000047-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE975470C6D7C80AF083F7FD89B10F

Object UUID : 00000047-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-db33ed41365805d012

Object UUID : 00000047-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE975470C6D7C80AF083F7FD89B10F

Object UUID : 00000047-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-db33ed41365805d012

Object UUID : 5252504b-4950-534e-57ac-4f1704230000
UUID : 9b3e3722-f2ed-d3da-4b50-525250494453, version 154.115
Description : Unknown RPC service
Annotation : PRRUniversal#432C0AECAA279DBD:8964
Type : Local RPC service
Named pipe : PRRUniversal#432C0AECAA279DBD:8964

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:8964

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#432C0AECAA279DBD:8964

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:8964

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#432C0AECAA279DBD:8964

Object UUID : 03634524-0000-0000-57ac-4f1704230000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:8964

Object UUID : 03634524-0000-0000-57ac-4f1704230000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#432C0AECAA279DBD:8964

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000047
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc028B37A0B47

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000047
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc028B37A0B47

Object UUID : 5252504b-4950-534e-53c0-bb69601a0000
UUID : 9b3e3722-08f7-4aa8-4b50-525250494453, version 205.0
Description : Unknown RPC service
Annotation : PRRUniversal#95981B1E5B6F514A:6752
Type : Local RPC service
Named pipe : PRRUniversal#95981B1E5B6F514A:6752

Object UUID : 5252504b-4950-534e-ab42-323a48360000
UUID : 9b3e3722-2b02-9035-4b50-525250494453, version 161.151
Description : Unknown RPC service
Annotation : PRRUniversal#660E9528FEB0F6A3:13896
Type : Local RPC service
Named pipe : PRRUniversal#660E9528FEB0F6A3:13896

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : LRPC-6ae093ed9dcb076e73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a4b8d482-80ce-40d6-934d-b22a01a44fe7, version 1.0
Description : Unknown RPC service
Annotation : LicenseManager
Type : Local RPC service
Named pipe : LicenseServiceEndpoint

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLECCDDC42E307486FA24D7D7AD1A75

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c9a6963f0956225df4

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3468ce27ef39c76898

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3468ce27ef39c76898

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0497b57d-2e66-424f-a0c6-157cd5d41700, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-013278b622e18b4c8c

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-013278b622e18b4c8c

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-013278b622e18b4c8c

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-013278b622e18b4c8c

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-013278b622e18b4c8c

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE432B135B252FFB573DDBB3E6646C

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-47dbe618cd4ddbc348

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE432B135B252FFB573DDBB3E6646C

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-47dbe618cd4ddbc348

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE432B135B252FFB573DDBB3E6646C

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-47dbe618cd4ddbc348

Object UUID : 5252504b-4950-534e-5923-cf2ec8320000
UUID : 9b3e3722-0bc1-8e5c-4b50-525250494453, version 154.115
Description : Unknown RPC service
Annotation : PRRUniversal#5AAB7F60B92DF799:13000
Type : Local RPC service
Named pipe : PRRUniversal#5AAB7F60B92DF799:13000

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:13000

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#5AAB7F60B92DF799:13000

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:13000

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#5AAB7F60B92DF799:13000

Object UUID : 00a4dedc-0000-0000-5923-cf2ec8320000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:13000

Object UUID : 00a4dedc-0000-0000-5923-cf2ec8320000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#5AAB7F60B92DF799:13000

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000002
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc03123B12

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000002
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc03123B12

Object UUID : 5252504b-4950-534e-c0b3-28385c0e0000
UUID : 9b3e3722-afe7-38e3-4b50-525250494453, version 154.115
Description : Unknown RPC service
Annotation : PRRUniversal#64050FBE0577FE4C:3676
Type : Local RPC service
Named pipe : PRRUniversal#64050FBE0577FE4C:3676

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:3676

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#64050FBE0577FE4C:3676

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:3676

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#64050FBE0577FE4C:3676

Object UUID : 0896c4ec-0000-0000-c0b3-28385c0e0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:3676

Object UUID : 0896c4ec-0000-0000-c0b3-28385c0e0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#64050FBE0577FE4C:3676

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4c9dbf19-d39e-4bb9-90ee-8f7179b20283, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-89623580e05893edfa

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd8be72b-a9cd-4b2c-a9ca-4ded242fbe4d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-89623580e05893edfa

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 95095ec8-32ea-4eb0-a3e2-041f97b36168, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-89623580e05893edfa

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e38f5360-8572-473e-b696-1b46873beeab, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-89623580e05893edfa

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d22895ef-aff4-42c5-a5b2-b14466d34ab4, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-89623580e05893edfa

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98cd761e-e77d-41c8-a3c0-0fb756d90ec2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-89623580e05893edfa

Object UUID : e16530d6-fec6-410d-b2dc-218f8cc0f610
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-5c3bc275c5bbd3348a

Object UUID : 474ddcaa-8dc5-4465-aa5b-2dc8e96ef20b
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-5c3bc275c5bbd3348a

Object UUID : 95e5236b-97df-49eb-ace7-4919043b7059
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-5c3bc275c5bbd3348a

Object UUID : 43bc4bbc-67fe-4ae7-b862-ec40e0db65a7
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : OLE1CF8E6E503D0DAA38E535C722618

Object UUID : 43bc4bbc-67fe-4ae7-b862-ec40e0db65a7
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-0ae335d5406cf130f4

Object UUID : 5252504b-4950-534e-83ed-5ca9640e0000
UUID : 9b3e3722-37ea-3824-4b50-525250494453, version 154.115
Description : Unknown RPC service
Annotation : PRRUniversal#D5394980980D6AC7:3684
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 05c60fa0-0000-0000-83ed-5ca9640e0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 05c60fa0-0000-0000-83ed-5ca9640e0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-abb6-0007-4b50-525250524944
UUID : 9b3e3722-7551-7dee-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpTEMPFILE_MEMMANAGER
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-abb6-0007-4b50-525250524944
UUID : 9b3e3722-7551-7dee-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpTEMPFILE_MEMMANAGER
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 00000000-0000-0000-83ed-5ca9640e0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 00000000-0000-0000-83ed-5ca9640e0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 005f671c-0000-0000-83ed-5ca9640e0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 005f671c-0000-0000-83ed-5ca9640e0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-8790-000c-4b50-525250524944
UUID : 9b3e3722-1441-c93d-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_TYPE_NAME
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-8790-000c-4b50-525250524944
UUID : 9b3e3722-1441-c93d-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_TYPE_NAME
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-a517-000d-4b50-525250524944
UUID : 9b3e3722-f9a8-d5cb-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_PROFILE_NAME
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-a517-000d-4b50-525250524944
UUID : 9b3e3722-f9a8-d5cb-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_PROFILE_NAME
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-b19c-0002-4b50-525250524944
UUID : 9b3e3722-050c-2b49-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_ID
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-b19c-0002-4b50-525250524944
UUID : 9b3e3722-050c-2b49-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_ID
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-1931-0005-4b50-525250524944
UUID : 9b3e3722-a39b-5baa-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npAVS_HTTP_REQ
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-1931-0005-4b50-525250524944
UUID : 9b3e3722-a39b-5baa-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npAVS_HTTP_REQ
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-4d95-0005-4b50-525250524944
UUID : 9b3e3722-f7aa-5ba3-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npAVS_HTTP_RSP
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-4d95-0005-4b50-525250524944
UUID : 9b3e3722-f7aa-5ba3-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npAVS_HTTP_RSP
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-b87a-0007-4b50-525250524944
UUID : 9b3e3722-86c2-73eb-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : MESSAGE_IS_INCOMING
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-b87a-0007-4b50-525250524944
UUID : 9b3e3722-86c2-73eb-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : MESSAGE_IS_INCOMING
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-5916-0003-4b50-525250524944
UUID : 9b3e3722-0276-35b6-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : MESSAGE_CHECK_ONLY
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-5916-0003-4b50-525250524944
UUID : 9b3e3722-0276-35b6-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : MESSAGE_CHECK_ONLY
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-20c7-000f-4b50-525250524944
UUID : 9b3e3722-c49b-fe45-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : PROTOCOL_TYPE
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-20c7-000f-4b50-525250524944
UUID : 9b3e3722-c49b-fe45-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : PROTOCOL_TYPE
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-c384-0000-4b50-525250524944
UUID : 9b3e3722-6122-0a2a-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npENGINE_VIRTUAL_OBJECT_NAME
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-c384-0000-4b50-525250524944
UUID : 9b3e3722-6122-0a2a-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npENGINE_VIRTUAL_OBJECT_NAME
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-7401-0008-4b50-525250524944
UUID : 9b3e3722-62c7-816c-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npUserContext
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-7401-0008-4b50-525250524944
UUID : 9b3e3722-62c7-816c-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npUserContext
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-0568-0001-4b50-525250524944
UUID : 9b3e3722-1d09-1186-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npAVS_SCAN_AREA_ID
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-0568-0001-4b50-525250524944
UUID : 9b3e3722-1d09-1186-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npAVS_SCAN_AREA_ID
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-618e-000d-4b50-525250524944
UUID : 9b3e3722-7819-d199-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : antimalware.am_core_dll.registered
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-618e-000d-4b50-525250524944
UUID : 9b3e3722-7819-d199-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : antimalware.am_core_dll.registered
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-4dfb-000b-4b50-525250524944
UUID : 9b3e3722-56be-b1b4-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npSCAN_OBJECT_CONTEXT
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-4dfb-000b-4b50-525250524944
UUID : 9b3e3722-56be-b1b4-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npSCAN_OBJECT_CONTEXT
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-5c94-000c-4b50-525250524944
UUID : 9b3e3722-7dc3-c215-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_READONLY_tERROR
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-5c94-000c-4b50-525250524944
UUID : 9b3e3722-7dc3-c215-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_READONLY_tERROR
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-66bb-0002-4b50-525250524944
UUID : 9b3e3722-b130-2d78-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_EXECUTABLE_PARENT_IO_hOBJECT
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-66bb-0002-4b50-525250524944
UUID : 9b3e3722-b130-2d78-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_EXECUTABLE_PARENT_IO_hOBJECT
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-0726-0007-4b50-525250524944
UUID : 9b3e3722-dfbb-7d89-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_SET_WRITE_ACCESS_tERROR
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-0726-0007-4b50-525250524944
UUID : 9b3e3722-dfbb-7d89-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_SET_WRITE_ACCESS_tERROR
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-21ab-0008-4b50-525250524944
UUID : 9b3e3722-da96-8fb3-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npENGINE_INTEGRAL_PARENT_IO
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-21ab-0008-4b50-525250524944
UUID : 9b3e3722-da96-8fb3-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npENGINE_INTEGRAL_PARENT_IO
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-554f-0006-4b50-525250524944
UUID : 9b3e3722-3fdc-66a9-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npOBJECT_STARTUP
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-554f-0006-4b50-525250524944
UUID : 9b3e3722-3fdc-66a9-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npOBJECT_STARTUP
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-ae59-0004-4b50-525250524944
UUID : 9b3e3722-49dd-4e78-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : antimalware.oas.PenderPtr
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-ae59-0004-4b50-525250524944
UUID : 9b3e3722-49dd-4e78-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : antimalware.oas.PenderPtr
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-e77b-0006-4b50-525250524944
UUID : 9b3e3722-d7d6-630a-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : native file io object is a stream really
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-e77b-0006-4b50-525250524944
UUID : 9b3e3722-d7d6-630a-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : native file io object is a stream really
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-54e6-0005-4b50-525250524944
UUID : 9b3e3722-97cf-5c32-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : native file io object streams
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-54e6-0005-4b50-525250524944
UUID : 9b3e3722-97cf-5c32-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : native file io object streams
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-c572-000b-4b50-525250524944
UUID : 9b3e3722-7d85-bb8f-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npTM_PROFILE
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-c572-000b-4b50-525250524944
UUID : 9b3e3722-7d85-bb8f-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npTM_PROFILE
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-2be7-0004-4b50-525250524944
UUID : 9b3e3722-2175-40a9-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpTEMPFILE_SYSCACHED
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-2be7-0004-4b50-525250524944
UUID : 9b3e3722-2175-40a9-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : cpTEMPFILE_SYSCACHED
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 068adf00-0000-0000-83ed-5ca9640e0000
UUID : 9b3e3722-b8eb-3e0b-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : TaskManager
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 068adf00-0000-0000-83ed-5ca9640e0000
UUID : 9b3e3722-b8eb-3e0b-4b50-52524f424a53, version 154.115
Description : Unknown RPC service
Annotation : TaskManager
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-aa75-0009-4b50-525250524944
UUID : 9b3e3722-b9de-913a-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : DEFER_THREAD_INIT
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-aa75-0009-4b50-525250524944
UUID : 9b3e3722-b9de-913a-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : DEFER_THREAD_INIT
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-1e7b-0004-4b50-525250524944
UUID : 9b3e3722-6afd-4748-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : MAILER_PID
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-1e7b-0004-4b50-525250524944
UUID : 9b3e3722-6afd-4748-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : MAILER_PID
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-487b-0006-4b50-525250524944
UUID : 9b3e3722-2a49-6623-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npMESSAGE_IS_COMPLETE
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-487b-0006-4b50-525250524944
UUID : 9b3e3722-2a49-6623-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : npMESSAGE_IS_COMPLETE
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-cf60-000f-4b50-525250524944
UUID : 9b3e3722-93c9-f5ca-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : NO_NEED_TREATMENT
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-cf60-000f-4b50-525250524944
UUID : 9b3e3722-93c9-f5ca-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : NO_NEED_TREATMENT
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 9b3e3722-7820-0006-4b50-525250524944
UUID : 9b3e3722-9839-6e01-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : MAILER_TID
Type : Local RPC service
Named pipe : PRRNameService:3684

Object UUID : 9b3e3722-7820-0006-4b50-525250524944
UUID : 9b3e3722-9839-6e01-4b50-525250524f50, version 154.115
Description : Unknown RPC service
Annotation : MAILER_TID
Type : Local RPC service
Named pipe : PRRUniversal#D5394980980D6AC7:3684

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : LRPC-5b675781672a12ead7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : RasmanLrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : VpnikeRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : LRPC-5c4bb6435d3864b783

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6b5bdd1e-528c-422c-af8c-a4079be4fe48, version 1.0
Description : Unknown RPC service
Annotation : Remote Fw APIs
Type : Local RPC service
Named pipe : ipsec

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98716d03-89ac-44c7-bb8c-285824e51c4a, version 1.0
Description : Unknown RPC service
Annotation : XactSrv service
Type : Local RPC service
Named pipe : LRPC-5259371e1ffd5e885e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a0d010f-1c33-432c-b0f5-8cf4e8053099, version 1.0
Description : Unknown RPC service
Annotation : IdSegSrv service
Type : Local RPC service
Named pipe : LRPC-5259371e1ffd5e885e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : LRPC-d695bee6fd7b4902c0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : LRPC-d695bee6fd7b4902c0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : LRPC-d695bee6fd7b4902c0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : LRPC-d695bee6fd7b4902c0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : OLEAAC7656D35BCA36231C54A918D84

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b58aa02e-2884-4e97-8176-4ee06d794184, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-e7a8f63931101dfda8

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345678-1234-abcd-ef00-0123456789ab, version 1.0
Description : IPsec Services (Windows XP & 2003)
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LRPC-ceab966bcf3ebf1c10

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ceab966bcf3ebf1c10

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : ae33069b-a2a8-46ee-a235-ddfd339be281, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ceab966bcf3ebf1c10

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4a452661-8290-4b36-8fbe-7f4093a94978, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ceab966bcf3ebf1c10

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76f03f96-cdfd-44fc-a22c-64950a001209, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ceab966bcf3ebf1c10

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : LRPC-db9e28a297323259cc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd490425-5325-4565-b774-7e27d6c09c24, version 1.0
Description : Unknown RPC service
Annotation : Base Firewall Engine API
Type : Local RPC service
Named pipe : LRPC-6481217735138475ca

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-6481217735138475ca

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-b718d69c951cacc892

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-6481217735138475ca

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-b718d69c951cacc892

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-698f10dcd22c2a0161

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-6481217735138475ca

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-b718d69c951cacc892

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-698f10dcd22c2a0161

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-4070956d935c8f4637

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE4F2B6ABAABE6CB2E1A458D8CAAE0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-6ebe4a29c7686b8a95

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE4F2B6ABAABE6CB2E1A458D8CAAE0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-6ebe4a29c7686b8a95

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : abfb6ca3-0c5e-4734-9285-0aee72fe8d1c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE86B03D28B8E86FE04DB86216E063

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : abfb6ca3-0c5e-4734-9285-0aee72fe8d1c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5857607ddf44b6ec06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b37f900a-eae4-4304-a2ab-12bb668c0188, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE86B03D28B8E86FE04DB86216E063

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b37f900a-eae4-4304-a2ab-12bb668c0188, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5857607ddf44b6ec06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e7f76134-9ef5-4949-a2d6-3368cc0988f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE86B03D28B8E86FE04DB86216E063

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e7f76134-9ef5-4949-a2d6-3368cc0988f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5857607ddf44b6ec06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7aeb6705-3ae6-471a-882d-f39c109edc12, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE86B03D28B8E86FE04DB86216E063

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7aeb6705-3ae6-471a-882d-f39c109edc12, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5857607ddf44b6ec06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f44e62af-dab1-44c2-8013-049a9de417d6, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE86B03D28B8E86FE04DB86216E063

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f44e62af-dab1-44c2-8013-049a9de417d6, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5857607ddf44b6ec06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c2d1b5dd-fa81-4460-9dd6-e7658b85454b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE86B03D28B8E86FE04DB86216E063

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c2d1b5dd-fa81-4460-9dd6-e7658b85454b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5857607ddf44b6ec06

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-21688e6ed506e60655

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-21688e6ed506e60655

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : LRPC-d6166011ceab9047fe

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : 91d8e86f-05e0-4572-b0e1-6be57b25e123

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f2c9b409-c1c9-4100-8639-d8ab1486694a, version 1.0
Description : Unknown RPC service
Annotation : Witness Client Upcall Server
Type : Local RPC service
Named pipe : LRPC-a26f85e31cf579854a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : eb081a0d-10ee-478a-a1dd-50995283e7a8, version 3.0
Description : Unknown RPC service
Annotation : Witness Client Test Interface
Type : Local RPC service
Named pipe : LRPC-a26f85e31cf579854a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Local RPC service
Named pipe : LRPC-a26f85e31cf579854a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d56df71242c5b6018c

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : senssvc

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-14dba358e7ba57c4ea

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-65daf12212d86b3996

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-65daf12212d86b3996

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-65daf12212d86b3996

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-65daf12212d86b3996

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5a4b49a16464654873

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-65daf12212d86b3996

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5a4b49a16464654873

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-65daf12212d86b3996

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5a4b49a16464654873

Object UUID : 666f7270-6c69-7365-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 6c637067-6569-746e-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-32ca1544343971a6eb

Object UUID : 24d1f7c7-76af-4f28-9ccd-7f6cb6468601
UUID : 2eb08e3e-639f-4fba-97b1-14f878961076, version 1.0
Description : Unknown RPC service
Annotation : Group Policy RPC Interface
Type : Local RPC service
Named pipe : LRPC-565cf99ec38049eb2b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7ea70bcf-48af-4f6a-8968-6a440754d5fa, version 1.0
Description : Unknown RPC service
Annotation : NSI server endpoint
Type : Local RPC service
Named pipe : LRPC-026600f1416f0252d1

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : eventlog

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : df4df73a-c52d-4e3a-8003-8437fdf8302a, version 0.0
Description : Unknown RPC service
Annotation : WM_WindowManagerRPC\Server
Type : Local RPC service
Named pipe : LRPC-3d754031ea806e7c1d

Object UUID : b5ccd5ef-4238-440b-bba0-999f828f1cfe
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-bd071392fb72b721e7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-bd071392fb72b721e7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-94efb66b0be1f1e7ba

Object UUID : fdd099c6-df06-4904-83b4-a87a27903c70
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-52724f68a95a17be95

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint for NCB Reset module
Type : Local RPC service
Named pipe : LRPC-52724f68a95a17be95

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint for NCB Reset module
Type : Local RPC service
Named pipe : LRPC-a19f4a4ab72bc7b841

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-52724f68a95a17be95

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-a19f4a4ab72bc7b841

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : OLE0AA794931F2DA2FCB73E7B7676BB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-ebc12c7c6158f7ab35

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-52724f68a95a17be95

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-a19f4a4ab72bc7b841

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : OLE0AA794931F2DA2FCB73E7B7676BB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-ebc12c7c6158f7ab35

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000001
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-225149a46ba8d3f9dd

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000001
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc0D9F51

Object UUID : 6d726574-7273-0076-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-39ef9f8389cc2622e4

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 085b0334-e454-4d91-9b8c-4134f9e793f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8782d3b9-ebbd-4644-a3d8-e8725381919b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3b338d89-6cfa-44b8-847e-531531bc9992, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5824833b-3c1a-4ad2-bdfd-c31d19e23ed2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0361ae94-0316-4c6c-8ad8-c594375800e2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b1d94dc58729c12e6f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b1d94dc58729c12e6f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b1d94dc58729c12e6f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 178d84be-9291-4994-82c6-3f909aca5a03, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e53d94ca-7464-4839-b044-09a2fb8b3ae5, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fae436b0-b864-4a87-9eda-298547cd82f2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 082a3471-31b6-422a-b931-a54401960c62, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6982a06e-5fe2-46b1-b39c-a2c545bfa069, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0ff1f646-13bb-400a-ab50-9a78f2b7a85a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4ed8abcc-f1e2-438b-981f-bb0e8abc010c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 95406f0b-b239-4318-91bb-cea3a46ff0dc, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d47017b-b33b-46ad-9e18-fe96456c5078, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd59071b-3215-4c59-8481-972edadc0f6a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b1d94dc58729c12e6f

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f2ca1c7b654b3f6c6e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b1d94dc58729c12e6f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f2ca1c7b654b3f6c6e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-e204b4171eca31aade

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b1d94dc58729c12e6f

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f2ca1c7b654b3f6c6e

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-e204b4171eca31aade

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b1d94dc58729c12e6f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f2ca1c7b654b3f6c6e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-e204b4171eca31aade

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-077da4832557502cd1

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b1d94dc58729c12e6f

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f2ca1c7b654b3f6c6e

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-e204b4171eca31aade

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-077da4832557502cd1

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8c77cf760e5c7e66d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEAC8C7B399B93B374EB8A5F74124

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3d2b93b0af5a2d7fff

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b1d94dc58729c12e6f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f2ca1c7b654b3f6c6e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-e204b4171eca31aade

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following DCERPC services are available remotely :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\MIDDLEWAREAPI

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Remote RPC service
Named pipe : \PIPE\ROUTER
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Remote RPC service
Named pipe : \PIPE\wkssvc
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\MIDDLEWAREAPI

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\MIDDLEWAREAPI

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49664/dce-rpc


The following DCERPC services are available on TCP port 49664 :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49664
IP : 172.17.100.112

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49665/dce-rpc


The following DCERPC services are available on TCP port 49665 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.112

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49666/dce-rpc


The following DCERPC services are available on TCP port 49666 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.112

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.112

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49667/dce-rpc


The following DCERPC services are available on TCP port 49667 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.112

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49668/dce-rpc


The following DCERPC services are available on TCP port 49668 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345678-1234-abcd-ef00-0123456789ab, version 1.0
Description : IPsec Services (Windows XP & 2003)
Windows process : lsass.exe
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.112

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.112

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : ae33069b-a2a8-46ee-a235-ddfd339be281, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.112

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4a452661-8290-4b36-8fbe-7f4093a94978, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.112

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76f03f96-cdfd-44fc-a22c-64950a001209, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.112

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49669/dce-rpc


The following DCERPC services are available on TCP port 49669 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6b5bdd1e-528c-422c-af8c-a4079be4fe48, version 1.0
Description : Unknown RPC service
Annotation : Remote Fw APIs
Type : Remote RPC service
TCP Port : 49669
IP : 172.17.100.112

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49742/dce-rpc


The following DCERPC services are available on TCP port 49742 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 367abb81-9844-35f1-ad32-98f038001003, version 2.0
Description : Service Control Manager
Windows process : svchost.exe
Type : Remote RPC service
TCP Port : 49742
IP : 172.17.100.112

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49833/dce-rpc


The following DCERPC services are available on TCP port 49833 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
TCP Port : 49833
IP : 172.17.100.112

139785 - DISM Package List (Windows)
-
Synopsis
Use DISM to extract package info from the host.
Description
Using the Deployment Image Servicing Management tool, this plugin enumerates installed packages.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/08/25, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following packages were enumerated using the Deployment Image Servicing and Management Tool:

Package : Microsoft-Windows-FodMetadata-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : Feature Pack
Install Time : 9/15/2018 9:08 AM

Package : Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : Foundation
Install Time : 9/15/2018 7:21 AM

Package : Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~~11.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/15/2018 9:07 AM

Package : Microsoft-Windows-LanguageFeatures-Basic-en-us-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/15/2018 9:08 AM

Package : Microsoft-Windows-LanguageFeatures-Handwriting-en-us-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/15/2018 9:08 AM

Package : Microsoft-Windows-LanguageFeatures-OCR-en-us-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/15/2018 9:08 AM

Package : Microsoft-Windows-LanguageFeatures-Speech-en-us-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/15/2018 9:08 AM

Package : Microsoft-Windows-LanguageFeatures-TextToSpeech-en-us-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/15/2018 9:08 AM

Package : Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/15/2018 9:08 AM

Package : Microsoft-Windows-Security-SPP-Component-SKU-ServerDatacenter-GVLK-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : Feature Pack
Install Time : 9/15/2018 9:11 AM

Package : Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~10.0.17763.1
State : Installed
Release Type : Language Pack
Install Time : 9/15/2018 9:07 AM

Package : Microsoft-Windows-ServerCore-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : Feature Pack
Install Time : 9/15/2018 7:21 AM

Package : Microsoft-Windows-ServerCore-SKU-Foundation-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : Feature Pack
Install Time : 9/15/2018 7:21 AM

Package : Microsoft-Windows-TabletPCMath-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/15/2018 9:09 AM

Package : Microsoft-Windows-Xps-Xps-Viewer-Opt-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/15/2018 9:08 AM

Package : OpenSSH-Client-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/15/2018 9:08 AM

Package : Package_for_DotNetRollup~31bf3856ad364e35~amd64~~10.0.3630.3
State : Superseded
Release Type : Update
Install Time : 7/10/2020 7:12 PM

Package : Package_for_DotNetRollup~31bf3856ad364e35~amd64~~10.0.3930.2
State : Installed
Release Type : Update
Install Time : 5/4/2022 5:38 AM

Package : Package_for_KB4486153~31bf3856ad364e35~amd64~~10.0.1.3106
State : Installed
Release Type : Update
Install Time : 12/27/2023 4:19 AM

Package : Package_for_KB4535680~31bf3856ad364e35~amd64~~10.0.1.0
State : Installed
Release Type : Security Update
Install Time : 12/7/2021 2:47 PM

Package : Package_for_KB4558997~31bf3856ad364e35~amd64~~17763.1337.1.1
State : Installed
Release Type : Security Update
Install Time : 7/10/2020 7:11 PM

Package : Package_for_KB4587735~31bf3856ad364e35~amd64~~17763.1574.1.2
State : Installed
Release Type : Security Update
Install Time : 12/6/2020 10:10 AM

Package : Package_for_KB4589208~31bf3856ad364e35~amd64~~10.0.2.4
State : Installed
Release Type : Update
Install Time : 12/7/2021 2:46 PM

Package : Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.1339.1.9
State : Superseded
Release Type : Security Update
Install Time : 7/10/2020 7:20 PM

Package : Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.4737.1.6
State : Installed
Release Type : Security Update
Install Time : 8/11/2023 8:55 AM

Package : Package_for_ServicingStack_2262~31bf3856ad364e35~amd64~~17763.2262.1.2
State : Installed
Release Type : Update
Install Time : 12/7/2021 12:52 PM

Package : Package_for_ServicingStack_2328~31bf3856ad364e35~amd64~~17763.2328.1.0
State : Installed
Release Type : Update
Install Time : 12/8/2021 1:47 AM

Package : Package_for_ServicingStack_2510~31bf3856ad364e35~amd64~~17763.2510.1.2
State : Installed
Release Type : Update
Install Time : 3/24/2022 6:18 AM

Package : Package_for_ServicingStack_2744~31bf3856ad364e35~amd64~~17763.2744.1.2
State : Installed
Release Type : Update
Install Time : 5/4/2022 4:40 AM

Package : Package_for_ServicingStack_4640~31bf3856ad364e35~amd64~~17763.4640.1.3
State : Installed
Release Type : Security Update
Install Time : 8/11/2023 8:04 AM

84239 - Debugging Log Report
-
Synopsis
This plugin gathers the logs written by other plugins and reports them.
Description
Logs generated by other plugins are reported by this plugin. Plugin debugging must be enabled in the policy in order for this plugin to run.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/06/17, Modified: 2025/07/14
Plugin Output

tcp/0

Plugin debug log(s) have been attached.
55472 - Device Hostname
-
Synopsis
It was possible to determine the remote system hostname.
Description
This plugin reports a device's hostname collected via SSH or WMI.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/06/30, Modified: 2025/12/15
Plugin Output

tcp/0


Hostname : MIDDLEWAREAPI
MIDDLEWAREAPI (WMI)
54615 - Device Type
-
Synopsis
It is possible to guess the remote device type.
Description
Based on the remote operating system, it is possible to determine what the remote system type is (eg: a printer, router, general-purpose computer, etc).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/05/23, Modified: 2025/03/12
Plugin Output

tcp/0

Remote device type : general-purpose
Confidence level : 100

19689 - Embedded Web Server Detection
-
Synopsis
The remote web server is embedded.
Description
The remote web server cannot host user-supplied CGIs. CGI scanning will be disabled on this server.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/09/14, Modified: 2025/09/29
Plugin Output

tcp/5800/www

71246 - Enumerate Local Group Memberships
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.
Description
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering Group data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/12/06, Modified: 2025/12/15
Plugin Output

tcp/0

Group Name : Access Control Assistance Operators
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-579
Members :

Group Name : Administrators
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-544
Members :
Name : production
Domain : MIDDLEWAREAPI
Class : Win32_UserAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-500
Name : CommonProduction
Domain : MIDDLEWAREAPI
Class : Win32_UserAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-1007
Name : tidua
Domain : MIDDLEWAREAPI
Class : Win32_UserAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-1009

Group Name : Backup Operators
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-551
Members :

Group Name : Certificate Service DCOM Access
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-574
Members :

Group Name : Cryptographic Operators
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-569
Members :

Group Name : Device Owners
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-583
Members :

Group Name : Distributed COM Users
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-562
Members :

Group Name : Event Log Readers
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-573
Members :

Group Name : Guests
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-546
Members :
Name : Guest
Domain : MIDDLEWAREAPI
Class : Win32_UserAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-501

Group Name : Hyper-V Administrators
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-578
Members :

Group Name : IIS_IUSRS
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-568
Members :

Group Name : Network Configuration Operators
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-556
Members :

Group Name : Performance Log Users
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-559
Members :
Name : MSSQLServerOLAPService
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
Name : production
Domain : MIDDLEWAREAPI
Class : Win32_UserAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-500
Name : INTERACTIVE
Domain : MIDDLEWAREAPI
Class : Win32_SystemAccount
SID : S-1-5-4

Group Name : Performance Monitor Users
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-558
Members :
Name : MSSQLSERVER
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
Name : SQLSERVERAGENT
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : Power Users
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-547
Members :

Group Name : Print Operators
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-550
Members :

Group Name : RDS Endpoint Servers
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-576
Members :

Group Name : RDS Management Servers
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-577
Members :

Group Name : RDS Remote Access Servers
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-575
Members :

Group Name : Remote Desktop Users
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-555
Members :

Group Name : Remote Management Users
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-580
Members :

Group Name : Replicator
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-552
Members :

Group Name : Storage Replica Administrators
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-582
Members :

Group Name : System Managed Accounts Group
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-581
Members :
Name : DefaultAccount
Domain : MIDDLEWAREAPI
Class : Win32_UserAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-503

Group Name : Users
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-32-545
Members :
Name : INTERACTIVE
Domain : MIDDLEWAREAPI
Class : Win32_SystemAccount
SID : S-1-5-4
Name : Authenticated Users
Domain : MIDDLEWAREAPI
Class : Win32_SystemAccount
SID : S-1-5-11
Name : Lkpadmin
Domain : MIDDLEWAREAPI
Class : Win32_UserAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-1000
Name : CommonProduction
Domain : MIDDLEWAREAPI
Class : Win32_UserAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-1007
Name : commoniis
Domain : MIDDLEWAREAPI
Class : Win32_UserAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-1008
Name : tidua
Domain : MIDDLEWAREAPI
Class : Win32_UserAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-1009

Group Name : Cyber Operators
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-21-1687551350-3880216100-4069998428-1006
Members :

Group Name : KLAdmins
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-21-1687551350-3880216100-4069998428-1004
Members :
Name : ksnproxy
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : KLOperators
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-21-1687551350-3880216100-4069998428-1005
Members :

Group Name : SQLRUserGroup
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-21-1687551350-3880216100-4069998428-1003
Members :
Name : MSSQLLaunchpad
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : SQLServer2005SQLBrowserUser$MIDDLEWAREAPI
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-21-1687551350-3880216100-4069998428-1001
Members :
Name : SQLBrowser
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : SQLServerMSASUser$MIDDLEWAREAPI$MSSQLSERVER
Host Name : MIDDLEWAREAPI
Group SID : S-1-5-21-1687551350-3880216100-4069998428-1002
Members :
Name : MSSQLServerOLAPService
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
72684 - Enumerate Users via WMI
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI.
Description
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI. Only identities that the authenticated SMB user has permissions to view will be retrieved by this plugin.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering User data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/02/25, Modified: 2025/12/15
Plugin Output

tcp/0


Name : commoniis
SID : S-1-5-21-1687551350-3880216100-4069998428-1008
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : CommonProduction
SID : S-1-5-21-1687551350-3880216100-4069998428-1007
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : DefaultAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-503
Disabled : True
Lockout : False
Change password : True
Source : Local

Name : Guest
SID : S-1-5-21-1687551350-3880216100-4069998428-501
Disabled : True
Lockout : False
Change password : False
Source : Local

Name : Lkpadmin
SID : S-1-5-21-1687551350-3880216100-4069998428-1000
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : production
SID : S-1-5-21-1687551350-3880216100-4069998428-500
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : tidua
SID : S-1-5-21-1687551350-3880216100-4069998428-1009
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : WDAGUtilityAccount
SID : S-1-5-21-1687551350-3880216100-4069998428-504
Disabled : True
Lockout : False
Change password : True
Source : Local

No. Of Users : 8
168980 - Enumerate the PATH Variables
-
Synopsis
Enumerates the PATH variable of the current scan user.
Description
Enumerates the PATH variables of the current scan user.
Solution
Ensure that directories listed here are in line with corporate policy.
Risk Factor
None
Plugin Information
Published: 2022/12/21, Modified: 2025/12/18
Plugin Output

tcp/0

Nessus has enumerated the path of the current scan user :

C:\Program Files\Common Files\Oracle\Java\javapath
C:\Program Files\Microsoft MPI\Bin\
C:\Windows\system32
C:\Windows
C:\Windows\System32\Wbem
C:\Windows\System32\WindowsPowerShell\v1.0\
C:\Windows\System32\OpenSSH\
C:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\
C:\Program Files\Microsoft SQL Server\150\Tools\Binn\
C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\
C:\Program Files\Microsoft SQL Server\150\DTS\Binn\
C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\
C:\Program Files (x86)\Microsoft SQL Server\160\DTS\Binn\
C:\Program Files\Azure Data Studio\bin
C:\Program Files\dotnet\
C:\Program Files (x86)\nodejs\
C:\Program Files\BackupClient\CommandLineTool\
C:\Program Files (x86)\Common Files\Acronis\FileProtector\
C:\Program Files (x86)\Common Files\Acronis\FileProtector64\
C:\Program Files\BackupClient\PyShell\bin\
C:\Program Files (x86)\Common Files\Acronis\SnapAPI\
C:\Windows\System32
C:\Program Files\Microsoft SQL Server\130\Tools\Binn\
C:\Users\tidua\AppData\Local\Microsoft\WindowsApps
35716 - Ethernet Card Manufacturer Detection
-
Synopsis
The manufacturer can be identified from the Ethernet OUI.
Description
Each ethernet MAC address starts with a 24-bit Organizationally Unique Identifier (OUI). These OUIs are registered by IEEE.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/02/19, Modified: 2020/05/13
Plugin Output

tcp/0


The following card manufacturers were identified :

00:50:56:BC:7D:2B : VMware, Inc.
86420 - Ethernet MAC Addresses
-
Synopsis
This plugin gathers MAC addresses from various sources and consolidates them into a list.
Description
This plugin gathers MAC addresses discovered from both remote probing of the host (e.g. SNMP and Netbios) and from running local checks (e.g. ifconfig). It then consolidates the MAC addresses into a single, unique, and uniform list.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/10/16, Modified: 2025/06/10
Plugin Output

tcp/0

The following is a consolidated list of detected MAC addresses:
- 00:50:56:BC:7D:2B
92439 - Explorer Search History
-
Synopsis
Nessus was able to gather a list of items searched for in the Windows UI.
Description
Nessus was able to gather evidence of cached search results from Windows Explorer searches.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0


Explorer search history report attached.
56310 - Firewall Rule Enumeration
-
Synopsis
A firewall is configured on the remote host.
Description
Using the supplied credentials, Nessus was able to get a list of firewall rules from the remote host.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/09/28, Modified: 2020/09/11
Plugin Output

tcp/0

report output too big - ending list here

34196 - Google Chrome Detection (Windows)
-
Synopsis
The remote Windows host contains a web browser.
Description
Google Chrome, a web browser from Google, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0511
Plugin Information
Published: 2008/09/12, Modified: 2025/07/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Google\Chrome\Application
Version : 143.0.7499.193

Note that Nessus only looked in the registry for evidence of Google
Chrome. If there are multiple users on this host, you may wish to
enable the 'Perform thorough tests' setting and re-scan. This will
cause Nessus to scan each local user's directory for installs.

84502 - HSTS Missing From HTTPS Server
-
Synopsis
The remote web server is not enforcing HSTS.
Description
The remote HTTPS server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections.
See Also
Solution
Configure the remote web server to use HSTS.
Risk Factor
None
Plugin Information
Published: 2015/07/02, Modified: 2024/08/09
Plugin Output

tcp/443/www


HTTP/1.1 404 Not Found

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Mon, 12 Jan 2026 12:30:03 GMT
Connection: close
Content-Length: 315


The remote HTTPS server does not send the HTTP
"Strict-Transport-Security" header.

43111 - HTTP Methods Allowed (per directory)
-
Synopsis
This plugin determines which HTTP methods are allowed on various CGI directories.
Description
By calling the OPTIONS method, it is possible to determine which HTTP methods are allowed on each directory.

The following HTTP methods are considered insecure:
PUT, DELETE, CONNECT, TRACE, HEAD

Many frameworks and languages treat 'HEAD' as a 'GET' request, albeit one without any body in the response. If a security constraint was set on 'GET' requests such that only 'authenticatedUsers' could access GET requests for a particular servlet or resource, it would be bypassed for the 'HEAD' version. This allowed unauthorized blind submission of any privileged GET request.

As this list may be incomplete, the plugin also tests - if 'Thorough tests' are enabled or 'Enable web applications tests' is set to 'yes'
in the scan policy - various known HTTP methods on each directory and considers them as unsupported if it receives a response code of 400, 403, 405, or 501.

Note that the plugin output is only informational and does not necessarily indicate the presence of any security vulnerabilities.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/12/10, Modified: 2022/04/11
Plugin Output

tcp/80/www

Based on the response to an OPTIONS request :

- HTTP methods GET HEAD POST TRACE OPTIONS are allowed on :

/
10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/80/www

The remote web server type is :

Microsoft-IIS/10.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/443/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/5800/www

The remote web server type is :

RealVNC/E4

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/5985/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/18018/www

The remote web server type is :

Crow/0.3

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/47001/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

12053 - Host Fully Qualified Domain Name (FQDN) Resolution
-
Synopsis
It was possible to resolve the name of the remote host.
Description
Nessus was able to resolve the fully qualified domain name (FQDN) of the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2004/02/11, Modified: 2025/03/13
Plugin Output

tcp/0


172.17.100.112 resolves as MiddlewareAPI.

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/80/www


Response Code : HTTP/1.1 200 OK

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html
Last-Modified: Wed, 27 Sep 2023 10:30:59 GMT
Accept-Ranges: bytes
ETag: "17b1a5b42df1d91:0"
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Mon, 12 Jan 2026 12:33:56 GMT
Content-Length: 427

Response Body :

<!DOCTYPE html><html><head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, user-scalable=no, initial-scale=1.0, maximum-scale=1.0, minimum-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<link rel="stylesheet" href="/umi.2a931e02.css">
<script async="" src="/scripts/loading.js"></script>
</head>
<body>
<div id="root"></div>
<script src="/umi.012f8f99.js"></script>

</body></html>

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/443/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: Yes
HTTP/2 Cleartext Support: No
SSL : yes
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Mon, 12 Jan 2026 12:33:54 GMT
Connection: close
Content-Length: 315

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/5985/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Mon, 12 Jan 2026 12:33:56 GMT
Connection: close
Content-Length: 315

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/18018/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : yes
Options allowed : (Not implemented)
Headers :

Content-Length: 15
Server: Crow/0.3
Date: Mon, 12 Jan 2026 12:33:56 GMT
Connection: Keep-Alive

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/47001/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Mon, 12 Jan 2026 12:33:56 GMT
Connection: close
Content-Length: 315

Response Body :

171410 - IP Assignment Method Detection
-
Synopsis
Enumerates the IP address assignment method(static/dynamic).
Description
Enumerates the IP address assignment method(static/dynamic).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/14, Modified: 2025/12/15
Plugin Output

tcp/0

+ Loopback Pseudo-Interface 1
+ IPv4
- Address : 127.0.0.1
Assign Method : static
+ IPv6
- Address : ::1
Assign Method : static
+ LAN
+ IPv4
- Address : 172.17.100.112
Assign Method : static

179947 - Intel CPUID detection
-
Synopsis
The processor CPUID was detected on the remote host.
Description
The CPUID of the Intel processor was detected on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/08/18, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Nessus was able to extract the following cpuid: C06F2

92421 - Internet Explorer Typed URLs
-
Synopsis
Nessus was able to enumerate URLs that were manually typed into the Internet Explorer address bar.
Description
Nessus was able to generate a list URLs that were manually typed into the Internet Explorer address bar.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2024/05/08
Plugin Output

tcp/0

http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
res://iesetup.dll/HardAdmin.htm
https://middleware.lkp.net.in/IVR/Login/Index
http://middlewareapi.lkp.net.in/
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://middlewareapi.lkp.net.in/swagger/index.html
https://middlewareapi.lkp.net.in/LocalPath/
https://middlewareapi.lkp.net.in/swagger/index.html
https://lkpconnect.net.in/IVR
http://localhost:5000/swagger
http://172.17.100.112/
http://localhost/
http://middlewareapi.lkp.net.in/swagger.index.html
https://middlewareapi.lkp.net.in/UCC_MATCH/
http://172.17.100.112/lkp.net.in
http://middlewareapi:5000/
http://middlewareapi:5000/swagger
http://localhost:5000/
http://localhost:5001/swagger/index.html
https://www.google.com/
https://middlewareapi.lkp.net.in/swagger/
http://localhost:5000/swagger/index.html
https://localhost:7194/swagger/index.html
http://middleware.lkp.net.in/
https://middlewareapi.lkp.net.in/LocalPath/FileUpload/UCC_MATCH/
https://middleware.lkp.net.in/
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141

Internet Explorer typed URL report attached.

148499 - Java Detection and Identification (Windows)
-
Synopsis
Java is installed on the remote Windows host.
Description
One or more instances of Java are installed on the remote Windows host. This may include private JREs bundled with the Java Development Kit (JDK).

- This plugin attempts to detect Oracle and non-Oracle JRE instances such as Zulu Java, Amazon Corretto, AdoptOpenJDK, IBM Java, etc

- Additional instances of Java may be discovered if 'Perform thorough tests' is enabled.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0690
Plugin Information
Published: 2021/04/14, Modified: 2025/12/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jdk-17\
Version : 17.0.12
Application : Oracle Java
Binary Location : C:\Program Files\Java\jdk-17\bin\java.exe
Details : This Java install appears to be Oracle Java, confirmed by associated
files (high confidence).
Detection Method : Found in Registry

65743 - Java JRE Enabled (Internet Explorer)
-
Synopsis
The remote host has Java JRE enabled for Internet Explorer.
Description
Java JRE is enabled in Internet Explorer. Internet Explorer is no longer supported by Microsoft.
See Also
Solution
Apply Microsoft 'Fix it' 50994 unless Java is needed.
Risk Factor
None
Plugin Information
Published: 2013/03/29, Modified: 2024/10/02
Plugin Output

tcp/445/cifs


Java is enabled for the following ActiveX controls and SIDs :
ActiveX CLSIDs :
{8AD9C840-044E-11D1-B3E9-00805F499D93}
{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0001-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0002-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0003-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0004-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0005-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0006-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}


Note that this check may be incomplete as Nessus can only check the
SIDs of logged on users.
65739 - Java JRE Universally Enabled
-
Synopsis
Java JRE has not been universally disabled on the remote host.
Description
Java JRE has not been universally disabled on the remote host via the Java control panel.
Note that while Java can be individually disabled for each browser, universally disabling Java prevents it from running for all users and browsers.
Functionality to disable Java universally in Windows may not be available in all versions of Java.
See Also
Solution
Disable Java universally unless it is needed.
Risk Factor
None
Plugin Information
Published: 2013/03/29, Modified: 2024/10/02
Plugin Output

tcp/445/cifs

53513 - Link-Local Multicast Name Resolution (LLMNR) Detection
-
Synopsis
The remote device supports LLMNR.
Description
The remote device answered to a Link-local Multicast Name Resolution (LLMNR) request. This protocol provides a name lookup service similar to NetBIOS or DNS. It is enabled by default on modern Windows versions.
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2011/04/21, Modified: 2023/10/17
Plugin Output

udp/5355/llmnr


According to LLMNR, the name of the remote host is 'MiddlewareAPI'.

160301 - Link-Local Multicast Name Resolution (LLMNR) Service Detection
-
Synopsis
Verify status of the LLMNR service on the remote host.
Description
The Link-Local Multicast Name Resolution (LLMNR) service allows both IPv4 and IPv6 hosts to perform name resolution for hosts on the same local link
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2022/04/28, Modified: 2022/12/29
Plugin Output

tcp/445/cifs


LLMNR Key SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast not found.

108761 - MSSQL Host Information in NTLM SSP
-
Synopsis
Nessus can obtain information about the host by examining the NTLM SSP message.
Description
Nessus can obtain information about the host by examining the NTLM SSP challenge issued during NTLM authentication, over MSSQL.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/03/30, Modified: 2025/12/15
Plugin Output

tcp/1433/mssql

Nessus was able to obtain the following information about the host, by
parsing the MSSQL server's NTLM SSP message:

Target Name: MIDDLEWAREAPI
NetBIOS Domain Name: MIDDLEWAREAPI
NetBIOS Computer Name: MIDDLEWAREAPI
DNS Domain Name: MiddlewareAPI
DNS Computer Name: MiddlewareAPI
DNS Tree Name: unknown
Product Version: 10.0.17763

92424 - MUICache Program Execution History
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to query the MUIcache registry key to find evidence of program execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

c:\windows\system32\mmc.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\mmc.exe.friendlyappname : Microsoft Management Console
langid : .
@%systemroot%\system32\themeservice.dll,-8192 : Themes
@%windir%\system32\inetsrv\iisres.dll,-20001 : Web Management Service
@%systemroot%\system32\mprmsg.dll,-32011 : Remote Access IP ARP Driver
@%systemroot%\system32\tabsvc.dll,-100 : Touch Keyboard and Handwriting Panel Service
@%systemroot%\system32\windows.devices.picker.dll,-1006 : DevicePicker
@%systemroot%\system32\bfe.dll,-1002 : The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications.
@%systemroot%\system32\icsvc.dll,-201 : Hyper-V Data Exchange Service
c:\windows\system32,@elscore.dll,-8 : Microsoft Malayalam to Latin Transliteration
@%systemroot%\system32\devicesflowbroker.dll,-103 : DevicesFlow
@%systemroot%\system32\msimsg.dll,-27 : Windows Installer
@%systemroot%\system32\rmapi.dll,-1001 : Radio Management Service
@%systemroot%\system32\drivers\winnat.sys,-10001 : Windows NAT Driver
@%systemroot%\system32\drivers\afd.sys,-1000 : Ancillary Function Driver for Winsock
@%windir%\system32\inetsrv\iisres.dll,-20002 : The Web Management Service enables remote and delegated management capabilities for administrators to manage for the Web server, sites and applications present on this machine.
@%systemroot%\system32\userdataaccessres.dll,-14000 : Provides apps access to structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@%systemroot%\system32\das.dll,-100 : Device Association Service
@%systemroot%\system32\tieringengineservice.exe,-701 : Optimizes the placement of data in storage tiers on all tiered storage spaces in the system.
@%systemroot%\system32\drivers\tunnel.sys,-500 : Microsoft Tunnel Miniport Adapter Driver
@%systemroot%\system32\wephostsvc.dll,-100 : Windows Encryption Provider Host Service
@%systemroot%\system32\devquerybroker.dll,-100 : DevQuery Background Discovery Broker
@%systemroot%\system32\drivers\ehstorclass.sys,-100 : Enhanced Storage Filter Driver
@%systemroot%\system32\cscsvc.dll,-201 : The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state.
@%systemroot%\system32\drivers\tsusbflt.sys,-1000 : Remote Desktop USB Hub Class Filter Driver
@%systemroot%\system32\appinfo.dll,-100 : Application Information
@%systemroot%\system32\wevtsvc.dll,-201 : This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system.
@%systemroot%\system32\sysmain.dll,-1001 : Maintains and improves system performance over time.
@%systemroot%\system32\locator.exe,-2 : Remote Procedure Call (RPC) Locator
@%systemroot%\system32\wecsvc.dll,-201 : This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.
@%systemroot%\system32\srvsvc.dll,-101 : Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\frameserver.dll,-100 : Windows Camera Frame Server
@%systemroot%\system32\btagservice.dll,-102 : Service supporting the audio gateway role of the Bluetooth Handsfree Profile.
@%systemroot%\system32\wcmsvc.dll,-4098 : Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings.
@%systemroot%\system32\phoneserviceres.dll,-10000 : Phone Service
@%systemroot%\system32\wkssvc.dll,-2001 : Browser
@%windir%\system32\rpcepmap.dll,-1002 : Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.
@comres.dll,-2947 : Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start.
@%systemroot%\system32\locator.exe,-3 : In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.
@%systemroot%\system32\fdrespub.dll,-101 : Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.
@%systemroot%\system32\drivers\appvvfs.sys,-101 : AppvVfs
@%windir%\system32\systemeventsbrokerserver.dll,-1001 : System Events Broker
@combase.dll,-5010 : Remote Procedure Call (RPC)
@%systemroot%\system32\wbiosrvc.dll,-101 : The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process.
@%systemroot%\system32\qwave.dll,-2 : Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization.
@%systemroot%\system32\drivers\ndisimplatform.sys,-501 : Microsoft Network Adapter Multiplexor Protocol
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8196 : Receives activation requests over the net.pipe protocol and passes them to the Windows Process Activation Service.
@%systemroot%\system32\drivers\mpsdrv.sys,-23092 : Windows Defender Firewall Authorization Driver
@%systemroot%\system32\printworkflowservice.dll,-100 : PrintWorkflow
@%windir%\system32\inetsrv\iisres.dll,-30015 : Provides W3C logging for Internet Information Services (IIS). If this service is stopped, W3C logging configured by IIS will not work.
@%systemroot%\system32\appvclient.exe,-102 : Microsoft App-V Client
@%systemroot%\system32\drivers\mslbfoprovider.sys,-501 : Microsoft Load Balancing/Failover Provider
@%systemroot%\system32\hnetcfgclient.dll,-201 : HNetCfg Client
@%systemroot%\system32\umpo.dll,-101 : Manages power policy and power policy notification delivery.
@%systemroot%\system32\sensorservice.dll,-1000 : Sensor Service
@combase.dll,-5011 : The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running.
@%systemroot%\syswow64\perfhost.exe,-2 : Performance Counter DLL Host
@%systemroot%\system32\upnphost.dll,-214 : Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\lfsvc.dll,-2 : This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences.
@%systemroot%\system32\storsvc.dll,-100 : Storage Service
@%systemroot%\system32\dssvc.dll,-10003 : Data Sharing Service
@%systemroot%\system32\svsvc.dll,-102 : Verifies potential file system corruptions.
@%systemroot%\system32\sgrmbroker.exe,-101 : Monitors and attests to the integrity of the Windows platform.
@%systemroot%\system32\printworkflowservice.dll,-101 : Print Workflow
@%systemroot%\system32\mprmsg.dll,-32012 : Remote Access IPv6 ARP Driver
@%systemroot%\system32\cdpsvc.dll,-100 : Connected Devices Platform Service
@%systemroot%\system32\defragsvc.dll,-102 : Helps the computer run more efficiently by optimizing files on storage drives.
@%systemroot%\system32\sppsvc.exe,-100 : Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service.
@%windir%\system32\bisrv.dll,-101 : Windows infrastructure service that controls which background tasks can run on the system.
@gpapi.dll,-113 : The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled.
@%systemroot%\system32\polstore.dll,-5011 : Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool ""netsh ipsec"". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped.
@%programfiles%\windows media player\wmpnetwk.exe,-101 : Windows Media Player Network Sharing Service
@%systemroot%\system32\tapisrv.dll,-10100 : Telephony
@%systemroot%\system32\wephostsvc.dll,-101 : Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts
@%systemroot%\system32\themeservice.dll,-8193 : Provides user experience theme management.
@%systemroot%\system32\dosvc.dll,-100 : Delivery Optimization
@%systemroot%\system32\wkssvc.dll,-1000 : Redirected Buffering Sub System
@%systemroot%\system32\ngcsvc.dll,-101 : Provides process isolation for cryptographic keys used to authenticate to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine logon and single-sign on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service.
@%systemroot%\system32\eapsvc.dll,-1 : Extensible Authentication Protocol
@%systemroot%\system32\cdpusersvc.dll,-100 : Connected Devices Platform User Service
@gpapi.dll,-115 : Provides a network service that processes requests to simulate application of Group Policy settings for a target user or computer in various situations and computes the Resultant Set of Policy settings.
@%systemroot%\system32\sensordataservice.exe,-102 : Delivers data from a variety of sensors
@%systemroot%\system32\bridgeres.dll,-1 : Microsoft MAC Bridge
@%systemroot%\system32\hvhostsvc.dll,-101 : Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system.
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-1 : ASP.NET State Service
@%systemroot%\system32\ngcctnrsvc.dll,-2 : Manages local user identity keys used to authenticate user to identity providers as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service.
@%windir%\system32\lsm.dll,-1002 : Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\tapisrv.dll,-10101 : Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.
@%windir%\system32\inetsrv\iisres.dll,-30012 : Provides administrative services for IIS, for example configuration history and Application Pool account mapping. If this service is stopped, configuration history and locking down files or directories with Application Pool specific Access Control Entries will not work.
@%systemroot%\system32\smphost.dll,-102 : Microsoft Storage Spaces SMP
@%systemroot%\system32\appreadiness.dll,-1001 : Gets apps ready for use the first time a user signs in to this PC and when adding new apps.
@%systemroot%\system32\lltdres.dll,-1 : Link-Layer Topology Discovery Mapper
@%systemroot%\system32\drivers\fileinfo.sys,-100 : File Information FS MiniFilter
@%systemroot%\system32\wuaueng.dll,-105 : Windows Update
@%systemroot%\system32\schedsvc.dll,-100 : Task Scheduler
@gpapi.dll,-114 : Resultant Set of Policy Provider
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1000 : Microsoft (R) Diagnostics Hub Standard Collector Service
@%systemroot%\system32\drivers\clfs.sys,-100 : Common Log (CLFS)
@%systemroot%\system32\sppsvc.exe,-101 : Software Protection
@%systemroot%\system32\drivers\wfplwfs.sys,-6000 : Microsoft Windows Filtering Platform
@%systemroot%\system32\fdphost.dll,-101 : The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources.
@keyiso.dll,-101 : The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements.
@appmgmts.dll,-3251 : Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\pushtoinstall.dll,-200 : Windows PushToInstall Service
@%systemroot%\system32\drivers\cnghwassist.sys,-100 : CNG Hardware Assist algorithm provider
@%systemroot%\system32\tokenbroker.dll,-100 : Web Account Manager
@%systemroot%\system32\spoolsv.exe,-2 : This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers.
@%systemroot%\system32\icsvc.dll,-301 : Hyper-V Guest Shutdown Service
@%systemroot%\system32\defragsvc.dll,-101 : Optimize drives
@%systemroot%\system32\axinstsv.dll,-103 : ActiveX Installer (AxInstSV)
@%systemroot%\system32\drivers\indirectkmd.sys,-100 : Indirect Displays Kernel-Mode Driver
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\hvhostsvc.dll,-100 : HV Host Service
@%systemroot%\system32\capabilityaccessmanager.dll,-2 : Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities
@%systemroot%\system32\sgrmbroker.exe,-100 : System Guard Runtime Monitor Broker
@%systemroot%\system32\windows.internal.management.dll,-100 : Device Management Enrollment Service
@%systemroot%\system32\icsvc.dll,-902 : Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network.
@%systemroot%\system32\srpapi.dll,-102 : Smartlocker Filter Driver
@%systemroot%\system32\ncasvc.dll,-3008 : Provides DirectAccess status notification for UI components
@%systemroot%\system32\pcasvc.dll,-1 : Program Compatibility Assistant Service
@%systemroot%\system32\wiaservc.dll,-9 : Windows Image Acquisition (WIA)
@%systemroot%\system32\drivers\appvvemgr.sys,-101 : AppvVemgr
@%systemroot%\system32\icsvc.dll,-801 : Hyper-V Guest Service Interface
@%systemroot%\system32\netman.dll,-109 : Network Connections
@%systemroot%\system32\scdeviceenum.dll,-100 : Smart Card Device Enumeration Service
c:\windows\system32,@elscore.dll,-7 : Microsoft Devanagari to Latin Transliteration
@%systemroot%\system32\drivers\volmgrx.sys,-100 : Dynamic Volume Manager
@%systemroot%\system32\fdrespub.dll,-100 : Function Discovery Resource Publication
@comres.dll,-2451 : Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\nlasvc.dll,-2 : Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ncasvc.dll,-3009 : Network Connectivity Assistant
@%systemroot%\system32\mprmsg.dll,-32002 : Remote Access NDIS WAN Driver
@%systemroot%\system32\rmapi.dll,-1002 : Radio Management and Airplane Mode Service
c:\windows\system32,@elscore.dll,-3 : Microsoft Traditional Chinese to Simplified Chinese Transliteration
@%systemroot%\system32\alg.exe,-113 : Provides support for 3rd party protocol plug-ins for Internet Connection Sharing
@%systemroot%\system32\das.dll,-101 : Enables pairing between the system and wired or wireless devices.
@%systemroot%\system32\samsrv.dll,-2 : The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled.
@%systemroot%\system32\umrdp.dll,-1000 : Remote Desktop Services UserMode Port Redirector
@%systemroot%\system32\audiosrv.dll,-200 : Windows Audio
@%systemroot%\system32\powrprof.dll,-15 : Balanced
@%systemroot%\system32\wpdbusenum.dll,-101 : Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.
@%systemroot%\system32\ipnathlp.dll,-106 : Internet Connection Sharing (ICS)
@%systemroot%\system32\semgrsvc.dll,-1001 : Payments and NFC/SE Manager
@%systemroot%\system32\powrprof.dll,-13 : High performance
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\usermgr.dll,-101 : User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly.
@%systemroot%\system32\drivers\hvservice.sys,-16 : Hypervisor/Virtual Machine Support Driver
@%systemroot%\system32\cscsvc.dll,-200 : Offline Files
@%systemroot%\system32\windows.staterepository.dll,-1 : State Repository Service
@%systemroot%\system32\audioendpointbuilder.dll,-204 : Windows Audio Endpoint Builder
@%systemroot%\system32\mprdim.dll,-200 : Routing and Remote Access
@%systemroot%\system32\userdataaccessres.dll,-10003 : User Data Storage
@%systemroot%\system32\tokenbroker.dll,-101 : This service is used by Web Account Manager to provide single-sign-on to apps and services.
@%systemroot%\system32\cryptsvc.dll,-1002 : Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\netlogon.dll,-102 : Netlogon
@%windir%\system32\drivers\pacer.sys,-101 : QoS Packet Scheduler
@%systemroot%\system32\drivers\msseccore.sys,-1001 : Microsoft Security Core Boot Driver
@%systemroot%\system32\semgrsvc.dll,-1002 : Manages payments and Near Field Communication (NFC) based secure elements.
@%systemroot%\system32\drivers\pdc.sys,-100 : PDC
@firewallapi.dll,-50323 : SNMP Trap
@%systemroot%\system32\mprmsg.dll,-32014 : Remote Access LEGACY NDIS WAN Driver
@%systemroot%\system32\mprmsg.dll,-32013 : IP Traffic Filter Driver
@%systemroot%\system32\drivers\fltmgr.sys,-10001 : FltMgr
@%systemroot%\system32\moshost.dll,-101 : Windows service for application access to downloaded maps. This service is started on-demand by application accessing downloaded maps. Disabling this service will prevent apps from accessing maps.
@%systemroot%\system32\drivers\wcnfs.sys,-100 : Windows Container Name Virtualization
@%systemroot%\system32\devicesflowbroker.dll,-104 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\wdi.dll,-502 : Diagnostic Service Host
@%systemroot%\system32\drivers\mssecflt.sys,-1001 : Microsoft Security Events Component Minifilter
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\drivers\verifierext.sys,-1000 : Driver Verifier Extension
@%systemroot%\system32\tzautoupdate.dll,-200 : Auto Time Zone Updater
@%systemroot%\system32\wpnuserservice.dll,-1 : Windows Push Notifications User Service
@%systemroot%\system32\cdpsvc.dll,-101 : This service is used for Connected Devices Platform scenarios
@%systemroot%\system32\userdataaccessres.dll,-15001 : Contact Data
@%systemroot%\system32\securityhealthagent.dll,-1001 : Windows Security Service handles unified device protection and health information
@%systemroot%\system32\drivers\mshidkmdf.sys,-100 : Pass-through HID to KMDF Filter Driver
@%systemroot%\system32\powrprof.dll,-12 : Favors performance, but may use more energy.
@%systemroot%\system32\sessenv.dll,-1027 : Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates.
@%systemroot%\system32\kpssvc.dll,-100 : KDC Proxy Server service (KPS)
@%systemroot%\system32\tetheringservice.dll,-4097 : Windows Mobile Hotspot Service
@%systemroot%\system32\windows.staterepository.dll,-2 : Provides required infrastructure support for the application model.
@%systemroot%\system32\rasauto.dll,-201 : Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
@%systemroot%\system32\flightsettings.dll,-103 : Windows Insider Service
@%systemroot%\system32\drivers\http.sys,-1 : HTTP Service
@winlangdb.dll,-1121 : English (United States)
@%systemroot%\system32\walletservice.dll,-1000 : WalletService
@%windir%\system32\inetsrv\iisres.dll,-30008 : Enables this server to administer the IIS metabase. The IIS metabase stores configuration for the SMTP and FTP services. If this service is stopped, the server will be unable to configure SMTP or FTP. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\umpnpmgr.dll,-101 : Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\drivers\netbt.sys,-2 : NETBT
@%systemroot%\system32\drivers\ipsecgw.sys,-10001 : Windows IPsec Gateway Driver
@%systemroot%\servicing\trustedinstaller.exe,-101 : Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer.
@%systemroot%\system32\icsvc.dll,-202 : Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\certprop.dll,-13 : Smart Card Removal Policy
@comres.dll,-2946 : KtmRm for Distributed Transaction Coordinator
@%systemroot%\system32\nlasvc.dll,-1 : Network Location Awareness
c:\windows\system32,@elscore.dll,-4 : Microsoft Simplified Chinese to Traditional Chinese Transliteration
@%systemroot%\system32\iscsidsc.dll,-5000 : Microsoft iSCSI Initiator Service
@%systemroot%\system32\drivers\wdf01000.sys,-1000 : Kernel Mode Driver Frameworks service
@%systemroot%\system32\audioendpointbuilder.dll,-205 : Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\scdeviceenum.dll,-101 : Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers.
@%systemroot%\system32\msimsg.dll,-32 : Adds, modifies, and removes applications provided as a Windows Installer (*.msi, *.msp) package. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ajrouter.dll,-1 : Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run.
@%systemroot%\system32\ngcctnrsvc.dll,-1 : Microsoft Passport Container
@%systemroot%\system32\powrprof.dll,-10 : Saves energy by reducing your computer’s performance where possible.
@%systemroot%\system32\vds.exe,-112 : Provides management services for disks, volumes, file systems, and storage arrays.
@%systemroot%\system32\ssdpsrv.dll,-100 : SSDP Discovery
@%systemroot%\system32\sstpsvc.dll,-202 : WAN Miniport (SSTP)
@%systemroot%\system32\embeddedmodesvc.dll,-202 : The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated.
@%systemroot%\system32\windows.warp.jitservice.dll,-101 : Provides a JIT out of process service for WARP when running with ACG enabled.
@%systemroot%\system32\drivers\sgrmagent.sys,-1001 : System Guard Runtime Monitor Agent
@%systemroot%\system32\profsvc.dll,-301 : This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them.
@%systemroot%\system32\seclogon.dll,-7001 : Secondary Logon
@appmgmts.dll,-3250 : Application Management
@%systemroot%\system32\iscsidsc.dll,-5001 : Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\umrdp.dll,-1001 : Allows the redirection of Printers/Drives/Ports for RDP connections
@%systemroot%\system32\wkssvc.dll,-1008 : DFS Namespace Client Driver
@%systemroot%\system32\lmhsvc.dll,-102 : Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\lltdres.dll,-6 : Link-Layer Topology Discovery Mapper I/O Driver
@%systemroot%\system32\pla.dll,-501 : Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\hwpolicy.sys,-101 : Hardware Policy Driver
@%systemroot%\system32\wcmsvc.dll,-4097 : Windows Connection Manager
@%systemroot%\system32\wsmsvc.dll,-102 : Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix.
@%systemroot%\system32\tieringengineservice.exe,-702 : Storage Tiers Management
@%systemroot%\system32\dps.dll,-500 : Diagnostic Policy Service
@%systemroot%\system32\sensrsvc.dll,-1001 : Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well.
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
c:\windows\system32,@elscore.dll,-1 : Microsoft Language Detection
@%systemroot%\system32\axinstsv.dll,-104 : Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings.
@%systemroot%\system32\mprmsg.dll,-32001 : Remote Access NDIS TAPI Driver
@%systemroot%\system32\drivers\mup.sys,-101 : MUP
@%systemroot%\system32\storsvc.dll,-101 : Provides enabling services for storage settings and external storage expansion
@enterpriseappmgmtsvc.dll,-2 : Enables enterprise application management.
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-100 : Shared PC Account Manager
@%systemroot%\system32\netsetupsvc.dll,-3 : Network Setup Service
@%systemroot%\system32\netlogon.dll,-103 : Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\scardsvr.dll,-1 : Smart Card
@%systemroot%\system32\clipsvc.dll,-104 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly.
@%systemroot%\servicing\trustedinstaller.exe,-100 : Windows Modules Installer
@%systemroot%\system32\pushtoinstall.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly.
@%systemroot%\system32\icsvcext.dll,-601 : Hyper-V Remote Desktop Virtualization Service
@%systemroot%\system32\phoneserviceres.dll,-10001 : Manages the telephony state on the device
@%systemroot%\system32\dot3svc.dll,-1103 : The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
@comres.dll,-948 : Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dmwappushsvc.dll,-201 : Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions
@%systemroot%\system32\netprofmsvc.dll,-202 : Network List Service
@waasmedicsvc.dll,-100 : Windows Update Medic Service
@%systemroot%\system32\efssvc.dll,-100 : Encrypting File System (EFS)
@%systemroot%\system32\wkssvc.dll,-1002 : SMB MiniRedirector Wrapper and Engine
@%systemroot%\system32\drivers\filecrypt.sys,-100 : FileCrypt
@%systemroot%\system32\captureservice.dll,-100 : CaptureService
@%windir%\system32\systemeventsbrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\powrprof.dll,-14 : Automatically balances performance with energy consumption on capable hardware.
@%systemroot%\system32\shsvcs.dll,-12289 : Provides notifications for AutoPlay hardware events.
@%systemroot%\system32\icsvcext.dll,-602 : Provides a platform for communication between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\dhcpcore.dll,-101 : Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wercplsupport.dll,-101 : Problem Reports and Solutions Control Panel Support
@%windir%\system32\inetsrv\iisres.dll,-30004 : Provides Web connectivity and administration through the Internet Information Services Manager
@%systemroot%\system32\devicesetupmanager.dll,-1000 : Device Setup Manager
@%systemroot%\system32\dmwappushsvc.dll,-200 : Device Management Wireless Application Protocol (WAP) Push message Routing Service
@%systemroot%\system32\rasmans.dll,-200 : Remote Access Connection Manager
@%systemroot%\system32\swprv.dll,-103 : Microsoft Software Shadow Copy Provider
c:\windows\system32,@elscore.dll,-9 : Microsoft Bengali to Latin Transliteration
@%systemroot%\system32\firewallapi.dll,-23091 : Windows Defender Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.
@%systemroot%\system32\icsvc.dll,-402 : Synchronizes the system time of this virtual machine with the system time of the physical computer.
@%systemroot%\system32\tzautoupdate.dll,-201 : Automatically sets the system time zone.
@%systemroot%\system32\usocore.dll,-102 : Manages Windows Updates. If stopped, your devices will not be able download and install latest udpates.
@%systemroot%\system32\cbdhsvc.dll,-100 : Clipboard User Service
@%systemroot%\system32\iphlpsvc.dll,-501 : Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.
@%systemroot%\system32\seclogon.dll,-7000 : Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\ahcache.sys,-102 : Application Compatibility Cache
@%systemroot%\system32\ncbservice.dll,-500 : Network Connection Broker
@%systemroot%\system32\iphlpsvc.dll,-500 : IP Helper
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1001 : Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them.
@%systemroot%\system32\icsvc.dll,-901 : Hyper-V PowerShell Direct Service
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-1 : Printer Extensions and Notifications
@%systemroot%\system32\installservice.dll,-200 : Microsoft Store Install Service
@%systemroot%\system32\searchindexer.exe,-104 : Provides content indexing, property caching, and search results for files, e-mail, and other content.
@%systemroot%\system32\windows.warp.jitservice.dll,-100 : WarpJITSvc
@%systemroot%\system32\icsvcext.dll,-502 : Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer.
@%systemroot%\system32\lfsvc.dll,-1 : Geolocation Service
@%systemroot%\system32\wbem\wmiapsrv.exe,-111 : Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.
@%systemroot%\system32\licensemanagersvc.dll,-200 : Windows License Manager Service
@%systemroot%\system32\drivers\mshidumdf.sys,-100 : Pass-through HID to UMDF Driver
@%systemroot%\system32\appvclient.exe,-101 : Manages App-V users and virtual applications
@%systemroot%\system32\lltdres.dll,-2 : Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly.
@%systemroot%\system32\vaultsvc.dll,-1003 : Credential Manager
@%systemroot%\system32\drivers\storqosflt.sys,-101 : Storage QoS Filter Driver
@%systemroot%\system32\wpnuserservice.dll,-2 : This service hosts Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw.
@%systemroot%\system32\wersvc.dll,-100 : Windows Error Reporting Service
@%systemroot%\system32\clipsvc.dll,-103 : Client License Service (ClipSVC)
@%systemroot%\system32\ualsvc.dll,-102 : User Access Logging Service
@combase.dll,-5012 : DCOM Server Process Launcher
@%systemroot%\system32\scardsvr.dll,-5 : Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\mprmsg.dll,-32007 : Remote Access PPPOE Driver
@%systemroot%\system32\shsvcs.dll,-12288 : Shell Hardware Detection
@%systemroot%\system32\wlidsvc.dll,-101 : Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account.
@%systemroot%\system32\dosvc.dll,-101 : Performs content delivery optimization tasks
@%systemroot%\system32\wkssvc.dll,-101 : Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\cbdhsvc.dll,-101 : This user service is used for Clipboard scenarios
@%systemroot%\system32\sensrsvc.dll,-1000 : Sensor Monitoring Service
@%systemroot%\system32\dps.dll,-501 : The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function.
@%systemroot%\system32\drivers\luafv.sys,-100 : UAC File Virtualization
@%systemroot%\system32\userdataaccessres.dll,-15000 : Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results.
@%systemroot%\system32\windows.devices.picker.dll,-1007 : This user service is used for managing the Miracast, DLNA, and DIAL UI
@%systemroot%\system32\icsvc.dll,-802 : Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine.
@%systemroot%\system32\sessenv.dll,-1026 : Remote Desktop Configuration
@%systemroot%\system32\nsisvc.dll,-201 : This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.
@%systemroot%\system32\btagservice.dll,-101 : Bluetooth Audio Gateway Service
c:\windows\system32,@elscore.dll,-10 : Microsoft Hangul Decomposition Transliteration
@%systemroot%\system32\userdataaccessres.dll,-10002 : Handles storage of structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-101 : Manages profiles and accounts on a SharedPC configured device
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\usocore.dll,-101 : Update Orchestrator Service
@%systemroot%\system32\bthserv.dll,-101 : Bluetooth Support Service
@%systemroot%\system32\mprmsg.dll,-32005 : WAN Miniport (L2TP)
@%systemroot%\system32\spoolsv.exe,-1 : Print Spooler
@%systemroot%\system32\tetheringservice.dll,-4098 : Provides the ability to share a cellular data connection with another device.
@%systemroot%\system32\smphost.dll,-101 : Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed.
@%systemroot%\system32\drivers\wimmount.sys,-101 : WIMMount
@%systemroot%\system32\ssdpsrv.dll,-101 : Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\devicesetupmanager.dll,-1001 : Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly.
@%systemroot%\system32\swprv.dll,-102 : Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\qmgr.dll,-1001 : Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information.
@%systemroot%\system32\certprop.dll,-11 : Certificate Propagation
@comres.dll,-2798 : Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dssvc.dll,-10002 : Provides data brokering between applications.
@%windir%\system32\inetsrv\iisres.dll,-30014 : W3C Logging Service
@%systemroot%\system32\wercplsupport.dll,-100 : This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports and Solutions control panel.
@%systemroot%\system32\cdpusersvc.dll,-101 : This user service is used for Connected Devices Platform scenarios
@c:\windows\system32\rdpendp.dll,-1001 : Remote Audio
@%systemroot%\system32\qwave.dll,-1 : Quality Windows Audio Video Experience
@%systemroot%\system32\drivers\tcpip.sys,-10001 : TCP/IP Protocol Driver
@firewallapi.dll,-50324 : Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\certprop.dll,-14 : Allows the system to be configured to lock the user desktop upon smart card removal.
@%systemroot%\system32\ikeext.dll,-502 : The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.
@%systemroot%\system32\wuaueng.dll,-106 : Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API.
@%systemroot%\system32\sensorservice.dll,-1001 : A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped.
@%systemroot%\system32\capabilityaccessmanager.dll,-1 : Capability Access Manager Service
@%systemroot%\system32\drivers\dam.sys,-100 : Desktop Activity Moderator Driver
@%systemroot%\system32\agentservice.exe,-102 : User Experience Virtualization Service
@%systemroot%\system32\drivers\mountmgr.sys,-100 : Mount Point Manager
@%systemroot%\system32\wiaservc.dll,-10 : Provides image acquisition services for scanners and cameras
@%systemroot%\syswow64\perfhost.exe,-1 : Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.
@%systemroot%\system32\bthserv.dll,-102 : The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated.
@%windir%\system32\timebrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\wpnservice.dll,-2 : This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server.
@%systemroot%\system32\wkssvc.dll,-1006 : SMB 2.0 MiniRedirector
@%systemroot%\system32\alg.exe,-112 : Application Layer Gateway Service
@%systemroot%\system32\usermgr.dll,-100 : User Manager
@%systemroot%\system32\drivers\ndproxy.sys,-6000 : NDIS Proxy Driver
@%systemroot%\system32\frameserver.dll,-101 : Enables multiple clients to access video frames from camera devices.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8198 : Receives activation requests over the net.tcp protocol and passes them to the Windows Process Activation Service.
@c:\windows\system32\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\system32\icsvcext.dll,-501 : Hyper-V Volume Shadow Copy Requestor
@%systemroot%\system32\sacsvr.dll,-500 : Special Administration Console Helper
@%systemroot%\system32\schedsvc.dll,-101 : Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wbem\wmisvc.dll,-204 : Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%windir%\system32\bisrv.dll,-100 : Background Tasks Infrastructure Service
@%systemroot%\system32\wersvc.dll,-101 : Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed.
@%systemroot%\system32\termsrv.dll,-267 : Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.
@%systemroot%\system32\sens.dll,-201 : Monitors system events and notifies subscribers to COM+ Event System of these events.
@%systemroot%\system32\drivers\mssecwfp.sys,-1001 : Microsoft Security WFP Callout Driver
@%systemroot%\system32\devquerybroker.dll,-101 : Enables apps to discover devices with a backgroud task
@%systemroot%\system32\tabsvc.dll,-101 : Enables Touch Keyboard and Handwriting Panel pen and ink functionality
@%systemroot%\system32\drivers\scfilter.sys,-11 : Smart card PnP Class Filter Driver
@%systemroot%\system32\userdataaccessres.dll,-14001 : User Data Access
@%systemroot%\system32\ncbservice.dll,-501 : Brokers connections that allow Windows Store Apps to receive notifications from the internet.
@%systemroot%\system32\wpnservice.dll,-1 : Windows Push Notifications System Service
@%systemroot%\system32\drivers\volsnap.sys,-100 : Volume Shadow Copy driver
@%systemroot%\system32\hidserv.dll,-102 : Activates and maintains the use of hot buttons on keyboards, remote controls, and other multimedia devices. It is recommended that you keep this service running.
@%systemroot%\system32\efssvc.dll,-101 : Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.
@%systemroot%\system32\vds.exe,-100 : Virtual Disk
@%systemroot%\system32\drivers\rdpdr.sys,-100 : Remote Desktop Device Redirector Driver
@%systemroot%\system32\wdi.dll,-500 : Diagnostic System Host
@%systemroot%\system32\lltdres.dll,-5 : Link-Layer Topology Discovery Responder
@%systemroot%\system32\drivers\appvstrm.sys,-101 : AppvStrm
@%systemroot%\system32\wbiosrvc.dll,-100 : Windows Biometric Service
@%systemroot%\system32\umpnpmgr.dll,-100 : Device Install Service
@%systemroot%\system32\sstpsvc.dll,-201 : Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.
@%systemroot%\system32\consentuxclient.dll,-101 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\captureservice.dll,-101 : OneCore Capture Service
@%systemroot%\system32\upnphost.dll,-213 : UPnP Device Host
@%systemroot%\system32\windows.internal.management.dll,-101 : Performs Device Enrollment Activities for Device Management
@%systemroot%\system32\diagtrack.dll,-3002 : The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics.
@%systemroot%\system32\svsvc.dll,-101 : Spot Verifier
@%systemroot%\system32\trkwks.dll,-2 : Maintains links between NTFS files within a computer or across computers in a network.
@%systemroot%\system32\drivers\wpdupfltr.sys,-100 : WPD Upper Class Filter Driver
@%systemroot%\system32\drivers\partmgr.sys,-100 : Partition driver
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\drivers\filetrace.sys,-10001 : FileTrace
@%systemroot%\system32\urlmon.dll,-4200 : Open File - Security Warning
@%systemroot%\system32\wecsvc.dll,-200 : Windows Event Collector
@%systemroot%\system32\drivers\wudfpf.sys,-1000 : User Mode Driver Frameworks Platform Driver
@%systemroot%\system32\icsvc.dll,-302 : Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer.
@%systemroot%\system32\drivers\bam.sys,-100 : Background Activity Moderator Driver
@%systemroot%\system32\wpdbusenum.dll,-100 : Portable Device Enumerator Service
@%systemroot%\system32\pla.dll,-500 : Performance Logs & Alerts
@comres.dll,-2450 : COM+ Event System
@%systemroot%\system32\vaultsvc.dll,-1004 : Provides secure storage and retrieval of credentials to users, applications and security service packages.
@%systemroot%\system32\installservice.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then installations will not function properly.
@%systemroot%\system32\mprmsg.dll,-32006 : WAN Miniport (PPTP)
@%systemroot%\system32\appxdeploymentserver.dll,-1 : AppX Deployment Service (AppXSVC)
@gpapi.dll,-112 : Group Policy Client
@%systemroot%\system32\vssvc.exe,-101 : Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\appreadiness.dll,-1000 : App Readiness
@%windir%\system32\drivers\netbios.sys,-503 : NetBIOS Interface
@%systemroot%\system32\drivers\qwavedrv.sys,-1 : QWAVE driver
c:\windows\system32,@elscore.dll,-5 : Microsoft Transliteration Engine
@%systemroot%\system32\certprop.dll,-12 : Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver.
@%systemroot%\system32\drivers\bindflt.sys,-100 : Windows Bind Filter Driver
@%systemroot%\system32\sensordataservice.exe,-101 : Sensor Data Service
@c:\windows\syswow64\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-2 : Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\flightsettings.dll,-104 : Provides infrastructure support for the Windows Insider Program. This service must remain enabled for the Windows Insider Program to work.
@%systemroot%\system32\moshost.dll,-100 : Downloaded Maps Manager
@%systemroot%\system32\hidserv.dll,-101 : Human Interface Device Service
@%systemroot%\system32\powrprof.dll,-11 : Power saver
@%systemroot%\system32\sacsvr.dll,-501 : Allows administrators to remotely access a command prompt using Emergency Management Services.
@%systemroot%\system32\graphicsperfsvc.dll,-101 : Graphics performance monitor service
@%systemroot%\system32\graphicsperfsvc.dll,-100 : GraphicsPerfSvc
@%systemroot%\system32\qmgr.dll,-1000 : Background Intelligent Transfer Service
@%systemroot%\system32\dnsapi.dll,-102 : The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-2 : This service opens custom printer dialog boxes and handles notifications from a remote print server or a printer. If you turn off this service, you won’t be able to see printer extensions or notifications.
@%systemroot%\system32\ualsvc.dll,-101 : This service logs unique client access requests, in the form of IP addresses and user names, of installed products and roles on the local server. This information can be queried, via Powershell, by administrators needing to quantify client demand of server software for offline Client Access License (CAL) management. If the service is disabled, client requests will not be logged and will not be retrievable via Powershell queries. Stopping the service will not affect query of historical data (see supporting documentation for steps to delete historical data). The local system administrator must consult his, or her, Windows Server license terms to determine the number of CALs that are required for the server software to be appropriately licensed; use of the UAL service and data does not alter this obligation.
@%systemroot%\system32\appidsvc.dll,-100 : Application Identity
@%systemroot%\system32\cryptsvc.dll,-1001 : Cryptographic Services
@%systemroot%\system32\embeddedmodesvc.dll,-201 : Embedded Mode
@%systemroot%\system32\ajrouter.dll,-2 : AllJoyn Router Service
@%systemroot%\system32\srpapi.dll,-100 : AppID Driver
@%systemroot%\system32\licensemanagersvc.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly.
@%systemroot%\system32\rasauto.dll,-200 : Remote Access Auto Connection Manager
@%systemroot%\system32\ngcsvc.dll,-100 : Microsoft Passport
@%systemroot%\system32\w32time.dll,-201 : Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\ndiscap.sys,-5000 : Microsoft NDIS Capture
@%systemroot%\system32\drivers\ndis.sys,-200 : NDIS System Driver
@%systemroot%\system32\winhttp.dll,-101 : WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol.
@%systemroot%\system32\diagtrack.dll,-3001 : Connected User Experiences and Telemetry
@%systemroot%\system32\kpssvc.dll,-101 : KDC Proxy Server service runs on edge servers to proxy Kerberos protocol messages to domain controllers on the corporate network.
@%systemroot%\system32\appxdeploymentserver.dll,-2 : Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly.
c:\windows\system32,@elscore.dll,-6 : Microsoft Cyrillic to Latin Transliteration
@%systemroot%\system32\mprdim.dll,-201 : Offers routing services to businesses in local area and wide area network environments.
@%systemroot%\system32\bthavctpsvc.dll,-101 : AVCTP service
@%systemroot%\system32\drivers\wudfrd.sys,-1000 : Windows Driver Foundation - User-mode Driver Framework Reflector
@%systemroot%\system32\sysmain.dll,-1000 : SysMain
@%systemroot%\system32\bthavctpsvc.dll,-102 : This is Audio Video Control Transport Protocol service
c:\windows\system32,@elscore.dll,-2 : Microsoft Script Detection
@%systemroot%\system32\wlidsvc.dll,-100 : Microsoft Account Sign-in Assistant
@%systemroot%\system32\wiarpc.dll,-1 : Launches applications associated with still image acquisition events.
@%systemroot%\system32\drivers\mslldp.sys,-200 : Microsoft Link-Layer Discovery Protocol
@%systemroot%\system32\wbem\wmisvc.dll,-205 : Windows Management Instrumentation
@%systemroot%\system32\consentuxclient.dll,-100 : ConsentUX
@%systemroot%\system32\appidsvc.dll,-101 : Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.
@%systemroot%\system32\rasmans.dll,-201 : Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\profsvc.dll,-300 : User Profile Service
@%systemroot%\system32\icsvc.dll,-102 : Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding.
@%windir%\system32\inetsrv\iisres.dll,-30002 : The Windows Process Activation Service (WAS) provides process activation, resource management and health management services for message-activated applications.
@%systemroot%\system32\netsetupsvc.dll,-4 : The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in-progress may be cancelled.
@%systemroot%\system32\drivers\wcifs.sys,-100 : Windows Container Isolation
@%systemroot%\system32\fdphost.dll,-100 : Function Discovery Provider Host
@%systemroot%\system32\ipnathlp.dll,-107 : Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
@%systemroot%\system32\agentservice.exe,-101 : Provides support for application and OS settings roaming
@%systemroot%\system32\wbem\wmiapsrv.exe,-110 : WMI Performance Adapter
@waasmedicsvc.dll,-101 : Enables remediation and protection of Windows Update components.
@combase.dll,-5013 : The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8200 : Provides ability to share TCP ports over the net.tcp protocol.
@%systemroot%\system32\drivers\mmcss.sys,-100 : Multimedia Class Scheduler
@%systemroot%\system32\walletservice.dll,-1001 : Hosts objects used by clients of the wallet
@%systemroot%\system32\icsvc.dll,-401 : Hyper-V Time Synchronization Service
@%systemroot%\system32\drivers\ndisvirtualbus.sys,-200 : Microsoft Virtual Network Adapter Enumerator
@%systemroot%\system32\audiosrv.dll,-201 : Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\pcasvc.dll,-2 : This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly.
@%systemroot%\system32\mprmsg.dll,-32000 : RAS Asynchronous Media Driver
@%systemroot%\system32\netman.dll,-110 : Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
@regsvc.dll,-2 : Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wdi.dll,-503 : The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\icsvc.dll,-101 : Hyper-V Heartbeat Service
@%systemroot%\system32\srvsvc.dll,-104 : Server SMB 2.xxx Driver
@%systemroot%\system32\netprofmsvc.dll,-203 : Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.
@%systemroot%\system32\dot3svc.dll,-1102 : Wired AutoConfig
@%systemroot%\system32\drivers\uevagentdriver.sys,-101 : UevAgentDriver
@%systemroot%\system32\tcpipcfg.dll,-50004 : NetIO Legacy TDI Support Driver
@%systemroot%\system32\appinfo.dll,-101 : Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.
@%systemroot%\system32\wiarpc.dll,-2 : Still Image Acquisition Events
@%systemroot%\system32\eapsvc.dll,-2 : The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication.
@%systemroot%\system32\securityhealthagent.dll,-1002 : Windows Security Service
@%systemroot%\system32\wdi.dll,-501 : The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function.
@enterpriseappmgmtsvc.dll,-1 : Enterprise App Management Service
@%systemroot%\system32\coremessaging.dll,-2 : Manages communication between system components.
@%systemroot%\system32\drivers\nsiproxy.sys,-2 : NSI Proxy Service Driver
@%systemroot%\system32\drivers\fsdepends.sys,-10001 : File System Dependency Minifilter
@%systemroot%\system32\fntcache.dll,-101 : Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.
@%programfiles%\windows media player\wmpnetwk.exe,-102 : Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
@%systemroot%\system32\searchindexer.exe,-103 : Windows Search
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\ci.dll,-101 : Enclave
c:\program files (x86)\microsoft visual studio\2017\professional\common7\ide\devenv.exe.friendlyappname : Microsoft Visual Studio 2017
c:\users\administrator\desktop\winrar-x64-590.exe.friendlyappname : WinRAR archiver
c:\windows\system32\msiexec.exe.applicationcompany : Microsoft Corporation
d:\backup\11042023\new\lkp_middleware.exe.applicationcompany : LKP_Middleware
c:\program files (x86)\common files\microsoft shared\msenv\vslauncher.exe.friendlyappname : Microsoft Visual Studio Version Selector
c:\program files\microsoft visual studio\2022\professional\common7\ide\blend.exe.friendlyappname : Blend for Visual Studio
\\192.168.150.67\d$\e\software\winrar-x64-590.exe.friendlyappname : WinRAR archiver
c:\windows\system32\shell32.dll.applicationcompany : Microsoft Corporation
c:\windows\system32\control.exe.friendlyappname : Windows Control Panel
c:\windows\system32\explorerframe.dll.applicationcompany : Microsoft Corporation
c:\program files\windows nt\accessories\wordpad.exe.applicationcompany : Microsoft Corporation
d:\backup\06112023\new\lkp_middleware.exe.friendlyappname : LKP_Middleware
c:\windows\system32\appresolver.dll.applicationcompany : Microsoft Corporation
c:\program files (x86)\microsoft visual studio\2017\professional\common7\ide\devenv.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\mmc.exe.friendlyappname : Microsoft Management Console
c:\windows\system32\openwith.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\compmgmtlauncher.exe.applicationcompany : Microsoft Corporation
c:\progra~2\mif5ba~1\office14\ois.exe.applicationcompany : Microsoft Corporation
d:\backup\31102023\new\lkp_middleware.exe.applicationcompany : LKP_Middleware
c:\users\administrator\appdata\local\programs\microsoft vs code\code.exe.friendlyappname : Visual Studio Code
c:\windows\system32\wscript.exe.friendlyappname : Microsoft ® Windows Based Script Host
c:\windows\system32\openwith.exe.friendlyappname : Pick an app
c:\program files (x86)\windows media player\wmplayer.exe.friendlyappname : Windows Media Player
c:\users\administrator\appdata\local\githubdesktop\app-3.3.1\githubdesktop.exe.applicationcompany : GitHub, Inc.
c:\program files\internet explorer\iexplore.exe.applicationcompany : Microsoft Corporation
c:\program files\microsoft visual studio\2022\professional\common7\ide\devenv.exe.applicationcompany : Microsoft Corporation
c:\program files\winrar\winrar.exe.friendlyappname : WinRAR archiver
c:\windows\explorer.exe.friendlyappname : Windows Explorer
c:\program files\microsoft visual studio\2022\professional\common7\ide\devenv.exe.friendlyappname : Microsoft Visual Studio 2022
c:\windows\system32\mspaint.exe.friendlyappname : Paint
c:\windows\system32\notepad.exe.friendlyappname : Notepad
c:\windows\system32\msiexec.exe.friendlyappname : Windows® installer
d:\backup\081120233\new\lkp_middleware.exe.applicationcompany : LKP_Middleware
d:\backup\081120233\new\lkp_middleware.exe.friendlyappname : LKP_Middleware
c:\windows\system32\wscript.exe.applicationcompany : Microsoft Corporation
c:\program files\winrar\winrar.exe.applicationcompany : Alexander Roshal
c:\progra~2\mif5ba~1\office14\ois.exe.friendlyappname : Microsoft Office 2010
c:\program files (x86)\windows media player\wmplayer.exe.applicationcompany : Microsoft Corporation
d:\backup\06112023\new\lkp_middleware.exe.applicationcompany : LKP_Middleware
c:\users\administrator\appdata\local\programs\microsoft vs code\code.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\control.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\windows.storage.dll.applicationcompany : Microsoft Corporation
c:\windows\system32\mmc.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\fsquirt.exe.friendlyappname : fsquirt
c:\windows\system32\windows.storage.dll.friendlyappname : Microsoft WinRT Storage API
c:\windows\system32\shell32.dll.friendlyappname : Windows Shell Common Dll
c:\windows\system32\notepad.exe.applicationcompany : Microsoft Corporation
c:\program files (x86)\microsoft office\office14\winword.exe.applicationcompany : Microsoft Corporation
c:\users\administrator\appdata\local\githubdesktop\app-3.3.1\githubdesktop.exe.friendlyappname : GitHubDesktop
c:\program files (x86)\microsoft office\office14\winword.exe.friendlyappname : Microsoft Word
c:\windows\system32\compmgmtlauncher.exe.friendlyappname : Computer Management Snapin Launcher
d:\backup\11042023\new\lkp_middleware.exe.friendlyappname : LKP_Middleware
c:\program files\microsoft visual studio\2022\professional\common7\ide\blend.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\explorerframe.dll.friendlyappname : ExplorerFrame
c:\program files\internet explorer\iexplore.exe.friendlyappname : Internet Explorer
c:\program files (x86)\common files\microsoft shared\msenv\vslauncher.exe.applicationcompany : Microsoft Corporation
d:\backup\.folderstructure.bat.friendlyappname : .FolderStructure
langid : .
c:\windows\system32\fsquirt.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\appresolver.dll.friendlyappname : App Resolver
c:\users\administrator\desktop\winrar-x64-590.exe.applicationcompany : Alexander Roshal
c:\program files\windows nt\accessories\wordpad.exe.friendlyappname : WordPad
c:\windows\explorer.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\mspaint.exe.applicationcompany : Microsoft Corporation
\\192.168.150.67\d$\e\software\winrar-x64-590.exe.applicationcompany : Alexander Roshal
d:\backup\31102023\new\lkp_middleware.exe.friendlyappname : LKP_Middleware
@%systemroot%\system32\themeservice.dll,-8192 : Themes
@%windir%\system32\inetsrv\iisres.dll,-20001 : Web Management Service
@%systemroot%\system32\mprmsg.dll,-32011 : Remote Access IP ARP Driver
@%systemroot%\system32\tabsvc.dll,-100 : Touch Keyboard and Handwriting Panel Service
@%systemroot%\system32\windows.devices.picker.dll,-1006 : DevicePicker
@%systemroot%\system32\bfe.dll,-1002 : The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications.
@%systemroot%\system32\icsvc.dll,-201 : Hyper-V Data Exchange Service
c:\windows\system32,@elscore.dll,-8 : Microsoft Malayalam to Latin Transliteration
@%systemroot%\system32\devicesflowbroker.dll,-103 : DevicesFlow
@%systemroot%\system32\msimsg.dll,-27 : Windows Installer
@%systemroot%\system32\rmapi.dll,-1001 : Radio Management Service
@%systemroot%\system32\drivers\winnat.sys,-10001 : Windows NAT Driver
@%systemroot%\system32\drivers\afd.sys,-1000 : Ancillary Function Driver for Winsock
@%windir%\system32\inetsrv\iisres.dll,-20002 : The Web Management Service enables remote and delegated management capabilities for administrators to manage for the Web server, sites and applications present on this machine.
@%systemroot%\system32\userdataaccessres.dll,-14000 : Provides apps access to structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@%systemroot%\system32\das.dll,-100 : Device Association Service
@%systemroot%\system32\tieringengineservice.exe,-701 : Optimizes the placement of data in storage tiers on all tiered storage spaces in the system.
@%systemroot%\system32\drivers\tunnel.sys,-500 : Microsoft Tunnel Miniport Adapter Driver
@%systemroot%\system32\wephostsvc.dll,-100 : Windows Encryption Provider Host Service
@%systemroot%\system32\devquerybroker.dll,-100 : DevQuery Background Discovery Broker
@%systemroot%\system32\drivers\ehstorclass.sys,-100 : Enhanced Storage Filter Driver
@%systemroot%\system32\cscsvc.dll,-201 : The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state.
@%systemroot%\system32\drivers\tsusbflt.sys,-1000 : Remote Desktop USB Hub Class Filter Driver
@%systemroot%\system32\appinfo.dll,-100 : Application Information
@%systemroot%\system32\wevtsvc.dll,-201 : This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system.
@%systemroot%\system32\sysmain.dll,-1001 : Maintains and improves system performance over time.
@%systemroot%\system32\locator.exe,-2 : Remote Procedure Call (RPC) Locator
@%systemroot%\system32\wecsvc.dll,-201 : This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.
@%systemroot%\system32\srvsvc.dll,-101 : Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\frameserver.dll,-100 : Windows Camera Frame Server
@%systemroot%\system32\btagservice.dll,-102 : Service supporting the audio gateway role of the Bluetooth Handsfree Profile.
@%systemroot%\system32\wcmsvc.dll,-4098 : Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings.
@%systemroot%\system32\phoneserviceres.dll,-10000 : Phone Service
@%systemroot%\system32\wkssvc.dll,-2001 : Browser
@%windir%\system32\rpcepmap.dll,-1002 : Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.
@comres.dll,-2947 : Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start.
@%systemroot%\system32\locator.exe,-3 : In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.
@%systemroot%\system32\fdrespub.dll,-101 : Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.
@%systemroot%\system32\drivers\appvvfs.sys,-101 : AppvVfs
@%windir%\system32\systemeventsbrokerserver.dll,-1001 : System Events Broker
@combase.dll,-5010 : Remote Procedure Call (RPC)
@%systemroot%\system32\wbiosrvc.dll,-101 : The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process.
@%systemroot%\system32\qwave.dll,-2 : Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization.
@%systemroot%\system32\drivers\ndisimplatform.sys,-501 : Microsoft Network Adapter Multiplexor Protocol
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8196 : Receives activation requests over the net.pipe protocol and passes them to the Windows Process Activation Service.
@%systemroot%\system32\drivers\mpsdrv.sys,-23092 : Windows Defender Firewall Authorization Driver
@%systemroot%\system32\printworkflowservice.dll,-100 : PrintWorkflow
@%windir%\system32\inetsrv\iisres.dll,-30015 : Provides W3C logging for Internet Information Services (IIS). If this service is stopped, W3C logging configured by IIS will not work.
@%systemroot%\system32\appvclient.exe,-102 : Microsoft App-V Client
@%systemroot%\system32\drivers\mslbfoprovider.sys,-501 : Microsoft Load Balancing/Failover Provider
@%systemroot%\system32\hnetcfgclient.dll,-201 : HNetCfg Client
@%systemroot%\system32\umpo.dll,-101 : Manages power policy and power policy notification delivery.
@%systemroot%\system32\sensorservice.dll,-1000 : Sensor Service
@combase.dll,-5011 : The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running.
@%systemroot%\syswow64\perfhost.exe,-2 : Performance Counter DLL Host
@%systemroot%\system32\upnphost.dll,-214 : Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\lfsvc.dll,-2 : This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences.
@%systemroot%\system32\storsvc.dll,-100 : Storage Service
@%systemroot%\system32\dssvc.dll,-10003 : Data Sharing Service
@%systemroot%\system32\svsvc.dll,-102 : Verifies potential file system corruptions.
@%systemroot%\system32\sgrmbroker.exe,-101 : Monitors and attests to the integrity of the Windows platform.
@%systemroot%\system32\printworkflowservice.dll,-101 : Print Workflow
@%systemroot%\system32\mprmsg.dll,-32012 : Remote Access IPv6 ARP Driver
@%systemroot%\system32\cdpsvc.dll,-100 : Connected Devices Platform Service
@%systemroot%\system32\defragsvc.dll,-102 : Helps the computer run more efficiently by optimizing files on storage drives.
@%systemroot%\system32\sppsvc.exe,-100 : Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service.
@%windir%\system32\bisrv.dll,-101 : Windows infrastructure service that controls which background tasks can run on the system.
@gpapi.dll,-113 : The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled.
@%systemroot%\system32\polstore.dll,-5011 : Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool ""netsh ipsec"". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped.
@%programfiles%\windows media player\wmpnetwk.exe,-101 : Windows Media Player Network Sharing Service
@%systemroot%\system32\tapisrv.dll,-10100 : Telephony
@%systemroot%\system32\wephostsvc.dll,-101 : Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts
@%systemroot%\system32\themeservice.dll,-8193 : Provides user experience theme management.
@%systemroot%\system32\dosvc.dll,-100 : Delivery Optimization
@%systemroot%\system32\wkssvc.dll,-1000 : Redirected Buffering Sub System
@%systemroot%\system32\ngcsvc.dll,-101 : Provides process isolation for cryptographic keys used to authenticate to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine logon and single-sign on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service.
@%systemroot%\system32\eapsvc.dll,-1 : Extensible Authentication Protocol
@%systemroot%\system32\cdpusersvc.dll,-100 : Connected Devices Platform User Service
@gpapi.dll,-115 : Provides a network service that processes requests to simulate application of Group Policy settings for a target user or computer in various situations and computes the Resultant Set of Policy settings.
@%systemroot%\system32\sensordataservice.exe,-102 : Delivers data from a variety of sensors
@%systemroot%\system32\bridgeres.dll,-1 : Microsoft MAC Bridge
@%systemroot%\system32\hvhostsvc.dll,-101 : Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system.
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-1 : ASP.NET State Service
@%systemroot%\system32\ngcctnrsvc.dll,-2 : Manages local user identity keys used to authenticate user to identity providers as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service.
@%windir%\system32\lsm.dll,-1002 : Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\tapisrv.dll,-10101 : Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.
@%windir%\system32\inetsrv\iisres.dll,-30012 : Provides administrative services for IIS, for example configuration history and Application Pool account mapping. If this service is stopped, configuration history and locking down files or directories with Application Pool specific Access Control Entries will not work.
@%systemroot%\system32\smphost.dll,-102 : Microsoft Storage Spaces SMP
@%systemroot%\system32\appreadiness.dll,-1001 : Gets apps ready for use the first time a user signs in to this PC and when adding new apps.
@%systemroot%\system32\lltdres.dll,-1 : Link-Layer Topology Discovery Mapper
@%systemroot%\system32\drivers\fileinfo.sys,-100 : File Information FS MiniFilter
@%systemroot%\system32\wuaueng.dll,-105 : Windows Update
@%systemroot%\system32\schedsvc.dll,-100 : Task Scheduler
@gpapi.dll,-114 : Resultant Set of Policy Provider
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1000 : Microsoft (R) Diagnostics Hub Standard Collector Service
@%systemroot%\system32\drivers\clfs.sys,-100 : Common Log (CLFS)
@%systemroot%\system32\sppsvc.exe,-101 : Software Protection
@%systemroot%\system32\drivers\wfplwfs.sys,-6000 : Microsoft Windows Filtering Platform
@%systemroot%\system32\fdphost.dll,-101 : The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources.
@keyiso.dll,-101 : The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements.
@appmgmts.dll,-3251 : Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\pushtoinstall.dll,-200 : Windows PushToInstall Service
@%systemroot%\system32\drivers\cnghwassist.sys,-100 : CNG Hardware Assist algorithm provider
@%systemroot%\system32\tokenbroker.dll,-100 : Web Account Manager
@%systemroot%\system32\spoolsv.exe,-2 : This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers.
@%systemroot%\system32\icsvc.dll,-301 : Hyper-V Guest Shutdown Service
@%systemroot%\system32\defragsvc.dll,-101 : Optimize drives
@%systemroot%\system32\axinstsv.dll,-103 : ActiveX Installer (AxInstSV)
@%systemroot%\system32\drivers\indirectkmd.sys,-100 : Indirect Displays Kernel-Mode Driver
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\hvhostsvc.dll,-100 : HV Host Service
@%systemroot%\system32\capabilityaccessmanager.dll,-2 : Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities
@%systemroot%\system32\sgrmbroker.exe,-100 : System Guard Runtime Monitor Broker
@%systemroot%\system32\windows.internal.management.dll,-100 : Device Management Enrollment Service
@%systemroot%\system32\icsvc.dll,-902 : Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network.
@%systemroot%\system32\srpapi.dll,-102 : Smartlocker Filter Driver
@%systemroot%\system32\ncasvc.dll,-3008 : Provides DirectAccess status notification for UI components
@%systemroot%\system32\pcasvc.dll,-1 : Program Compatibility Assistant Service
@%systemroot%\system32\wiaservc.dll,-9 : Windows Image Acquisition (WIA)
@%systemroot%\system32\drivers\appvvemgr.sys,-101 : AppvVemgr
@%systemroot%\system32\icsvc.dll,-801 : Hyper-V Guest Service Interface
@%systemroot%\system32\netman.dll,-109 : Network Connections
@%systemroot%\system32\scdeviceenum.dll,-100 : Smart Card Device Enumeration Service
c:\windows\system32,@elscore.dll,-7 : Microsoft Devanagari to Latin Transliteration
@%systemroot%\system32\drivers\volmgrx.sys,-100 : Dynamic Volume Manager
@%systemroot%\system32\fdrespub.dll,-100 : Function Discovery Resource Publication
@comres.dll,-2451 : Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\nlasvc.dll,-2 : Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ncasvc.dll,-3009 : Network Connectivity Assistant
@%systemroot%\system32\mprmsg.dll,-32002 : Remote Access NDIS WAN Driver
@%systemroot%\system32\rmapi.dll,-1002 : Radio Management and Airplane Mode Service
c:\windows\system32,@elscore.dll,-3 : Microsoft Traditional Chinese to Simplified Chinese Transliteration
@%systemroot%\system32\alg.exe,-113 : Provides support for 3rd party protocol plug-ins for Internet Connection Sharing
@%systemroot%\system32\das.dll,-101 : Enables pairing between the system and wired or wireless devices.
@%systemroot%\system32\samsrv.dll,-2 : The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled.
@%systemroot%\system32\umrdp.dll,-1000 : Remote Desktop Services UserMode Port Redirector
@%systemroot%\system32\audiosrv.dll,-200 : Windows Audio
@%systemroot%\system32\powrprof.dll,-15 : Balanced
@%systemroot%\system32\wpdbusenum.dll,-101 : Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.
@%systemroot%\system32\ipnathlp.dll,-106 : Internet Connection Sharing (ICS)
@%systemroot%\system32\semgrsvc.dll,-1001 : Payments and NFC/SE Manager
@%systemroot%\system32\powrprof.dll,-13 : High performance
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\usermgr.dll,-101 : User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly.
@%systemroot%\system32\drivers\hvservice.sys,-16 : Hypervisor/Virtual Machine Support Driver
@%systemroot%\system32\cscsvc.dll,-200 : Offline Files
@%systemroot%\system32\windows.staterepository.dll,-1 : State Repository Service
@%systemroot%\system32\audioendpointbuilder.dll,-204 : Windows Audio Endpoint Builder
@%systemroot%\system32\mprdim.dll,-200 : Routing and Remote Access
@%systemroot%\system32\userdataaccessres.dll,-10003 : User Data Storage
@%systemroot%\system32\tokenbroker.dll,-101 : This service is used by Web Account Manager to provide single-sign-on to apps and services.
@%systemroot%\system32\cryptsvc.dll,-1002 : Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\netlogon.dll,-102 : Netlogon
@%windir%\system32\drivers\pacer.sys,-101 : QoS Packet Scheduler
@%systemroot%\system32\drivers\msseccore.sys,-1001 : Microsoft Security Core Boot Driver
@%systemroot%\system32\semgrsvc.dll,-1002 : Manages payments and Near Field Communication (NFC) based secure elements.
@%systemroot%\system32\drivers\pdc.sys,-100 : PDC
@firewallapi.dll,-50323 : SNMP Trap
@%systemroot%\system32\mprmsg.dll,-32014 : Remote Access LEGACY NDIS WAN Driver
@%systemroot%\system32\mprmsg.dll,-32013 : IP Traffic Filter Driver
@%systemroot%\system32\drivers\fltmgr.sys,-10001 : FltMgr
@%systemroot%\system32\moshost.dll,-101 : Windows service for application access to downloaded maps. This service is started on-demand by application accessing downloaded maps. Disabling this service will prevent apps from accessing maps.
@%systemroot%\system32\drivers\wcnfs.sys,-100 : Windows Container Name Virtualization
@%systemroot%\system32\devicesflowbroker.dll,-104 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\wdi.dll,-502 : Diagnostic Service Host
@%systemroot%\system32\drivers\mssecflt.sys,-1001 : Microsoft Security Events Component Minifilter
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\drivers\verifierext.sys,-1000 : Driver Verifier Extension
@%systemroot%\system32\tzautoupdate.dll,-200 : Auto Time Zone Updater
@%systemroot%\system32\wpnuserservice.dll,-1 : Windows Push Notifications User Service
@%systemroot%\system32\cdpsvc.dll,-101 : This service is used for Connected Devices Platform scenarios
@%systemroot%\system32\userdataaccessres.dll,-15001 : Contact Data
@%systemroot%\system32\securityhealthagent.dll,-1001 : Windows Security Service handles unified device protection and health information
@%systemroot%\system32\drivers\mshidkmdf.sys,-100 : Pass-through HID to KMDF Filter Driver
@%systemroot%\system32\powrprof.dll,-12 : Favors performance, but may use more energy.
@%systemroot%\system32\sessenv.dll,-1027 : Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates.
@%systemroot%\system32\kpssvc.dll,-100 : KDC Proxy Server service (KPS)
@%systemroot%\system32\tetheringservice.dll,-4097 : Windows Mobile Hotspot Service
@%systemroot%\system32\windows.staterepository.dll,-2 : Provides required infrastructure support for the application model.
@%systemroot%\system32\rasauto.dll,-201 : Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
@%systemroot%\system32\flightsettings.dll,-103 : Windows Insider Service
@%systemroot%\system32\drivers\http.sys,-1 : HTTP Service
@winlangdb.dll,-1121 : English (United States)
@%systemroot%\system32\walletservice.dll,-1000 : WalletService
@%windir%\system32\inetsrv\iisres.dll,-30008 : Enables this server to administer the IIS metabase. The IIS metabase stores configuration for the SMTP and FTP services. If this service is stopped, the server will be unable to configure SMTP or FTP. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\umpnpmgr.dll,-101 : Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\drivers\netbt.sys,-2 : NETBT
@%systemroot%\system32\drivers\ipsecgw.sys,-10001 : Windows IPsec Gateway Driver
@%systemroot%\servicing\trustedinstaller.exe,-101 : Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer.
@%systemroot%\system32\icsvc.dll,-202 : Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\certprop.dll,-13 : Smart Card Removal Policy
@comres.dll,-2946 : KtmRm for Distributed Transaction Coordinator
@%systemroot%\system32\nlasvc.dll,-1 : Network Location Awareness
c:\windows\system32,@elscore.dll,-4 : Microsoft Simplified Chinese to Traditional Chinese Transliteration
@%systemroot%\system32\iscsidsc.dll,-5000 : Microsoft iSCSI Initiator Service
@%systemroot%\system32\drivers\wdf01000.sys,-1000 : Kernel Mode Driver Frameworks service
@%systemroot%\system32\audioendpointbuilder.dll,-205 : Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\scdeviceenum.dll,-101 : Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers.
@%systemroot%\system32\msimsg.dll,-32 : Adds, modifies, and removes applications provided as a Windows Installer (*.msi, *.msp) package. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ajrouter.dll,-1 : Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run.
@%systemroot%\system32\ngcctnrsvc.dll,-1 : Microsoft Passport Container
@%systemroot%\system32\powrprof.dll,-10 : Saves energy by reducing your computer’s performance where possible.
@%systemroot%\system32\vds.exe,-112 : Provides management services for disks, volumes, file systems, and storage arrays.
@%systemroot%\system32\ssdpsrv.dll,-100 : SSDP Discovery
@%systemroot%\system32\sstpsvc.dll,-202 : WAN Miniport (SSTP)
@%systemroot%\system32\embeddedmodesvc.dll,-202 : The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated.
@%systemroot%\system32\windows.warp.jitservice.dll,-101 : Provides a JIT out of process service for WARP when running with ACG enabled.
@%systemroot%\system32\drivers\sgrmagent.sys,-1001 : System Guard Runtime Monitor Agent
@%systemroot%\system32\profsvc.dll,-301 : This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them.
@%systemroot%\system32\seclogon.dll,-7001 : Secondary Logon
@appmgmts.dll,-3250 : Application Management
@%systemroot%\system32\iscsidsc.dll,-5001 : Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\umrdp.dll,-1001 : Allows the redirection of Printers/Drives/Ports for RDP connections
@%systemroot%\system32\wkssvc.dll,-1008 : DFS Namespace Client Driver
@%systemroot%\system32\lmhsvc.dll,-102 : Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\lltdres.dll,-6 : Link-Layer Topology Discovery Mapper I/O Driver
@%systemroot%\system32\pla.dll,-501 : Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\hwpolicy.sys,-101 : Hardware Policy Driver
@%systemroot%\system32\wcmsvc.dll,-4097 : Windows Connection Manager
@%systemroot%\system32\wsmsvc.dll,-102 : Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix.
@%systemroot%\system32\tieringengineservice.exe,-702 : Storage Tiers Management
@%systemroot%\system32\dps.dll,-500 : Diagnostic Policy Service
@%systemroot%\system32\sensrsvc.dll,-1001 : Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well.
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
c:\windows\system32,@elscore.dll,-1 : Microsoft Language Detection
@%systemroot%\system32\axinstsv.dll,-104 : Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings.
@%systemroot%\system32\mprmsg.dll,-32001 : Remote Access NDIS TAPI Driver
@%systemroot%\system32\drivers\mup.sys,-101 : MUP
@%systemroot%\system32\storsvc.dll,-101 : Provides enabling services for storage settings and external storage expansion
@enterpriseappmgmtsvc.dll,-2 : Enables enterprise application management.
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-100 : Shared PC Account Manager
@%systemroot%\system32\netsetupsvc.dll,-3 : Network Setup Service
@%systemroot%\system32\netlogon.dll,-103 : Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\scardsvr.dll,-1 : Smart Card
@%systemroot%\system32\clipsvc.dll,-104 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly.
@%systemroot%\servicing\trustedinstaller.exe,-100 : Windows Modules Installer
@%systemroot%\system32\pushtoinstall.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly.
@%systemroot%\system32\icsvcext.dll,-601 : Hyper-V Remote Desktop Virtualization Service
@%systemroot%\system32\phoneserviceres.dll,-10001 : Manages the telephony state on the device
@%systemroot%\system32\dot3svc.dll,-1103 : The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
@comres.dll,-948 : Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dmwappushsvc.dll,-201 : Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions
@%systemroot%\system32\netprofmsvc.dll,-202 : Network List Service
@waasmedicsvc.dll,-100 : Windows Update Medic Service
@%systemroot%\system32\efssvc.dll,-100 : Encrypting File System (EFS)
@%systemroot%\system32\wkssvc.dll,-1002 : SMB MiniRedirector Wrapper and Engine
@%systemroot%\system32\drivers\filecrypt.sys,-100 : FileCrypt
@%systemroot%\system32\captureservice.dll,-100 : CaptureService
@%windir%\system32\systemeventsbrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\powrprof.dll,-14 : Automatically balances performance with energy consumption on capable hardware.
@%systemroot%\system32\shsvcs.dll,-12289 : Provides notifications for AutoPlay hardware events.
@%systemroot%\system32\icsvcext.dll,-602 : Provides a platform for communication between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\dhcpcore.dll,-101 : Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wercplsupport.dll,-101 : Problem Reports and Solutions Control Panel Support
@%windir%\system32\inetsrv\iisres.dll,-30004 : Provides Web connectivity and administration through the Internet Information Services Manager
@%systemroot%\system32\devicesetupmanager.dll,-1000 : Device Setup Manager
@%systemroot%\system32\dmwappushsvc.dll,-200 : Device Management Wireless Application Protocol (WAP) Push message Routing Service
@%systemroot%\system32\rasmans.dll,-200 : Remote Access Connection Manager
@%systemroot%\system32\swprv.dll,-103 : Microsoft Software Shadow Copy Provider
c:\windows\system32,@elscore.dll,-9 : Microsoft Bengali to Latin Transliteration
@%systemroot%\system32\firewallapi.dll,-23091 : Windows Defender Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.
@%systemroot%\system32\icsvc.dll,-402 : Synchronizes the system time of this virtual machine with the system time of the physical computer.
@%systemroot%\system32\tzautoupdate.dll,-201 : Automatically sets the system time zone.
@%systemroot%\system32\usocore.dll,-102 : Manages Windows Updates. If stopped, your devices will not be able download and install latest udpates.
@%systemroot%\system32\cbdhsvc.dll,-100 : Clipboard User Service
@%systemroot%\system32\iphlpsvc.dll,-501 : Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.
@%systemroot%\system32\seclogon.dll,-7000 : Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\ahcache.sys,-102 : Application Compatibility Cache
@%systemroot%\system32\ncbservice.dll,-500 : Network Connection Broker
@%systemroot%\system32\iphlpsvc.dll,-500 : IP Helper
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1001 : Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them.
@%systemroot%\system32\icsvc.dll,-901 : Hyper-V PowerShell Direct Service
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-1 : Printer Extensions and Notifications
@%systemroot%\system32\installservice.dll,-200 : Microsoft Store Install Service
@%systemroot%\system32\searchindexer.exe,-104 : Provides content indexing, property caching, and search results for files, e-mail, and other content.
@%systemroot%\system32\windows.warp.jitservice.dll,-100 : WarpJITSvc
@%systemroot%\system32\icsvcext.dll,-502 : Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer.
@%systemroot%\system32\lfsvc.dll,-1 : Geolocation Service
@%systemroot%\system32\wbem\wmiapsrv.exe,-111 : Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.
@%systemroot%\system32\licensemanagersvc.dll,-200 : Windows License Manager Service
@%systemroot%\system32\drivers\mshidumdf.sys,-100 : Pass-through HID to UMDF Driver
@%systemroot%\system32\appvclient.exe,-101 : Manages App-V users and virtual applications
@%systemroot%\system32\lltdres.dll,-2 : Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly.
@%systemroot%\system32\vaultsvc.dll,-1003 : Credential Manager
@%systemroot%\system32\drivers\storqosflt.sys,-101 : Storage QoS Filter Driver
@%systemroot%\system32\wpnuserservice.dll,-2 : This service hosts Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw.
@%systemroot%\system32\wersvc.dll,-100 : Windows Error Reporting Service
@%systemroot%\system32\clipsvc.dll,-103 : Client License Service (ClipSVC)
@%systemroot%\system32\ualsvc.dll,-102 : User Access Logging Service
@combase.dll,-5012 : DCOM Server Process Launcher
@%systemroot%\system32\scardsvr.dll,-5 : Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\mprmsg.dll,-32007 : Remote Access PPPOE Driver
@%systemroot%\system32\shsvcs.dll,-12288 : Shell Hardware Detection
@%systemroot%\system32\wlidsvc.dll,-101 : Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account.
@%systemroot%\system32\dosvc.dll,-101 : Performs content delivery optimization tasks
@%systemroot%\system32\wkssvc.dll,-101 : Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\cbdhsvc.dll,-101 : This user service is used for Clipboard scenarios
@%systemroot%\system32\sensrsvc.dll,-1000 : Sensor Monitoring Service
@%systemroot%\system32\dps.dll,-501 : The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function.
@%systemroot%\system32\drivers\luafv.sys,-100 : UAC File Virtualization
@%systemroot%\system32\userdataaccessres.dll,-15000 : Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results.
@%systemroot%\system32\windows.devices.picker.dll,-1007 : This user service is used for managing the Miracast, DLNA, and DIAL UI
@%systemroot%\system32\icsvc.dll,-802 : Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine.
@%systemroot%\system32\sessenv.dll,-1026 : Remote Desktop Configuration
@%systemroot%\system32\nsisvc.dll,-201 : This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.
@%systemroot%\system32\btagservice.dll,-101 : Bluetooth Audio Gateway Service
c:\windows\system32,@elscore.dll,-10 : Microsoft Hangul Decomposition Transliteration
@%systemroot%\system32\userdataaccessres.dll,-10002 : Handles storage of structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-101 : Manages profiles and accounts on a SharedPC configured device
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\usocore.dll,-101 : Update Orchestrator Service
@%systemroot%\system32\bthserv.dll,-101 : Bluetooth Support Service
@%systemroot%\system32\mprmsg.dll,-32005 : WAN Miniport (L2TP)
@%systemroot%\system32\spoolsv.exe,-1 : Print Spooler
@%systemroot%\system32\tetheringservice.dll,-4098 : Provides the ability to share a cellular data connection with another device.
@%systemroot%\system32\smphost.dll,-101 : Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed.
@%systemroot%\system32\drivers\wimmount.sys,-101 : WIMMount
@%systemroot%\system32\ssdpsrv.dll,-101 : Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\devicesetupmanager.dll,-1001 : Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly.
@%systemroot%\system32\swprv.dll,-102 : Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\qmgr.dll,-1001 : Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information.
@%systemroot%\system32\certprop.dll,-11 : Certificate Propagation
@comres.dll,-2798 : Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dssvc.dll,-10002 : Provides data brokering between applications.
@%windir%\system32\inetsrv\iisres.dll,-30014 : W3C Logging Service
@%systemroot%\system32\wercplsupport.dll,-100 : This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports and Solutions control panel.
@%systemroot%\system32\cdpusersvc.dll,-101 : This user service is used for Connected Devices Platform scenarios
@c:\windows\system32\rdpendp.dll,-1001 : Remote Audio
@%systemroot%\system32\qwave.dll,-1 : Quality Windows Audio Video Experience
@%systemroot%\system32\drivers\tcpip.sys,-10001 : TCP/IP Protocol Driver
@firewallapi.dll,-50324 : Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\certprop.dll,-14 : Allows the system to be configured to lock the user desktop upon smart card removal.
@%systemroot%\system32\ikeext.dll,-502 : The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.
@%systemroot%\system32\wuaueng.dll,-106 : Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API.
@%systemroot%\system32\sensorservice.dll,-1001 : A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped.
@%systemroot%\system32\capabilityaccessmanager.dll,-1 : Capability Access Manager Service
@%systemroot%\system32\drivers\dam.sys,-100 : Desktop Activity Moderator Driver
@%systemroot%\system32\agentservice.exe,-102 : User Experience Virtualization Service
@%systemroot%\system32\drivers\mountmgr.sys,-100 : Mount Point Manager
@%systemroot%\system32\wiaservc.dll,-10 : Provides image acquisition services for scanners and cameras
@%systemroot%\syswow64\perfhost.exe,-1 : Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.
@%systemroot%\system32\bthserv.dll,-102 : The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated.
@%windir%\system32\timebrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\wpnservice.dll,-2 : This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server.
@%systemroot%\system32\wkssvc.dll,-1006 : SMB 2.0 MiniRedirector
@%systemroot%\system32\alg.exe,-112 : Application Layer Gateway Service
@%systemroot%\system32\usermgr.dll,-100 : User Manager
@%systemroot%\system32\drivers\ndproxy.sys,-6000 : NDIS Proxy Driver
@%systemroot%\system32\frameserver.dll,-101 : Enables multiple clients to access video frames from camera devices.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8198 : Receives activation requests over the net.tcp protocol and passes them to the Windows Process Activation Service.
@c:\windows\system32\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\system32\icsvcext.dll,-501 : Hyper-V Volume Shadow Copy Requestor
@%systemroot%\system32\sacsvr.dll,-500 : Special Administration Console Helper
@%systemroot%\system32\schedsvc.dll,-101 : Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wbem\wmisvc.dll,-204 : Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%windir%\system32\bisrv.dll,-100 : Background Tasks Infrastructure Service
@%systemroot%\system32\wersvc.dll,-101 : Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed.
@%systemroot%\system32\termsrv.dll,-267 : Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.
@%systemroot%\system32\sens.dll,-201 : Monitors system events and notifies subscribers to COM+ Event System of these events.
@%systemroot%\system32\drivers\mssecwfp.sys,-1001 : Microsoft Security WFP Callout Driver
@%systemroot%\system32\devquerybroker.dll,-101 : Enables apps to discover devices with a backgroud task
@%systemroot%\system32\tabsvc.dll,-101 : Enables Touch Keyboard and Handwriting Panel pen and ink functionality
@%systemroot%\system32\drivers\scfilter.sys,-11 : Smart card PnP Class Filter Driver
@%systemroot%\system32\userdataaccessres.dll,-14001 : User Data Access
@%systemroot%\system32\ncbservice.dll,-501 : Brokers connections that allow Windows Store Apps to receive notifications from the internet.
@%systemroot%\system32\wpnservice.dll,-1 : Windows Push Notifications System Service
@%systemroot%\system32\drivers\volsnap.sys,-100 : Volume Shadow Copy driver
@%systemroot%\system32\hidserv.dll,-102 : Activates and maintains the use of hot buttons on keyboards, remote controls, and other multimedia devices. It is recommended that you keep this service running.
@%systemroot%\system32\efssvc.dll,-101 : Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.
@%systemroot%\system32\vds.exe,-100 : Virtual Disk
@%systemroot%\system32\drivers\rdpdr.sys,-100 : Remote Desktop Device Redirector Driver
@%systemroot%\system32\wdi.dll,-500 : Diagnostic System Host
@%systemroot%\system32\lltdres.dll,-5 : Link-Layer Topology Discovery Responder
@%systemroot%\system32\drivers\appvstrm.sys,-101 : AppvStrm
@%systemroot%\system32\wbiosrvc.dll,-100 : Windows Biometric Service
@%systemroot%\system32\umpnpmgr.dll,-100 : Device Install Service
@%systemroot%\system32\sstpsvc.dll,-201 : Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.
@%systemroot%\system32\consentuxclient.dll,-101 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\captureservice.dll,-101 : OneCore Capture Service
@%systemroot%\system32\upnphost.dll,-213 : UPnP Device Host
@%systemroot%\system32\windows.internal.management.dll,-101 : Performs Device Enrollment Activities for Device Management
@%systemroot%\system32\diagtrack.dll,-3002 : The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics.
@%systemroot%\system32\svsvc.dll,-101 : Spot Verifier
@%systemroot%\system32\trkwks.dll,-2 : Maintains links between NTFS files within a computer or across computers in a network.
@%systemroot%\system32\drivers\wpdupfltr.sys,-100 : WPD Upper Class Filter Driver
@%systemroot%\system32\drivers\partmgr.sys,-100 : Partition driver
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\drivers\filetrace.sys,-10001 : FileTrace
@%systemroot%\system32\urlmon.dll,-4200 : Open File - Security Warning
@%systemroot%\system32\wecsvc.dll,-200 : Windows Event Collector
@%systemroot%\system32\drivers\wudfpf.sys,-1000 : User Mode Driver Frameworks Platform Driver
@%systemroot%\system32\icsvc.dll,-302 : Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer.
@%systemroot%\system32\drivers\bam.sys,-100 : Background Activity Moderator Driver
@%systemroot%\system32\wpdbusenum.dll,-100 : Portable Device Enumerator Service
@%systemroot%\system32\pla.dll,-500 : Performance Logs & Alerts
@comres.dll,-2450 : COM+ Event System
@%systemroot%\system32\vaultsvc.dll,-1004 : Provides secure storage and retrieval of credentials to users, applications and security service packages.
@%systemroot%\system32\installservice.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then installations will not function properly.
@%systemroot%\system32\mprmsg.dll,-32006 : WAN Miniport (PPTP)
@%systemroot%\system32\appxdeploymentserver.dll,-1 : AppX Deployment Service (AppXSVC)
@gpapi.dll,-112 : Group Policy Client
@%systemroot%\system32\vssvc.exe,-101 : Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\appreadiness.dll,-1000 : App Readiness
@%windir%\system32\drivers\netbios.sys,-503 : NetBIOS Interface
@%systemroot%\system32\drivers\qwavedrv.sys,-1 : QWAVE driver
c:\windows\system32,@elscore.dll,-5 : Microsoft Transliteration Engine
@%systemroot%\system32\certprop.dll,-12 : Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver.
@%systemroot%\system32\drivers\bindflt.sys,-100 : Windows Bind Filter Driver
@%systemroot%\system32\sensordataservice.exe,-101 : Sensor Data Service
@c:\windows\syswow64\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-2 : Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\flightsettings.dll,-104 : Provides infrastructure support for the Windows Insider Program. This service must remain enabled for the Windows Insider Program to work.
@%systemroot%\system32\moshost.dll,-100 : Downloaded Maps Manager
@%systemroot%\system32\hidserv.dll,-101 : Human Interface Device Service
@%systemroot%\system32\powrprof.dll,-11 : Power saver
@%systemroot%\system32\sacsvr.dll,-501 : Allows administrators to remotely access a command prompt using Emergency Management Services.
@%systemroot%\system32\graphicsperfsvc.dll,-101 : Graphics performance monitor service
@%systemroot%\system32\graphicsperfsvc.dll,-100 : GraphicsPerfSvc
@%systemroot%\system32\qmgr.dll,-1000 : Background Intelligent Transfer Service
@%systemroot%\system32\dnsapi.dll,-102 : The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-2 : This service opens custom printer dialog boxes and handles notifications from a remote print server or a printer. If you turn off this service, you won’t be able to see printer extensions or notifications.
@%systemroot%\system32\ualsvc.dll,-101 : This service logs unique client access requests, in the form of IP addresses and user names, of installed products and roles on the local server. This information can be queried, via Powershell, by administrators needing to quantify client demand of server software for offline Client Access License (CAL) management. If the service is disabled, client requests will not be logged and will not be retrievable via Powershell queries. Stopping the service will not affect query of historical data (see supporting documentation for steps to delete historical data). The local system administrator must consult his, or her, Windows Server license terms to determine the number of CALs that are required for the server software to be appropriately licensed; use of the UAL service and data does not alter this obligation.
@%systemroot%\system32\appidsvc.dll,-100 : Application Identity
@%systemroot%\system32\cryptsvc.dll,-1001 : Cryptographic Services
@%systemroot%\system32\embeddedmodesvc.dll,-201 : Embedded Mode
@%systemroot%\system32\ajrouter.dll,-2 : AllJoyn Router Service
@%systemroot%\system32\srpapi.dll,-100 : AppID Driver
@%systemroot%\system32\licensemanagersvc.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly.
@%systemroot%\system32\rasauto.dll,-200 : Remote Access Auto Connection Manager
@%systemroot%\system32\ngcsvc.dll,-100 : Microsoft Passport
@%systemroot%\system32\w32time.dll,-201 : Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\ndiscap.sys,-5000 : Microsoft NDIS Capture
@%systemroot%\system32\drivers\ndis.sys,-200 : NDIS System Driver
@%systemroot%\system32\winhttp.dll,-101 : WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol.
@%systemroot%\system32\diagtrack.dll,-3001 : Connected User Experiences and Telemetry
@%systemroot%\system32\kpssvc.dll,-101 : KDC Proxy Server service runs on edge servers to proxy Kerberos protocol messages to domain controllers on the corporate network.
@%systemroot%\system32\appxdeploymentserver.dll,-2 : Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly.
c:\windows\system32,@elscore.dll,-6 : Microsoft Cyrillic to Latin Transliteration
@%systemroot%\system32\mprdim.dll,-201 : Offers routing services to businesses in local area and wide area network environments.
@%systemroot%\system32\bthavctpsvc.dll,-101 : AVCTP service
@%systemroot%\system32\drivers\wudfrd.sys,-1000 : Windows Driver Foundation - User-mode Driver Framework Reflector
@%systemroot%\system32\sysmain.dll,-1000 : SysMain
@%systemroot%\system32\bthavctpsvc.dll,-102 : This is Audio Video Control Transport Protocol service
c:\windows\system32,@elscore.dll,-2 : Microsoft Script Detection
@%systemroot%\system32\wlidsvc.dll,-100 : Microsoft Account Sign-in Assistant
@%systemroot%\system32\wiarpc.dll,-1 : Launches applications associated with still image acquisition events.
@%systemroot%\system32\drivers\mslldp.sys,-200 : Microsoft Link-Layer Discovery Protocol
@%systemroot%\system32\wbem\wmisvc.dll,-205 : Windows Management Instrumentation
@%systemroot%\system32\consentuxclient.dll,-100 : ConsentUX
@%systemroot%\system32\appidsvc.dll,-101 : Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.
@%systemroot%\system32\rasmans.dll,-201 : Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\profsvc.dll,-300 : User Profile Service
@%systemroot%\system32\icsvc.dll,-102 : Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding.
@%windir%\system32\inetsrv\iisres.dll,-30002 : The Windows Process Activation Service (WAS) provides process activation, resource management and health management services for message-activated applications.
@%systemroot%\system32\netsetupsvc.dll,-4 : The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in-progress may be cancelled.
@%systemroot%\system32\drivers\wcifs.sys,-100 : Windows Container Isolation
@%systemroot%\system32\fdphost.dll,-100 : Function Discovery Provider Host
@%systemroot%\system32\ipnathlp.dll,-107 : Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
@%systemroot%\system32\agentservice.exe,-101 : Provides support for application and OS settings roaming
@%systemroot%\system32\wbem\wmiapsrv.exe,-110 : WMI Performance Adapter
@waasmedicsvc.dll,-101 : Enables remediation and protection of Windows Update components.
@combase.dll,-5013 : The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8200 : Provides ability to share TCP ports over the net.tcp protocol.
@%systemroot%\system32\drivers\mmcss.sys,-100 : Multimedia Class Scheduler
@%systemroot%\system32\walletservice.dll,-1001 : Hosts objects used by clients of the wallet
@%systemroot%\system32\icsvc.dll,-401 : Hyper-V Time Synchronization Service
@%systemroot%\system32\drivers\ndisvirtualbus.sys,-200 : Microsoft Virtual Network Adapter Enumerator
@%systemroot%\system32\audiosrv.dll,-201 : Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\pcasvc.dll,-2 : This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly.
@%systemroot%\system32\mprmsg.dll,-32000 : RAS Asynchronous Media Driver
@%systemroot%\system32\netman.dll,-110 : Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
@regsvc.dll,-2 : Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wdi.dll,-503 : The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\icsvc.dll,-101 : Hyper-V Heartbeat Service
@%systemroot%\system32\srvsvc.dll,-104 : Server SMB 2.xxx Driver
@%systemroot%\system32\netprofmsvc.dll,-203 : Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.
@%systemroot%\system32\dot3svc.dll,-1102 : Wired AutoConfig
@%systemroot%\system32\drivers\uevagentdriver.sys,-101 : UevAgentDriver
@%systemroot%\system32\tcpipcfg.dll,-50004 : NetIO Legacy TDI Support Driver
@%systemroot%\system32\appinfo.dll,-101 : Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.
@%systemroot%\system32\wiarpc.dll,-2 : Still Image Acquisition Events
@%systemroot%\system32\eapsvc.dll,-2 : The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication.
@%systemroot%\system32\securityhealthagent.dll,-1002 : Windows Security Service
@%systemroot%\system32\wdi.dll,-501 : The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function.
@enterpriseappmgmtsvc.dll,-1 : Enterprise App Management Service
@%systemroot%\system32\coremessaging.dll,-2 : Manages communication between system components.
@%systemroot%\system32\drivers\nsiproxy.sys,-2 : NSI Proxy Service Driver
@%systemroot%\system32\drivers\fsdepends.sys,-10001 : File System Dependency Minifilter
@%systemroot%\system32\fntcache.dll,-101 : Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.
@%programfiles%\windows media player\wmpnetwk.exe,-102 : Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
@%systemroot%\system32\searchindexer.exe,-103 : Windows Search
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\ci.dll,-101 : Enclave

MUICache report attached.

108712 - Microsoft .NET Core SDK for Windows
-
Synopsis
.NET Core SDK is installed on the remote Windows host.
Description
.NET Core SDK, a managed software framework, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0654
Plugin Information
Published: 2018/03/29, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Nessus detected 3 installs of .NET Core SDK Windows:

Path : C:\\program files\dotnet\\sdk\1.1.0
Version : 1.1.0
File Version : 1.1.0.0

Path : C:\\program files\dotnet\\sdk\7.0.400
Version : 7.0.400
File Version : 7.4.23.36916

Path : C:\\program files\dotnet\\sdk\8.0.303
Version : 8.0.303
File Version : 8.3.324.31708
104668 - Microsoft .NET Core for Windows
-
Synopsis
.NET Core runtime is installed on the remote Windows host.
Description
.NET Core, a managed software framework, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0653
Plugin Information
Published: 2017/11/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Nessus detected 9 installs of .NET Core Windows:

Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\1.0.5\
Version : 1.0.5

Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\1.1.2\
Version : 1.1.2

Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Version : 6.0.25

Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.10\
Version : 7.0.10.32713

Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Version : 8.0.0

Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.7\
Version : 8.0.7

Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NetCore.App\7.0.10\
Version : 7.0.10.32713

Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\6.0.25\
Version : 6.0.25

Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.0\
Version : 8.0.0
51351 - Microsoft .NET Framework Detection
-
Synopsis
A software framework is installed on the remote host.
Description
Microsoft .NET Framework, a software framework for Microsoft Windows operating systems, is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0655
Plugin Information
Published: 2010/12/20, Modified: 2025/10/15
Plugin Output

tcp/445/cifs


Nessus detected 2 installs of Microsoft .NET Framework:

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.8
Full Version : 4.8.03761
Install Type : Full
Release : 528049

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.8
Full Version : 4.8.03761
Install Type : Client
Release : 528049
99364 - Microsoft .NET Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft .NET security rollups.
Description
Nessus was able to enumerate the Microsoft .NET security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/04/14, Modified: 2025/10/23
Plugin Output

tcp/445/cifs


Path : C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.workflow.runtime.dll
Version : 4.8.4110.0
.NET Version : 4.8
Associated KB : 4532937
Latest effective update level : 01_2020
104667 - Microsoft ASP .NET Core for Windows
-
Synopsis
ASP .NET Core runtime packages are installed on the remote Windows host.
Description
ASP .NET Core runtime, web application server side components, are installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0657
Plugin Information
Published: 2017/11/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Nessus detected 7 installs of ASP .NET Core Windows:

Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\8.0.7
Version : 8.0.7

Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\7.0.10
Version : 7.0.10

Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\8.0.0
Version : 8.0.0

Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\6.0.25
Version : 6.0.25

Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\6.0.25
Version : 6.0.25

Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\8.0.0
Version : 8.0.0

Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\7.0.10
Version : 7.0.10

192148 - Microsoft Azure Data Studio Installed (Windows)
-
Synopsis
Microsoft Azure Data Studio is installed on the remote Windows host.
Description
Microsoft Azure Data Studio is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/03/15, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\Azure Data Studio\
Version : 1.44.0.0

72879 - Microsoft Internet Explorer Enhanced Security Configuration Detection
-
Synopsis
The remote host supports IE Enhanced Security Configuration.
Description
Nessus detects if the remote Windows host supports IE Enhanced Security Configuration (ESC) and if IE ESC features are enabled or disabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/03/07, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Type : Admin Groups
Is Enabled : True

Type : User Groups
Is Enabled : True

162560 - Microsoft Internet Explorer Installed
-
Synopsis
A web browser is installed on the remote Windows host.
Description
Microsoft Internet Explorer, a web browser bundled with Microsoft Windows, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/06/28, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Windows\system32\mshtml.dll
Version : 11.0.17763.4720

72367 - Microsoft Internet Explorer Version Detection
-
Synopsis
Internet Explorer is installed on the remote host.
Description
The remote Windows host contains Internet Explorer, a web browser created by Microsoft.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0509
Plugin Information
Published: 2014/02/06, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Version : 11.1790.17763.0

139615 - Microsoft Internet Information Services (IIS) Installed
-
Synopsis
Checks Windows registry keys and executables for a Microsoft Internet Information Services (IIS) installation.
Description
Microsoft Internet Information Services installation (IIS) has been detected on the remote Windows host.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0030
XREF IAVT:0001-T-0944
Plugin Information
Published: 2020/08/17, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Windows\system32\inetsrv
Version : 10.0.17763.4492

140655 - Microsoft Internet Information Services (IIS) Sites Enumeration
-
Synopsis
Checks IIS configuration file for configured sites and their bound addresses.
Description
Microsoft Internet Information Services configuration file has been parsed to extract information about the existing sites, their protocols, domains and IP addresses.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/09/18, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

Nessus found the following sites configured on the remote host:
+ site name: middleware frontend
+ binding 0
- IP address : *
- port : 80
- domain : middleware.lkp.net.in
- protocol : http
+ binding 1
- IP address : *
- port : 443
- domain : middleware.lkp.net.in
- protocol : https
+ site name: Default Web Site
+ binding 0
- IP address : *
- port : 80
- domain :
- protocol : http
+ binding 1
- IP address : 808
- port : *
- domain :
- protocol : net.tcp
+ binding 2
- IP address : *
- port :
- domain :
- protocol : net.pipe
+ site name: uatmiddlewareapi.lkp.net.in
+ binding 0
- IP address : *
- port : 80
- domain : uatmiddlewareapi.lkp.net.in
- protocol : http
+ binding 1
- IP address : *
- port : 443
- domain : uatmiddlewareapi.lkp.net.in
- protocol : https
+ site name: middlewareapi.lkp.net.in
+ binding 0
- IP address : *
- port : 443
- domain : middlewareapi.lkp.net.in
- protocol : https
66424 - Microsoft Malicious Software Removal Tool Installed
-
Synopsis
An antimalware application is installed on the remote Windows host.
Description
The Microsoft Malicious Software Removal Tool is installed on the remote host. This tool is an application that attempts to detect and remove known malware from Windows systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/05/15, Modified: 2023/01/10
Plugin Output

tcp/445/cifs


File : C:\Windows\system32\MRT.exe
Version : 5.118.23100.1
Release at last run : unknown
Report infection information to Microsoft : Yes
174413 - Microsoft ODBC Driver for SQL Server Installed (Windows)
-
Synopsis
Microsoft ODBC Driver for SQL Server is installed on the remote Windows host.
Description
Microsoft ODBC Driver for SQL Server is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msodbcsql17.dll
Version : 17.10.3.1
174405 - Microsoft OLE DB Driver for SQL Server Installed (Windows)
-
Synopsis
Microsoft OLE DB Driver for SQL Server is installed on the remote Windows host.
Description
Microsoft OLE DB Driver for SQL Server is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msoledbsql.dll
Version : 18.6.5.0
93232 - Microsoft Office Compatibility Pack Installed (credentialed check)
-
Synopsis
A compatibility application is installed on the remote host.
Description
Microsoft Office Compatibility Pack, used to enable older versions of Microsoft Office applications to view and edit files created with newer versions of Microsoft Office applications, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0663
Plugin Information
Published: 2016/08/30, Modified: 2025/09/29
Plugin Output

tcp/445/cifs


Office Compatibility Pack is installed with the following components:

Component : Excel Converter
Version : 14.0.6024.1000
Path : C:\Program Files (x86)\Microsoft Office\Office14\Excelcnv.exe

Component : Word Converter
Version : 14.0.4762.1000
Path : C:\Program Files (x86)\Microsoft Office\Office14\Wordconv.exe
27524 - Microsoft Office Detection
-
Synopsis
The remote Windows host contains an office suite.
Description
Microsoft Office is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0505
Plugin Information
Published: 2007/10/23, Modified: 2025/10/14
Plugin Output

tcp/445/cifs


The remote host has the following Microsoft Office 2010 Service Pack 1 components installed :

- WordCnv : 14.0.4762.1000
- ExcelCnv : 14.0.6024.1000
- Word : 14.0.6024.1000

124120 - Microsoft Outlook Attachment Previewing Enabled
-
Synopsis
Microsoft Outlook application that is installed on the remote host has attachment previewing enabled.
Description
Microsoft Outlook application that is installed on the remote host has attachment previewing enabled.
Solution
Disable attachment previewing settings.
Risk Factor
None
Plugin Information
Published: 2019/04/17, Modified: 2019/04/17
Plugin Output

tcp/0

Outlook application in Microsoft Office 2010 has attachment previewing enabled.
92427 - Microsoft Paint Recent File History
-
Synopsis
Nessus was able to enumerate files opened in Microsoft Paint on the remote host.
Description
Nessus was able to generate a list of files opened using the Microsoft Paint program.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

production
- D:\FileUpload\Compliance\sample.jpg
- D:\FileUpload\Compliance\IMG_2774_15012025061404.jpg
- D:\FileUpload\Compliance\04_04_2025_11_44_54AM_jpg.jpg
- D:\Backup\29082023\Fontend\icons\favicon.ico
- D:\FileUpload\Compliance\04_04_2025_2_17_34PM_dddddddd_jpg.jpg
- D:\Middleware_Api\wwwroot\assets\img\Header_Wealth.png
- D:\Middleware_Api\Logo.png
- D:\Middleware_Api\wwwroot\assets\img\Header.png
- D:\Middleware_Api\wwwroot\assets\img\logo.png

57033 - Microsoft Patch Bulletin Feasibility Check
-
Synopsis
Nessus is able to check for Microsoft patch bulletins.
Description
Using credentials supplied in the scan policy, Nessus is able to collect information about the software and patches installed on the remote Windows host and will use that information to check for missing Microsoft security updates.

Note that this plugin is purely informational.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/06, Modified: 2021/07/12
Plugin Output

tcp/445/cifs



Nessus is able to test for missing patches using :
Nessus

125835 - Microsoft Remote Desktop Connection Installed
-
Synopsis
A graphical interface connection utility is installed on the remote Windows host
Description
Microsoft Remote Desktop Connection (also known as Remote Desktop Protocol or Terminal Services Client) is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/06/12, Modified: 2022/10/10
Plugin Output

tcp/0


Path : C:\Windows\\System32\\mstsc.exe
Version : 10.0.17763.2867

11217 - Microsoft SQL Server Detection (credentialed check)
-
Synopsis
The remote host has a database server installed.
Description
Nessus has detected one or more installs of Microsoft SQL server by examining the registry and file systems on the remote host.
See Also
Solution
Ensure the latest service pack and hotfixes are installed.
Risk Factor
None
References
XREF IAVT:0001-T-0800
Plugin Information
Published: 2003/01/26, Modified: 2025/09/24
Plugin Output

tcp/445/cifs


Nessus detected 3 installs of Microsoft SQL Server:

Path : C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn
Version : 15.0.2000.5
arch : x64
instance_name : MSSQLSERVER
is_accessible_share : 1
local_db : 0
localdb : 0

Path : C:\Program Files\Microsoft SQL Server\150\LocalDB\Binn\
Version : 15.0.4153.1
arch : x64
instance_name : MSSQL15E.LOCALDB
is_accessible_share : 1
local_db : 1
localdb : 1

Path : C:\Program Files\Microsoft SQL Server\130\LocalDB\Binn\
Version : 13.0.4001.0
arch : x64
instance_name : MSSQL13E.LOCALDB
is_accessible_share : 1
local_db : 1
localdb : 1


Nessus detected 4 installs of Microsoft SQL Server:

Version : 15.0.2000.5
Edition : Standard Edition
Path : C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn
Named Instance : MSSQLSERVER

Version : 15.0.4153.1
Edition : Express Edition
Path : C:\Program Files\Microsoft SQL Server\150\LocalDB\Binn\
Named Instance : MSSQL15E.LOCALDB

Version : 13.0.4001.0
Edition : Express Edition
Path : C:\Program Files\Microsoft SQL Server\130\LocalDB\Binn\
Named Instance : MSSQL13E.LOCALDB
Recommended Version : 13.0.6419.1 (2016 GDR (KB5014355)).

69482 - Microsoft SQL Server STARTTLS Support
-
Synopsis
The remote service supports encrypting traffic.
Description
The remote Microsoft SQL Server service supports the use of encryption initiated during pre-login to switch from a cleartext to an encrypted communications channel.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/07/04, Modified: 2022/04/11
Plugin Output

tcp/1433/mssql


Here is the Microsoft SQL Server's SSL certificate that Nessus
was able to collect after sending a pre-login packet :

------------------------------ snip ------------------------------
Subject Name:

Common Name: SSL_Self_Signed_Fallback

Issuer Name:

Common Name: SSL_Self_Signed_Fallback

Serial Number: 6A 1A 0F A8 C0 4A B4 A9 42 18 5C 32 2A 89 A4 56

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Jan 01 03:49:40 2026 GMT
Not Valid After: Jan 01 03:49:40 2056 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 E4 5C 13 19 70 6E 0C 87 B5 36 F5 41 DA 2D 43 E1 5D 39 13
78 12 00 DD C1 08 0F 73 71 51 8D 17 8D 8E 76 25 0A CF 7A A4
4D 79 78 8A F6 C8 F6 DD 0C 7E 1C 0A BA BE D3 C6 00 3F BD EF
4F F7 2D 12 D4 29 E8 48 0F A1 59 9A 3C 86 CF 51 DD 4A 73 F2
E8 F3 D5 3C 83 3E 68 14 88 06 8A DC 69 E6 05 93 15 B0 2E D4
9A 68 59 DF 0D B4 37 2A E6 2E 87 10 96 68 13 15 99 10 4D DE
10 A4 C7 B2 F8 38 5C 7F 77 7A C7 DE 55 2F 30 26 C3 8A 78 C0
C2 DE B5 A7 B6 C3 74 4E 88 2A 26 A4 F7 34 8D 45 19 27 FB FA
A4 C1 A1 43 A9 D2 5F 56 DD E9 E2 01 0E 1D D6 DC 51 8A A7 C1
CB 3C 5B D2 69 C8 FD 5E CE 88 AD 4B 90 34 20 23 21 A2 C6 DE
20 D7 21 F1 27 26 3C DD 83 87 29 D2 F8 4E 67 D7 22 4F CB AE
13 24 D6 C0 50 33 23 62 2D 2D F0 F0 DC DE E8 1B 83 CD 27 A1
22 70 31 1C 2F D0 72 DC 16 7D 62 E3 F3 B1 69 61 B1
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 43 DF D8 EF 41 4A 4D 0C F5 88 43 09 43 B9 C2 6C 55 5F EE
FB 7D 1D 15 06 00 56 A3 34 D8 71 B6 49 45 D3 31 49 7D 2B 78
95 4A CA 04 CA 4B 5E CF 32 B5 B1 B4 6F 17 39 CE 94 B6 17 98
00 CC D7 D0 F3 1B 5B 73 DC D5 2B 68 CF ED 20 C4 FC A1 82 D8
DA 06 FE 58 53 68 E2 E0 1C ED A1 98 99 5B 1D F0 D9 0F 5A 37
A8 5F DA 04 F0 03 AD D2 BF 81 F6 21 C6 EA 85 5D 86 4C 21 08
CE F1 0E BB 98 E0 5A 0B 77 44 EB A7 67 F9 21 EC 6D 31 4A E3
D0 00 EB 06 81 4D 80 CE 74 C6 15 CE 23 BA 7C B6 A0 39 43 36
B3 5C D1 DE E4 9B 5F 46 F9 3A 2A EA 4B 43 CF 36 45 45 3B 6C
BD 24 6D B4 89 E8 FC F6 E6 22 B6 38 AE 60 DD 02 83 D5 A7 6C
78 D8 10 A2 3C AF A9 FD 37 DE 86 41 18 04 07 4F 2D 59 D2 CE
8B 6C FA D0 53 FB AA BA 59 22 BB 65 9F 0C 8F D4 42 E9 1D 3D
B9 10 89 CA DC E4 F8 9D 27 3C B7 AB 79 A3 43 C5 AF


------------------------------ snip ------------------------------


SQL Server Version : 15.0.2000.0
10144 - Microsoft SQL Server TCP/IP Listener Detection
-
Synopsis
A database server is listening on the remote port.
Description
The remote host is running MSSQL, a database server from Microsoft. It is possible to extract the version number of the remote installation from the server pre-login response.
Solution
Restrict access to the database to allowed IPs only.
Risk Factor
None
References
XREF IAVT:0001-T-0800
Plugin Information
Published: 1999/10/12, Modified: 2024/07/29
Plugin Output

tcp/1433/mssql


Service : mssql-Instance name not determined
Version : 15.0.2000.0
Note : The remote MSSQL server accepts cleartext logins.

93962 - Microsoft Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft security rollups.
Description
Nessus was able to enumerate the Microsoft security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/10/11, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Cumulative Rollup : 08_2023 [KB5029247]
Cumulative Rollup : 07_2023
Cumulative Rollup : 06_2023
Cumulative Rollup : 05_2023
Cumulative Rollup : 04_2023
Cumulative Rollup : 03_2023
Cumulative Rollup : 02_2023
Cumulative Rollup : 01_2023
Cumulative Rollup : 12_2022
Cumulative Rollup : 11_2022
Cumulative Rollup : 10_2022
Cumulative Rollup : 09_2022
Cumulative Rollup : 08_2022
Cumulative Rollup : 07_2022
Cumulative Rollup : 06_2022
Cumulative Rollup : 05_2022
Cumulative Rollup : 04_2022
Cumulative Rollup : 03_2022
Cumulative Rollup : 02_2022
Cumulative Rollup : 01_2022
Cumulative Rollup : 12_2021
Cumulative Rollup : 11_2021
Cumulative Rollup : 10_2021
Cumulative Rollup : 09_2021
Cumulative Rollup : 08_2021
Cumulative Rollup : 07_2021
Cumulative Rollup : 06_2021_07_01
Cumulative Rollup : 06_2021
Cumulative Rollup : 05_2021
Cumulative Rollup : 04_2021
Cumulative Rollup : 03_2021
Cumulative Rollup : 02_2021
Cumulative Rollup : 01_2021
Cumulative Rollup : 12_2020
Cumulative Rollup : 11_2020
Cumulative Rollup : 10_2020
Cumulative Rollup : 09_2020
Cumulative Rollup : 08_2020
Cumulative Rollup : 07_2020 [KB4558998]
Cumulative Rollup : 06_2020
Cumulative Rollup : 05_2020
Cumulative Rollup : 04_2020
Cumulative Rollup : 03_2020
Cumulative Rollup : 02_2020
Cumulative Rollup : 01_2020
Cumulative Rollup : 12_2019
Cumulative Rollup : 11_2019
Cumulative Rollup : 10_2019
Cumulative Rollup : 09_2019
Cumulative Rollup : 08_2019
Cumulative Rollup : 07_2019
Cumulative Rollup : 06_2019
Cumulative Rollup : 05_2019
Cumulative Rollup : 04_2019
Cumulative Rollup : 03_2019
Cumulative Rollup : 02_2019
Cumulative Rollup : 01_2019
Cumulative Rollup : 12_2018
Cumulative Rollup : 11_2018
Cumulative Rollup : 10_2018

Latest effective update level : 08_2023
File checked : C:\Windows\system32\ntoskrnl.exe
File version : 10.0.17763.4737
Associated KB : 5029247
50346 - Microsoft Update Installed
-
Synopsis
A software updating service is installed.
Description
Microsoft Update, an expanded version of Windows Update, is installed on the remote Windows host. This service provides updates for the operating system and Internet Explorer as well as other Windows software such as Microsoft Office, Exchange, and SQL Server.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/10/26, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

136618 - Microsoft Visual Studio Code Extensions Installed
-
Synopsis
One or more extensions for an integrated development environment software application are installed on the remote Windows host.
Description
One or more extensions for Microsoft Visual Studio Code, an integrated development environment software application, are installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/05/15, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following extensions of Visual Studio code were found:


Extension : vs-code::gitlens
Path : C:\Users\Administrator\.vscode\extensions\eamodio.gitlens-14.5.2\
Version : 14.5.2

122256 - Microsoft Visual Studio Code Installed
-
Synopsis
An integrated development environment software application is installed on the remote Windows host.
Description
Microsoft Visual Studio Code, an integrated development environment software application, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/02/15, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\
Version : 1.81.1
File Version : 1.81.1.0

88700 - Microsoft Visual Studio Installed
-
Synopsis
The remote Windows host has an integrated development environment installed.
Description
Microsoft Visual Studio, an integrated development environment application, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0668
Plugin Information
Published: 2016/02/11, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Nessus detected 2 installs of Microsoft Visual Studio:

Path : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Version : 17.8.34330.188
Product : Visual Studio
product_version : 2022

Path : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Version : 15.3.26730.8
Product : Visual Studio
product_version : 2017

265694 - Microsoft Visual Studio Tools for Applications Installed (Windows)
-
Synopsis
The remote Windows host has an integrated development environment installed.
Description
Microsoft Visual Studio Tools for Applications (VSTA) is a set of tools that independent software vendors (ISVs) can use to build customization abilities into their applications for both automation and extensibility, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/09/22, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus detected 2 installs of Microsoft Visual Studio Tools for Applications:

Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\15.0\Bin\VstaCore.dll
Version : 15.0.27520
product_version : 2017

Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\16.0\Bin\VstaCore.dll
Version : 16.0.31110
product_version : 2019
249136 - Microsoft Web Deploy Installed (Windows)
-
Synopsis
Microsoft Web Deploy is installed on the remote Windows host.
Description
Microsoft Web Deploy is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/08/12, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\IIS\Microsoft Web Deploy V3\
Version : 10.0.7421

10902 - Microsoft Windows 'Administrators' Group User List
-
Synopsis
There is at least one user in the 'Administrators' group.
Description
Using the supplied credentials, it is possible to extract the member list of the 'Administrators' group. Members of this group have complete access to the remote system.
Solution
Verify that each member of the group should have this type of access.
Risk Factor
None
Plugin Information
Published: 2002/03/15, Modified: 2018/05/16
Plugin Output

tcp/445/cifs


The following users are members of the 'Administrators' group :

- MIDDLEWAREAPI\production (User)
- MIDDLEWAREAPI\CommonProduction (User)
- MIDDLEWAREAPI\tidua (User)
48763 - Microsoft Windows 'CWDIllegalInDllSearch' Registry Setting
-
Synopsis
CWDIllegalInDllSearch Settings: Improper settings could allow code execution attacks.
Description
Windows Hosts can be hardened against DLL hijacking attacks by setting the The 'CWDIllegalInDllSearch' registry entry in to one of the following settings:

- 0xFFFFFFFF (Removes the current working directory from the default DLL search order)

- 1 (Blocks a DLL Load from the current working directory if the current working directory is set to a WebDAV folder)

- 2 (Blocks a DLL Load from the current working directory if the current working directory is set to a remote folder)
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/26, Modified: 2019/12/20
Plugin Output

tcp/445/cifs


Name : SYSTEM\CurrentControlSet\Control\Session Manager\CWDIllegalInDllSearch
Value : Registry Key Empty or Missing

92370 - Microsoft Windows ARP Table
-
Synopsis
Nessus was able to collect and report ARP table information from the remote host.
Description
Nessus was able to collect ARP table information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

172.17.100.10 : 78-64-a0-ba-d1-47
172.17.100.31 : d4-f5-ef-60-4d-20
172.17.100.33 : d4-f5-ef-60-36-fc
172.17.100.35 : 00-50-56-bc-fc-73
172.17.100.38 : 00-50-56-88-a7-ac
172.17.100.39 : 00-50-56-bc-4f-46
172.17.100.53 : 00-50-56-88-ef-ed
172.17.100.56 : 00-50-56-88-08-9c
172.17.100.59 : 00-50-56-88-e7-eb
172.17.100.60 : 00-50-56-bc-47-5e
172.17.100.62 : 00-50-56-bc-30-36
172.17.100.67 : 00-50-56-bc-cf-90
172.17.100.68 : 00-50-56-93-38-d4
172.17.100.69 : 00-50-56-93-20-59
172.17.100.73 : 40-a8-f0-20-84-35
172.17.100.79 : 00-50-56-bc-fe-be
172.17.100.81 : 00-50-56-93-1e-75
172.17.100.83 : 00-50-56-bc-b4-9f
172.17.100.91 : 00-50-56-88-23-83
172.17.100.120 : 00-50-56-bc-29-b3
172.17.100.137 : 00-50-56-bc-37-2c
172.17.100.140 : 00-50-56-88-13-c1
172.17.100.146 : 00-50-56-93-e4-72
172.17.100.149 : 00-50-56-93-04-7f
172.17.100.154 : 00-50-56-bc-f3-c3
172.17.100.160 : 00-50-56-88-49-b4
172.17.100.164 : 00-50-56-88-81-ac
172.17.100.183 : 00-50-56-bc-ed-d0
172.17.100.186 : 00-50-56-bc-ad-94
172.17.100.189 : 00-50-56-bc-6b-55
172.17.100.190 : 00-50-56-88-d4-3e
172.17.100.226 : 00-50-56-a9-fc-32
172.17.100.254 : 1a-c2-41-87-f6-3d
172.17.100.255 : ff-ff-ff-ff-ff-ff
224.0.0.22 : 01-00-5e-00-00-16
224.0.0.251 : 01-00-5e-00-00-fb
224.0.0.252 : 01-00-5e-00-00-fc
239.255.255.250 : 01-00-5e-7f-ff-fa
255.255.255.255 : ff-ff-ff-ff-ff-ff

Extended ARP table information attached.
70615 - Microsoft Windows AutoRuns Boot Execute
-
Synopsis
Report programs that startup associates with session manager subsystem.
Description
Report registry startup locations associated with the session manager subsystem during boot time.

These registry keys start-up with the smss.exe service during boot time and perform system tasks that cannot be performed while Windows is running.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\System\CurrentControlSet\Control\Session Manager\bootexecute
- autocheck autochk /q /v *

70616 - Microsoft Windows AutoRuns Codecs
-
Synopsis
Report programs set to normally start with multimedia.
Description
Codecs are encoders and decoders for digital data streams commonly associated with video and audio playback.

The following keys are codecs that are set to start automatically to control different types of digital media encoding and decoding.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\System32\l3codeca.acm
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\SysWOW64\l3codeca.acm
- vidc.cvid : iccvid.dll
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {A888DF60-1E90-11CF-AC98-00AA004C0FA9}
- Name : AVI Draw
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {A888DF60-1E90-11CF-AC98-00AA004C0FA9}
- Name : AVI Draw
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


70617 - Microsoft Windows AutoRuns Explorer
-
Synopsis
Reports programs that startup associates with the explorer process.
Description
Report the startup locations associated with the explorer.exe process.

These items could add controls to menus, add extensions for common protocols such as HTTP or FTP, or set control user activity with the desktop and control panels.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Protocols\Filter
+ CLSID : {807573E5-5146-11D5-A672-00B0D022E945}
- Name : text/xml
- Value : C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL


+ HKLM\SOFTWARE\Classes\Protocols\Handler
+ CLSID : {3050F406-98B5-11CF-BB82-00AA00BDCE0B}
- Name : about
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {3dd53d40-7b8b-11D0-b013-00aa0059ce02}
- Name : cdl
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {12D51199-0DB5-46FE-A120-47A3D7D937CC}
- Name : dvd
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : file
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e3-baf9-11ce-8c82-00aa004ba90b}
- Name : ftp
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e2-baf9-11ce-8c82-00aa004ba90b}
- Name : http
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e5-baf9-11ce-8c82-00aa004ba90b}
- Name : https
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : javascript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : local
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
- Name : mailto
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {05300401-BCBC-11d0-85E3-00C04FD85AB4}
- Name : mhtml
- Value : C:\Windows\System32\inetcomm.dll

+ CLSID : {79eac9e6-baf9-11ce-8c82-00aa004ba90b}
- Name : mk
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {314111c7-a502-11d2-bbca-00c04f8ec294}
- Name : ms-help
- Value :

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : ms-its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
- Name : res
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : tbauth
- Value : C:\Windows\System32\tbauth.dll

+ CLSID : {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E}
- Name : tv
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : vbscript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : windows.tbauth
- Value : C:\Windows\System32\tbauth.dll


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers
+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {e2bf9676-5f8f-435c-97eb-11607a5bedf7}
- Name : ModernSharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {09799AFB-AD67-11d1-ABCD-00C04FC30936}
- Name : Open With
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : Open With EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {90AA3A4E-1CBA-4233-B8BB-535773D48449}
- Name : Taskband Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {C539A15A-3AF9-4c92-B771-50CB78F5C751}
- Name :
- Value : C:\Program Files\BackupClient\ShellExtensions\tishell64.dll


+ HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers
+ CLSID : {7444C719-39BF-11D1-8CD9-00C04FC29D45}
- Name : CryptoSignMenu
- Value : %SystemRoot%\system32\cryptext.dll

+ CLSID : {748F920F-FB24-4D09-B360-BAF6F199AD6D}
- Name : FCI Properties
- Value : C:\Windows\System32\srmshell.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {3EA48300-8CF6-101B-84FB-666CCB9BCD32}
- Name : OLE DocFile Property Page
- Value : %SystemRoot%\system32\docprop.dll

+ CLSID : {883373C3-BF89-11D1-BE35-080036B11A03}
- Name : Summary Properties Page
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers
+ CLSID : {f3d06e7c-1e45-4a26-847e-f9fcdee59be0}
- Name : CopyAsPathMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {7BA4C740-9E81-11CF-99D3-00AA004AE837}
- Name : SendTo
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name :
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers
+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name :
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers
+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll


+ HKLM\Software\Classes\Directory\Shellex\PropertySheetHandlers
+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {4a7ded0a-ad25-11d0-98a8-0800361b1103}
- Name :
- Value : %SystemRoot%\system32\mydocs.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}
- Name :
- Value : C:\Windows\System32\DfsShlEx.dll

+ CLSID : {ef43ecfe-2ab9-4632-bf21-58909dd177f0}
- Name :
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\Directory\Shellex\CopyHookHandlers
+ CLSID : {217FC9C0-3AEA-1069-A2DB-08002B30309D}
- Name : FileSystem
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {40dd6e20-7c17-11ce-a804-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll


+ HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
+ CLSID : {D969A300-E7FF-11d0-A93B-00A0C90F2719}
- Name : New
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll


+ HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers
+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {3dad6c5d-2167-4cae-9914-f99e41c12cfa}
- Name : Library Location
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {470C0EBD-5D73-4d58-9CED-E91E22E23282}
- Name : PintoStartScreen
- Value : C:\Windows\System32\appresolver.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {C539A15A-3AF9-4c92-B771-50CB78F5C751}
- Name :
- Value : C:\Program Files\BackupClient\ShellExtensions\tishell64.dll


+ HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers
+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {BD472F60-27FA-11cf-B8B4-444553540000}
- Name :
- Value : %SystemRoot%\system32\zipfldr.dll


+ HKLM\Software\Classes\Folder\ShellEx\PropertySheetHandlers
+ CLSID : {748F920F-FB24-4D09-B360-BAF6F199AD6D}
- Name : FCI Properties
- Value : C:\Windows\System32\srmshell.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
+ CLSID : {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}
- Name : EnhancedStorageShell
- Value : C:\Windows\System32\EhStorShell.dll

+ CLSID : {4E77131D-3629-431c-9818-C5679DC83E81}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


70619 - Microsoft Windows AutoRuns Internet Explorer
-
Synopsis
Report programs that startup associates with Internet Explorer.
Description
Report registry startup locations associated with the Internet Explorer (IE) application.

The startup values include Internet Explorer plugins to extend the functionality of IE, browser toolbars, hooks into browser controls, and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {B4F3A835-0E21-4959-BA22-42B3008E02FF}
- Name : URLRedirectionBHO
- Value : C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL


HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {B4F3A835-0E21-4959-BA22-42B3008E02FF}
- Name : URLRedirectionBHO
- Value : C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL


70620 - Microsoft Windows AutoRuns Known DLLs
-
Synopsis
DLLs listed to be shared by processes.
Description
The known DLLs registry setting is used to define DLLs that are shared between processes without a process having to search for the DLL location.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs
- imagehlp : IMAGEHLP.dll
- shcore : SHCORE.dll
- oleaut32 : OLEAUT32.dll
- normaliz : NORMALIZ.dll
- msvcrt : MSVCRT.dll
- shell32 : SHELL32.dll
- msctf : MSCTF.dll
- gdi32 : gdi32.dll
- nsi : NSI.dll
- advapi32 : advapi32.dll
- coml2 : coml2.dll
- _wowarmhw : wowarmhw.dll
- clbcatq : clbcatq.dll
- wow64win : wow64win.dll
- shlwapi : SHLWAPI.dll
- psapi : PSAPI.DLL
- imm32 : IMM32.dll
- combase : combase.dll
- user32 : user32.dll
- sechost : sechost.dll
- _xtajit : xtajit.dll
- _wow64cpu : wow64cpu.dll
- wow64 : wow64.dll
- rpcrt4 : rpcrt4.dll
- kernel32 : kernel32.dll
- ws2_32 : WS2_32.dll
- wldap32 : WLDAP32.dll
- ole32 : ole32.dll
- difxapi : difxapi.dll
- setupapi : Setupapi.dll
- comdlg32 : COMDLG32.dll
- gdiplus : gdiplus.dll
70613 - Microsoft Windows AutoRuns LSA Providers
-
Synopsis
Programs set to start as Local Security Authority.
Description
An LSA (Local Security Authority) is an application that can be used to authorize users to their systems. The reported autoruns are available to provide this service or features to this service.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0



+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\authentication packages
- msv1_0


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\notification packages
- rassfm
- scecli


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\security packages
- ""
70621 - Microsoft Windows AutoRuns Logon
-
Synopsis
Report programs that start-up from the most common registry locations.
Description
Report the most common startup locations used by programs. These are commonly associated with programs that start automatically when the computer is turned on, users log in, users log off, or remote sessions are started.

Such keys can be set from a program install, GPO, or through a malicious process to maintain persistence.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd
- rdpclip


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\userinit
- C:\Windows\system32\userinit.exe


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\vmapplet
- SystemPropertiesPerformance.exe /pagefile


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell
- explorer.exe


+ HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
- AlternateShell : cmd.exe


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name : vmware user process
- Value : "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe" -n vmusr

- Name : securityhealth
- Value : %windir%\system32\SecurityHealthSystray.exe

- Name : mmsmonitor.exe
- Value : C:\Program Files\BackupClient\TrayMonitor\MmsMonitor.exe

- Name : acronis scheduler2 service
- Value : "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
- Name : acronistibmountermonitor
- Value : C:\Program Files (x86)\Common Files\Acronis\TibMounter\tib_mounter_monitor.exe


+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {2C7339CF-2B09-4501-B3F3-F3508C9228ED}
- Name : Themes Setup
- Value : /UserInstall

+ CLSID : {49210152-871f-4ffa-961d-a172abcbc09d}
- Name : Google Platform Experience Helper
- Value : "C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe" --first-run

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4340}
- Name : Windows Desktop Update
- Value : U

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4383}
- Name : Web Platform Customizations
- Value : C:\Windows\System32\ie4uinit.exe -UserConfig

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install

+ CLSID : {8A69D345-D564-463c-AFF1-A69D9E530F96}
- Name : Google Chrome
- Value : "C:\Program Files\Google\Chrome\Application\143.0.7499.193\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable

+ CLSID : {A509B1A7-37EF-4b3f-8CFC-4F3A74704073}
- Name : Applying Enhanced Security Configuration
- Value : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenAdmin

+ CLSID : {A509B1A8-37EF-4b3f-8CFC-4F3A74704073}
- Name : Applying Enhanced Security Configuration
- Value : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenUser


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows
- iconservicelib : IconCodecService.dll
- Load :


70622 - Microsoft Windows AutoRuns Network Providers
-
Synopsis
Report programs set to automatically start-up as a Network Provider.
Description
The DLLs listed under the registry key are used to provide network services for new protocols.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\ProviderOrder
- RDPNP : %SystemRoot%\System32\drprov.dll
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll

+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\HwOrder\ProviderOrder
- RDPNP : %SystemRoot%\System32\drprov.dll
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll
70623 - Microsoft Windows AutoRuns Print Monitor
-
Synopsis
Report programs set to start automatically as a print monitor.
Description
Report the DLLs that control print monitor functions for multiple programs and systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
- Local Port : localspl.dll
- Standard TCP/IP Port : tcpmon.dll
- USB Monitor : usbmon.dll
- WSD Port : APMon.dll
70618 - Microsoft Windows AutoRuns Registry Hijack Possible Locations
-
Synopsis
Report common registry keys used to hijack execution.
Description
Report common registry keys that can be used to hijack system process execution.

These registry keys can be used to either replace execution or shim a process in the middle of execution to hijack control. Confirm that everything listed here is set to the appropriate settings and that it doesn't look like another process is taking control of the process's execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command
- Command : "%1" %*


+ HKLM\Software\Classes\.exe : exefile
- open : "%1" %*
- runas : "%1" %*
- runasuser :


+ HKLM\Software\Classes\.cmd : cmdfile
- edit : %SystemRoot%\System32\NOTEPAD.EXE %1
- open : "%1" %*
- print : %SystemRoot%\System32\NOTEPAD.EXE /p %1
- runas : %SystemRoot%\System32\cmd.exe /C "%1" %*
- runasuser :


+ HKLM\Software\Classes\.htm : htmlfile
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1
- open : "C:\Program Files\Internet Explorer\iexplore.exe" %1
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1
- printto : "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.html : htmlfile
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1
- open : "C:\Program Files\Internet Explorer\iexplore.exe" %1
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1
- printto : "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.doc : Word.Document.8
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vu "%1"
- New : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n /f "%1"
- OnenotePrintto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- Open : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n "%1"
- OpenAsReadOnly : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /h /n "%1"
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /i "%1"
- Printto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- ViewProtected : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vp "%1"


+ HKLM\Software\Classes\.docx : Word.Document.12
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vu "%1"
- New : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n /f "%1"
- OnenotePrintto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- Open : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n "%1"
- OpenAsReadOnly : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /h /n "%1"
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /i "%1"
- Printto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- ViewProtected : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vp "%1"


+ HKLM\Software\Classes\.vbs : VBSFile
- Edit : "%SystemRoot%\System32\Notepad.exe" %1
- Open : "%SystemRoot%\System32\WScript.exe" "%1" %*
- Open2 : "%SystemRoot%\System32\CScript.exe" "%1" %*
- Print : "%SystemRoot%\System32\Notepad.exe" /p %1


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.xls : Excel.Sheet.8
- Edit :
- New :
- Open :
- OpenAsReadOnly :
- Print :
- Printto :
- ViewProtected :


+ HKLM\Software\Classes\.xml : xmlfile
- edit : "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb edit "%1"
- open : "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "%1"


+ HKLM\Software\Classes\.pif : piffile
- open : "%1" %*


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"



70624 - Microsoft Windows AutoRuns Report
-
Synopsis
Generate a CSV report of all autoruns.
Description
Collect all autoruns listed in the Windows autoruns plugins and report the primary content in a CSV report.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+Enabled Autoruns Detection Types
- LSA Provider
- Boot Execute
- WinLogon
- Known DLLs
- Winsock Provider
- Service
- Explorer
- Logon
- Codecs
- Driver
- Image Hijack
- Network Provider
- Scheduled Tasks
- Print Monitor
- Internet Explorer


The attached CSV contains information about Windows autoruns.
70625 - Microsoft Windows AutoRuns Scheduled Tasks
-
Synopsis
Report processes that start-up via the scheduled task manager.
Description
This plugin lists the scheduled tasks for the system. The scheduled tasks are often used to update software, for systems administrators to run processes, and can be used by malware to spread on systems.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ Task
+ RegistrationInfo
- Date : 2023-10-31T12:27:46.498956
- Author : MIDDLEWAREAPI\production
- Description : API Accessibility Check
- URI : \API Accessibility Check
+ Principals
+ Principal
- UserId : S-1-5-21-1687551350-3880216100-4069998428-500
- LogonType : Password
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2023-10-31T12:30:00
+ Repetition
- Interval : PT5M
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : D:\CheckAPIAccessibility\CheckAPI.exe

+ Task
+ RegistrationInfo
- Date : 2025-06-03T18:08:14.923436
- Author : MIDDLEWAREAPI\production
- Description : This will call the api and emails will be sent to the clients
- URI : \CallDPEmailAPI
+ Principals
+ Principal
- UserId : S-1-5-21-1687551350-3880216100-4069998428-500
- LogonType : InteractiveToken
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2025-09-18T21:00:00
+ Actions
+ Exec
- Command : powershell.exe
- Arguments : -ExecutionPolicy Bypass -File "C:\Users\Administrator\Desktop\CallDPEmailAPI.ps1"

+ Task
+ RegistrationInfo
- Date : 2024-01-11T13:34:18.6000774
- Author : MIDDLEWAREAPI\production
- URI : \IPO Status Update
+ Principals
+ Principal
- UserId : S-1-5-21-1687551350-3880216100-4069998428-500
- LogonType : Password
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2024-01-11T10:05:38
+ Repetition
- Interval : PT1H
- Duration : PT12H
+ ScheduleByWeek
- WeeksInterval : 1
+ DaysOfWeek
+ Monday
+ Tuesday
+ Wednesday
+ Thursday
+ Friday
+ Actions
+ Exec
- Command : D:\IPO_RemarkStatus_Update\bin\Debug\net6.0\IPO_RemarkStatus_Update.exe

+ Task
+ RegistrationInfo
- Date : 2025-09-09T17:52:18.7779025
- Author : MIDDLEWAREAPI\production
- URI : \IVR_Daily_Client_Push_Task
+ Principals
+ Principal
- UserId : S-1-5-21-1687551350-3880216100-4069998428-500
- LogonType : Password
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2025-09-23T08:00:00
+ ScheduleByWeek
- WeeksInterval : 1
+ DaysOfWeek
+ Monday
+ Tuesday
+ Wednesday
+ Thursday
+ Friday
+ Actions
+ Exec
- Command : powershell.exe
- Arguments : -ExecutionPolicy Bypass -File "D:\Schedulers\IVR_Client_Push\RunClientInfoJob.ps1"

+ Task
+ RegistrationInfo
- Date : 2025-10-03T14:23:47.8702968
- Author : MIDDLEWAREAPI\production
- Description : This Job does client registration on BSE Star MF for Mutual Funds on daily bases new clients are added.
- URI : \MFClientRegistration
+ Principals
+ Principal
- UserId : S-1-5-21-1687551350-3880216100-4069998428-500
- LogonType : InteractiveToken
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2025-10-06T10:00:00
+ ScheduleByWeek
- WeeksInterval : 1
+ DaysOfWeek
+ Monday
+ Tuesday
+ Wednesday
+ Thursday
+ Friday
+ Actions
+ Exec
- Command : D:\Schedulers\MFClientRegistration\MFClientRegister.exe

+ Task
+ RegistrationInfo
- Version : 1.3.215.9
- Description : Keeps your Microsoft software up to date. If this task is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This task uninstalls itself when there is no Microsoft software using it.
- URI : \MicrosoftEdgeUpdateTaskMachineCore{3D4DA8A1-3B41-4A36-8F4F-6160B3A99E20}
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
+ CalendarTrigger
- StartBoundary : 2025-12-22T22:37:57
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
- Arguments : /c

+ Task
+ RegistrationInfo
- Version : 1.3.215.9
- Description : Keeps your Microsoft software up to date. If this task is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This task uninstalls itself when there is no Microsoft software using it.
- URI : \MicrosoftEdgeUpdateTaskMachineUA{B6BEF039-7EEF-47F0-8104-5FA7E569F02A}
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2025-12-22T22:07:57
+ Repetition
- Interval : PT1H
- Duration : P1D
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
- Arguments : /ua /installsource scheduler

+ Task
+ RegistrationInfo
- Date : 2025-04-24T11:26:47.3515303
- Author : MIDDLEWAREAPI\production
- Description : downloads the pnl file for all the clients from financial year 24-25
- URI : \PNL Scheduler
+ Principals
+ Principal
- UserId : S-1-5-21-1687551350-3880216100-4069998428-500
- LogonType : Password
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2025-04-24T12:00:00
+ Actions
+ Exec
- Command : D:\Schedulers\PNLScheduler\PNLScheduler.exe

+ Task
+ RegistrationInfo
- Date : 2024-12-31T14:54:12.9969981
- Author : MIDDLEWAREAPI\production
- URI : \SchemeMasterUpdation
+ Principals
+ Principal
- UserId : S-1-5-21-1687551350-3880216100-4069998428-500
- LogonType : Password
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : P2D
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2024-12-31T12:30:00
+ ScheduleByWeek
- WeeksInterval : 1
+ DaysOfWeek
+ Monday
+ Tuesday
+ Wednesday
+ Thursday
+ Friday
+ Saturday
+ Actions
+ Exec
- Command : D:\Schedulers\SchemeMasterUpdation\net8.0\SchemeListIntoTable.exe

+ Task
+ RegistrationInfo
- Author : MIDDLEWAREAPI\production
- Description : Updates out-of-date system feeds.
- URI : \User_Feed_Synchronization-{F5FA602E-3C7F-432D-8311-DABA92C37A94}
+ Principals
+ Principal
- UserId : S-1-5-21-1687551350-3880216100-4069998428-500
- LogonType : InteractiveToken
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2026-01-12T23:49:56+05:30
- EndBoundary : 2036-01-12T23:49:56+05:30
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : C:\Windows\system32\msfeedssync.exe
- Arguments : sync

+ Task
+ RegistrationInfo
- Author : NT AUTHORITY\SYSTEM
- Description : GoogleUpdater Task System 144.0.7547.0
- URI : \GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem144.0.7547.0{8264E42D-33A4-413B-A4C3-AF9D7648B6EA}
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
+ CalendarTrigger
- StartBoundary : 2025-12-03T00:33:21+05:30
+ Repetition
- Interval : PT1H
- Duration : P1D
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe"
- Arguments : --wake --system

+ Task
+ RegistrationInfo
- Author : Microsoft Visual Studio
- URI : \Microsoft\VisualStudio\Updates\BackgroundDownload
+ Principals
+ Principal
- UserId : S-1-5-21-1687551350-3880216100-4069998428-500
- LogonType : InteractiveToken
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P1D
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
+ Triggers
+ IdleTrigger
+ Actions
+ Exec
- Command : C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe

+ Task
+ RegistrationInfo
- Author : $(@%systemroot%\system32\SrvInitConfig.exe,-100)
- Description : $(@%systemroot%\system32\SrvInitConfig.exe,-101)
- URI : \Microsoft\Windows\Server Initial Configuration Task
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
+ Actions
+ Exec
- Command : %windir%\system32\srvinitconfig.exe
- Arguments : /disableconfigtask

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {84F0FAE1-C27B-4F6F-807B-28CF6F96287D}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {429BC048-379E-45E0-80E4-EB1977941B5C}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- WakeToRun : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ IdleTrigger
+ Actions
+ ComHandler
- ClassId : {613FBA38-A3DF-4AB8-9674-5604984A299A}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- WakeToRun : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ IdleTrigger
+ Actions
+ ComHandler
- ClassId : {DE434264-8FE9-4C0B-A83B-89EBEEBFF78E}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2006-11-10T14:29:55.5851926
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Author : $(@%systemRoot%\System32\msdrm.dll,-6001)
- Description : $(@%systemRoot%\System32\msdrm.dll,-6002)
- URI : \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
+ Principals
+ Principal
- GroupId : S-1-1-0
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2006-11-09T03:00:00
- RandomDelay : PT1H
+ ScheduleByDay
- DaysInterval : 1
+ LogonTrigger
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {CF2CF428-325B-48D3-8CA8-7633E36E5A32}

+ Task
+ RegistrationInfo
- Date : 2006-11-10T14:29:55.5851926
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Author : $(@%systemRoot%\System32\msdrm.dll,-6001)
- Description : $(@%systemRoot%\System32\msdrm.dll,-6003)
- URI : \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
+ Principals
+ Principal
- GroupId : S-1-1-0
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Enabled : false
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {BF5CB148-7C77-4D8A-A53E-D81C70CF743C}

+ Task
+ RegistrationInfo
- Date : 2015-02-09T10:54:13.9629482
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;S-1-5-87-2978287140-3787137133-1749738600-1988163579-2060695581)
- Source : $(@%SystemRoot%\system32\ApplockerCsp.dll,-101)
- Author : $(@%SystemRoot%\system32\ApplockerCsp.dll,-100)
- Description : $(@%SystemRoot%\system32\ApplockerCsp.dll,-102)
- URI : \Microsoft\Windows\AppID\EDP Policy Manager
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7588BCA328009213
+ WnfStateChangeTrigger
- StateName : 75E0BCA328009213
+ Actions
+ ComHandler
- ClassId : {DECA92E0-AF85-439E-9204-86679978DA08}
- Data : EdpPolicyManager

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;CI;FA;;;LS)(A;CI;FA;;;S-1-5-80-2078495744-2416903469-4072184685-3943858305-976987417)
- Source : $(@%systemroot%\system32\appidsvc.dll,-300)
- Author : $(@%systemroot%\system32\appidsvc.dll,-301)
- Description : $(@%systemroot%\system32\appidsvc.dll,-302)
- URI : \Microsoft\Windows\AppID\PolicyConverter
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\appidpolicyconverter.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;CI;FA;;;LS)(A;CI;FA;;;S-1-5-80-2078495744-2416903469-4072184685-3943858305-976987417)
- Source : $(@%systemroot%\system32\appidsvc.dll,-200)
- Author : $(@%systemroot%\system32\appidsvc.dll,-201)
- Description : $(@%systemroot%\system32\appidsvc.dll,-202)
- URI : \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : Queue
- Priority : 10
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT3M
- WaitTimeout : PT23H
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT30M
+ Repetition
- Interval : P1D
+ Actions
+ Exec
- Command : %windir%\system32\appidcertstorecheck.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\appraiser.dll,-500)
- Author : $(@%SystemRoot%\system32\appraiser.dll,-501)
- Description : $(@%SystemRoot%\system32\appraiser.dll,-502)
- URI : \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P4D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-09-01T03:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 750CBCA3290B9641
- Data : 01
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7510BCA323028B41
- Data : 01
+ Actions
+ Exec
- Command : %windir%\system32\compattelrunner.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\invagent.dll,-701)
- Author : $(@%SystemRoot%\system32\invagent.dll,-701)
- Description : $(@%SystemRoot%\system32\invagent.dll,-702)
- URI : \Microsoft\Windows\Application Experience\ProgramDataUpdater
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1DT12H
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\compattelrunner.exe
- Arguments : -maintenance

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;LA)(A;OICI;FA;;;SY)(A;OICI;FRFX;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\Startupscan.dll,-701)
- Author : $(@%SystemRoot%\system32\Startupscan.dll,-701)
- Description : $(@%SystemRoot%\system32\Startupscan.dll,-702)
- URI : \Microsoft\Windows\Application Experience\StartupAppTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P2D
- Deadline : P3D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : Startupscan.dll,SusRunTask

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)(A;;FRFX;;;AU)(A;;FRFX;;;IU)
- Source : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10005)
- Author : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10004)
- Description : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10002)
- URI : \Microsoft\Windows\ApplicationData\appuriverifierdaily
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT15M
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\AppHostRegistrationVerifier.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)(A;;FRFX;;;AU)(A;;FRFX;;;IU)
- Source : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10005)
- Author : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10004)
- Description : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10002)
- URI : \Microsoft\Windows\ApplicationData\appuriverifierinstall
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT15M
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT1M
- StateName : 7508BCA32C7C8741
+ Actions
+ Exec
- Command : %windir%\system32\AppHostRegistrationVerifier.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5001)
- Author : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5002)
- Description : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5003)
- URI : \Microsoft\Windows\ApplicationData\CleanupTemporaryState
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : Windows.Storage.ApplicationData.dll,CleanupTemporaryState

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%systemroot%\system32\dssvc.dll,-10005)
- Author : $(@%systemroot%\system32\dssvc.dll,-10004)
- Description : $(@%systemroot%\system32\dssvc.dll,-10006)
- URI : \Microsoft\Windows\ApplicationData\DsSvcCleanup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\dstokenclean.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;GA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- URI : \Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT15M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ LogonTrigger
- Delay : PT1H
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask

+ Task
+ RegistrationInfo
- Source : $(@%systemroot%\system32\acproxy.dll,-100)
- Author : $(@%systemroot%\system32\acproxy.dll,-101)
- Description : $(@%systemroot%\system32\acproxy.dll,-102)
- URI : \Microsoft\Windows\Autochk\Proxy
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : P365D
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT30M
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : /d acproxy.dll,PerformAutochkOperations

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\BitLocker\BitLocker Encrypt All Drives
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7568BCA32B188341
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : BitLockerEncryptAllDrives

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\BitLocker\BitLocker MDM policy Refresh
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7540BCA32B188341
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : BitLockerPolicy

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Author : $(@%SystemRoot%\system32\BthUdTask.exe,-1002)
- Description : $(@%SystemRoot%\system32\BthUdTask.exe,-1001)
- URI : \Microsoft\Windows\Bluetooth\UninstallDeviceTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : BthUdTask.exe
- Arguments : $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Author : $(@%systemRoot%\System32\bisrv.dll,-102)
- Description : $(@%systemRoot%\System32\bisrv.dll,-103)
- URI : \Microsoft\Windows\BrokerInfrastructure\BgTaskRegistrationMaintenanceTask
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT6M
- MultipleInstancesPolicy : IgnoreNew
- Priority : 6
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT1S
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {E984D939-0E00-4DD9-AC3A-7ACA04745521}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-103)
- URI : \Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7510BCA323098541
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : AIKCertEnroll

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-104)
- URI : \Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7530BCA323098541
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : CryptoPolicy

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\KeyPreGenTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA323098541
+ WnfStateChangeTrigger
- Delay : PT10M
- StateName : 7520BCA323098541
+ WnfStateChangeTrigger
- Delay : PT10M
- StateName : 75C0BCA33E06830D
+ LogonTrigger
- Enabled : false
- Delay : PT10M
+ SessionStateChangeTrigger
- Enabled : false
- Delay : PT10M
- StateChange : ConsoleConnect
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : NGCKeyPregen

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\SystemTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ RegistrationTrigger
+ BootTrigger
- Delay : PT10S
+ Repetition
- Interval : PT8H
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : SYSTEM

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\UserTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : F510BCA32A1E890D
+ RegistrationTrigger
+ LogonTrigger
+ Repetition
- Interval : PT8H
+ EventTrigger
- ExecutionTimeLimit : PT30M
- Delay : PT25M
+ Repetition
- Interval : PT1H
- Duration : PT4H
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-User Device Registration/Admin"><Select Path="Microsoft-Windows-User Device Registration/Admin">*[System[Provider[@Name='Microsoft-Windows-User Device Registration'] and EventID=300]]</Select></Query></QueryList>
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : USER

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFW;;;IU)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ SessionStateChangeTrigger
- StateChange : SessionLock
+ SessionStateChangeTrigger
- StateChange : SessionUnlock
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : KEYROAMING

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\pstask.dll,-100)
- Author : $(@%systemroot%\system32\pstask.dll,-101)
- Description : $(@%systemroot%\system32\pstask.dll,-102)
- URI : \Microsoft\Windows\Chkdsk\ProactiveScan
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {CF4270F5-2E43-4468-83B3-A8C45BB33EA1}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FR;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\Chkdsk\SyspartRepair
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32C0D8E0A
+ Actions
+ Exec
- Command : %windir%\system32\bcdboot.exe
- Arguments : %windir% /sysrepair

+ Task
+ RegistrationInfo
- Date : 2014-01-01T00:00:00
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)(A;;FA;;;S-1-5-80-65843127-2189646064-2697706863-2125155322-3141006483)(A;;FR;;;S-1-5-87-1452649159-2109950929-2856838567-3638795029-1283063528)
- Source : $(@%SystemRoot%\system32\ClipUp.exe,-102)
- Author : $(@%SystemRoot%\system32\ClipUp.exe,-100)
- Description : $(@%SystemRoot%\system32\ClipUp.exe,-101)
- URI : \Microsoft\Windows\Clip\License Validation
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
+ Actions
+ Exec
- Command : %SystemRoot%\system32\ClipUp.exe
- Arguments : -p -s -o

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;IU)
- URI : \Microsoft\Windows\CloudExperienceHost\CreateObjectTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {E4544ABA-62BF-4C54-AAB2-EC246342626C}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)
- Source : $(@%systemRoot%\system32\wsqmcons.exe,-106)
- Author : $(@%systemRoot%\system32\wsqmcons.exe,-108)
- Description : $(@%systemRoot%\system32\wsqmcons.exe,-107)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2004-01-02T00:00:00
+ Repetition
- Interval : PT6H
+ Actions
+ Exec
- Command : %SystemRoot%\System32\wsqmcons.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)(A;OICI;SD;;;S-1-5-87-1060603329-121822201-3452730971-4292368946-61207722)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\usbceip.dll,-601)
- Author : $(@%SystemRoot%\system32\usbceip.dll,-600)
- Description : $(@%SystemRoot%\system32\usbceip.dll,-602)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {C27F6B1D-FE0B-45E4-9257-38799FA69BC8}
- Data : SYSTEM

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\discan.dll,-601)
- Author : $(@%systemroot%\system32\discan.dll,-600)
- Description : $(@%systemroot%\system32\discan.dll,-602)
- URI : \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2011-01-01T23:00:00
- RandomDelay : P7D
+ ScheduleByWeek
- WeeksInterval : 4
+ DaysOfWeek
+ Saturday
+ BootTrigger
- Enabled : false
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {DCFD3EA8-D960-4719-8206-490AE315F94F}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\discan.dll,-601)
- Author : $(@%systemroot%\system32\discan.dll,-600)
- Description : $(@%systemroot%\system32\discan.dll,-603)
- URI : \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 5
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT5M
- StateName : 7508BCA32907950A
+ Actions
+ ComHandler
- ClassId : {DCFD3EA8-D960-4719-8206-490AE315F94F}
- Data : -CrashRecovery

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\defragsvc.dll,-800)
- Author : $(@%systemroot%\system32\defragsvc.dll,-801)
- Description : $(@%systemroot%\system32\defragsvc.dll,-802)
- URI : \Microsoft\Windows\Defrag\ScheduledDefrag
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\defrag.exe
- Arguments : -c -h -k -g -$

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\Device Information\Device
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P4D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-09-01T03:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 750CBCA3290B9641
- Data : 01
+ Actions
+ Exec
- Command : %windir%\system32\devicecensus.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-601)
- Author : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-600)
- Description : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-602)
- URI : \Microsoft\Windows\Device Setup\Metadata Refresh
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P10D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {23C1F3CF-C110-4512-ACA9-7B6174ECE888}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\sdiagschd.dll,-102)
- Author : $(@%systemroot%\system32\sdiagschd.dll,-101)
- Description : $(@%systemroot%\system32\sdiagschd.dll,-103)
- URI : \Microsoft\Windows\Diagnosis\Scheduled
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {C1F85EF8-BCC2-4606-BB39-70C523715EB3}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- URI : \Microsoft\Windows\DirectX\DXGIAdapterCache
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : StopExisting
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7580BCA32916C641
+ WnfStateChangeTrigger
- StateName : 7588BCA32916C641
+ Actions
+ Exec
- Command : %windir%\system32\dxgiadaptercache.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\cleanmgr.exe,-1300)
- Author : $(@%systemroot%\system32\cleanmgr.exe,-1300)
- Description : $(@%systemroot%\system32\cleanmgr.exe,-1301)
- URI : \Microsoft\Windows\DiskCleanup\SilentCleanup
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT15M
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\cleanmgr.exe
- Arguments : /autoclean /d %systemdrive%

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\System32\DFDTS.dll,-100)
- Author : $(@%SystemRoot%\System32\DFDTS.dll,-101)
- Description : $(@%SystemRoot%\System32\DFDTS.dll,-119)
- URI : \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P14D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : dfdts.dll,DfdGetDefaultPolicyAndSMART

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FR;;;BU)
- Source : $(@%SystemRoot%\System32\DFDTS.dll,-100)
- Author : $(@%SystemRoot%\System32\DFDTS.dll,-101)
- Description : $(@%SystemRoot%\System32\DFDTS.dll,-118)
- URI : \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- Hidden : true
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\system32\DFDWiz.exe

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\DiskFootprint\Diagnostics
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\disksnapshot.exe
- Arguments : -z

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\DiskFootprint\StorageSense
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {AB2A519B-03B0-43CE-940A-A73DF850B49A}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\EDP App Launch Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 3508BCA3280A9641
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : AppLaunch

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\EDP Auth Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7538BCA3280A9641
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : ReAuth

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\EDP Inaccessible Credentials Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7560BCA3280A9641
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : MissingCredentials

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\StorageCardEncryption Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7548BCA32B188341
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : SDCardEncryptionPolicy

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\mitigationconfiguration.dll,-601)
- Author : $(@%systemroot%\system32\mitigationconfiguration.dll,-600)
- Description : $(@%systemroot%\system32\mitigationconfiguration.dll,-602)
- URI : \Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BEA328009213
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ BootTrigger
+ Actions
+ ComHandler
- ClassId : {711001CD-CC1D-4470-9B7E-1EF73849C79E}
- Data : ExploitGuardPolicy

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(D;;SD;;;AU)(A;;FRFWFX;;;AU)
- Source : $(@%systemroot%\system32\srm.dll,-18000)
- Author : $(@%systemroot%\system32\srm.dll,-18001)
- Description : $(@%systemroot%\system32\srm.dll,-18002)
- URI : \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT1M
- WaitTimeout : PT1M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2006-11-09T03:00:00
- RandomDelay : PT4H
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ ComHandler
- ClassId : {2AE64751-B728-4D6B-97A0-B2DA2E7D2A3B}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\fcon.dll,-602)
- Author : $(@%systemroot%\system32\fcon.dll,-601)
- Description : $(@%systemroot%\system32\fcon.dll,-603)
- URI : \Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ Actions
+ ComHandler
- ClassId : {59EECBFE-C2F5-4419-9B99-13FE05FF2675}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\wosc.dll,-602)
- Author : $(@%systemroot%\system32\wosc.dll,-601)
- Description : $(@%systemroot%\system32\wosc.dll,-603)
- URI : \Microsoft\Windows\Flighting\OneSettings\RefreshCache
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2025-07-10T20:58:29+05:30
+ Repetition
- Interval : PT23H
- RandomDelay : PT1H
+ Actions
+ ComHandler
- ClassId : {E07647F7-AED2-48D9-9720-939BC24A8A3C}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)
- URI : \Microsoft\Windows\InstallService\ScanForUpdates
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
+ Repetition
- Interval : P1D
- RandomDelay : P1D
+ WnfStateChangeTrigger
- Delay : PT15M
- StateName : 7524BCA33E06830D
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
- Enabled : false
+ Actions
+ ComHandler
- ClassId : {A558C6A5-B42B-4C98-B610-BF9559143139}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;IU)
- URI : \Microsoft\Windows\InstallService\ScanForUpdatesAsUser
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P3D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {DDAFAEA2-8842-4E96-BADE-D44A8D676FDB}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)
- URI : \Microsoft\Windows\InstallService\SmartRetry
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- DisallowStartOnRemoteAppSession : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
- Delay : PT6M
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
- Enabled : false
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7538BDA33E06830D
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7518BCA33E06830D
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7510BCA33E0B8441
- Data : 03
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
- Enabled : false
+ Actions
+ ComHandler
- ClassId : {F3A219C3-2698-4CBF-9C07-037EDB8E72E6}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)
- URI : \Microsoft\Windows\InstallService\WakeUpAndContinueUpdates
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {0DC331EE-8438-49D5-A721-E10B937CE459}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)
- URI : \Microsoft\Windows\InstallService\WakeUpAndScanForUpdates
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
+ Repetition
- Interval : P1D
- RandomDelay : P1D
+ Actions
+ ComHandler
- ClassId : {D5A04D91-6FE6-4FE4-A98A-FEB4500C5AF7}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;IU)
- Source : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-601)
- Author : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-600)
- Description : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-602)
- URI : \Microsoft\Windows\LanguageComponentsInstaller\Installation
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT15M
+ Repetition
- Interval : P1D
+ IdleTrigger
+ Repetition
- Interval : P1D
+ Actions
+ ComHandler
- ClassId : {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE}
- Data : Install $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-601)
- Author : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-600)
- Description : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-603)
- URI : \Microsoft\Windows\LanguageComponentsInstaller\Uninstallation
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE}
- Data : Uninstall

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)
- Source : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-601)
- Author : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-600)
- Description : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-602)
- URI : \Microsoft\Windows\License Manager\TempSignedLicenseExchange
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {77646A68-AD14-4D53-897D-7BE4DDE5F929}

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Description : $(@%systemRoot%\system32\LocationNotificationWindows.exe,-102)
- URI : \Microsoft\Windows\Location\Notifications
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA321089541
- Data : 01
+ Actions
+ Exec
- Command : %windir%\System32\LocationNotificationWindows.exe

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Description : $(@%systemRoot%\System32\WindowsActionDialog.exe,-102)
- URI : \Microsoft\Windows\Location\WindowsActionDialog
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7548BCA321089541
+ Actions
+ Exec
- Command : %windir%\System32\WindowsActionDialog.exe

+ Task
+ RegistrationInfo
- Date : 2008-02-25T19:15:00
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\winsatapi.dll,-113)
- Author : $(@%systemroot%\system32\winsatapi.dll,-112)
- Description : $(@%systemroot%\system32\winsatapi.dll,-114)
- URI : \Microsoft\Windows\Maintenance\WinSAT
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT30M
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
- Exclusive : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {A9A33436-678B-4C9C-A211-7CC38785E79D}

+ Task
+ RegistrationInfo
- Date : 2014-11-05T00:00:00
- SecurityDescriptor : D:(A;;0x111FFFFF;;;SY)(A;;0x111FFFFF;;;BA)(A;;0x111FFFFF;;;S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376)(A;;FRFX;;;AU)
- Author : $(@%SystemRoot%\system32\mapstoasttask.dll,-600)
- Description : $(@%SystemRoot%\system32\mapstoasttask.dll,-602)
- URI : \Microsoft\Windows\Maps\MapsToastTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT5S
- Hidden : true
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {9885AEF2-BD9F-41E0-B15E-B3141395E803}
- Data : $(Arg0);$(Arg1);$(Arg2);$(Arg3);$(Arg4);$(Arg5);$(Arg6);$(Arg7)

+ Task
+ RegistrationInfo
- Date : 2014-11-05T00:00:00
- SecurityDescriptor : D:(A;;0x111FFFFF;;;SY)(A;;0x111FFFFF;;;BA)(A;;0x111FFFFF;;;S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376)(A;;FRFX;;;NS)(A;;FRFX;;;AU)
- Author : $(@%SystemRoot%\system32\mapsupdatetask.dll,-600)
- Description : $(@%SystemRoot%\system32\mapsupdatetask.dll,-602)
- URI : \Microsoft\Windows\Maps\MapsUpdateTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT40S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-10-21T00:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ Actions
+ ComHandler
- ClassId : {B9033E87-33CF-4D77-BC9B-895AFBBA72E4}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)
- Source : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-601)
- Author : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-600)
- Description : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-603)
- URI : \Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Microsoft-Windows-WER-SystemErrorReporting'] and (EventID=1000 or EventID=1001 or EventID=1006)]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Application"><Select Path="Application">*[System[Provider[@Name='Application Error'] and EventID=1000]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Application Popup'] and EventID=1801]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-Kernel-StoreMgr/Operational"><Select Path="Microsoft-Windows-Kernel-StoreMgr/Operational">*[System[Provider[@Name='Microsoft-Windows-Kernel-StoreMgr'] and EventID=6]]</Select></Query></QueryList>
+ Actions
+ ComHandler
- ClassId : {8168E74A-B39F-46D8-ADCD-7BED477B80A3}
- Data : Event

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-601)
- Author : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-600)
- Description : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-602)
- URI : \Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P2M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {8168E74A-B39F-46D8-ADCD-7BED477B80A3}
- Data : Time

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Source : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1901)
- Author : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1902)
- Description : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1903)
- URI : \Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT3M
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList>
<Query Id='1'>
<Select Path='Microsoft-Windows-DeviceSetupManager/Operational'>*[System/EventID=302] and *[EventData/Data[@Name='Prop_ServiceInfoNamespace']='http://schemas.microsoft.com/windows/2010/12/DeviceMetadata/MobileBroadBandInfo']</Select>
</Query>
</QueryList>
+ Actions
+ Exec
- Command : %SystemRoot%\System32\MbaeParserTask.exe

+ Task
+ RegistrationInfo
- Source : $(@%systemRoot%\System32\lpremove.exe,-100)
- Author : $(@%systemRoot%\System32\lpremove.exe,-100)
- Description : $(@%systemRoot%\System32\lpremove.exe,-101)
- URI : \Microsoft\Windows\MUI\LPRemove
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT9H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P3D
- Deadline : P4D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\lpremove.exe

+ Task
+ RegistrationInfo
- Date : 2005-06-23T13:48:00-08:00
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)
- Source : $(@%systemRoot%\System32\PlaySndSrv.Dll,-106)
- Description : $(@%systemRoot%\System32\PlaySndSrv.Dll,-105)
- URI : \Microsoft\Windows\Multimedia\SystemSoundsService
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {2DEA658F-54C1-4227-AF9B-260AB5FC3543}

+ Task
+ RegistrationInfo
- Source : $(@%SystemRoot%\system32\nettrace.dll,-6910)
- Author : $(@%SystemRoot%\system32\nettrace.dll,-6911)
- Description : $(@%SystemRoot%\system32\nettrace.dll,-6912)
- URI : \Microsoft\Windows\NetTrace\GatherNetworkInfo
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\gatherNetworkInfo.vbs
- WorkingDirectory : $(Arg1)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-500)
- Author : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-500)
- Description : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-501)
- URI : \Microsoft\Windows\Network Controller\SDN Diagnostics Task
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2015-08-21T00:00:00
+ Repetition
- Interval : PT30M
+ BootTrigger
+ Actions
+ Exec
- Command : %windir%\System32\SDNDiagnosticsTask.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- Source : $(@%systemroot%\system32\cscui.dll,-5000)
- Author : $(@%systemroot%\system32\cscui.dll,-5001)
- Description : $(@%systemroot%\system32\cscui.dll,-5003)
- URI : \Microsoft\Windows\Offline Files\Background Synchronization
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : P1D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-01-01T00:00:00
+ Repetition
- Interval : PT2H
- RandomDelay : PT20M
+ Actions
+ ComHandler
- ClassId : {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8}

+ Task
+ RegistrationInfo
- Version : 1.0
- Source : $(@%systemroot%\system32\cscui.dll,-5000)
- Author : $(@%systemroot%\system32\cscui.dll,-5001)
- Description : $(@%systemroot%\system32\cscui.dll,-5002)
- URI : \Microsoft\Windows\Offline Files\Logon Synchronization
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : P1D
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT4M
+ Actions
+ ComHandler
- ClassId : {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8}
- Data : Logon

+ Task
+ RegistrationInfo
- Date : 2012-02-07T16:39:20
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-604)
- URI : \Microsoft\Windows\PI\Secure-Boot-Update
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33E0C9541
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : SBServicing

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\PI\SecureBootEncodeUEFI
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1M
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P20D
- Deadline : P25D
+ Triggers
+ RegistrationTrigger
+ Actions
+ Exec
- Command : %WINDIR%\system32\SecureBootEncodeUEFI.exe

+ Task
+ RegistrationInfo
- Date : 2011-07-22T00:00:00.8844064
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-603)
- URI : \Microsoft\Windows\PI\Sqm-Tasks
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : PiSqmTasks

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;BA)(A;;0x1301ff;;;S-1-5-80-2661322625-712705077-2999183737-3043590567-590698655)(A;;FRFX;;;LU)
- Source : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-101)
- Author : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-8197)
- URI : \Microsoft\Windows\PLA\Server Manager Performance Monitor
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 2
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Data
+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)
- Author : $(@%SystemRoot%\system32\pnppolicy.dll,-600)
- Description : $(@%SystemRoot%\system32\pnppolicy.dll,-602)
- URI : \Microsoft\Windows\Plug and Play\Device Install Group Policy
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P1D
- Hidden : true
- MultipleInstancesPolicy : Queue
- Priority : 6
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ Actions
+ ComHandler
- ClassId : {60400283-B242-4FA8-8C25-CAF695B88209}

+ Task
+ RegistrationInfo
- SecurityDescriptor : O:BAG:BAD:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;;FR;;;IU)
- Author : $(@%SystemRoot%\system32\pnpui.dll,-600)
- Description : $(@%SystemRoot%\system32\pnpui.dll,-602)
- URI : \Microsoft\Windows\Plug and Play\Device Install Reboot Required
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : Queue
- Priority : 6
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33D009602
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {48794782-6A1F-47B9-BD52-1D5F95D49C1B}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Author : $(@%SystemRoot%\System32\sppnp.dll,-2000)
- Description : $(@%SystemRoot%\System32\sppnp.dll,-2001)
- URI : \Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %SystemRoot%\System32\drvinst.exe
- Arguments : 6

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%systemRoot%\system32\energytask.dll,-601)
- Author : $(@%systemRoot%\system32\energytask.dll,-600)
- Description : $(@%systemRoot%\system32\energytask.dll,-602)
- URI : \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
- Exclusive : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {927EA2AF-1C54-43D5-825E-0074CE028EEE}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)
- URI : \Microsoft\Windows\PushToInstall\LoginCheck
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- DisallowStartOnRemoteAppSession : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- StartBoundary : 2017-01-01T05:30:00+05:30
- EndBoundary : 2017-01-01T05:30:00+05:30
- Delay : PT5M
+ Actions
+ Exec
- Command : %windir%\system32\sc.exe
- Arguments : start pushtoinstall login

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)
- URI : \Microsoft\Windows\PushToInstall\Registration
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- DisallowStartOnRemoteAppSession : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2017-01-01T05:30:00+05:30
+ Repetition
- Interval : P20D
+ WnfStateChangeTrigger
- Delay : PT15M
- StateName : 750CBCA3290B9641
- Data : 01
+ Actions
+ Exec
- Command : %windir%\system32\sc.exe
- Arguments : start pushtoinstall registration

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;LS)
- Author : $(@%SystemRoot%\system32\rasmbmgr.dll,-201)
- Description : $(@%SystemRoot%\system32\rasmbmgr.dll,-202)
- URI : \Microsoft\Windows\Ras\MobilityManager
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList>







<Query







Id="0"







Path="Application"







>







<Select Path="Application">*[System[Provider[@Name='RasClient'] and (Level=4 or Level=0) and (EventID=20281)]]</Select>







</Query>







</QueryList>
+ Actions
+ ComHandler
- ClassId : {C463A0FC-794F-4FDF-9201-01938CEACAFA}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\ReAgentTask.dll,-602)
- Author : $(@%SystemRoot%\system32\ReAgentTask.dll,-601)
- Description : $(@%SystemRoot%\system32\ReAgentTask.dll,-603)
- URI : \Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P14D
- Deadline : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {89D1D0C2-A3CF-490C-ABE3-B86CDE34B047}
- Data : VerifyWinRE

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)(A;;FRFX;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\regidle.dll,-601)
- Author : $(@%systemroot%\system32\regidle.dll,-600)
- Description : $(@%systemroot%\system32\regidle.dll,-602)
- URI : \Microsoft\Windows\Registry\RegIdleBackup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 5
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P10D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {CA767AA8-9157-4604-B64B-40747123D5F2}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:SYD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)(A;;FRFX;;;LU)
- Source : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-101)
- Author : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-8197)
- URI : \Microsoft\Windows\Server Manager\CleanupOldPerfLogs
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %systemroot%\system32\cscript.exe
- Arguments : /B /nologo %systemroot%\system32\calluxxprovider.vbs $(Arg0) $(Arg1) $(Arg2)

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- Source : $(@%SystemRoot%\system32\svrmgrnc.dll,-101)
- Author : $(@%SystemRoot%\system32\svrmgrnc.dll,-103)
- Description : $(@%SystemRoot%\system32\svrmgrnc.dll,-104)
- URI : \Microsoft\Windows\Server Manager\ServerManager
+ Principals
+ Principal
- GroupId : S-1-5-32-544
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- Priority : 4
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\system32\ServerManagerLauncher.exe

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\Servicing\StartComponentCleanup
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {752073A1-23F2-4396-85F0-8FDB879ED0ED}

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\SharedPC\Account Cleanup
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT30M
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\System32\rundll32.exe
- Arguments : %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;IU)
- Source : $(@%SystemRoot%\system32\shell32.dll,-14349)
- Author : $(@%SystemRoot%\system32\shell32.dll,-14349)
- Description : $(@%SystemRoot%\system32\shell32.dll,-14350)
- URI : \Microsoft\Windows\Shell\CreateObjectTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT30S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {990A9F8F-301F-45F7-8D0E-68C5952DBA43}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;LS)(A;;FR;;;BA)
- Source : $(@%systemroot%\system32\srchadmin.dll,-1901)
- Author : $(@%systemroot%\system32\srchadmin.dll,-1901)
- Description : $(@%systemroot%\system32\srchadmin.dll,-1902)
- URI : \Microsoft\Windows\Shell\IndexerAutomaticMaintenance
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {3FBA60A6-7BF5-4868-A2CA-6623B3DFFEA6}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- URI : \Microsoft\Windows\Software Inventory Logging\Collection
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT10M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2000-01-01T03:00:00
+ Repetition
- Interval : PT1H
- RandomDelay : PT30M
+ Actions
+ Exec
- Command : %systemroot%\system32\cmd.exe
- Arguments : /d /c %systemroot%\system32\silcollector.cmd publish

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- URI : \Microsoft\Windows\Software Inventory Logging\Configuration
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT1M
+ Actions
+ Exec
- Command : %systemroot%\system32\cmd.exe
- Arguments : /d /c %systemroot%\system32\silcollector.cmd configure

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FA;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-87-2912274048-3994893941-1669128114-1310430903-1263774323)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-201)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2125-12-19T11:20:44+05:30
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : timer

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFW;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-4)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-202)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : logon

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFW;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-87-431836887-2321537645-4075769387-3393595759-2187231311)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-203)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-NetworkProfile/Operational"><Select Path="Microsoft-Windows-NetworkProfile/Operational">*[System[EventID=10000]]</Select></Query></QueryList>
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : network

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\SpaceAgent.exe,-1)
- Author : $(@%SystemRoot%\system32\SpaceAgent.exe,-2)
- Description : $(@%SystemRoot%\system32\SpaceAgent.exe,-3)
- URI : \Microsoft\Windows\SpacePort\SpaceAgentTask
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT6H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
- Delay : PT2M
+ WnfStateChangeTrigger
- StateName : 7508BCA33E1E8702
+ Actions
+ Exec
- Command : %windir%\system32\SpaceAgent.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\spaceman.exe,-1)
- Author : $(@%SystemRoot%\system32\spaceman.exe,-2)
- Description : $(@%SystemRoot%\system32\spaceman.exe,-3)
- URI : \Microsoft\Windows\SpacePort\SpaceManagerTask
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
- Delay : PT2M
+ WnfStateChangeTrigger
- StateName : 7510BCA33E1E8702
+ Actions
+ Exec
- Command : %windir%\system32\spaceman.exe
- Arguments : /Work

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;AU)
- URI : \Microsoft\Windows\Speech\HeadsetButtonPress
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7510BCA33E1E8509
+ Actions
+ Exec
- Command : %windir%\system32\speech_onecore\common\SpeechRuntime.exe
- Arguments : StartedFromTask

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GA;;;NU)
- URI : \Microsoft\Windows\Speech\SpeechModelDownloadTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT10M
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2004-01-01T00:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT4H
+ Actions
+ Exec
- Command : %windir%\system32\speech_onecore\common\SpeechModelDownload.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\TieringEngineService.exe,-601)
- Author : $(@%systemroot%\system32\TieringEngineService.exe,-600)
- Description : $(@%systemroot%\system32\TieringEngineService.exe,-602)
- URI : \Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32B1D940D
+ Actions
+ ComHandler
- ClassId : {5C9AB547-345D-4175-9AF6-65133463A100}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\TieringEngineService.exe,-601)
- Author : $(@%systemroot%\system32\TieringEngineService.exe,-600)
- Description : $(@%systemroot%\system32\TieringEngineService.exe,-603)
- URI : \Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2013-01-01T01:00:00
+ Repetition
- Interval : PT4H
+ Actions
+ Exec
- Command : %windir%\system32\defrag.exe
- Arguments : -c -h -g -# -m 8 -i 13500

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)
- Source : $(@%systemroot%\system32\wdc.dll,-10042)
- Author : $(@%systemroot%\system32\wdc.dll,-10041)
- Description : $(@%systemroot%\system32\wdc.dll,-10043)
- URI : \Microsoft\Windows\Task Manager\Interactive
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 5
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {855FEC53-D2E4-4999-9E87-3414E9CF0FF4}
- Data : $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- Source : $(@%systemRoot%\system32\MsCtfMonitor.dll,-1000)
- Description : $(@%systemRoot%\system32\MsCtfMonitor.dll,-1001)
- URI : \Microsoft\Windows\TextServicesFramework\MsCtfMonitor
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 5
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {01575CFE-9A55-4003-A5E1-F38D1EBDCBE1}

+ Task
+ RegistrationInfo
- Source : $(@%SystemRoot%\system32\TimeSyncTask.dll,-601)
- Author : $(@%SystemRoot%\system32\TimeSyncTask.dll,-600)
- Description : $(@%SystemRoot%\system32\TimeSyncTask.dll,-602)
- URI : \Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
+ Principals
+ Principal
- UserId : S-1-5-19
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT1M
- StateName : 7510BCA32F018915
+ Actions
+ ComHandler
- ClassId : {A31AD6C2-FF4C-43D4-8E90-7101023096F9}
- Data : TimeSyncTask

+ Task
+ RegistrationInfo
- Source : $(@%systemroot%\system32\w32time.dll,-200)
- Author : $(@%systemroot%\system32\w32time.dll,-202)
- Description : $(@%systemroot%\system32\w32time.dll,-201)
- URI : \Microsoft\Windows\Time Synchronization\SynchronizeTime
+ Principals
+ Principal
- UserId : S-1-5-19
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\sc.exe
- Arguments : start w32time task_started

+ Task
+ RegistrationInfo
- Date : 2013-01-10T16:32:04.2837388
- Author : $(@%SystemRoot%\system32\tzsyncres.dll,-101)
- Description : $(@%SystemRoot%\system32\tzsyncres.dll,-102)
- URI : \Microsoft\Windows\Time Zone\SynchronizeTimeZone
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\tzsync.exe

+ Task
+ RegistrationInfo
- Date : 2015-02-16T17:49:20.8844064
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-605)
- URI : \Microsoft\Windows\TPM\Tpm-HASCertRetr
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA3250F9541
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : HASCertRetr

+ Task
+ RegistrationInfo
- Date : 2010-06-10T17:49:20.8844064
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;S-1-5-87-1469317444-2401623638-2778953283-1691679301-3481717153)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-602)
- URI : \Microsoft\Windows\TPM\Tpm-Maintenance
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7518BCA3391E8B41
+ WnfStateChangeTrigger
- StateName : 7560BCA322028F02
+ WnfStateChangeTrigger
- StateName : 7510BCA3391E8B41
+ WnfStateChangeTrigger
- StateName : 3528BCA32E1D8E0D
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : TpmTasks

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\AC Power Download
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA3380C960C
- Data : 01000000
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartDownload

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Backup Scan
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2025-07-24T16:12:26+05:30
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartScan

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Maintenance Install
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartInstall

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
- Delay : PT40S
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : LogonDisplay

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Reboot
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT10M
- StartWhenAvailable : true
- WakeToRun : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2023-08-11T17:25:00+05:30
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : RebootDialog

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA)
- URI : \Microsoft\Windows\UpdateOrchestrator\Schedule Scan
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2020-12-07T23:55:49+05:30
+ Repetition
- Interval : PT22H
- RandomDelay : PT4H
+ WnfStateChangeTrigger
- StateName : 7508BCA3380C960C
- Data : 01000000
+ WnfStateChangeTrigger
- StateName : 7508BCA33E0B8441
- Data : 00000000
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartScan

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA)
- Source : $(@%systemRoot%\system32\usocore.dll,-104)
- Author : $(@%systemRoot%\system32\usocore.dll,-103)
- Description : $(@%systemRoot%\system32\usocore.dll,-105)
- URI : \Microsoft\Windows\UpdateOrchestrator\Schedule Scan Static Task
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT2H5M
- StateName : 7524BCA33E06830D
- Data : 01
+ WnfStateChangeTrigger
- Delay : PT2H5M
- StateName : 750CBCA3290B9641
- Data : 01
+ WnfStateChangeTrigger
- StateName : 7550BCA322028F02
+ WnfStateChangeTrigger
- StateName : 7508BCA32E07C641
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[EventID=8202]]</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartScan

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA)
- Source : $(@%systemRoot%\system32\usocore.dll,-104)
- Author : $(@%systemRoot%\system32\usocore.dll,-103)
- Description : $(@%systemRoot%\system32\usocore.dll,-106)
- URI : \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7510BCA3381D8941
+ CalendarTrigger
- StartBoundary : 2000-01-01T03:00:00
- RandomDelay : P1D
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Author : $(@%systemroot%\system32\upnphost.dll,-215)
- Description : $(@%systemroot%\system32\upnphost.dll,-216)
- URI : \Microsoft\Windows\UPnP\UPnPHostConfig
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : sc.exe
- Arguments : config upnphost start= auto

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\profsvc,-500)
- Author : $(@%SystemRoot%\system32\profsvc,-500)
- Description : $(@%SystemRoot%\system32\profsvc,-501)
- URI : \Microsoft\Windows\User Profile Service\HiveUploadTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT2M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT2H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2007-08-28T00:00:00
+ Repetition
- Interval : PT12H
- RandomDelay : PT1H
+ Actions
+ ComHandler
- ClassId : {BA677074-762C-444B-94C8-8C83F93F6605}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA)
- Source : $(@%systemroot%\system32\WaasMedicSvc.dll,-103)
- Author : $(@%systemroot%\system32\WaasMedicSvc.dll,-102)
- Description : $(@%systemroot%\system32\WaasMedicSvc.dll,-104)
- URI : \Microsoft\Windows\WaaSMedic\PerformRemediation
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2000-10-15T03:00:00
+ Repetition
- Interval : P7D
- RandomDelay : PT4H
+ Actions
+ ComHandler
- ClassId : {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32}
- Data : None

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)(A;;FRFX;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)
- Source : $(@%systemroot%\system32\dps.dll,-601)
- Author : $(@%systemroot%\system32\dps.dll,-600)
- Description : $(@%systemroot%\system32\dps.dll,-602)
- URI : \Microsoft\Windows\WDI\ResolutionHost
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 10
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {900BE39D-6BE8-461A-BC4D-B0FA71F5ECB1}

+ Task
+ RegistrationInfo
- Version : 1.5
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Source : $(@%SystemRoot%\system32\wer.dll,-292)
- Author : $(@%SystemRoot%\system32\wer.dll,-293)
- Description : $(@%SystemRoot%\system32\wer.dll,-294)
- URI : \Microsoft\Windows\Windows Error Reporting\QueueReporting
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT3M
+ WnfStateChangeTrigger
- StateName : 7510BCA33A0B9441
- Data : 01
+ WnfStateChangeTrigger
- StateName : 7510BCA33E0B8441
- Data : 03
+ TimeTrigger
- StartBoundary : 2025-11-06T14:11:12+05:30
- Enabled : false
+ Repetition
- Interval : PT30M
- RandomDelay : PT30M
+ Actions
+ Exec
- Command : %windir%\system32\wermgr.exe
- Arguments : -upload

+ Task
+ RegistrationInfo
- Author : $(@%SystemRoot%\system32\bfe.dll,-2001)
- Description : $(@%SystemRoot%\system32\bfe.dll,-2002)
- URI : \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*/System/Provider[@Name='Service Control Manager'] and */System/EventID='7040' and */EventData/Data[@Name='param4']='BFE'</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : bfe.dll,BfeOnServiceStartTypeChange

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Author : $(@%ProgramFiles%\Windows Media Player\wmpnscfg.exe,-1001)
- Description : $(@%ProgramFiles%\Windows Media Player\wmpnscfg.exe,-1002)
- URI : \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList>
<Query
Id="0"
Path="System"
>
<Select Path="System">*[System[Provider[@Name='Microsoft-Windows-WMPNSS-Service'] and (EventID=14210)]]</Select>
</Query>
</QueryList>
+ Actions
+ Exec
- Command : "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FWFR;;;BU)
- Source : $(@%SystemRoot%\system32\mscms.dll,-200)
- Author : $(@%SystemRoot%\system32\mscms.dll,-201)
- Description : $(@%SystemRoot%\system32\mscms.dll,-202)
- URI : \Microsoft\Windows\WindowsColorSystem\Calibration Loader
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ SessionStateChangeTrigger
- StateChange : ConsoleConnect
+ Actions
+ ComHandler
- ClassId : {B210D694-C8DF-490D-9576-9E20CDBC20BD}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- Source : Microsoft Corporation.
- Author : Microsoft Corporation.
- Description : This task is used to start the Windows Update service when needed to perform scheduled operations such as scans.
- URI : \Microsoft\Windows\WindowsUpdate\Scheduled Start
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2026-01-13T16:35:25+05:30
- RandomDelay : PT1M
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : ConsoleDisconnect
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : RemoteDisconnect
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7508BCA3380C960C
- Data : 01
+ Actions
+ Exec
- Command : C:\Windows\system32\sc.exe
- Arguments : start wuauserv

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;0x001200a9;;;BU)(A;;0x001200a9;;;WD)(A;;0x001200a9;;;LW)
- Author : $(@%systemroot%\system32\wininet.dll,-16000)
- Description : $(@%systemroot%\system32\wininet.dll,-16001)
- URI : \Microsoft\Windows\Wininet\CacheTask
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {0358B920-0AC7-461F-98F4-58E32CD89148}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;NS)(A;;GA;;;SY)(A;ID;FA;;;BA)(A;ID;GRGX;;;AU)
- Description : $(@%SystemRoot%\system32\dsregcmd.exe,-101)
- URI : \Microsoft\Windows\Workplace Join\Automatic-Device-Join
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT1M
+ EventTrigger
+ Repetition
- Interval : PT1H
- Duration : P1D
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-User Device Registration/Admin"><Select Path="Microsoft-Windows-User Device Registration/Admin">*[System[Provider[@Name='Microsoft-Windows-User Device Registration'] and EventID=4096]]</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %SystemRoot%\System32\dsregcmd.exe
- Arguments : $(Arg0) $(Arg1) $(Arg2)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;NS)(A;;GA;;;SY)(A;ID;FA;;;BA)(A;ID;GRGX;;;AU)
- Description : $(@%SystemRoot%\system32\dsregcmd.exe,-102)
- URI : \Microsoft\Windows\Workplace Join\Recovery-Check
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT2H
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %SystemRoot%\System32\dsregcmd.exe
- Arguments : /checkrecovery

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FA;;;S-1-5-20)
- Source : $(@%systemroot%\system32\osppc.dll,-200)
- Author : $(@%systemroot%\system32\osppc.dll,-200)
- Description : $(@%systemroot%\system32\osppc.dll,-201)
- URI : \OfficeSoftwareProtectionPlatform\SvcRestartTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2004-01-01T00:00:00
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : %systemroot%\system32\sc.exe
- Arguments : start osppsvc
70626 - Microsoft Windows AutoRuns Services and Drivers
-
Synopsis
Report programs that are set to start automatically on boot as a service or driver.
Description
Report the registry keys that track programs that are set to start on boot as a service.

These programs can start as a system wide service or be loaded as a driver.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services
Drivers :
+ Acronis Agent Core Service
- "C:\Program Files\Common Files\Acronis\Agent\aakore.exe" run
- Auto Load
- Enables Acronis Agent Core Service.

+ Acronis Update Controller
- "C:\Program Files\BackupClient\UpdateController\acp-update-controller.exe" --update-controller
- Auto Load
- Enables Acronis Update Controller.

+ Acronis Active Protection Service
- "C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe"
- Auto Load
- Acronis Active Protection Service

+ Acronis Scheduler2 Service
- "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
- Auto Load
- Provides scheduling for tasks of Acronis components.

+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ @%windir%\system32\inetsrv\iisres.dll,-30011
- %windir%\system32\svchost.exe -k apphost
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30012

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness -p
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
- Load on Demand
- @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-2

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\audiosrv.dll,-201

+ Kaspersky Endpoint Security Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r
- Auto Load
- Provides computer protection against viruses, other malicious applications, and network attacks.

+ Kaspersky Seamless Update Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"
- Auto Load
- Lets you install and roll back critical and approved updates of application modules.

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- disabled
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ AzureAttestService
- C:\Windows\system32\svchost.exe -k AzureAttestService
- Auto Load
-

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ @%SystemRoot%\system32\qmgr.dll,-1000
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%SystemRoot%\system32\BTAGService.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\BTAGService.dll,-102

+ @%SystemRoot%\system32\BthAvctpSvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\BthAvctpSvc.dll,-102

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ @%SystemRoot%\system32\CapabilityAccessManager.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\CapabilityAccessManager.dll,-2

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- disabled
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @combase.dll,-5013

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc -p
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dosvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%systemroot%\system32\dosvc.dll,-101

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ Microsoft Edge Update Service (edgeupdate)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
- Auto Load
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ Microsoft Edge Update Service (edgeupdatem)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
- Load on Demand
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @comres.dll,-2451

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ Google Chrome Elevation Service (GoogleChromeElevationService)
- "C:\Program Files\Google\Chrome\Application\143.0.7499.193\elevation_service.exe"
- Load on Demand
- Provides encryption services and a secure way for recovering Google Chrome if it gets out of date. If this service is disabled, Google Chrome may lose access to encrypted data, and Google Chrome may not be able recover itself.

+ Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update-internal
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ Google Updater Service (GoogleUpdaterService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\system32\GraphicsPerfSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k GraphicsPerfSvcGroup
- disabled
- @%SystemRoot%\system32\GraphicsPerfSvc.dll,-101

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- disabled
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%windir%\system32\inetsrv\iisres.dll,-30007
- %windir%\system32\inetsrv\inetinfo.exe
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30008

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\InstallService.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\InstallService.dll,-201

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ Kaspersky Security Center Network Agent
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"
- Auto Load
- Network Agent coordinates interaction between the Administration Server and Kaspersky applications installed on devices.

+ @%systemroot%\system32\kpssvc.dll,-100
- %systemroot%\system32\svchost.exe -k KpsSvcGroup
- Load on Demand
- @%systemroot%\system32\kpssvc.dll,-101

+ Kaspersky Security Network proxy server
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"
- Load on Demand
- The KSN proxy service retranslates requests to Kaspersky Security Network and caches the responses.

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- disabled
- @%SystemRoot%\System32\moshost.dll,-101

+ Acronis Managed Machine Service
- "C:\Program Files\BackupClient\BackupAndRecovery\mms.exe"
- Auto Load
- Enables data backup and recovery on the machine.

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Auto Load
- @comres.dll,-2798

+ SQL Server Integration Services 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\MsDtsSrvr.exe"
- Auto Load
- Provides management support for SSIS package storage and execution.

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ MS-MPI Launch Service
- "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"
- Load on Demand
- Service for launching MS-MPI applications

+ SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER
- Load on Demand
- Service to launch full-text filter daemon process which will perform document filtering and word breaking for SQL Server full-text search. Disabling this service will make full-text search features of SQL Server unavailable.

+ SQL Server Launchpad (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
- Auto Load
- Service to launch Advanced Analytics Extensions Launchpad process that enables integration with Microsoft R Open using standard T-SQL statements. Disabling this service will make Advanced Analytics features of SQL Server unavailable.

+ SQL Server (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
- Auto Load
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ SQL Server Analysis Services (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Config"
- Auto Load
- Supplies online analytical processing (OLAP) and data mining functionality for business intelligence applications.

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8196

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8198

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Load on Demand
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ NXLog
- "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
- Auto Load
- This service is responsible for running the NXLog agent. See www.nxlog.co.

+ Office Source Engine
- "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ Office Software Protection Platform
- "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
- Load on Demand
- Office Software Protection Platform Service (unlocalized description)

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\pushtoinstall.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\pushtoinstall.dll,-201

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\rasmans.dll,-201

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService -p
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- disabled
- @%SystemRoot%\system32\RMapi.dll,-1002

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS -p
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss -p
- Auto Load
- @combase.dll,-5011

+ @gpapi.dll,-114
- %SystemRoot%\system32\RSoPProv.exe
- Load on Demand
- @gpapi.dll,-115

+ @%systemroot%\system32\sacsvr.dll,-500
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\sacsvr.dll,-501

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- disabled
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ SecPod Saner Upgrade Controller v2
- "C:\Program Files (x86)\SecPod Saner\Upgrader\bin\spupgradecontroller.exe"
- Load on Demand
- Controller for monitoring SecPod's SanerNow agent upgrade.

+ @%systemroot%\system32\SecurityHealthAgent.dll,-1002
- %SystemRoot%\system32\SecurityHealthService.exe
- Load on Demand
- @%systemroot%\system32\SecurityHealthAgent.dll,-1001

+ @%SystemRoot%\System32\SEMgrSvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\System32\SEMgrSvc.dll,-1002

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001
- "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1002

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- disabled
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\System32\SgrmBroker.exe,-100
- %SystemRoot%\system32\SgrmBroker.exe
- Load on Demand
- @%SystemRoot%\System32\SgrmBroker.exe,-101

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-101

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @firewallapi.dll,-50323
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @firewallapi.dll,-50324

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Browser
- "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
- disabled
- Provides SQL Server connection information to client computers.

+ SQL Server Agent (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
- Load on Demand
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server CEIP service (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service
- Auto Load
- CEIP service for Sql server

+ SQL Server VSS Writer
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- Auto Load
- Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.

+ SQL Server Analysis Services CEIP (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Bin\sqlceip.exe" -Service MSSQLSERVER MSAS
- Auto Load
- CEIP service for Sql Server Analysis Services

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\ssdpsrv.dll,-101

+ OpenSSH Authentication Agent
- %SystemRoot%\System32\OpenSSH\ssh-agent.exe
- disabled
- Agent to hold private keys used for public key authentication.

+ SQL Server Integration Services CEIP service 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\sqlceip.exe" -Service default MSIS
- Auto Load
- CEIP service for Sql server Integration Services

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k termsvcs
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ Tib Mounter Service
- "C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe"
- Load on Demand
-

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ @%systemroot%\system32\tokenbroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\tokenbroker.dll,-101

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\ualsvc.dll,-102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%systemroot%\system32\ualsvc.dll,-101

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usocore.dll,-101
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usocore.dll,-102

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ VMware Alias Manager and Ticket Service
- "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"
- Auto Load
- Alias Manager and Ticket Service

+ @oem7.inf,%VM3DSERVICE_DISPLAYNAME%;VMware SVGA Helper Service
- %SystemRoot%\system32\vm3dservice.exe
- Auto Load
- @oem7.inf,%VM3DSERVICE_DESCRIPTION%;Helps VMware SVGA driver by collecting and conveying user mode information

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ VMware Tools
- "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"
- Auto Load
- Provides support for synchronizing objects between the host and guest operating systems.

+ VMware Snapshot Provider
- C:\Windows\system32\dllhost.exe /Processid:{901C72D2-92C9-4A2F-885B-44DA86E6E0A9}
- Load on Demand
- VMware Snapshot Provider

+ Visual Studio Installer Elevation Service
- "C:\Program Files (x86)\Microsoft Visual Studio\Installer\VSInstallerElevationService.exe"
- Load on Demand
- This service is responsible for elevating the Visual Studio Installer.

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ Visual Studio Standard Collector Service 150
- "C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe"
- Load on Demand
- Visual Studio Data Collection Service. When running, this service collects real-time ETW events and processes them.

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\w32time.dll,-201

+ @%windir%\system32\inetsrv\iisres.dll,-30014
- %windir%\system32\svchost.exe -k apphost
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30015

+ @%windir%\system32\inetsrv\iisres.dll,-30003
- %windir%\system32\svchost.exe -k iissvcs
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30004

+ @WaaSMedicSvc.dll,-100
- %systemroot%\system32\svchost.exe -k wusvcs -p
- Load on Demand
- @WaaSMedicSvc.dll,-101

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel -p
- disabled
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%SystemRoot%\System32\Windows.WARP.JITService.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\Windows.WARP.JITService.dll,-101

+ @%windir%\system32\inetsrv\iisres.dll,-30001
- %windir%\system32\svchost.exe -k iissvcs
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30002

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Load on Demand
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%Systemroot%\system32\wsmsvc.dll,-102

+ VNC Server Version 4
- "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service
- Auto Load
-

+ @%SystemRoot%\system32\flightsettings.dll,-103
- %systemroot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\flightsettings.dll,-104

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101
- "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe"
- Load on Demand
- @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102

+ @%windir%\system32\inetsrv\iisres.dll,-20001
- %windir%\system32\inetsrv\wmsvc.exe
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-20002

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- disabled
- @%systemroot%\system32\SearchIndexer.exe,-104

+ @%systemroot%\system32\wuaueng.dll,-105
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\wuaueng.dll,-106

+ @wpdfs.inf,%WPDFS_SvcName%;WPD File System driver
- \SystemRoot\system32\DRIVERS\WUDFRd.sys
- Load on Demand
- @wpdfs.inf,%WPDFS_SvcDesc%;User mode driver that enables communication with removable storage devices via the WPD interface


Services :
+ Acronis Agent Core Service
- "C:\Program Files\Common Files\Acronis\Agent\aakore.exe" run
- Auto Load
- Enables Acronis Agent Core Service.

+ Acronis Update Controller
- "C:\Program Files\BackupClient\UpdateController\acp-update-controller.exe" --update-controller
- Auto Load
- Enables Acronis Update Controller.

+ Acronis Active Protection Service
- "C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe"
- Auto Load
- Acronis Active Protection Service

+ Acronis Scheduler2 Service
- "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
- Auto Load
- Provides scheduling for tasks of Acronis components.

+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ @%windir%\system32\inetsrv\iisres.dll,-30011
- %windir%\system32\svchost.exe -k apphost
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30012

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness -p
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
- Load on Demand
- @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-2

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\audiosrv.dll,-201

+ Kaspersky Endpoint Security Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r
- Auto Load
- Provides computer protection against viruses, other malicious applications, and network attacks.

+ Kaspersky Seamless Update Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"
- Auto Load
- Lets you install and roll back critical and approved updates of application modules.

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- disabled
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ AzureAttestService
- C:\Windows\system32\svchost.exe -k AzureAttestService
- Auto Load
-

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ @%SystemRoot%\system32\qmgr.dll,-1000
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%SystemRoot%\system32\BTAGService.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\BTAGService.dll,-102

+ @%SystemRoot%\system32\BthAvctpSvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\BthAvctpSvc.dll,-102

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ @%SystemRoot%\system32\CapabilityAccessManager.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\CapabilityAccessManager.dll,-2

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- disabled
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @combase.dll,-5013

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc -p
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dosvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%systemroot%\system32\dosvc.dll,-101

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ Microsoft Edge Update Service (edgeupdate)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
- Auto Load
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ Microsoft Edge Update Service (edgeupdatem)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
- Load on Demand
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @comres.dll,-2451

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ Google Chrome Elevation Service (GoogleChromeElevationService)
- "C:\Program Files\Google\Chrome\Application\143.0.7499.193\elevation_service.exe"
- Load on Demand
- Provides encryption services and a secure way for recovering Google Chrome if it gets out of date. If this service is disabled, Google Chrome may lose access to encrypted data, and Google Chrome may not be able recover itself.

+ Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update-internal
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ Google Updater Service (GoogleUpdaterService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\system32\GraphicsPerfSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k GraphicsPerfSvcGroup
- disabled
- @%SystemRoot%\system32\GraphicsPerfSvc.dll,-101

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- disabled
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%windir%\system32\inetsrv\iisres.dll,-30007
- %windir%\system32\inetsrv\inetinfo.exe
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30008

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\InstallService.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\InstallService.dll,-201

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ Kaspersky Security Center Network Agent
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"
- Auto Load
- Network Agent coordinates interaction between the Administration Server and Kaspersky applications installed on devices.

+ @%systemroot%\system32\kpssvc.dll,-100
- %systemroot%\system32\svchost.exe -k KpsSvcGroup
- Load on Demand
- @%systemroot%\system32\kpssvc.dll,-101

+ Kaspersky Security Network proxy server
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"
- Load on Demand
- The KSN proxy service retranslates requests to Kaspersky Security Network and caches the responses.

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- disabled
- @%SystemRoot%\System32\moshost.dll,-101

+ Acronis Managed Machine Service
- "C:\Program Files\BackupClient\BackupAndRecovery\mms.exe"
- Auto Load
- Enables data backup and recovery on the machine.

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Auto Load
- @comres.dll,-2798

+ SQL Server Integration Services 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\MsDtsSrvr.exe"
- Auto Load
- Provides management support for SSIS package storage and execution.

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ MS-MPI Launch Service
- "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"
- Load on Demand
- Service for launching MS-MPI applications

+ SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER
- Load on Demand
- Service to launch full-text filter daemon process which will perform document filtering and word breaking for SQL Server full-text search. Disabling this service will make full-text search features of SQL Server unavailable.

+ SQL Server Launchpad (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
- Auto Load
- Service to launch Advanced Analytics Extensions Launchpad process that enables integration with Microsoft R Open using standard T-SQL statements. Disabling this service will make Advanced Analytics features of SQL Server unavailable.

+ SQL Server (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
- Auto Load
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ SQL Server Analysis Services (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Config"
- Auto Load
- Supplies online analytical processing (OLAP) and data mining functionality for business intelligence applications.

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8196

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8198

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Load on Demand
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ NXLog
- "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
- Auto Load
- This service is responsible for running the NXLog agent. See www.nxlog.co.

+ Office Source Engine
- "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ Office Software Protection Platform
- "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
- Load on Demand
- Office Software Protection Platform Service (unlocalized description)

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\pushtoinstall.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\pushtoinstall.dll,-201

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\rasmans.dll,-201

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService -p
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- disabled
- @%SystemRoot%\system32\RMapi.dll,-1002

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS -p
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss -p
- Auto Load
- @combase.dll,-5011

+ @gpapi.dll,-114
- %SystemRoot%\system32\RSoPProv.exe
- Load on Demand
- @gpapi.dll,-115

+ @%systemroot%\system32\sacsvr.dll,-500
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\sacsvr.dll,-501

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- disabled
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ SecPod Saner Upgrade Controller v2
- "C:\Program Files (x86)\SecPod Saner\Upgrader\bin\spupgradecontroller.exe"
- Load on Demand
- Controller for monitoring SecPod's SanerNow agent upgrade.

+ @%systemroot%\system32\SecurityHealthAgent.dll,-1002
- %SystemRoot%\system32\SecurityHealthService.exe
- Load on Demand
- @%systemroot%\system32\SecurityHealthAgent.dll,-1001

+ @%SystemRoot%\System32\SEMgrSvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\System32\SEMgrSvc.dll,-1002

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001
- "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1002

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- disabled
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\System32\SgrmBroker.exe,-100
- %SystemRoot%\system32\SgrmBroker.exe
- Load on Demand
- @%SystemRoot%\System32\SgrmBroker.exe,-101

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-101

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @firewallapi.dll,-50323
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @firewallapi.dll,-50324

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Browser
- "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
- disabled
- Provides SQL Server connection information to client computers.

+ SQL Server Agent (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
- Load on Demand
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server CEIP service (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service
- Auto Load
- CEIP service for Sql server

+ SQL Server VSS Writer
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- Auto Load
- Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.

+ SQL Server Analysis Services CEIP (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Bin\sqlceip.exe" -Service MSSQLSERVER MSAS
- Auto Load
- CEIP service for Sql Server Analysis Services

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\ssdpsrv.dll,-101

+ OpenSSH Authentication Agent
- %SystemRoot%\System32\OpenSSH\ssh-agent.exe
- disabled
- Agent to hold private keys used for public key authentication.

+ SQL Server Integration Services CEIP service 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\sqlceip.exe" -Service default MSIS
- Auto Load
- CEIP service for Sql server Integration Services

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k termsvcs
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ Tib Mounter Service
- "C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe"
- Load on Demand
-

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ @%systemroot%\system32\tokenbroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\tokenbroker.dll,-101

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\ualsvc.dll,-102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%systemroot%\system32\ualsvc.dll,-101

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usocore.dll,-101
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usocore.dll,-102

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ VMware Alias Manager and Ticket Service
- "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"
- Auto Load
- Alias Manager and Ticket Service

+ @oem7.inf,%VM3DSERVICE_DISPLAYNAME%;VMware SVGA Helper Service
- %SystemRoot%\system32\vm3dservice.exe
- Auto Load
- @oem7.inf,%VM3DSERVICE_DESCRIPTION%;Helps VMware SVGA driver by collecting and conveying user mode information

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ VMware Tools
- "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"
- Auto Load
- Provides support for synchronizing objects between the host and guest operating systems.

+ VMware Snapshot Provider
- C:\Windows\system32\dllhost.exe /Processid:{901C72D2-92C9-4A2F-885B-44DA86E6E0A9}
- Load on Demand
- VMware Snapshot Provider

+ Visual Studio Installer Elevation Service
- "C:\Program Files (x86)\Microsoft Visual Studio\Installer\VSInstallerElevationService.exe"
- Load on Demand
- This service is responsible for elevating the Visual Studio Installer.

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ Visual Studio Standard Collector Service 150
- "C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe"
- Load on Demand
- Visual Studio Data Collection Service. When running, this service collects real-time ETW events and processes them.

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\w32time.dll,-201

+ @%windir%\system32\inetsrv\iisres.dll,-30014
- %windir%\system32\svchost.exe -k apphost
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30015

+ @%windir%\system32\inetsrv\iisres.dll,-30003
- %windir%\system32\svchost.exe -k iissvcs
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30004

+ @WaaSMedicSvc.dll,-100
- %systemroot%\system32\svchost.exe -k wusvcs -p
- Load on Demand
- @WaaSMedicSvc.dll,-101

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel -p
- disabled
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%SystemRoot%\System32\Windows.WARP.JITService.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\Windows.WARP.JITService.dll,-101

+ @%windir%\system32\inetsrv\iisres.dll,-30001
- %windir%\system32\svchost.exe -k iissvcs
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30002

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Load on Demand
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%Systemroot%\system32\wsmsvc.dll,-102

+ VNC Server Version 4
- "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service
- Auto Load
-

+ @%SystemRoot%\system32\flightsettings.dll,-103
- %systemroot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\flightsettings.dll,-104

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101
- "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe"
- Load on Demand
- @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102

+ @%windir%\system32\inetsrv\iisres.dll,-20001
- %windir%\system32\inetsrv\wmsvc.exe
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-20002

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- disabled
- @%systemroot%\system32\SearchIndexer.exe,-104

+ @%systemroot%\system32\wuaueng.dll,-105
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\wuaueng.dll,-106
70629 - Microsoft Windows AutoRuns Winlogon
-
Synopsis
Report programs that startup associates with the winlogon process.
Description
Report the startup locations associated with the winlogon process.

These values could add features to the logon process, assist in authentication, or set screen savers.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers
+ CLSID : {1b283861-754f-4022-ad47-a5eaaa618894}
- Name : Smartcard Reader Selection Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {1ee7337f-85ac-45e2-a23c-37c753209769}
- Name : Smartcard WinRT Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {2135f72a-90b5-4ed3-a7f1-8bb705ac276a}
- Name : PicturePasswordLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {25CBB996-92ED-457e-B28C-4774084BD562}
- Name : GenericProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {27FBDB57-B613-4AF2-9D7E-4FA7A66C21AD}
- Name : TrustedSignal Credential Provider
- Value : %systemroot%\system32\TrustedSignalCredProv.dll

+ CLSID : {3dd6bec0-8193-4ffe-ae25-e08e39ea4063}
- Name : NPProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {48B4E58D-2791-456C-9091-D524C6C706F2}
- Name : Secondary Authentication Factor Credential Provider
- Value : C:\Windows\System32\devicengccredprov.dll

+ CLSID : {600e7adb-da3e-41a4-9225-3c0399e88c0c}
- Name : CngCredUICredentialProvider
- Value : %systemroot%\system32\cngcredui.dll

+ CLSID : {60b78e88-ead8-445c-9cfd-0b87f74ea6cd}
- Name : PasswordProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {8FD7E19C-3BF7-489B-A72C-846AB3678C96}
- Name : Smartcard Credential Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {94596c7e-3744-41ce-893e-bbf09122f76a}
- Name : Smartcard Pin Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {BEC09223-B018-416D-A0AC-523971B639F5}
- Name : WinBio Credential Provider
- Value : %SystemRoot%\System32\BioCredProv.dll

+ CLSID : {C5D7540A-CD51-453B-B22B-05305BA03F07}
- Name : Cloud Experience Credential Provider
- Value : C:\Windows\System32\cxcredprov.dll

+ CLSID : {cb82ea12-9f71-446d-89e1-8d0924e1256e}
- Name : PINLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {D6886603-9D2F-4EB2-B667-1971041FA96B}
- Name : NGC Credential Provider
- Value : C:\Windows\System32\ngccredprov.dll

+ CLSID : {e74e57b0-6c6d-44d5-9cda-fb2df5ed7435}
- Name : CertCredProvider
- Value : %systemroot%\system32\certCredProvider.dll

+ CLSID : {F8A0B131-5F68-486c-8040-7E8FC3C85BB6}
- Name : WLIDCredentialProvider
- Value : %SystemRoot%\system32\wlidcredprov.dll

+ CLSID : {F8A1793B-7873-4046-B2A7-1F318747F427}
- Name : FIDO Credential Provider
- Value : %systemroot%\system32\fidocredprov.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters
+ CLSID : {DDC0EED2-ADBE-40b6-A217-EDE16A79A0DE}
- Name : GenericFilter
- Value : %SystemRoot%\system32\credprovs.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers
+ CLSID : {5537E283-B1E7-4EF8-9C6E-7AB0AFE5056D}
- Name : RasProvider
- Value : %SystemRoot%\system32\rasplap.dll




70630 - Microsoft Windows AutoRuns Winsock Provider
-
Synopsis
Report Winsock providers extensions.
Description
A Winsock provider is a type of Layered Service Provider (LSP) that can be used to control protocols by inserting itself into the TCP/IP stack. This can commonly be used to help filter web traffic, enable QoS type services, or anything to hook network traffic controls.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
- Name : AF_UNIX
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD L2CAP [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD RfComm [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : vSockets DGRAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll

- Name : vSockets STREAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll
- LibararyPath : %SystemRoot%\system32\wshbth.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64
- Name : AF_UNIX
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD L2CAP [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD RfComm [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : vSockets DGRAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll

- Name : vSockets STREAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll
- LibararyPath : %SystemRoot%\system32\wshbth.dll

92371 - Microsoft Windows DNS Cache
-
Synopsis
Nessus was able to collect and report DNS cache information from the remote host.
Description
Nessus was able to collect details of the DNS cache from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

33.100.17.172.in-addr.arpa
46.100.17.172.in-addr.arpa
aimstarapi.reedos.com
api.lkp.net.in
backoffice.lkp.net.in
backoffice.lkp.net.in
middlewareapi.lkp.net.in
trading.lkponline.com
trading.lkponline.com

DNS cache information attached.
92363 - Microsoft Windows Device Logs
-
Synopsis
Nessus was able to collect available device logs from the remote host.
Description
Nessus was able to collect available device logs from the remote Windows host and add them as attachments.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Device logs attached.
92364 - Microsoft Windows Environment Variables
-
Synopsis
Nessus was able to collect and report environment variables from the remote host.
Description
Nessus was able to collect system and active account environment variables on the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0757
Plugin Information
Published: 2016/07/19, Modified: 2022/06/24
Plugin Output

tcp/0

Global Environment Variables :
processor_level : 6
comspec : %SystemRoot%\system32\cmd.exe
msmpi_benchmarks : C:\Program Files\Microsoft MPI\Benchmarks\
username : SYSTEM
os : Windows_NT
number_of_processors : 24
temp : %SystemRoot%\TEMP
processor_revision : cf02
path : C:\Program Files\Common Files\Oracle\Java\javapath;C:\Program Files\Microsoft MPI\Bin\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\;C:\Program Files\Microsoft SQL Server\150\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\;C:\Program Files\Microsoft SQL Server\150\DTS\Binn\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\160\DTS\Binn\;C:\Program Files\Azure Data Studio\bin;C:\Program Files\dotnet\;C:\Program Files (x86)\nodejs\;C:\Program Files\BackupClient\CommandLineTool\;C:\Program Files (x86)\Common Files\Acronis\FileProtector\;C:\Program Files (x86)\Common Files\Acronis\FileProtector64\;C:\Program Files\BackupClient\PyShell\bin\;C:\Program Files (x86)\Common Files\Acronis\SnapAPI\;C:\Windows\System32;C:\Program Files\Microsoft SQL Server\130\Tools\Binn\
tmp : %SystemRoot%\TEMP
processor_identifier : Intel64 Family 6 Model 207 Stepping 2, GenuineIntel
driverdata : C:\Windows\System32\Drivers\DriverData
msmpi_bin : C:\Program Files\Microsoft MPI\Bin\
pathext : .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
processor_architecture : AMD64
psmodulepath : %ProgramFiles%\WindowsPowerShell\Modules;%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules;C:\Program Files (x86)\Microsoft SQL Server\150\Tools\PowerShell\Modules\
windir : %SystemRoot%

Active User Environment Variables
- S-1-5-21-1687551350-3880216100-4069998428-500
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;C:\Program Files\Azure Data Studio\bin;%USERPROFILE%\.dotnet\tools;C:\Users\Administrator\AppData\Local\GitHubDesktop\bin;C:\Users\Administrator\AppData\Roaming\npm;C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\bin
tmp : %USERPROFILE%\AppData\Local\Temp
- S-1-5-21-1687551350-3880216100-4069998428-1009
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;
tmp : %USERPROFILE%\AppData\Local\Temp
92365 - Microsoft Windows Hosts File
-
Synopsis
Nessus was able to collect the hosts file from the remote host.
Description
Nessus was able to collect the hosts file from the remote Windows host and report it as attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/01/27
Plugin Output

tcp/0

Windows hosts file attached.

MD5: 4c8f8717ddff02ae3ea130bd84fb95cc
SHA-1: c561f0b3f2fe73fc638748c27786be1b481df8cc
SHA-256: da5697a6fa15d359802873f0b4c68e7102173a582a8ba7ddd46c37f685c98a13
187318 - Microsoft Windows Installed
-
Synopsis
The remote host is running Microsoft Windows.
Description
The remote host is running Microsoft Windows.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/12/27, Modified: 2025/12/10
Plugin Output

tcp/0


OS Name : Microsoft Windows Server 2019 1809
Vendor : Microsoft
Product : Windows Server
Release : 2019 1809
Edition : Datacenter
Version : 10.0.17763.4737
Role : server
Kernel : Windows NT 10.0
Architecture : x64
CPE v2.2 : cpe:/o:microsoft:windows_server_2019:10.0.17763.4737:-:~~datacenter~~x64~
CPE v2.3 : cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.4737:-:*:*:datacenter:*:x64:*
Type : local
Method : SMB
Confidence : 100

20811 - Microsoft Windows Installed Software Enumeration (credentialed check)
-
Synopsis
It is possible to enumerate installed software.
Description
This plugin lists software potentially installed on the remote host by crawling the registry entries in :

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall HKLM\SOFTWARE\Microsoft\Updates

Note that these entries do not necessarily mean the applications are actually installed on the remote host - they may have been left behind by uninstallers, or the associated files may have been manually removed.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0501
Plugin Information
Published: 2006/01/26, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following software are installed on the remote host :

Visual Studio Professional 2022 [version 17.8.3] [installed on 2023/12/26]
Visual Studio Professional 2017 [version 15.3.1] [installed on 2023/11/16]
Acronis Cyber Protect [version 15.0.36514]
Kaspersky Security Center Network Agent [version 14.2.0.26967]
Microsoft Azure Compute Emulator - v2.9.5.3 [version 2.9.8699.20] [installed on 11/16/2023]
Microsoft Azure Storage Emulator - v5.1 [version 5.1.1760.1722]
Microsoft Edge Update [version 1.3.215.9]
Microsoft Edge WebView2 Runtime [version 143.0.3650.139] [installed on 2026/01/09]
Microsoft Help Viewer 2.3 [version 2.3.28307]
Microsoft SQL Server 2019 (64-bit)
Microsoft Office Standard 2010 [version 14.0.6029.1000]
VNC Enterprise Edition E4.6.1 [version E4.6.1] [installed on 2020/12/06]
WinRAR 5.90 (64-bit) [version 5.90.0]
Microsoft .NET Host - 7.0.10 (x86) [version 56.43.64668] [installed on 2023/08/17]
Microsoft .NET AppHost Pack - 8.0.7 (x64) [version 64.28.16731] [installed on 2024/08/06]
Microsoft SQL Server 2019 Setup (English) [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft .NET 7.0 Templates 7.0.400 (x64) [version 28.6.43700] [installed on 2023/08/11]
Microsoft .NET SDK 7.0.400 (x64) [version 7.4.23.36916]
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 [version 12.0.30501.0]
Microsoft .NET SDK 8.0.303 (x64) [version 8.3.324.31708]
Microsoft .NET Targeting Pack - 8.0.0 (x86) [version 64.0.4211] [installed on 2023/12/26]
IIS Express Application Compatibility Database for x64
Microsoft Azure Authoring Tools - v2.9.5.3 [version 2.9.8699.20] [installed on 2023/11/16]
SQL Server 2019 Data quality client [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft.NET.Workload.Mono.Toolchain.Current.Manifest (x64) [version 64.0.4211] [installed on 2023/12/26]
Visual Studio 2017 Isolated Shell for SSMS [version 15.0.28308.421] [installed on 2023/08/11]
Microsoft ASP.NET Core 6.0.25 Targeting Pack (x64) [version 6.0.25.23523] [installed on 2023/12/27]
Microsoft.NET.Workload.Emscripten.net6.Manifest (x64) [version 56.35.64642] [installed on 2023/08/11]
vs_minshellmsi [version 15.0.26711] [installed on 2023/11/16]
SQL Server 2019 Common Files [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft Windows Desktop Runtime - 8.0.0 (x64) [version 64.0.5329] [installed on 2023/12/26]
Microsoft.NET.Sdk.Maui.Manifest-8.0.100 (x64) [version 8.0.3] [installed on 2023/12/26]
Microsoft .NET Framework 4.7.2 Targeting Pack [version 4.7.03062] [installed on 2023/12/26]
vs_CoreEditorFonts [version 17.7.40001] [installed on 2023/12/26]
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack [version 4.5.51651] [installed on 2023/11/16]
Microsoft .NET Framework Cumulative Intellisense Pack for Visual Studio (ENU) [version 4.8.09037] [installed on 2023/12/26]
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.38.33130 [version 14.38.33130] [installed on 2023/12/26]
Microsoft .NET AppHost Pack - 6.0.25 (x64_arm64) [version 48.100.4028] [installed on 2023/12/27]
Microsoft .NET Core 1.0.6 - Host FX Resolver (x64) [version 4.1.21306] [installed on 2023/11/16]
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.38.33130 [version 14.38.33130.0]
SQL Server 2019 XEvent [version 15.0.2000.5] [installed on 2023/08/11]
ClickOnce Bootstrapper Package for Microsoft .NET Framework [version 4.8.09037] [installed on 2023/12/26]
Microsoft .NET AppHost Pack - 6.0.25 (x64) [version 48.100.4028] [installed on 2023/12/27]
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm (x64) [version 7.0.14.0] [installed on 2023/12/26]
VMware Tools [version 12.3.5.22544099] [installed on 2025/03/08]
SQL Server 2019 SQL Diagnostics [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft.NET.Workload.Mono.Toolchain.net6.Manifest (x64) [version 64.28.16731] [installed on 2024/08/06]
Microsoft .NET 6.0 Templates 8.0.100 (x64) [version 24.6.61899] [installed on 2023/12/27]
Microsoft VSS Writer for SQL Server 2019 [version 15.0.2000.5] [installed on 2023/08/11]
Node.js [version 18.16.1] [installed on 2023/08/31]
Microsoft .NET Framework 4.6 Targeting Pack [version 4.6.00081] [installed on 2023/11/16]
Microsoft.NET.Workload.Emscripten.net6.Manifest (x64) [version 64.0.4194] [installed on 2023/12/26]
Microsoft .NET Framework 4.6.1 SDK [version 4.6.01055] [installed on 2023/11/16]
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.38.33130 [version 14.38.33130.0]
icecap_collectionresourcesx64 [version 15.0.26621] [installed on 2023/11/16]
Microsoft SQL Server 2019 T-SQL Language Service [version 15.0.2000.5] [installed on 2023/08/11]
SQL Server Management Studio [version 19.1.56.0] [installed on 2023/08/11]
Microsoft .NET AppHost Pack - 8.0.0 (x64_arm64) [version 64.0.4211] [installed on 2023/12/26]
Microsoft.NET.Runtime.MonoAOTCompiler.Task (x64) [version 6.0.25.0] [installed on 2023/12/26]
Microsoft .NET Runtime - 6.0.25 (x64) [version 48.100.4028] [installed on 2023/12/27]
SQL Server 2019 Integration Services [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft SQL Server 2019 LocalDB [version 15.0.4153.1] [installed on 2023/12/26]
Microsoft .NET AppHost Pack - 8.0.0 (x64) [version 64.0.4211] [installed on 2023/12/26]
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm (x64) [version 6.0.25.0] [installed on 2023/12/26]
Microsoft .NET Core 1.1.3 - Host (x64) [version 4.16.1560] [installed on 2023/11/16]
vs_minshellmsires [version 17.8.34205] [installed on 2023/12/26]
Microsoft .NET Host FX Resolver - 8.0.0 (x64) [version 64.0.4211] [installed on 2023/12/26]
vs_communitymsires [version 17.8.34205] [installed on 2023/12/26]
Microsoft Windows Desktop Targeting Pack - 6.0.25 (x86) [version 48.100.4037] [installed on 2023/12/27]
SQL Server Management Studio Language Pack - English [version 19.1.56.0] [installed on 2023/08/11]
Microsoft Windows Desktop Targeting Pack - 8.0.0 (x64) [version 64.0.5329] [installed on 2023/12/26]
vs_devenx64vmsi [version 17.8.34129] [installed on 2023/12/26]
Microsoft .NET Host FX Resolver - 8.0.7 (x64) [version 64.28.16731] [installed on 2024/08/06]
Entity Framework 6.2.0 Tools for Visual Studio 2022 [version 6.2.0.0] [installed on 2023/12/26]
Microsoft .NET 7.0.10 - Windows Server Hosting [version 7.0.10.23364]
Microsoft .NET AppHost Pack - 7.0.10 (x64_x86) [version 56.43.64668] [installed on 2023/08/11]
Microsoft Command Line Utilities 15 for SQL Server [version 15.0.1300.359] [installed on 2023/12/26]
Microsoft Windows Communication Foundation Diagnostic Pack for x86 [version 15.0.26621] [installed on 2023/11/16]
vs_tipsmsi [version 17.8.34129] [installed on 2023/12/26]
SQL Server 2019 Analysis Services [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft .NET Host - 7.0.10 (x64) [version 56.43.64668] [installed on 2023/08/11]
vs_clickoncebootstrappermsi [version 17.8.34205] [installed on 2023/12/26]
Microsoft ASP.NET Core 7.0.10 Targeting Pack (x64) [version 7.0.10.23364] [installed on 2023/08/11]
vs_githubprotocolhandlermsi [version 17.8.34129] [installed on 2023/12/26]
vcpp_crt.redist.clickonce [version 14.38.33130] [installed on 2023/12/26]
Microsoft.NET.Workload.Mono.Toolchain.net7.Manifest (x64) [version 56.3.64668] [installed on 2023/08/11]
Microsoft Windows Desktop Runtime - 8.0.0 (x86) [version 64.0.5329] [installed on 2023/12/26]
vs_communitymsi [version 15.0.26711] [installed on 2023/11/16]
Active Directory Authentication Library for SQL Server [version 13.1.4001.0] [installed on 2023/11/16]
Microsoft.NET.Sdk.iOS.Manifest-7.0.100 (x64) [version 16.0.0] [installed on 2023/08/11]
Microsoft.NET.Sdk.tvOS.Manifest-8.0.100 (x64) [version 17.0.8478] [installed on 2023/12/26]
Microsoft .NET Framework 4.5 Multi-Targeting Pack [version 4.5.50710] [installed on 2023/11/16]
Microsoft.NET.Sdk.macOS.Manifest-7.0.100 (x64) [version 12.3.0] [installed on 2023/08/11]
Microsoft SQL Server 2019 RsFx Driver [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft System CLR Types for SQL Server 2019 [version 15.0.2000.5] [installed on 2023/12/26]
Microsoft.NET.Runtime.Emscripten.Cache (x64) [version 7.0.14.0] [installed on 2023/12/26]
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33130 [version 14.38.33130] [installed on 2023/12/26]
Microsoft .NET AppHost Pack - 7.0.10 (x64_arm) [version 56.43.64668] [installed on 2023/08/11]
Browser for SQL Server 2019 [version 15.0.2000.5] [installed on 2023/08/11]
vs_minshellinteropx64msi [version 17.8.34129] [installed on 2023/12/26]
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [version 9.0.30729.6161] [installed on 2021/12/07]
Microsoft .NET SDK 8.0.100 (x64) from Visual Studio [version 8.1.23.55115] [installed on 2023/12/26]
SQL Server 2019 Database Engine Shared [version 15.0.2000.5] [installed on 2023/08/11]
SQL Server 2019 Shared Management Objects [version 15.0.2000.5] [installed on 2023/08/11]
icecap_collectionresources [version 17.8.34205] [installed on 2023/12/26]
Azure Data Studio [version 1.44.0] [installed on 2023/08/11]
icecap_collectionresources [version 15.0.26621] [installed on 2023/11/16]
.NET Core SDK 1.1.0 (x64) [version 1.1.0]
SQL Server 2019 Client Tools [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack [version 4.5.50932] [installed on 2023/11/16]
Google Chrome [version 143.0.7499.193] [installed on 2023/08/31]
icecap_collection_x64 [version 15.0.26621] [installed on 2023/11/16]
Microsoft.NET.Sdk.iOS.Manifest-8.0.100 (x64) [version 17.0.8478] [installed on 2023/12/26]
Microsoft.NET.Workload.Emscripten.net7.Manifest (x64) [version 64.0.4194] [installed on 2023/12/26]
icecap_collectionresourcesx64 [version 17.8.34205] [installed on 2023/12/26]
Microsoft .NET Runtime - 6.0.25 (x86) [version 48.100.4028] [installed on 2023/12/27]
Microsoft.NET.Sdk.tvOS.Manifest-7.0.100 (x64) [version 16.0.0] [installed on 2023/08/11]
Microsoft.NET.Workload.Emscripten.Current.Manifest (x64) [version 64.0.4194] [installed on 2023/12/26]
Microsoft ASP.NET Core 8.0.7 Targeting Pack (x64) [version 8.0.7.24314] [installed on 2024/08/06]
Microsoft Visual Studio Installer [version 3.8.2112.61926] [installed on 2023/11/16]
Microsoft .NET Toolset 8.0.100 (x64) [version 32.6.61899] [installed on 2023/12/26]
Microsoft Windows Desktop Targeting Pack - 7.0.10 (x64) [version 56.43.64722] [installed on 2023/08/11]
vs_clickoncesigntoolmsi [version 17.8.34129] [installed on 2023/12/26]
Microsoft NetStandard SDK [version 15.0.51105] [installed on 2023/11/16]
Microsoft ASP.NET Core 7.0.10 - Shared Framework (x86) [version 7.0.10.23364]
Microsoft .NET Core 1.0.5 - Runtime (x64) [version 1.0.5] [installed on 2023/11/16]
icecap_collection_neutral [version 15.0.26621] [installed on 2023/11/16]
Microsoft .NET Runtime - 8.0.0 (x64) [version 64.0.4211] [installed on 2023/12/26]
Microsoft ASP.NET Core 1.1 Local Feed - Visual Studio 2017 [version 15.0.11725.0] [installed on 2023/11/16]
Microsoft ASP.NET Core 8.0.0 Targeting Pack (x86) [version 8.0.0.23531] [installed on 2023/12/26]
Microsoft ASP.NET Core 1.0 Local Feed - Visual Studio 2017 [version 15.0.11725.0] [installed on 2023/11/16]
Microsoft.NET.Workload.Emscripten.net6.Manifest (x64) [version 64.28.16721] [installed on 2024/08/06]
Microsoft.NET.Sdk.MacCatalyst.Manifest-7.0.100 (x64) [version 15.4.0] [installed on 2023/08/11]
Microsoft .NET AppHost Pack - 7.0.10 (x64) [version 56.43.64668] [installed on 2023/08/11]
Microsoft ASP.NET Core 7.0.10 Shared Framework (x86) [version 7.0.10.23364] [installed on 2023/08/17]
Microsoft Analysis Services OLE DB Provider [version 16.0.5143.0] [installed on 2023/08/11]
Microsoft.NET.Workload.Emscripten.net7.Manifest (x64) [version 64.28.16721] [installed on 2024/08/06]
Microsoft ASP.NET Diagnostic Pack for Visual Studio [version 17.8.358.6298] [installed on 2023/12/26]
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 [version 12.0.40664] [installed on 2023/08/11]
Microsoft Portable Library Multi-Targeting Pack [version 15.0.26621.02] [installed on 2023/11/16]
SQL Server 2019 DMF [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft.NET.Workload.Mono.Toolchain.Current.Manifest (x64) [version 64.28.16731] [installed on 2024/08/06]
Microsoft TestPlatform SDK Local Feed [version 17.0.0.5175695] [installed on 2023/12/26]
Microsoft .NET Framework 4.7 Targeting Pack (ENU) [version 4.7.02046] [installed on 2023/11/16]
Kaspersky Endpoint Security for Windows [version 11.15.8.493]
Kaspersky Endpoint Security for Windows [version 12.3.0.493] [installed on 2023/12/13]
Microsoft MPI (10.0.12498.5) [version 10.0.12498.5] [installed on 2023/08/11]
Microsoft.NETCore.App.Runtime.Mono.browser-wasm (x64) [version 6.0.25.0] [installed on 2023/12/26]
Microsoft .NET 8.0 Templates 8.0.100 (x64) [version 32.6.61899] [installed on 2023/12/26]
Microsoft Windows Desktop Runtime - 7.0.10 (x64) [version 56.43.64722] [installed on 2023/08/11]
Microsoft.NET.Workload.Mono.Toolchain.net6.Manifest (x64) [version 56.3.64668] [installed on 2023/08/11]
vs_FileTracker_Singleton [version 17.8.34205] [installed on 2023/12/26]
Microsoft .NET Host FX Resolver - 7.0.10 (x64) [version 56.43.64668] [installed on 2023/08/11]
Microsoft .NET Runtime - 7.0.10 (x64) [version 56.43.64668] [installed on 2023/08/11]
vs_clickoncebootstrappermsires [version 17.8.34129] [installed on 2023/12/26]
Microsoft.NET.Sdk.Maui.Manifest-7.0.100 (x64) [version 7.0.49] [installed on 2023/08/11]
Microsoft.NET.Sdk.MacCatalyst.Manifest-8.0.100 (x64) [version 17.0.8478] [installed on 2023/12/26]
Microsoft .NET Framework 4.6.1 Targeting Pack [version 4.6.01055] [installed on 2023/11/16]
Microsoft .NET Targeting Pack - 6.0.25 (x64) [version 48.100.4028] [installed on 2023/12/27]
SQL Server 2019 Shared Management Objects Extensions [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft Visual Studio Tools for Applications 2019 x64 Hosting Support [version 16.0.31110] [installed on 2023/08/11]
Microsoft.NET.Runtime.Emscripten.Node (x64) [version 7.0.14.0] [installed on 2023/12/26]
Microsoft ASP.NET Core 8.0.0 Shared Framework (x64) [version 8.0.0.23531] [installed on 2023/12/26]
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Excel MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office PowerPoint MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Publisher MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Outlook MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Word MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Proof (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Proof (French) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Proof (Spanish) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Office 64-bit Components 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Shared 64-bit MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Proofing (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Shared MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office OneNote MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Shared Setup Metadata MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/02/20]
Microsoft SQL Server 2016 LocalDB [version 13.1.4001.0] [installed on 2023/11/16]
Microsoft .NET AppHost Pack - 8.0.7 (x64_x86) [version 64.28.16731] [installed on 2024/08/06]
Microsoft SQL Server 2012 Command Line Utilities [version 11.3.6020.0] [installed on 2023/11/16]
Microsoft Windows Desktop Targeting Pack - 8.0.0 (x86) [version 64.0.5329] [installed on 2023/12/26]
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 [version 12.0.21005] [installed on 2023/11/16]
SSMS Post Install Tasks [version 19.1.56.0] [installed on 2023/08/11]
Microsoft .NET Framework 4.8 SDK [version 4.8.03928] [installed on 2023/12/26]
Microsoft .NET Targeting Pack - 8.0.0 (x64) [version 64.0.4211] [installed on 2023/12/26]
Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support [version 15.0.27520] [installed on 2023/08/11]
vs_communitysharedmsi [version 17.8.34205] [installed on 2023/12/26]
Microsoft SQL Server Management Studio - 19.1 [version 19.1.56.0]
Microsoft.NET.Sdk.macOS.Manifest-8.0.100 (x64) [version 14.0.8478] [installed on 2023/12/26]
Microsoft ASP.NET Core 8.0.0 Shared Framework (x86) [version 8.0.0.23531] [installed on 2023/12/26]
SQL Server 2019 Connection Info [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft System CLR Types for SQL Server 2017 CTP2.1 [version 14.0.600.250] [installed on 2023/11/16]
IIS URL Rewrite Module 2 [version 7.2.1993] [installed on 2023/09/01]
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [version 9.0.30729.6161] [installed on 2021/12/07]
Microsoft.NET.Workload.Mono.Toolchain.net6.Manifest (x64) [version 64.0.4211] [installed on 2023/12/26]
Microsoft ASP.NET Core 8.0.0 Targeting Pack (x64) [version 8.0.0.23531] [installed on 2023/12/26]
SQL Server 2019 Data quality service [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft .NET Targeting Pack - 7.0.10 (x64) [version 56.43.64668] [installed on 2023/08/11]
Microsoft SQL Server 2012 Native Client [version 11.4.7462.6] [installed on 2023/08/11]
vs_communityx64msi [version 17.8.34205] [installed on 2023/12/26]
icecap_collection_neutral [version 17.8.34205] [installed on 2023/12/26]
Microsoft Visual Studio Setup WMI Provider [version 3.8.2091.34612] [installed on 2023/12/26]
Microsoft .NET Host FX Resolver - 7.0.10 (x86) [version 56.43.64668] [installed on 2023/08/17]
Microsoft.NETCore.App.Runtime.Mono.browser-wasm (x64) [version 7.0.14.0] [installed on 2023/12/26]
Microsoft.NET.Workload.Mono.Toolchain.net7.Manifest (x64) [version 64.28.16731] [installed on 2024/08/06]
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 [version 12.0.40664.0]
Microsoft Windows Desktop Targeting Pack - 6.0.25 (x64) [version 48.100.4037] [installed on 2023/12/27]
Microsoft.NET.Runtime.MonoTargets.Sdk (x64) [version 7.0.14.0] [installed on 2023/12/26]
Microsoft Visual Studio Team Foundation Server 2017 Office Integration (x64) [version 15.117.26816] [installed on 2023/11/16]
Microsoft.NET.Runtime.Emscripten.Python (x64) [version 6.0.25.0] [installed on 2023/12/26]
Microsoft .NET Framework 4.8 Targeting Pack (ENU) [version 4.8.03761] [installed on 2023/12/26]
SQL Server 2019 Database Engine Services [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft .NET Standard Targeting Pack - 2.1.0 (x64) [version 24.0.28113] [installed on 2023/08/11]
vs_filehandler_x86 [version 17.8.34205] [installed on 2023/12/26]
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 [version 12.0.21005] [installed on 2023/11/16]
Microsoft Windows Desktop Runtime - 6.0.25 (x86) [version 48.100.4037] [installed on 2023/12/27]
vs_vswebprotocolselectormsi [version 17.8.34129] [installed on 2023/12/26]
Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support [version 15.0.27520] [installed on 2023/08/11]
Microsoft .NET AppHost Pack - 7.0.10 (x64_arm64) [version 56.43.64668] [installed on 2023/08/11]
Microsoft .NET Targeting Pack - 6.0.25 (x86) [version 48.100.4028] [installed on 2023/12/27]
Microsoft Visual Studio Team Foundation Server 2017 Office Integration Language Pack (x64) - ENU [version 15.117.26816] [installed on 2023/11/16]
Microsoft.NET.Runtime.MonoTargets.Sdk (x64) [version 6.0.25.0] [installed on 2023/12/26]
Microsoft.NET.Runtime.Emscripten.Python (x64) [version 7.0.14.0] [installed on 2023/12/26]
Microsoft .NET Host - 8.0.0 (x86) [version 64.0.4211] [installed on 2023/12/26]
Microsoft .NET Framework 4.7.2 Targeting Pack (ENU) [version 4.7.03062] [installed on 2023/12/26]
Microsoft.NET.Sdk.Android.Manifest-8.0.100 (x64) [version 34.0.43] [installed on 2023/12/26]
Microsoft ASP.NET Core 8.0.7 Shared Framework (x64) [version 8.0.7.24314] [installed on 2024/08/06]
Integration Services [version 16.0.5107.6] [installed on 2023/08/11]
Microsoft .NET AppHost Pack - 8.0.7 (x64_arm64) [version 64.28.16731] [installed on 2024/08/06]
Microsoft Portable Library Multi-Targeting Pack Language Pack - enu [version 15.0.26621.02] [installed on 2023/11/16]
Microsoft .NET Runtime - 8.0.0 (x86) [version 64.0.4211] [installed on 2023/12/26]
Microsoft .NET Framework 4.8 Targeting Pack [version 4.8.03761] [installed on 2023/12/26]
Microsoft ASP.NET Core 7.0.10 Hosting Bundle Options [version 7.0.10.23364] [installed on 2023/08/17]
Microsoft .NET AppHost Pack - 6.0.25 (x64_arm) [version 48.100.4028] [installed on 2023/12/27]
SQL Server 2019 Advanced Analytics [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft ASP.NET Web Tools Packages 17.0 - ENU [version 17.0.30714.0] [installed on 2023/12/26]
NXLog-CE [version 3.2.2329] [installed on 2024/12/12]
Microsoft ASP.NET Core Module V2 [version 17.0.23196.0] [installed on 2023/08/17]
Microsoft.NET.Runtime.Emscripten.Sdk (x64) [version 7.0.14.0] [installed on 2023/12/26]
Microsoft .NET Core 1.1.2 - Runtime (x64) [version 1.1.2] [installed on 2023/11/16]
SQL Server 2019 Full text search [version 15.0.2000.5] [installed on 2023/08/11]
vs_devenvmsi [version 15.0.26621] [installed on 2023/11/16]
vs_professionalmsi [version 15.0.26621] [installed on 2023/11/16]
VS JIT Debugger [version 17.0.125.0] [installed on 2023/12/26]
Microsoft.NET.Workload.Mono.Toolchain.net7.Manifest (x64) [version 64.0.4211] [installed on 2023/12/26]
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.38.33130 [version 14.38.33130] [installed on 2023/12/26]
Cyber Protect [version 15.0.36514] [installed on 2023/10/13]
Microsoft Azure Libraries for .NET – v2.9 [version 3.0.0127.060] [installed on 2023/11/16]
Microsoft Visual Studio Setup Configuration [version 3.8.2091.34612] [installed on 2023/12/26]
Microsoft .NET Toolset 8.0.303 (x64) [version 32.8.56572] [installed on 2024/08/06]
Microsoft .NET Core 1.1.3 - Host FX Resolver (x64) [version 4.16.34328] [installed on 2023/11/16]
IntelliTraceProfilerProxy [version 15.0.21225.01] [installed on 2023/12/26]
vs_minshellx64msi [version 17.8.34205] [installed on 2023/12/26]
Microsoft .NET Runtime - 8.0.7 (x64) [version 64.28.16731] [installed on 2024/08/06]
Microsoft Web Deploy 4.0 [version 10.0.7421] [installed on 2023/12/26]
Microsoft.NET.Runtime.Emscripten.Sdk (x64) [version 6.0.25.0] [installed on 2023/12/26]
Microsoft ODBC Driver 17 for SQL Server [version 17.10.3.1] [installed on 2023/08/11]
vs_devenvsharedmsi [version 17.8.34129] [installed on 2023/12/26]
Microsoft OLE DB Driver for SQL Server [version 18.6.5.0] [installed on 2023/08/11]
Microsoft .NET Framework 4.7 Targeting Pack [version 4.7.02046] [installed on 2023/11/16]
Microsoft.NET.Runtime.WebAssembly.Sdk (x64) [version 6.0.25.0] [installed on 2023/12/26]
TypeScript SDK [version 2.3.5.0] [installed on 2023/11/16]
Microsoft ASP.NET Core 7.0.10 Shared Framework (x64) [version 7.0.10.23364] [installed on 2023/08/11]
icecap_collection_x64 [version 17.8.34205] [installed on 2023/12/26]
Microsoft .NET Framework 4 Multi-Targeting Pack [version 4.0.30319] [installed on 2023/11/16]
Update for (KB2504637) [version 1]
vs_minshellinteropmsi [version 15.0.26621] [installed on 2023/11/16]
Microsoft Windows Desktop Targeting Pack - 8.0.7 (x64) [version 64.28.16739] [installed on 2024/08/06]
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 [version 12.0.40664] [installed on 2023/08/11]
SQL Server 2019 Batch Parser [version 15.0.2000.5] [installed on 2023/08/11]
VS Script Debugging Common [version 17.0.125.0] [installed on 2023/12/26]
Microsoft .NET Targeting Pack - 8.0.7 (x64) [version 64.28.16731] [installed on 2024/08/06]
Microsoft ASP.NET Core 6.0.25 Shared Framework (x86) [version 6.0.25.23523] [installed on 2023/12/27]
IIS 10.0 Express [version 10.0.08412] [installed on 2023/12/26]
Microsoft .NET AppHost Pack - 8.0.0 (x64_x86) [version 64.0.4211] [installed on 2023/12/26]
Microsoft .NET 8.0 Templates 8.0.303 (x64) [version 32.9.56572] [installed on 2024/08/06]
Java(TM) SE Development Kit 17.0.12 (64-bit) [version 17.0.12.0] [installed on 2024/12/26]
Microsoft .NET Runtime - 7.0.10 (x86) [version 56.43.64668] [installed on 2023/08/17]
Microsoft .NET Host FX Resolver - 8.0.0 (x86) [version 64.0.4211] [installed on 2023/12/26]
SQL Server 2019 SQL Data Quality Common [version 15.0.2000.5] [installed on 2023/08/11]
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33130 [version 14.38.33130] [installed on 2023/12/26]
SQL Server 2019 Client Tools Extensions [version 15.0.2000.5] [installed on 2023/08/11]
.NET Core SDK 1.1.0 (x64) [version 4.16.5124] [installed on 2023/11/16]
Microsoft Windows Desktop Runtime - 6.0.25 (x64) [version 48.100.4037] [installed on 2023/12/27]
Microsoft ASP.NET Web Tools Packages 15.0 - ENU [version 1.0.20531.0] [installed on 2023/11/16]
Microsoft.NET.Runtime.Emscripten.Node (x64) [version 6.0.25.0] [installed on 2023/12/26]
vs_minshellsharedmsi [version 17.8.34205] [installed on 2023/12/26]
Microsoft .NET Host - 8.0.7 (x64) [version 64.28.16731] [installed on 2024/08/06]
Microsoft.NET.Runtime.MonoAOTCompiler.Task (x64) [version 7.0.14.0] [installed on 2023/12/26]
vs_minshellinteropsharedmsi [version 17.8.34205] [installed on 2023/12/26]
Microsoft.NET.Workload.Emscripten.net7.Manifest (x64) [version 56.35.64642] [installed on 2023/08/11]
Microsoft.NET.Workload.Emscripten.Current.Manifest (x64) [version 64.28.16721] [installed on 2024/08/06]
Microsoft .NET Toolset 7.0.400 (x64) [version 28.6.43700] [installed on 2023/08/11]
Microsoft Visual Studio Tools for Applications 2019 x86 Hosting Support [version 16.0.31110] [installed on 2023/08/11]
Microsoft ASP.NET Core 6.0.25 Targeting Pack (x86) [version 6.0.25.23523] [installed on 2023/12/27]
vs_SQLClickOnceBootstrappermsi [version 17.8.34129] [installed on 2023/12/26]
Microsoft ASP.NET Core 6.0.25 Shared Framework (x64) [version 6.0.25.23523] [installed on 2023/12/27]
Microsoft.NET.Runtime.WebAssembly.Sdk (x64) [version 7.0.14.0] [installed on 2023/12/26]
VS WCF Debugging [version 16.0.71.0] [installed on 2023/11/16]
Microsoft ASP.NET Core Module V2 for IIS Express [version 17.0.22116.0] [installed on 2023/12/26]
vs_filehandler_amd64 [version 17.8.34205] [installed on 2023/12/26]
Microsoft.NET.Sdk.Aspire.Manifest-8.0.100 (x64) [version 64.0.5426] [installed on 2024/08/06]
Microsoft .NET Framework 4.7 SDK [version 4.7.02046] [installed on 2023/11/16]
vs_BlendMsi [version 17.8.34129] [installed on 2023/12/26]
Microsoft Windows Desktop Runtime - 8.0.7 (x64) [version 64.28.16739] [installed on 2024/08/06]
Entity Framework 6.1.3 Tools for Visual Studio 15 [version 6.1.60104.0] [installed on 2023/11/16]
Microsoft .NET AppHost Pack - 6.0.25 (x64_x86) [version 48.100.4028] [installed on 2023/12/27]
Microsoft ASP.NET Core Module for IIS Express [version 12.2.18292.0] [installed on 2023/12/26]
Microsoft .NET Core 1.0.6 - Host (x64) [version 4.0.21306] [installed on 2023/11/16]
Microsoft.NET.Sdk.Android.Manifest-7.0.100 (x64) [version 33.0.4] [installed on 2023/08/11]
DiagnosticsHub_CollectionService [version 17.3.32601] [installed on 2023/12/26]
VS Immersive Activate Helper [version 17.0.125.0] [installed on 2023/12/26]
IIS Express Application Compatibility Database for x86
Microsoft .NET Runtime - 7.0.10 (x86) [version 7.0.10.32713]
Microsoft Visual Studio Tools for Applications 2019 [version 16.0.31110]
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 [version 12.0.30501.0]
Microsoft Visual Studio Tools for Applications 2017 [version 15.0.27520]

The following updates are installed :

.NET :
Microsoft .NET 7.0.10 - Windows Server Hosting (x86) [version 7.0.10.23364] [installed on 8/17/2023]
Microsoft ASP.NET Core 7.0.10 - Shared Framework (x86) [version 7.0.10.23364] [installed on 8/17/2023]
Microsoft .NET Framework 4 Multi-Targeting Pack :
KB2504637 [version 1] [installed on 11/16/2023]
178102 - Microsoft Windows Installed Software Version Enumeration
-
Synopsis
Enumerates installed software versions.
Description
This plugin enumerates the installed software version by interrogating information obtained from various registry entries and files on disk. This plugin provides a best guess at the software version and a confidence level for that version.

Note that the versions detected here do not necessarily indicate the actual installed version nor do they necessarily mean that the application is actually installed on the remote host. In some cases there may be artifacts left behind by uninstallers on the system.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2023/07/10, Modified: 2024/07/15
Plugin Output

tcp/445/cifs

report output too big - ending list here

92366 - Microsoft Windows Last Boot Time
-
Synopsis
Nessus was able to collect the remote host's last boot time in a human readable format.
Description
Nessus was able to collect and report the remote host's last boot time as an ISO 8601 timestamp.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/07/09
Plugin Output

tcp/0

Last reboot : 2026-01-01T09:19:33+05:30 (20260101091933.500000+330)

161502 - Microsoft Windows Logged On Users
-
Synopsis
Nessus was able to determine the logged on users from the registry
Description
Using the HKU registry, Nessus was able to enumerate the SIDs of logged on users
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/05/25, Modified: 2025/10/01
Plugin Output

tcp/445/cifs

Logged on users :
- S-1-5-21-1687551350-3880216100-4069998428-1009
Domain : MIDDLEWAREAPI
Username : tidua
- S-1-5-21-1687551350-3880216100-4069998428-500
Domain : MIDDLEWAREAPI
Username : production
63080 - Microsoft Windows Mounted Devices
-
Synopsis
It is possible to get a list of mounted devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates mounted devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that the mounted drives agree with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/11/28, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Name : \dosdevices\e:
Data : DMIO:ID:D<^Homep
Raw data : 444d494f3a49443a443c0b5e84dfc248b6a56f6d6570d1c0

Name : \??\volume{73d8349d-37ef-11eb-9a05-806e6f6e6963}
Data : \??\FDC#GENERIC_FLOPPY_DRIVE#6&1b0d1d81&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c004600440043002300470045004e0045005200490043005f0046004c004f005000500059005f004400520049005600450023003600260031006200300064003100640038003100260030002600300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{73d8349c-37ef-11eb-9a05-806e6f6e6963}
Data : \??\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#5&2a3267f0&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c0049004400450023004300640052006f006d004e004500430056004d005700610072005f0056004d0077006100720065005f004900440045005f00430044005200310030005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f0031002e00300030005f005f005f005f002300350026003200610033003200360037006600300026003000260031002e0030002e00300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\d:
Data : DMIO:ID:aK)}J
Raw data : 444d494f3a49443ac3a1aec0ba61034ba5e629a1157d4a0f

Name : \dosdevices\c:
Data : +nK`"
Raw data : 2b6e4bfa0000602200000000

Name : \??\volume{897903c6-37fa-11ee-9a15-005056bc7d2b}
Data : \??\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004d007300660074002600500072006f0064005f005600690072007400750061006c005f004400560044002d0052004f004d002300320026003100660034006100640066006600650026003000260030003000300030003000310023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\a:
Data : \??\FDC#GENERIC_FLOPPY_DRIVE#6&1b0d1d81&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c004600440043002300470045004e0045005200490043005f0046004c004f005000500059005f004400520049005600450023003600260031006200300064003100640038003100260030002600300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

92372 - Microsoft Windows NetBIOS over TCP/IP Info
-
Synopsis
Nessus was able to collect and report NBT information from the remote host.
Description
Nessus was able to collect details for NetBIOS over TCP/IP from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

NBT information attached.
First 10 lines of all CSVs:
nbtstat_local.csv:
Interface,Name,Suffix,Type,Status,MAC
172.17.100.112,MIDDLEWAREAPI,<20>,UNIQUE,Registered,00:50:56:BC:7D:2B
172.17.100.112,MIDDLEWAREAPI,<00>,UNIQUE,Registered,00:50:56:BC:7D:2B
172.17.100.112,WORKGROUP,<00>,GROUP,Registered,00:50:56:BC:7D:2B

103871 - Microsoft Windows Network Adapters
-
Synopsis
Identifies the network adapters installed on the remote host.
Description
Using the supplied credentials, this plugin enumerates and reports the installed network adapters on the remote Windows host.
Solution
Make sure that all of the installed network adapters agrees with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0758
Plugin Information
Published: 2017/10/17, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Network Adapter Driver Description : Intel(R) 82574L Gigabit Network Connection
Network Adapter Driver Version : 12.15.22.6
65791 - Microsoft Windows Portable Devices
-
Synopsis
It is possible to get a list of portable devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates portable devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that use of the portable devices agrees with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2013/04/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Friendly name : DATA
Device : SWD#WPDBUSENUM#{1B82F0F5-AB35-11EC-9A0E-806E6F6E6963}#0000000001000000

Friendly name : DATA
Device : SWD#WPDBUSENUM#{A8405163-5AFC-11EE-9A20-005056BC7D2B}#0000000001000000

92367 - Microsoft Windows PowerShell Execution Policy
-
Synopsis
Nessus was able to collect and report the PowerShell execution policy for the remote host.
Description
Nessus was able to collect and report the PowerShell execution policy for the remote Windows host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/06/12
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : RemoteSigned
HKLM\SOFTWARE\Wow6432Node\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : RemoteSigned

151440 - Microsoft Windows Print Spooler Service Enabled
-
Synopsis
The Microsoft Windows Print Spooler service on the remote host is enabled.
Description
The Microsoft Windows Print Spooler service (spoolsv.exe) on the remote host is enabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/07/07, Modified: 2021/07/07
Plugin Output

tcp/445/cifs

The Microsoft Windows Print Spooler service on the remote host is enabled.

70329 - Microsoft Windows Process Information
-
Synopsis
Use WMI to obtain running process information.
Description
Report details on the running processes on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to confirm that your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process Overview :
SID: Process (PID)
0 : System Idle Process (0)
0 : |- System (4)
0 : |- smss.exe (708)
2 : explorer.exe (13896)
2 : |- InetMgr.exe (14428)
2 : |- schedhlp.exe (14768)
2 : |- MmsMonitor.exe (14796)
2 : |- MmsMonitor.exe (15400)
2 : |- MmsMonitor.exe (15472)
2 : |- MmsMonitor.exe (15804)
2 : |- notepad.exe (18608)
2 : |- mmc.exe (20504)
2 : |- powershell.exe (6752)
2 : |- conhost.exe (17264)
2 : tib_mounter_monitor.exe (16056)
71 : tib_mounter_monitor.exe (16240)
71 : winlogon.exe (17252)
71 : |- dwm.exe (14748)
71 : |- LogonUI.exe (15280)
71 : |- fontdrvhost.exe (1704)
71 : csrss.exe (20492)
71 : explorer.exe (20948)
71 : |- schedhlp.exe (22172)
71 : |- MmsMonitor.exe (22208)
71 : |- MmsMonitor.exe (18808)
71 : |- MmsMonitor.exe (22448)
71 : |- MmsMonitor.exe (7136)
0 : Registry (276)
2 : csrss.exe (4540)
2 : winlogon.exe (5952)
2 : |- dwm.exe (11892)
2 : |- fontdrvhost.exe (13208)
2 : |- LogonUI.exe (17572)
0 : csrss.exe (812)
0 : wininit.exe (920)
0 : |- fontdrvhost.exe (1044)
0 : |- lsass.exe (180)
0 : |- services.exe (220)
0 : |- fdlauncher.exe (10600)
0 : |- fdhost.exe (10660)
0 : |- conhost.exe (10668)
0 : |- Launchpad.exe (10640)
0 : |- svchost.exe (1128)
0 : |- svchost.exe (11284)
0 : |- svchost.exe (1184)
0 : |- svchost.exe (1228)
0 : |- svchost.exe (12356)
0 : |- svchost.exe (12480)
0 : |- svchost.exe (1348)
2 : |- rdpclip.exe (12348)
71 : |- rdpclip.exe (17992)
0 : |- svchost.exe (13636)
2 : |- ctfmon.exe (13804)
71 : |- ctfmon.exe (21788)
0 : |- mms.exe (1448)
0 : |- svchost.exe (1456)
0 : |- svchost.exe (1480)
0 : |- svchost.exe (1488)
0 : |- svchost.exe (14880)
0 : |- svchost.exe (1548)
0 : |- svchost.exe (15960)
0 : |- svchost.exe (1696)
0 : |- svchost.exe (1744)
0 : |- svchost.exe (176)
0 : |- WmiPrvSE.exe (1208)
71 : |- ShellExperienceHost.exe (13392)
2 : |- dllhost.exe (13752)
71 : |- RuntimeBroker.exe (13908)
2 : |- RuntimeBroker.exe (14188)
2 : |- ShellExperienceHost.exe (14204)
2 : |- SearchUI.exe (14324)
2 : |- smartscreen.exe (15068)
0 : |- WmiPrvSE.exe (15488)
71 : |- smartscreen.exe (17416)
71 : |- SearchUI.exe (17696)
0 : |- WmiPrvSE.exe (20292)
71 : |- RuntimeBroker.exe (20400)
71 : |- RuntimeBroker.exe (21964)
0 : |- WmiPrvSE.exe (6424)
2 : |- RuntimeBroker.exe (6616)
2 : |- RuntimeBroker.exe (7456)
0 : |- svchost.exe (1788)
2 : |- svchost.exe (1824)
0 : |- svchost.exe (1832)
0 : |- WUDFHost.exe (1856)
0 : |- avpsus.exe (1896)
0 : |- svchost.exe (1940)
0 : |- svchost.exe (1948)
2 : |- taskhostw.exe (12276)
71 : |- taskhostw.exe (18216)
0 : |- svchost.exe (1956)
0 : |- svchost.exe (1964)
71 : |- svchost.exe (19668)
0 : |- svchost.exe (2052)
0 : |- svchost.exe (20636)
0 : |- svchost.exe (2088)
0 : |- svchost.exe (2096)
71 : |- svchost.exe (2160)
0 : |- svchost.exe (22380)
0 : |- svchost.exe (2408)
0 : |- svchost.exe (2424)
0 : |- svchost.exe (2436)
0 : |- svchost.exe (2520)
0 : |- svchost.exe (2580)
0 : |- svchost.exe (2604)
0 : |- svchost.exe (2640)
0 : |- svchost.exe (2688)
0 : |- svchost.exe (2768)
0 : |- svchost.exe (2808)
71 : |- sihost.exe (13012)
2 : |- sihost.exe (6680)
0 : |- svchost.exe (2820)
0 : |- svchost.exe (2900)
0 : |- svchost.exe (2996)
0 : |- svchost.exe (3020)
0 : |- svchost.exe (3040)
0 : |- svchost.exe (3080)
0 : |- spoolsv.exe (3288)
0 : |- svchost.exe (3300)
0 : |- acp-update-controller.exe (3396)
0 : |- svchost.exe (3404)
0 : |- aakore.exe (3476)
0 : |- updater.exe (6316)
0 : |- conhost.exe (7044)
0 : |- cyber-desktop-service.exe (6516)
0 : |- conhost.exe (12796)
0 : |- cred-store.exe (6972)
0 : |- conhost.exe (7008)
0 : |- sh-inventory.exe (7000)
0 : |- conhost.exe (7056)
0 : |- feedback-collector.exe (7036)
0 : |- conhost.exe (7096)
0 : |- mi-monitoring.exe (7104)
0 : |- conhost.exe (2532)
0 : |- task-manager.exe (7152)
0 : |- conhost.exe (7200)
0 : |- adp-agent.exe (7212)
0 : |- conhost.exe (7264)
0 : |- cyber-scripting-executor.exe (7252)
0 : |- conhost.exe (7304)
0 : |- network-isolation-unit.exe (7336)
0 : |- conhost.exe (7420)
0 : |- grpm-sync-unit.exe (7448)
0 : |- conhost.exe (7504)
0 : |- grpm.exe (7488)
0 : |- conhost.exe (7556)
0 : |- svchost.exe (3512)
0 : |- svchost.exe (3524)
0 : |- inetinfo.exe (3532)
0 : |- svchost.exe (3540)
0 : |- svchost.exe (3548)
0 : |- svchost.exe (3556)
0 : |- w3wp.exe (12652)
0 : |- conhost.exe (11832)
0 : |- w3wp.exe (13820)
0 : |- conhost.exe (11344)
0 : |- w3wp.exe (6496)
0 : |- klnagent.exe (3676)
0 : |- avp.exe (3684)
2 : |- avpui.exe (13000)
71 : |- avpui.exe (8964)
0 : |- svchost.exe (3736)
0 : |- svchost.exe (3748)
0 : |- vm3dservice.exe (3796)
1 : |- vm3dservice.exe (4340)
0 : |- svchost.exe (3808)
0 : |- vmtoolsd.exe (3816)
0 : |- svchost.exe (3824)
0 : |- winvnc4.exe (3832)
1 : |- winvnc4.exe (4592)
0 : |- svchost.exe (3840)
0 : |- svchost.exe (3852)
0 : |- VGAuthService.exe (3860)
0 : |- sqlwriter.exe (3872)
0 : |- SMSvcHost.exe (3896)
0 : |- nxlog.exe (3904)
0 : |- svchost.exe (4040)
0 : |- svchost.exe (4148)
0 : |- svchost.exe (4316)
0 : |- svchost.exe (4584)
0 : |- svchost.exe (4644)
0 : |- active_protection_service.exe (5272)
0 : |- sqlceip.exe (5352)
0 : |- MsDtsSrvr.exe (5360)
0 : |- sqlceip.exe (5612)
0 : |- sqlceip.exe (5672)
0 : |- sqlservr.exe (5680)
0 : |- msmdsrv.exe (6080)
0 : |- svchost.exe (6284)
0 : |- schedul2.exe (6312)
0 : |- svchost.exe (6504)
0 : |- dllhost.exe (6608)
0 : |- msdtc.exe (7568)
0 : |- svchost.exe (7672)
0 : |- svchost.exe (8772)
0 : |- svchost.exe (916)
2 : |- svchost.exe (9916)
1 : csrss.exe (928)
1 : winlogon.exe (992)
1 : |- fontdrvhost.exe (1036)
1 : |- LogonUI.exe (1248)
1 : |- dwm.exe (1256)

Process_Information_172.17.100.112.csv : information about the running process.
70331 - Microsoft Windows Process Module Information
-
Synopsis
Use WMI to obtain running process module information.
Description
Report details on the running processes modules on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to that confirm your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process_Modules_172.17.100.112.csv : lists the loaded modules for each process.

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/80/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/123


The Win32 process 'svchost.exe' is listening on this port (pid 3852).

This process 'svchost.exe' (pid 3852) is hosting the following Windows services :
W32Time (@%SystemRoot%\system32\w32time.dll,-200)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/135/epmap


The Win32 process 'svchost.exe' is listening on this port (pid 1128).

This process 'svchost.exe' (pid 1128) is hosting the following Windows services :
RpcEptMapper (@%windir%\system32\RpcEpMap.dll,-1001)
RpcSs (@combase.dll,-5010)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/137/netbios-ns


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/138


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/139/smb


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/443/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/500


The Win32 process 'svchost.exe' is listening on this port (pid 3040).

This process 'svchost.exe' (pid 3040) is hosting the following Windows services :
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/1433/mssql


The Win32 process 'sqlservr.exe' is listening on this port (pid 5680).

This process 'sqlservr.exe' (pid 5680) is hosting the following Windows services :
MSSQLSERVER (SQL Server (MSSQLSERVER))

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/2383


The Win32 process 'msmdsrv.exe' is listening on this port (pid 6080).

This process 'msmdsrv.exe' (pid 6080) is hosting the following Windows services :
MSSQLServerOLAPService (SQL Server Analysis Services (MSSQLSERVER))

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/3389/msrdp


The Win32 process 'svchost.exe' is listening on this port (pid 1348).

This process 'svchost.exe' (pid 1348) is hosting the following Windows services :
TermService (@%SystemRoot%\System32\termsrv.dll,-268)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/3389


The Win32 process 'svchost.exe' is listening on this port (pid 1348).

This process 'svchost.exe' (pid 1348) is hosting the following Windows services :
TermService (@%SystemRoot%\System32\termsrv.dll,-268)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/3702


The Win32 process 'svchost.exe' is listening on this port (pid 11284).

This process 'svchost.exe' (pid 11284) is hosting the following Windows services :
FDResPub (@%systemroot%\system32\fdrespub.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/4500


The Win32 process 'svchost.exe' is listening on this port (pid 3040).

This process 'svchost.exe' (pid 3040) is hosting the following Windows services :
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5353


The Win32 process 'svchost.exe' is listening on this port (pid 2424).

This process 'svchost.exe' (pid 2424) is hosting the following Windows services :
Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5355/llmnr


The Win32 process 'svchost.exe' is listening on this port (pid 2424).

This process 'svchost.exe' (pid 2424) is hosting the following Windows services :
Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5357/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5800/www


The Win32 process 'winvnc4.exe' is listening on this port (pid 4592).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5900/vnc


The Win32 process 'winvnc4.exe' is listening on this port (pid 4592).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5985/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/6111


The Win32 process 'network-isolation-unit.exe' is listening on this port (pid 7336).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/6771


The Win32 process 'updater.exe' is listening on this port (pid 6316).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/6888


The Win32 process 'updater.exe' is listening on this port (pid 6316).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/6888


The Win32 process 'updater.exe' is listening on this port (pid 6316).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/15000


The Win32 process 'klnagent.exe' is listening on this port (pid 3676).

This process 'klnagent.exe' (pid 3676) is hosting the following Windows services :
klnagent (Kaspersky Security Center Network Agent)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/18018/www


The Win32 process 'updater.exe' is listening on this port (pid 6316).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/47001/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49664/dce-rpc


The Win32 process 'wininit.exe' is listening on this port (pid 920).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49665/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 1480).

This process 'svchost.exe' (pid 1480) is hosting the following Windows services :
EventLog (@%SystemRoot%\system32\wevtsvc.dll,-200)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49666/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 1948).

This process 'svchost.exe' (pid 1948) is hosting the following Windows services :
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49667/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 2820).

This process 'svchost.exe' (pid 2820) is hosting the following Windows services :
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49668/dce-rpc


The Win32 process 'spoolsv.exe' is listening on this port (pid 3288).

This process 'spoolsv.exe' (pid 3288) is hosting the following Windows services :
Spooler (@%systemroot%\system32\spoolsv.exe,-1)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49669/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 3080).

This process 'svchost.exe' (pid 3080) is hosting the following Windows services :
PolicyAgent (@%SystemRoot%\System32\polstore.dll,-5010)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49742/dce-rpc


The Win32 process 'services.exe' is listening on this port (pid 220).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49833/dce-rpc


The Win32 process 'lsass.exe' is listening on this port (pid 180).

This process 'lsass.exe' (pid 180) is hosting the following Windows services :
KeyIso (@keyiso.dll,-100)
SamSs (@%SystemRoot%\system32\samsrv.dll,-1)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/52702


The Win32 process 'nxlog.exe' is listening on this port (pid 3904).

This process 'nxlog.exe' (pid 3904) is hosting the following Windows services :
nxlog (NXLog)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/57281


The Win32 process 'svchost.exe' is listening on this port (pid 3540).

This process 'svchost.exe' (pid 3540) is hosting the following Windows services :
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/59033


The Win32 process 'svchost.exe' is listening on this port (pid 11284).

This process 'svchost.exe' (pid 11284) is hosting the following Windows services :
FDResPub (@%systemroot%\system32\fdrespub.dll,-100)

126527 - Microsoft Windows SAM user enumeration
-
Synopsis
Nessus was able to enumerate domain users from the local SAM.
Description
Using the domain security identifier (SID), Nessus was able to enumerate the domain users on the remote Windows system using the Security Accounts Manager.

Note: Unable to obtain SMB SAMR user data during Agent scans.
Rendering User data obtained by plugin 171956
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/07/08, Modified: 2025/06/04
Plugin Output

tcp/0

- commoniis (id S-1-5-21-1687551350-3880216100-1008, commoniis)
- CommonProduction (id S-1-5-21-1687551350-3880216100-1007, CommonProduction, CommonProduction is created to share drive access in IIS)
- DefaultAccount (id S-1-5-21-1687551350-3880216100-503, A user account managed by the system.)
- Guest (id S-1-5-21-1687551350-3880216100-501, Built-in account for guest access to the computer/domain, Guest account)
- Lkpadmin (id S-1-5-21-1687551350-3880216100-1000, Lkpadmin)
- production (id S-1-5-21-1687551350-3880216100-500, Administrator account, Built-in account for administering the computer/domain)
- tidua (id S-1-5-21-1687551350-3880216100-1009, O0n$s2024#)
- WDAGUtilityAccount (id S-1-5-21-1687551350-3880216100-504, A user account managed and used by the system for Windows Defender Application Guard scenarios.)

17651 - Microsoft Windows SMB : Obtains the Password Policy
-
Synopsis
It is possible to retrieve the remote host's password policy using the supplied credentials.
Description
Using the supplied credentials it was possible to extract the password policy for the remote Windows host. The password policy must conform to the Informational System Policy.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/03/30, Modified: 2015/01/12
Plugin Output

tcp/445/cifs

The following password policy is defined on the remote host:

Minimum password len: 0
Password history len: 0
Maximum password age (d): 42
Password must meet complexity requirements: Enabled
Minimum password age (d): 0
Forced logoff time (s): Not set
Locked account time (s): 1800
Time between failed logon (s): 1800
Number of invalid logon before locked out (s): 0
50859 - Microsoft Windows SMB : WSUS Client Configured
-
Synopsis
The remote Windows host is utilizing a WSUS server.
Description
The remote host is configured to utilize a Windows Server Update Services (WSUS) server.
See Also
Solution
Verify the remote host is configured to utilize the correct WSUS server.
Risk Factor
None
Plugin Information
Published: 2010/12/01, Modified: 2018/11/15
Plugin Output

tcp/445/cifs


This host is configured to get updates from the following WSUS server :

http://localhost:1550

WSUS Environment Options :

ElevateNonAdmins : undefined
TargetGroup : Automatic Windows Update Policy
TargetGroupEnabled : 1

Automatic Update settings :

AUOptions : 2
AutoInstallMinorUpdates : 0
DetectionFrequency : 22
DetectionFrequencyEnabled : 1
NoAutoRebootWithLoggedOnUsers : 1
NoAutoUpdate : 1
RebootRelaunchTimeout : undefined
RebootRelaunchTimeoutEnabled : undefined
RebootWarningTimeout : undefined
RebootWarningTimeoutEnabled : undefined
RescheduleWaitTime : undefined
RescheduleWaitTimeEnabled : 0
ScheduledInstallDay : 0
ScheduledInstallTime : 10
38689 - Microsoft Windows SMB Last Logged On User Disclosure
-
Synopsis
Nessus was able to identify the last logged on user on the remote host.
Description
By connecting to the remote host with the supplied credentials, Nessus was able to identify the username associated with the last successful logon.

Microsoft documentation notes that interactive console logons change the DefaultUserName registry entry to be the last logged-on user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/05/05, Modified: 2019/09/02
Plugin Output

tcp/445/cifs


Last Successful logon : .\production
10394 - Microsoft Windows SMB Log In Possible
-
Synopsis
It was possible to log into the remote host.
Description
The remote host is running a Microsoft Windows operating system or Samba, a CIFS/SMB server for Unix. It was possible to log into it using one of the following accounts :

- Guest account
- Supplied credentials
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/07/21
Plugin Output

tcp/445/cifs

- The SMB tests will be done as tidua/******
10859 - Microsoft Windows SMB LsaQueryInformationPolicy Function SID Enumeration
-
Synopsis
It is possible to obtain the host SID for the remote host.
Description
By emulating the call to LsaQueryInformationPolicy(), it was possible to obtain the host SID (Security Identifier).

The host SID can then be used to get the list of local users.
See Also
Solution
You can prevent anonymous lookups of the host SID by setting the 'RestrictAnonymous' registry setting to an appropriate value.

Refer to the 'See also' section for guidance.
Risk Factor
None
Plugin Information
Published: 2002/02/13, Modified: 2024/01/31
Plugin Output

tcp/445/cifs


The remote host SID value is : S-1-5-21-1687551350-3880216100-4069998428

The value of 'RestrictAnonymous' setting is : 0
10785 - Microsoft Windows SMB NativeLanManager Remote System Information Disclosure
-
Synopsis
It was possible to obtain information about the remote operating system.
Description
Nessus was able to obtain the remote operating system name and version (Windows and/or Samba) by sending an authentication request to port 139 or 445. Note that this plugin requires SMB to be enabled on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/10/17, Modified: 2021/09/20
Plugin Output

tcp/445/cifs

Nessus was able to obtain the following information about the host, by
parsing the SMB2 Protocol's NTLM SSP message:

Target Name: MIDDLEWAREAPI
NetBIOS Domain Name: MIDDLEWAREAPI
NetBIOS Computer Name: MIDDLEWAREAPI
DNS Domain Name: MiddlewareAPI
DNS Computer Name: MiddlewareAPI
DNS Tree Name: unknown
Product Version: 10.0.17763
48942 - Microsoft Windows SMB Registry : OS Version and Processor Architecture
-
Synopsis
It was possible to determine the processor architecture, build lab strings, and Windows OS version installed on the remote system.
Description
Nessus was able to determine the processor architecture, build lab strings, and the Windows OS version installed on the remote system by connecting to the remote registry with the supplied credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/31, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Operating system version = 10.17763
Architecture = x64
Build lab extended = 17763.1.amd64fre.rs5_release.180914-1434
11457 - Microsoft Windows SMB Registry : Winlogon Cached Password Weakness
-
Synopsis
User credentials are stored in memory.
Description
The registry key 'HKLM\Software\Microsoft\WindowsNT\CurrentVersion\ Winlogon\CachedLogonsCount' is not 0. Using a value greater than 0 for the CachedLogonsCount key indicates that the remote Windows host locally caches the passwords of the users when they login, in order to continue to allow the users to login in the case of the failure of the primary domain controller (PDC).

Cached logon credentials could be accessed by an attacker and subjected to brute force attacks.
See Also
Solution
Consult Microsoft documentation and best practices.
Risk Factor
None
Plugin Information
Published: 2003/03/24, Modified: 2018/06/05
Plugin Output

tcp/445/cifs


Max cached logons : 10
10400 - Microsoft Windows SMB Registry Remotely Accessible
-
Synopsis
Access the remote Windows Registry.
Description
It was possible to access the remote Windows Registry using the login / password combination used for the Windows local checks (SMB tests).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/12/16
Plugin Output

tcp/445/cifs

44401 - Microsoft Windows SMB Service Config Enumeration
-
Synopsis
It was possible to enumerate configuration parameters of remote services.
Description
Nessus was able to obtain, via the SMB protocol, the launch parameters of each active service on the remote host (executable path, logon type, etc.).
Solution
Ensure that each service is configured properly.
Risk Factor
None
References
XREF IAVT:0001-T-0752
Plugin Information
Published: 2010/02/05, Modified: 2022/05/16
Plugin Output

tcp/445/cifs


The following services are set to start automatically :

AVP.KES.21.15 startup parameters :
Display name : Kaspersky Endpoint Security Service (KES.21.15)
Service name : AVP.KES.21.15
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r

AcrSch2Svc startup parameters :
Display name : Acronis Scheduler2 Service
Service name : AcrSch2Svc
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
Dependencies : RpcSs/

AcronisActiveProtectionService startup parameters :
Display name : Acronis Active Protection Service
Service name : AcronisActiveProtectionService
Log on as : LocalSystem
Executable path : "C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe"
Dependencies : file_protector/CryptSvc/

AppHostSvc startup parameters :
Display name : Application Host Helper Service
Service name : AppHostSvc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k apphost

Audiosrv startup parameters :
Display name : Windows Audio
Service name : Audiosrv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : AudioEndpointBuilder/RpcSs/

AzureAttestService startup parameters :
Display name : AzureAttestService
Service name : AzureAttestService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k AzureAttestService

BFE startup parameters :
Display name : Base Filtering Engine
Service name : BFE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
Dependencies : RpcSs/

BITS startup parameters :
Display name : Background Intelligent Transfer Service
Service name : BITS
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

BrokerInfrastructure startup parameters :
Display name : Background Tasks Infrastructure Service
Service name : BrokerInfrastructure
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

CDPSvc startup parameters :
Display name : Connected Devices Platform Service
Service name : CDPSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : ncbservice/RpcSS/Tcpip/

CDPUserSvc_28b546d7 startup parameters :
Display name : Connected Devices Platform User Service_28b546d7
Service name : CDPUserSvc_28b546d7
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

CDPUserSvc_31e79f startup parameters :
Display name : Connected Devices Platform User Service_31e79f
Service name : CDPUserSvc_31e79f
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

CoreMessagingRegistrar startup parameters :
Display name : CoreMessaging
Service name : CoreMessagingRegistrar
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p
Dependencies : rpcss/

CryptSvc startup parameters :
Display name : Cryptographic Services
Service name : CryptSvc
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService -p
Dependencies : RpcSs/

DPS startup parameters :
Display name : Diagnostic Policy Service
Service name : DPS
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p

DcomLaunch startup parameters :
Display name : DCOM Server Process Launcher
Service name : DcomLaunch
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

Dhcp startup parameters :
Display name : DHCP Client
Service name : Dhcp
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : NSI/Afd/

DiagTrack startup parameters :
Display name : Connected User Experiences and Telemetry
Service name : DiagTrack
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k utcsvc -p
Dependencies : RpcSs/

Dnscache startup parameters :
Display name : DNS Client
Service name : Dnscache
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService -p
Dependencies : nsi/

EventLog startup parameters :
Display name : Windows Event Log
Service name : EventLog
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p

EventSystem startup parameters :
Display name : COM+ Event System
Service name : EventSystem
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/

FontCache startup parameters :
Display name : Windows Font Cache Service
Service name : FontCache
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

GoogleUpdaterInternalService144.0.7547.0 startup parameters :
Display name : Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0)
Service name : GoogleUpdaterInternalService144.0.7547.0
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update-internal
Dependencies : RPCSS/

GoogleUpdaterService144.0.7547.0 startup parameters :
Display name : Google Updater Service (GoogleUpdaterService144.0.7547.0)
Service name : GoogleUpdaterService144.0.7547.0
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update
Dependencies : RPCSS/

IISADMIN startup parameters :
Display name : IIS Admin Service
Service name : IISADMIN
Log on as : localSystem
Executable path : C:\Windows\system32\inetsrv\inetinfo.exe
Dependencies : RPCSS/SamSS/HTTP/

IKEEXT startup parameters :
Display name : IKE and AuthIP IPsec Keying Modules
Service name : IKEEXT
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : BFE/nsi/

LSM startup parameters :
Display name : Local Session Manager
Service name : LSM
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

LanmanServer startup parameters :
Display name : Server
Service name : LanmanServer
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k smbsvcs
Dependencies : SamSS/Srv2/

LanmanWorkstation startup parameters :
Display name : Workstation
Service name : LanmanWorkstation
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : Bowser/MRxSmb20/NSI/

MMS startup parameters :
Display name : Acronis Managed Machine Service
Service name : MMS
Log on as : LocalSystem
Executable path : "C:\Program Files\BackupClient\BackupAndRecovery\mms.exe"
Dependencies : winmgmt/AcrSch2Svc/aakore/

MSDTC startup parameters :
Display name : Distributed Transaction Coordinator
Service name : MSDTC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\msdtc.exe
Dependencies : RPCSS/SamSS/

MSSQLLaunchpad startup parameters :
Display name : SQL Server Launchpad (MSSQLSERVER)
Service name : MSSQLLaunchpad
Log on as : NT Service\MSSQLLaunchpad
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
Dependencies : MSSQLServer/

MSSQLSERVER startup parameters :
Display name : SQL Server (MSSQLSERVER)
Service name : MSSQLSERVER
Log on as : NT Service\MSSQLSERVER
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
Dependencies : KEYISO/

MSSQLServerOLAPService startup parameters :
Display name : SQL Server Analysis Services (MSSQLSERVER)
Service name : MSSQLServerOLAPService
Log on as : NT Service\MSSQLServerOLAPService
Executable path : "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Config"

MsDtsServer150 startup parameters :
Display name : SQL Server Integration Services 15.0
Service name : MsDtsServer150
Log on as : NT Service\MsDtsServer150
Executable path : "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\MsDtsSrvr.exe"

NetPipeActivator startup parameters :
Display name : Net.Pipe Listener Adapter
Service name : NetPipeActivator
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
Dependencies : was/

NetTcpActivator startup parameters :
Display name : Net.Tcp Listener Adapter
Service name : NetTcpActivator
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
Dependencies : was/NetTcpPortSharing/

NlaSvc startup parameters :
Display name : Network Location Awareness
Service name : NlaSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : NSI/RpcSs/TcpIp/Dhcp/Eventlog/

Power startup parameters :
Display name : Power
Service name : Power
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

ProfSvc startup parameters :
Display name : User Profile Service
Service name : ProfSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

RasMan startup parameters :
Display name : Remote Access Connection Manager
Service name : RasMan
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : SstpSvc/DnsCache/

RpcEptMapper startup parameters :
Display name : RPC Endpoint Mapper
Service name : RpcEptMapper
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k RPCSS -p

RpcSs startup parameters :
Display name : Remote Procedure Call (RPC)
Service name : RpcSs
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k rpcss -p
Dependencies : RpcEptMapper/DcomLaunch/

SENS startup parameters :
Display name : System Event Notification Service
Service name : SENS
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : EventSystem/

SQLTELEMETRY startup parameters :
Display name : SQL Server CEIP service (MSSQLSERVER)
Service name : SQLTELEMETRY
Log on as : NT Service\SQLTELEMETRY
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service

SQLWriter startup parameters :
Display name : SQL Server VSS Writer
Service name : SQLWriter
Log on as : LocalSystem
Executable path : "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"

SSASTELEMETRY startup parameters :
Display name : SQL Server Analysis Services CEIP (MSSQLSERVER)
Service name : SSASTELEMETRY
Log on as : NT Service\SSASTELEMETRY
Executable path : "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Bin\sqlceip.exe" -Service MSSQLSERVER MSAS

SSISTELEMETRY150 startup parameters :
Display name : SQL Server Integration Services CEIP service 15.0
Service name : SSISTELEMETRY150
Log on as : NT Service\SSISTELEMETRY150
Executable path : "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\sqlceip.exe" -Service default MSIS

SamSs startup parameters :
Display name : Security Accounts Manager
Service name : SamSs
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : RPCSS/

Schedule startup parameters :
Display name : Task Scheduler
Service name : Schedule
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/SystemEventsBroker/

ShellHWDetection startup parameters :
Display name : Shell Hardware Detection
Service name : ShellHWDetection
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

Spooler startup parameters :
Display name : Print Spooler
Service name : Spooler
Log on as : LocalSystem
Executable path : C:\Windows\System32\spoolsv.exe
Dependencies : RPCSS/http/

SysMain startup parameters :
Display name : SysMain
Service name : SysMain
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : rpcss/

SystemEventsBroker startup parameters :
Display name : System Events Broker
Service name : SystemEventsBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/RpcSs/

Themes startup parameters :
Display name : Themes
Service name : Themes
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p

TrkWks startup parameters :
Display name : Distributed Link Tracking Client
Service name : TrkWks
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

UALSVC startup parameters :
Display name : User Access Logging Service
Service name : UALSVC
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : WinMgmt/

UserManager startup parameters :
Display name : User Manager
Service name : UserManager
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

UsoSvc startup parameters :
Display name : Update Orchestrator Service
Service name : UsoSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

VGAuthService startup parameters :
Display name : VMware Alias Manager and Ticket Service
Service name : VGAuthService
Log on as : LocalSystem
Executable path : "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"

VMTools startup parameters :
Display name : VMware Tools
Service name : VMTools
Log on as : LocalSystem
Executable path : "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"

W32Time startup parameters :
Display name : Windows Time
Service name : W32Time
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService

W3SVC startup parameters :
Display name : World Wide Web Publishing Service
Service name : W3SVC
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k iissvcs
Dependencies : WAS/HTTP/

Wcmsvc startup parameters :
Display name : Windows Connection Manager
Service name : Wcmsvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/NSI/

WinRM startup parameters :
Display name : Windows Remote Management (WS-Management)
Service name : WinRM
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : RPCSS/HTTP/

WinVNC4 startup parameters :
Display name : VNC Server Version 4
Service name : WinVNC4
Log on as : LocalSystem
Executable path : "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service

Winmgmt startup parameters :
Display name : Windows Management Instrumentation
Service name : Winmgmt
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/

WpnService startup parameters :
Display name : Windows Push Notifications System Service
Service name : WpnService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

WpnUserService_28b546d7 startup parameters :
Display name : Windows Push Notifications User Service_28b546d7
Service name : WpnUserService_28b546d7
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

WpnUserService_31e79f startup parameters :
Display name : Windows Push Notifications User Service_31e79f
Service name : WpnUserService_31e79f
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

aakore startup parameters :
Display name : Acronis Agent Core Service
Service name : aakore
Log on as : LocalSystem
Executable path : "C:\Program Files\Common Files\Acronis\Agent\aakore.exe" run

acp-update-controller startup parameters :
Display name : Acronis Update Controller
Service name : acp-update-controller
Log on as : LocalSystem
Executable path : "C:\Program Files\BackupClient\UpdateController\acp-update-controller.exe" --update-controller

avpsus.KES.21.15 startup parameters :
Display name : Kaspersky Seamless Update Service (KES.21.15)
Service name : avpsus.KES.21.15
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"

edgeupdate startup parameters :
Display name : Microsoft Edge Update Service (edgeupdate)
Service name : edgeupdate
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
Dependencies : RPCSS/

gpsvc startup parameters :
Display name : Group Policy Client
Service name : gpsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/Mup/

iphlpsvc startup parameters :
Display name : IP Helper
Service name : iphlpsvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k NetSvcs -p
Dependencies : RpcSS/winmgmt/tcpip/nsi/WinHttpAutoProxySvc/

klnagent startup parameters :
Display name : Kaspersky Security Center Network Agent
Service name : klnagent
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"

mpssvc startup parameters :
Display name : Windows Defender Firewall
Service name : mpssvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
Dependencies : mpsdrv/bfe/

nsi startup parameters :
Display name : Network Store Interface Service
Service name : nsi
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/nsiproxy/

nxlog startup parameters :
Display name : nxlog
Service name : nxlog
Log on as : LocalSystem
Executable path : "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
Dependencies : eventlog/

sppsvc startup parameters :
Display name : Software Protection
Service name : sppsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\sppsvc.exe
Dependencies : RpcSs/

vm3dservice startup parameters :
Display name : VMware SVGA Helper Service
Service name : vm3dservice
Log on as : LocalSystem
Executable path : C:\Windows\system32\vm3dservice.exe

The following services must be started manually :

AJRouter startup parameters :
Display name : AllJoyn Router Service
Service name : AJRouter
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p

ALG startup parameters :
Display name : Application Layer Gateway Service
Service name : ALG
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\alg.exe

AppIDSvc startup parameters :
Display name : Application Identity
Service name : AppIDSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/AppID/CryptSvc/

AppMgmt startup parameters :
Display name : Application Management
Service name : AppMgmt
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p

AppReadiness startup parameters :
Display name : App Readiness
Service name : AppReadiness
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k AppReadiness -p

AppXSvc startup parameters :
Display name : AppX Deployment Service (AppXSVC)
Service name : AppXSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k wsappx -p
Dependencies : rpcss/staterepository/

Appinfo startup parameters :
Display name : Application Information
Service name : Appinfo
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

AudioEndpointBuilder startup parameters :
Display name : Windows Audio Endpoint Builder
Service name : AudioEndpointBuilder
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

BTAGService startup parameters :
Display name : Bluetooth Audio Gateway Service
Service name : BTAGService
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : bthserv/rpcss/

BthAvctpSvc startup parameters :
Display name : AVCTP service
Service name : BthAvctpSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/

COMSysApp startup parameters :
Display name : COM+ System Application
Service name : COMSysApp
Log on as : LocalSystem
Executable path : C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Dependencies : RpcSs/EventSystem/SENS/

CaptureService_28b546d7 startup parameters :
Display name : CaptureService_28b546d7
Service name : CaptureService_28b546d7
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

CaptureService_31e79f startup parameters :
Display name : CaptureService_31e79f
Service name : CaptureService_31e79f
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

CertPropSvc startup parameters :
Display name : Certificate Propagation
Service name : CertPropSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

ClipSVC startup parameters :
Display name : Client License Service (ClipSVC)
Service name : ClipSVC
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k wsappx -p
Dependencies : rpcss/

ConsentUxUserSvc_28b546d7 startup parameters :
Display name : ConsentUX_28b546d7
Service name : ConsentUxUserSvc_28b546d7
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

ConsentUxUserSvc_31e79f startup parameters :
Display name : ConsentUX_31e79f
Service name : ConsentUxUserSvc_31e79f
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevQueryBroker startup parameters :
Display name : DevQuery Background Discovery Broker
Service name : DevQueryBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

DeviceAssociationService startup parameters :
Display name : Device Association Service
Service name : DeviceAssociationService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

DeviceInstall startup parameters :
Display name : Device Install Service
Service name : DeviceInstall
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

DevicesFlowUserSvc_28b546d7 startup parameters :
Display name : DevicesFlow_28b546d7
Service name : DevicesFlowUserSvc_28b546d7
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevicesFlowUserSvc_31e79f startup parameters :
Display name : DevicesFlow_31e79f
Service name : DevicesFlowUserSvc_31e79f
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DmEnrollmentSvc startup parameters :
Display name : Device Management Enrollment Service
Service name : DmEnrollmentSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

DoSvc startup parameters :
Display name : Delivery Optimization
Service name : DoSvc
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : rpcss/

DsSvc startup parameters :
Display name : Data Sharing Service
Service name : DsSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

DsmSvc startup parameters :
Display name : Device Setup Manager
Service name : DsmSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

EFS startup parameters :
Display name : Encrypting File System (EFS)
Service name : EFS
Log on as : LocalSystem
Executable path : C:\Windows\System32\lsass.exe
Dependencies : RPCSS/

Eaphost startup parameters :
Display name : Extensible Authentication Protocol
Service name : Eaphost
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/KeyIso/

EntAppSvc startup parameters :
Display name : Enterprise App Management Service
Service name : EntAppSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel -p
Dependencies : rpcss/

FDResPub startup parameters :
Display name : Function Discovery Resource Publication
Service name : FDResPub
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : RpcSs/http/fdphost/

FrameServer startup parameters :
Display name : Windows Camera Frame Server
Service name : FrameServer
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k Camera
Dependencies : rpcss/

GoogleChromeElevationService startup parameters :
Display name : Google Chrome Elevation Service (GoogleChromeElevationService)
Service name : GoogleChromeElevationService
Log on as : LocalSystem
Executable path : "C:\Program Files\Google\Chrome\Application\143.0.7499.193\elevation_service.exe"
Dependencies : RPCSS/

HvHost startup parameters :
Display name : HV Host Service
Service name : HvHost
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : hvservice/

InstallService startup parameters :
Display name : Microsoft Store Install Service
Service name : InstallService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

KPSSVC startup parameters :
Display name : KDC Proxy Server service (KPS)
Service name : KPSSVC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k KpsSvcGroup
Dependencies : rpcss/http/

KeyIso startup parameters :
Display name : CNG Key Isolation
Service name : KeyIso
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : RpcSs/

KtmRm startup parameters :
Display name : KtmRm for Distributed Transaction Coordinator
Service name : KtmRm
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
Dependencies : RPCSS/SamSS/

LicenseManager startup parameters :
Display name : Windows License Manager Service
Service name : LicenseManager
Log on as : NT Authority\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p
Dependencies : rpcss/

MSSQLFDLauncher startup parameters :
Display name : SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
Service name : MSSQLFDLauncher
Log on as : NT Service\MSSQLFDLauncher
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER

MSiSCSI startup parameters :
Display name : Microsoft iSCSI Initiator Service
Service name : MSiSCSI
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p

MsMpiLaunchSvc startup parameters :
Display name : MS-MPI Launch Service
Service name : MsMpiLaunchSvc
Log on as : LocalSystem
Executable path : "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"

NcaSvc startup parameters :
Display name : Network Connectivity Assistant
Service name : NcaSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k NetSvcs -p
Dependencies : BFE/dnscache/NSI/iphlpsvc/

NcbService startup parameters :
Display name : Network Connection Broker
Service name : NcbService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSS/tcpip/

NetSetupSvc startup parameters :
Display name : Network Setup Service
Service name : NetSetupSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

NetTcpPortSharing startup parameters :
Display name : Net.Tcp Port Sharing Service
Service name : NetTcpPortSharing
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

Netlogon startup parameters :
Display name : Netlogon
Service name : Netlogon
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : LanmanWorkstation/

Netman startup parameters :
Display name : Network Connections
Service name : Netman
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/nsi/

NgcCtnrSvc startup parameters :
Display name : Microsoft Passport Container
Service name : NgcCtnrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/

NgcSvc startup parameters :
Display name : Microsoft Passport
Service name : NgcSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

PcaSvc startup parameters :
Display name : Program Compatibility Assistant Service
Service name : PcaSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

PerfHost startup parameters :
Display name : Performance Counter DLL Host
Service name : PerfHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\SysWow64\perfhost.exe
Dependencies : RPCSS/

PimIndexMaintenanceSvc_28b546d7 startup parameters :
Display name : Contact Data_28b546d7
Service name : PimIndexMaintenanceSvc_28b546d7
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

PimIndexMaintenanceSvc_31e79f startup parameters :
Display name : Contact Data_31e79f
Service name : PimIndexMaintenanceSvc_31e79f
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

PlugPlay startup parameters :
Display name : Plug and Play
Service name : PlugPlay
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

PolicyAgent startup parameters :
Display name : IPsec Policy Agent
Service name : PolicyAgent
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
Dependencies : Tcpip/bfe/

PrintNotify startup parameters :
Display name : Printer Extensions and Notifications
Service name : PrintNotify
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k print
Dependencies : RpcSs/

PrintWorkflowUserSvc_28b546d7 startup parameters :
Display name : PrintWorkflow_28b546d7
Service name : PrintWorkflowUserSvc_28b546d7
Executable path : C:\Windows\system32\svchost.exe -k PrintWorkflow

PrintWorkflowUserSvc_31e79f startup parameters :
Display name : PrintWorkflow_31e79f
Service name : PrintWorkflowUserSvc_31e79f
Executable path : C:\Windows\system32\svchost.exe -k PrintWorkflow

QWAVE startup parameters :
Display name : Quality Windows Audio Video Experience
Service name : QWAVE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : rpcss/psched/QWAVEdrv/LLTDIO/

RSoPProv startup parameters :
Display name : Resultant Set of Policy Provider
Service name : RSoPProv
Log on as : LocalSystem
Executable path : C:\Windows\system32\RSoPProv.exe
Dependencies : RPCSS/

RasAuto startup parameters :
Display name : Remote Access Auto Connection Manager
Service name : RasAuto
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RasAcd/

RemoteRegistry startup parameters :
Display name : Remote Registry
Service name : RemoteRegistry
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k localService -p
Dependencies : RPCSS/

RpcLocator startup parameters :
Display name : Remote Procedure Call (RPC) Locator
Service name : RpcLocator
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\locator.exe

SCPolicySvc startup parameters :
Display name : Smart Card Removal Policy
Service name : SCPolicySvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

SCardSvr startup parameters :
Display name : Smart Card
Service name : SCardSvr
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

SNMPTRAP startup parameters :
Display name : SNMP Trap
Service name : SNMPTRAP
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\snmptrap.exe

SQLSERVERAGENT startup parameters :
Display name : SQL Server Agent (MSSQLSERVER)
Service name : SQLSERVERAGENT
Log on as : NT Service\SQLSERVERAGENT
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
Dependencies : MSSQLSERVER/

SecPod Saner Upgrade Controller v2 startup parameters :
Display name : SecPod Saner Upgrade Controller v2
Service name : SecPod Saner Upgrade Controller v2
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\SecPod Saner\Upgrader\bin\spupgradecontroller.exe"

SecurityHealthService startup parameters :
Display name : Windows Security Service
Service name : SecurityHealthService
Log on as : LocalSystem
Executable path : C:\Windows\system32\SecurityHealthService.exe
Dependencies : RpcSs/

Sense startup parameters :
Display name : Sense
Service name : Sense
Log on as : LocalSystem
Executable path : "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe"

SensorService startup parameters :
Display name : Sensor Service
Service name : SensorService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

SensrSvc startup parameters :
Display name : Sensor Monitoring Service
Service name : SensrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p

SessionEnv startup parameters :
Display name : Remote Desktop Configuration
Service name : SessionEnv
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/LanmanWorkstation/

SgrmBroker startup parameters :
Display name : System Guard Runtime Monitor Broker
Service name : SgrmBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\SgrmBroker.exe
Dependencies : RpcSs/

SstpSvc startup parameters :
Display name : Secure Socket Tunneling Protocol Service
Service name : SstpSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

StateRepository startup parameters :
Display name : State Repository Service
Service name : StateRepository
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel -p
Dependencies : rpcss/

StorSvc startup parameters :
Display name : Storage Service
Service name : StorSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

TabletInputService startup parameters :
Display name : Touch Keyboard and Handwriting Panel Service
Service name : TabletInputService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

TermService startup parameters :
Display name : Remote Desktop Services
Service name : TermService
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k termsvcs
Dependencies : RPCSS/

Tib Mounter Service startup parameters :
Display name : Tib Mounter Service
Service name : Tib Mounter Service
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe"
Dependencies : RPCSS/

TieringEngineService startup parameters :
Display name : Storage Tiers Management
Service name : TieringEngineService
Log on as : localSystem
Executable path : C:\Windows\system32\TieringEngineService.exe

TimeBrokerSvc startup parameters :
Display name : Time Broker
Service name : TimeBrokerSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p

TokenBroker startup parameters :
Display name : Web Account Manager
Service name : TokenBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : UserManager/

TrustedInstaller startup parameters :
Display name : Windows Modules Installer
Service name : TrustedInstaller
Log on as : localSystem
Executable path : C:\Windows\servicing\TrustedInstaller.exe

UmRdpService startup parameters :
Display name : Remote Desktop Services UserMode Port Redirector
Service name : UmRdpService
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : TermService/RDPDR/

UnistoreSvc_28b546d7 startup parameters :
Display name : User Data Storage_28b546d7
Service name : UnistoreSvc_28b546d7
Executable path : C:\Windows\System32\svchost.exe -k UnistackSvcGroup

UnistoreSvc_31e79f startup parameters :
Display name : User Data Storage_31e79f
Service name : UnistoreSvc_31e79f
Executable path : C:\Windows\System32\svchost.exe -k UnistackSvcGroup

UserDataSvc_28b546d7 startup parameters :
Display name : User Data Access_28b546d7
Service name : UserDataSvc_28b546d7
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

UserDataSvc_31e79f startup parameters :
Display name : User Data Access_31e79f
Service name : UserDataSvc_31e79f
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

VSInstallerElevationService startup parameters :
Display name : Visual Studio Installer Elevation Service
Service name : VSInstallerElevationService
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft Visual Studio\Installer\VSInstallerElevationService.exe"

VSS startup parameters :
Display name : Volume Shadow Copy
Service name : VSS
Log on as : LocalSystem
Executable path : C:\Windows\system32\vssvc.exe
Dependencies : RPCSS/

VSStandardCollectorService150 startup parameters :
Display name : Visual Studio Standard Collector Service 150
Service name : VSStandardCollectorService150
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe"

VaultSvc startup parameters :
Display name : Credential Manager
Service name : VaultSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : rpcss/

WAS startup parameters :
Display name : Windows Process Activation Service
Service name : WAS
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k iissvcs
Dependencies : RPCSS/

WEPHOSTSVC startup parameters :
Display name : Windows Encryption Provider Host Service
Service name : WEPHOSTSVC
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k WepHostSvcGroup
Dependencies : rpcss/

WMPNetworkSvc startup parameters :
Display name : Windows Media Player Network Sharing Service
Service name : WMPNetworkSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : "C:\Program Files\Windows Media Player\wmpnetwk.exe"
Dependencies : http/WSearch/

WMSVC startup parameters :
Display name : Web Management Service
Service name : WMSVC
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\inetsrv\wmsvc.exe
Dependencies : HTTP/

WPDBusEnum startup parameters :
Display name : Portable Device Enumerator Service
Service name : WPDBusEnum
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

WaaSMedicSvc startup parameters :
Display name : Windows Update Medic Service
Service name : WaaSMedicSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k wusvcs -p
Dependencies : rpcss/

WarpJITSvc startup parameters :
Display name : WarpJITSvc
Service name : WarpJITSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

WbioSrvc startup parameters :
Display name : Windows Biometric Service
Service name : WbioSrvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k WbioSvcGroup
Dependencies : RpcSs/

WdiServiceHost startup parameters :
Display name : Diagnostic Service Host
Service name : WdiServiceHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p

WdiSystemHost startup parameters :
Display name : Diagnostic System Host
Service name : WdiSystemHost
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

Wecsvc startup parameters :
Display name : Windows Event Collector
Service name : Wecsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService -p
Dependencies : HTTP/Eventlog/

WerSvc startup parameters :
Display name : Windows Error Reporting Service
Service name : WerSvc
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k WerSvcGroup

WiaRpc startup parameters :
Display name : Still Image Acquisition Events
Service name : WiaRpc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

WinHttpAutoProxySvc startup parameters :
Display name : WinHTTP Web Proxy Auto-Discovery Service
Service name : WinHttpAutoProxySvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : Dhcp/

aspnet_state startup parameters :
Display name : ASP.NET State Service
Service name : aspnet_state
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe

bthserv startup parameters :
Display name : Bluetooth Support Service
Service name : bthserv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

camsvc startup parameters :
Display name : Capability Access Manager Service
Service name : camsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel -p

cbdhsvc_28b546d7 startup parameters :
Display name : Clipboard User Service_28b546d7
Service name : cbdhsvc_28b546d7
Executable path : C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p

cbdhsvc_31e79f startup parameters :
Display name : Clipboard User Service_31e79f
Service name : cbdhsvc_31e79f
Executable path : C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p

defragsvc startup parameters :
Display name : Optimize drives
Service name : defragsvc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k defragsvc
Dependencies : RPCSS/

diagnosticshub.standardcollector.service startup parameters :
Display name : Microsoft (R) Diagnostics Hub Standard Collector Service
Service name : diagnosticshub.standardcollector.service
Log on as : LocalSystem
Executable path : C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe

dot3svc startup parameters :
Display name : Wired AutoConfig
Service name : dot3svc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/Ndisuio/Eaphost/

edgeupdatem startup parameters :
Display name : Microsoft Edge Update Service (edgeupdatem)
Service name : edgeupdatem
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
Dependencies : RPCSS/

embeddedmode startup parameters :
Display name : Embedded Mode
Service name : embeddedmode
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : BrokerInfrastructure/

fdPHost startup parameters :
Display name : Function Discovery Provider Host
Service name : fdPHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/http/

hidserv startup parameters :
Display name : Human Interface Device Service
Service name : hidserv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

ksnproxy startup parameters :
Display name : Kaspersky Security Network proxy server
Service name : ksnproxy
Log on as : NT SERVICE\ksnproxy
Executable path : "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"

lmhosts startup parameters :
Display name : TCP/IP NetBIOS Helper
Service name : lmhosts
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : Afd/

msiserver startup parameters :
Display name : Windows Installer
Service name : msiserver
Log on as : LocalSystem
Executable path : C:\Windows\system32\msiexec.exe /V
Dependencies : rpcss/

netprofm startup parameters :
Display name : Network List Service
Service name : netprofm
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p
Dependencies : RpcSs/nlasvc/

ose startup parameters :
Display name : Office Source Engine
Service name : ose
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"

osppsvc startup parameters :
Display name : Office Software Protection Platform
Service name : osppsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
Dependencies : RpcSs/

pla startup parameters :
Display name : Performance Logs & Alerts
Service name : pla
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p
Dependencies : RPCSS/

sacsvr startup parameters :
Display name : Special Administration Console Helper
Service name : sacsvr
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p

seclogon startup parameters :
Display name : Secondary Logon
Service name : seclogon
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p

smphost startup parameters :
Display name : Microsoft Storage Spaces SMP
Service name : smphost
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k smphost
Dependencies : RPCSS/

stisvc startup parameters :
Display name : Windows Image Acquisition (WIA)
Service name : stisvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k imgsvc
Dependencies : RpcSs/

svsvc startup parameters :
Display name : Spot Verifier
Service name : svsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

swprv startup parameters :
Display name : Microsoft Software Shadow Copy Provider
Service name : swprv
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k swprv
Dependencies : RPCSS/

tapisrv startup parameters :
Display name : Telephony
Service name : tapisrv
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : RpcSs/

vds startup parameters :
Display name : Virtual Disk
Service name : vds
Log on as : LocalSystem
Executable path : C:\Windows\System32\vds.exe
Dependencies : RpcSs/

vmicguestinterface startup parameters :
Display name : Hyper-V Guest Service Interface
Service name : vmicguestinterface
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicheartbeat startup parameters :
Display name : Hyper-V Heartbeat Service
Service name : vmicheartbeat
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k ICService -p

vmickvpexchange startup parameters :
Display name : Hyper-V Data Exchange Service
Service name : vmickvpexchange
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicrdv startup parameters :
Display name : Hyper-V Remote Desktop Virtualization Service
Service name : vmicrdv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k ICService -p

vmicshutdown startup parameters :
Display name : Hyper-V Guest Shutdown Service
Service name : vmicshutdown
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmictimesync startup parameters :
Display name : Hyper-V Time Synchronization Service
Service name : vmictimesync
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : VmGid/

vmicvmsession startup parameters :
Display name : Hyper-V PowerShell Direct Service
Service name : vmicvmsession
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicvss startup parameters :
Display name : Hyper-V Volume Shadow Copy Requestor
Service name : vmicvss
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmvss startup parameters :
Display name : VMware Snapshot Provider
Service name : vmvss
Log on as : LocalSystem
Executable path : C:\Windows\system32\dllhost.exe /Processid:{901C72D2-92C9-4A2F-885B-44DA86E6E0A9}
Dependencies : rpcss/

w3logsvc startup parameters :
Display name : W3C Logging Service
Service name : w3logsvc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k apphost
Dependencies : HTTP/

wercplsupport startup parameters :
Display name : Problem Reports and Solutions Control Panel Support
Service name : wercplsupport
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p

wlidsvc startup parameters :
Display name : Microsoft Account Sign-in Assistant
Service name : wlidsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

wmiApSrv startup parameters :
Display name : WMI Performance Adapter
Service name : wmiApSrv
Log on as : localSystem
Executable path : C:\Windows\system32\wbem\WmiApSrv.exe

wuauserv startup parameters :
Display name : Windows Update
Service name : wuauserv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

The following services are disabled :

AppVClient startup parameters :
Display name : Microsoft App-V Client
Service name : AppVClient
Log on as : LocalSystem
Executable path : C:\Windows\system32\AppVClient.exe
Dependencies : RpcSS/netprofm/AppvVfs/AppVStrm/

AxInstSV startup parameters :
Display name : ActiveX Installer (AxInstSV)
Service name : AxInstSV
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k AxInstSVGroup
Dependencies : rpcss/

CscService startup parameters :
Display name : Offline Files
Service name : CscService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

DevicePickerUserSvc_28b546d7 startup parameters :
Display name : DevicePicker_28b546d7
Service name : DevicePickerUserSvc_28b546d7
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevicePickerUserSvc_31e79f startup parameters :
Display name : DevicePicker_31e79f
Service name : DevicePickerUserSvc_31e79f
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

GraphicsPerfSvc startup parameters :
Display name : GraphicsPerfSvc
Service name : GraphicsPerfSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k GraphicsPerfSvcGroup

MapsBroker startup parameters :
Display name : Downloaded Maps Manager
Service name : MapsBroker
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : rpcss/

PhoneSvc startup parameters :
Display name : Phone Service
Service name : PhoneSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/

PushToInstall startup parameters :
Display name : Windows PushToInstall Service
Service name : PushToInstall
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

RemoteAccess startup parameters :
Display name : Routing and Remote Access
Service name : RemoteAccess
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : RpcSS/Bfe/RasMan/Http/+NetBIOSGroup/

RmSvc startup parameters :
Display name : Radio Management Service
Service name : RmSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/

SEMgrSvc startup parameters :
Display name : Payments and NFC/SE Manager
Service name : SEMgrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/

SQLBrowser startup parameters :
Display name : SQL Server Browser
Service name : SQLBrowser
Log on as : NT AUTHORITY\LOCALSERVICE
Executable path : "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"

SSDPSRV startup parameters :
Display name : SSDP Discovery
Service name : SSDPSRV
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : HTTP/NSI/

ScDeviceEnum startup parameters :
Display name : Smart Card Device Enumeration Service
Service name : ScDeviceEnum
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

SensorDataService startup parameters :
Display name : Sensor Data Service
Service name : SensorDataService
Log on as : LocalSystem
Executable path : C:\Windows\System32\SensorDataService.exe

SharedAccess startup parameters :
Display name : Internet Connection Sharing (ICS)
Service name : SharedAccess
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : BFE/

UevAgentService startup parameters :
Display name : User Experience Virtualization Service
Service name : UevAgentService
Log on as : LocalSystem
Executable path : C:\Windows\system32\AgentService.exe

WSearch startup parameters :
Display name : Windows Search
Service name : WSearch
Log on as : LocalSystem
Executable path : C:\Windows\system32\SearchIndexer.exe /Embedding
Dependencies : RPCSS/BrokerInfrastructure/

WalletService startup parameters :
Display name : WalletService
Service name : WalletService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k appmodel -p

dmwappushservice startup parameters :
Display name : Device Management Wireless Application Protocol (WAP) Push message Routing Service
Service name : dmwappushservice
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

icssvc startup parameters :
Display name : Windows Mobile Hotspot Service
Service name : icssvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/wcmsvc/

lfsvc startup parameters :
Display name : Geolocation Service
Service name : lfsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

lltdsvc startup parameters :
Display name : Link-Layer Topology Discovery Mapper
Service name : lltdsvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p
Dependencies : rpcss/lltdio/

shpamsvc startup parameters :
Display name : Shared PC Account Manager
Service name : shpamsvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

ssh-agent startup parameters :
Display name : OpenSSH Authentication Agent
Service name : ssh-agent
Log on as : LocalSystem
Executable path : C:\Windows\System32\OpenSSH\ssh-agent.exe

tzautoupdate startup parameters :
Display name : Auto Time Zone Updater
Service name : tzautoupdate
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

upnphost startup parameters :
Display name : UPnP Device Host
Service name : upnphost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : SSDPSRV/HTTP/

wisvc startup parameters :
Display name : Windows Insider Service
Service name : wisvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/139/smb


An SMB server is running on this port.

11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/445/cifs


A CIFS server is running on this port.
10456 - Microsoft Windows SMB Service Enumeration
-
Synopsis
It is possible to enumerate remote services.
Description
This plugin implements the SvcOpenSCManager() and SvcEnumServices() calls to obtain, using the SMB protocol, the list of active and inactive services of the remote host.

An attacker may use this feature to gain better knowledge of the remote host.
Solution
To prevent the listing of the services from being obtained, you should either have tight login restrictions, so that only trusted users can access your host, and/or you should filter incoming traffic to this port.
Risk Factor
None
References
XREF IAVT:0001-T-0751
Plugin Information
Published: 2000/07/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Active Services :

Acronis Agent Core Service [ aakore ]
Acronis Update Controller [ acp-update-controller ]
Acronis Active Protection Service [ AcronisActiveProtectionService ]
Acronis Scheduler2 Service [ AcrSch2Svc ]
Application Host Helper Service [ AppHostSvc ]
Application Information [ Appinfo ]
Windows Audio Endpoint Builder [ AudioEndpointBuilder ]
Windows Audio [ Audiosrv ]
Kaspersky Endpoint Security Service (KES.21.15) [ AVP.KES.21.15 ]
Kaspersky Seamless Update Service (KES.21.15) [ avpsus.KES.21.15 ]
AzureAttestService [ AzureAttestService ]
Base Filtering Engine [ BFE ]
Background Tasks Infrastructure Service [ BrokerInfrastructure ]
Connected Devices Platform Service [ CDPSvc ]
Certificate Propagation [ CertPropSvc ]
COM+ System Application [ COMSysApp ]
CoreMessaging [ CoreMessagingRegistrar ]
Cryptographic Services [ CryptSvc ]
DCOM Server Process Launcher [ DcomLaunch ]
DHCP Client [ Dhcp ]
Connected User Experiences and Telemetry [ DiagTrack ]
DNS Client [ Dnscache ]
Diagnostic Policy Service [ DPS ]
Data Sharing Service [ DsSvc ]
Windows Event Log [ EventLog ]
COM+ Event System [ EventSystem ]
Function Discovery Provider Host [ fdPHost ]
Function Discovery Resource Publication [ FDResPub ]
Windows Font Cache Service [ FontCache ]
Group Policy Client [ gpsvc ]
IIS Admin Service [ IISADMIN ]
IKE and AuthIP IPsec Keying Modules [ IKEEXT ]
IP Helper [ iphlpsvc ]
CNG Key Isolation [ KeyIso ]
Kaspersky Security Center Network Agent [ klnagent ]
Server [ LanmanServer ]
Workstation [ LanmanWorkstation ]
Windows License Manager Service [ LicenseManager ]
TCP/IP NetBIOS Helper [ lmhosts ]
Local Session Manager [ LSM ]
Acronis Managed Machine Service [ MMS ]
Windows Defender Firewall [ mpssvc ]
Distributed Transaction Coordinator [ MSDTC ]
SQL Server Integration Services 15.0 [ MsDtsServer150 ]
SQL Full-text Filter Daemon Launcher (MSSQLSERVER) [ MSSQLFDLauncher ]
SQL Server Launchpad (MSSQLSERVER) [ MSSQLLaunchpad ]
SQL Server (MSSQLSERVER) [ MSSQLSERVER ]
SQL Server Analysis Services (MSSQLSERVER) [ MSSQLServerOLAPService ]
Network Connection Broker [ NcbService ]
Net.Pipe Listener Adapter [ NetPipeActivator ]
Network List Service [ netprofm ]
Net.Tcp Listener Adapter [ NetTcpActivator ]
Net.Tcp Port Sharing Service [ NetTcpPortSharing ]
Network Location Awareness [ NlaSvc ]
Network Store Interface Service [ nsi ]
nxlog [ nxlog ]
Program Compatibility Assistant Service [ PcaSvc ]
Plug and Play [ PlugPlay ]
IPsec Policy Agent [ PolicyAgent ]
Power [ Power ]
User Profile Service [ ProfSvc ]
Remote Access Connection Manager [ RasMan ]
Remote Registry [ RemoteRegistry ]
RPC Endpoint Mapper [ RpcEptMapper ]
Remote Procedure Call (RPC) [ RpcSs ]
Security Accounts Manager [ SamSs ]
Task Scheduler [ Schedule ]
System Event Notification Service [ SENS ]
Remote Desktop Configuration [ SessionEnv ]
Shell Hardware Detection [ ShellHWDetection ]
Print Spooler [ Spooler ]
SQL Server CEIP service (MSSQLSERVER) [ SQLTELEMETRY ]
SQL Server VSS Writer [ SQLWriter ]
SQL Server Analysis Services CEIP (MSSQLSERVER) [ SSASTELEMETRY ]
SQL Server Integration Services CEIP service 15.0 [ SSISTELEMETRY150 ]
Secure Socket Tunneling Protocol Service [ SstpSvc ]
State Repository Service [ StateRepository ]
Storage Service [ StorSvc ]
SysMain [ SysMain ]
System Events Broker [ SystemEventsBroker ]
Touch Keyboard and Handwriting Panel Service [ TabletInputService ]
Remote Desktop Services [ TermService ]
Themes [ Themes ]
Time Broker [ TimeBrokerSvc ]
Web Account Manager [ TokenBroker ]
Distributed Link Tracking Client [ TrkWks ]
Windows Modules Installer [ TrustedInstaller ]
User Access Logging Service [ UALSVC ]
Remote Desktop Services UserMode Port Redirector [ UmRdpService ]
User Manager [ UserManager ]
Update Orchestrator Service [ UsoSvc ]
VMware Alias Manager and Ticket Service [ VGAuthService ]
VMware SVGA Helper Service [ vm3dservice ]
VMware Tools [ VMTools ]
Windows Time [ W32Time ]
World Wide Web Publishing Service [ W3SVC ]
Windows Process Activation Service [ WAS ]
Windows Connection Manager [ Wcmsvc ]
Diagnostic Service Host [ WdiServiceHost ]
WinHTTP Web Proxy Auto-Discovery Service [ WinHttpAutoProxySvc ]
Windows Management Instrumentation [ Winmgmt ]
Windows Remote Management (WS-Management) [ WinRM ]
VNC Server Version 4 [ WinVNC4 ]
Windows Push Notifications System Service [ WpnService ]
Connected Devices Platform User Service_31e79f [ CDPUserSvc_31e79f ]
Windows Push Notifications User Service_31e79f [ WpnUserService_31e79f ]
Connected Devices Platform User Service_28b546d7 [ CDPUserSvc_28b546d7 ]
Windows Push Notifications User Service_28b546d7 [ WpnUserService_28b546d7 ]

Inactive Services :

AllJoyn Router Service [ AJRouter ]
Application Layer Gateway Service [ ALG ]
Application Identity [ AppIDSvc ]
Application Management [ AppMgmt ]
App Readiness [ AppReadiness ]
Microsoft App-V Client [ AppVClient ]
AppX Deployment Service (AppXSVC) [ AppXSvc ]
ASP.NET State Service [ aspnet_state ]
ActiveX Installer (AxInstSV) [ AxInstSV ]
Background Intelligent Transfer Service [ BITS ]
Bluetooth Audio Gateway Service [ BTAGService ]
AVCTP service [ BthAvctpSvc ]
Bluetooth Support Service [ bthserv ]
Capability Access Manager Service [ camsvc ]
Client License Service (ClipSVC) [ ClipSVC ]
Offline Files [ CscService ]
Optimize drives [ defragsvc ]
Device Association Service [ DeviceAssociationService ]
Device Install Service [ DeviceInstall ]
DevQuery Background Discovery Broker [ DevQueryBroker ]
Microsoft (R) Diagnostics Hub Standard Collector Service [ diagnosticshub.standardcollector.service ]
Device Management Enrollment Service [ DmEnrollmentSvc ]
Device Management Wireless Application Protocol (WAP) Push message Routing Service [ dmwappushservice ]
Delivery Optimization [ DoSvc ]
Wired AutoConfig [ dot3svc ]
Device Setup Manager [ DsmSvc ]
Extensible Authentication Protocol [ Eaphost ]
Microsoft Edge Update Service (edgeupdate) [ edgeupdate ]
Microsoft Edge Update Service (edgeupdatem) [ edgeupdatem ]
Encrypting File System (EFS) [ EFS ]
Embedded Mode [ embeddedmode ]
Enterprise App Management Service [ EntAppSvc ]
Windows Camera Frame Server [ FrameServer ]
Google Chrome Elevation Service (GoogleChromeElevationService) [ GoogleChromeElevationService ]
Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0) [ GoogleUpdaterInternalService144.0.7547.0 ]
Google Updater Service (GoogleUpdaterService144.0.7547.0) [ GoogleUpdaterService144.0.7547.0 ]
GraphicsPerfSvc [ GraphicsPerfSvc ]
Human Interface Device Service [ hidserv ]
HV Host Service [ HvHost ]
Windows Mobile Hotspot Service [ icssvc ]
Microsoft Store Install Service [ InstallService ]
KDC Proxy Server service (KPS) [ KPSSVC ]
Kaspersky Security Network proxy server [ ksnproxy ]
KtmRm for Distributed Transaction Coordinator [ KtmRm ]
Geolocation Service [ lfsvc ]
Link-Layer Topology Discovery Mapper [ lltdsvc ]
Downloaded Maps Manager [ MapsBroker ]
Microsoft iSCSI Initiator Service [ MSiSCSI ]
Windows Installer [ msiserver ]
MS-MPI Launch Service [ MsMpiLaunchSvc ]
Network Connectivity Assistant [ NcaSvc ]
Netlogon [ Netlogon ]
Network Connections [ Netman ]
Network Setup Service [ NetSetupSvc ]
Microsoft Passport Container [ NgcCtnrSvc ]
Microsoft Passport [ NgcSvc ]
Office Source Engine [ ose ]
Office Software Protection Platform [ osppsvc ]
Performance Counter DLL Host [ PerfHost ]
Phone Service [ PhoneSvc ]
Performance Logs & Alerts [ pla ]
Printer Extensions and Notifications [ PrintNotify ]
Windows PushToInstall Service [ PushToInstall ]
Quality Windows Audio Video Experience [ QWAVE ]
Remote Access Auto Connection Manager [ RasAuto ]
Routing and Remote Access [ RemoteAccess ]
Radio Management Service [ RmSvc ]
Remote Procedure Call (RPC) Locator [ RpcLocator ]
Resultant Set of Policy Provider [ RSoPProv ]
Special Administration Console Helper [ sacsvr ]
Smart Card [ SCardSvr ]
Smart Card Device Enumeration Service [ ScDeviceEnum ]
Smart Card Removal Policy [ SCPolicySvc ]
Secondary Logon [ seclogon ]
SecPod Saner Upgrade Controller v2 [ SecPod Saner Upgrade Controller v2 ]
Windows Security Service [ SecurityHealthService ]
Payments and NFC/SE Manager [ SEMgrSvc ]
Sense [ Sense ]
Sensor Data Service [ SensorDataService ]
Sensor Service [ SensorService ]
Sensor Monitoring Service [ SensrSvc ]
System Guard Runtime Monitor Broker [ SgrmBroker ]
Internet Connection Sharing (ICS) [ SharedAccess ]
Shared PC Account Manager [ shpamsvc ]
Microsoft Storage Spaces SMP [ smphost ]
SNMP Trap [ SNMPTRAP ]
Software Protection [ sppsvc ]
SQL Server Browser [ SQLBrowser ]
SQL Server Agent (MSSQLSERVER) [ SQLSERVERAGENT ]
SSDP Discovery [ SSDPSRV ]
OpenSSH Authentication Agent [ ssh-agent ]
Windows Image Acquisition (WIA) [ stisvc ]
Spot Verifier [ svsvc ]
Microsoft Software Shadow Copy Provider [ swprv ]
Telephony [ tapisrv ]
Tib Mounter Service [ Tib Mounter Service ]
Storage Tiers Management [ TieringEngineService ]
Auto Time Zone Updater [ tzautoupdate ]
User Experience Virtualization Service [ UevAgentService ]
UPnP Device Host [ upnphost ]
Credential Manager [ VaultSvc ]
Virtual Disk [ vds ]
Hyper-V Guest Service Interface [ vmicguestinterface ]
Hyper-V Heartbeat Service [ vmicheartbeat ]
Hyper-V Data Exchange Service [ vmickvpexchange ]
Hyper-V Remote Desktop Virtualization Service [ vmicrdv ]
Hyper-V Guest Shutdown Service [ vmicshutdown ]
Hyper-V Time Synchronization Service [ vmictimesync ]
Hyper-V PowerShell Direct Service [ vmicvmsession ]
Hyper-V Volume Shadow Copy Requestor [ vmicvss ]
VMware Snapshot Provider [ vmvss ]
Visual Studio Installer Elevation Service [ VSInstallerElevationService ]
Volume Shadow Copy [ VSS ]
Visual Studio Standard Collector Service 150 [ VSStandardCollectorService150 ]
W3C Logging Service [ w3logsvc ]
Windows Update Medic Service [ WaaSMedicSvc ]
WalletService [ WalletService ]
WarpJITSvc [ WarpJITSvc ]
Windows Biometric Service [ WbioSrvc ]
Diagnostic System Host [ WdiSystemHost ]
Windows Event Collector [ Wecsvc ]
Windows Encryption Provider Host Service [ WEPHOSTSVC ]
Problem Reports and Solutions Control Panel Support [ wercplsupport ]
Windows Error Reporting Service [ WerSvc ]
Still Image Acquisition Events [ WiaRpc ]
Windows Insider Service [ wisvc ]
Microsoft Account Sign-in Assistant [ wlidsvc ]
WMI Performance Adapter [ wmiApSrv ]
Windows Media Player Network Sharing Service [ WMPNetworkSvc ]
Web Management Service [ WMSVC ]
Portable Device Enumerator Service [ WPDBusEnum ]
Windows Search [ WSearch ]
Windows Update [ wuauserv ]
CaptureService_31e79f [ CaptureService_31e79f ]
Clipboard User Service_31e79f [ cbdhsvc_31e79f ]
ConsentUX_31e79f [ ConsentUxUserSvc_31e79f ]
DevicePicker_31e79f [ DevicePickerUserSvc_31e79f ]
DevicesFlow_31e79f [ DevicesFlowUserSvc_31e79f ]
Contact Data_31e79f [ PimIndexMaintenanceSvc_31e79f ]
PrintWorkflow_31e79f [ PrintWorkflowUserSvc_31e79f ]
User Data Storage_31e79f [ UnistoreSvc_31e79f ]
User Data Access_31e79f [ UserDataSvc_31e79f ]
CaptureService_28b546d7 [ CaptureService_28b546d7 ]
Clipboard User Service_28b546d7 [ cbdhsvc_28b546d7 ]
ConsentUX_28b546d7 [ ConsentUxUserSvc_28b546d7 ]
DevicePicker_28b546d7 [ DevicePickerUserSvc_28b546d7 ]
DevicesFlow_28b546d7 [ DevicesFlowUserSvc_28b546d7 ]
Contact Data_28b546d7 [ PimIndexMaintenanceSvc_28b546d7 ]
PrintWorkflow_28b546d7 [ PrintWorkflowUserSvc_28b546d7 ]
User Data Storage_28b546d7 [ UnistoreSvc_28b546d7 ]
User Data Access_28b546d7 [ UserDataSvc_28b546d7 ]

92373 - Microsoft Windows SMB Sessions
-
Synopsis
Nessus was able to collect and report SMB session information from the remote host.
Description
Nessus was able to collect details of SMB sessions from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

tidua

Extended SMB session information attached.

23974 - Microsoft Windows SMB Share Hosting Office Files
-
Synopsis
The remote share contains Office-related files.
Description
This plugin connects to the remotely accessible SMB shares and attempts to find office related files (such as .doc, .ppt, .xls, .pdf etc).
Solution
Make sure that the files containing confidential information have proper access controls set on them.
Risk Factor
None
Plugin Information
Published: 2007/01/04, Modified: 2011/03/21
Plugin Output

tcp/445/cifs


Here is a list of office files which have been found on the remote SMB
shares :

+ D$ :

- D:\FileUpload\RMS\ClientWiseHoldReport.xls.xls
- D:\WebPortal_LKPNETIN\CTCL_Certificates\EQTU06052025.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160820.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160830.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160909.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160919.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160929.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20161009.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20161019.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20161029.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170127.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170206.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170216.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170226.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170308.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170318.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170328.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170407.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170626.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170706.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170716.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170726.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170805.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170817.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170825.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20171113.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20171123.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20171203.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20171213.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20171223.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180102.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180112.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180412.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180422.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180502.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180504.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180512.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180522.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180601.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160620.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160701.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160711.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160721.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160731.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160810.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160820.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20161108.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20161118.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20161128.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20161208.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20161218.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20161228.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170107.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170328.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170407.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170417.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170427.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170507.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170517.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170527.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170817.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170825.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170904.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170914.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170924.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20171123.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20171203.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20171213.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20171223.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180102.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180303.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180313.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180402.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180412.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180422.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180611.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180621.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180701.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180711.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180721.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160711.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160721.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160731.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160810.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160820.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20161019.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20161029.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20161108.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20161118.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20161128.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170127.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170206.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170216.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170226.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170308.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170507.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170517.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170527.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170606.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170616.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170817.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170825.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170904.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170914.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170924.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20171123.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20171203.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20171213.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20171223.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180102.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180303.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180313.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180402.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180412.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180422.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180502.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180701.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180711.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180721.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180731.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180810.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180621.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180611.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180601.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180522.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180512.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180504.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180221.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180211.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180201.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180122.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20180112.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20171113.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20171103.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20171024.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20171014.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20171004.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170805.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170726.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170716.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170706.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170626.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170427.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170417.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170407.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170328.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170318.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170117.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20170107.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20161228.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20161218.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20161208.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20161009.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160929.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160919.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160909.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160830.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160701.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\SMSText20160620.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\MarginShortfallSMS20160628.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180810.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180731.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180601.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180522.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180512.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180504.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180502.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180221.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180211.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180201.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180122.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20180112.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20171113.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20171103.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20171024.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20171014.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20171004.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170805.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170726.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170716.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170706.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170626.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170616.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170606.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170318.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170308.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170226.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170216.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170206.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170127.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20170117.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20161029.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20161019.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20161009.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160929.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160919.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160909.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalMobileBlank20160830.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180810.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180731.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180721.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180711.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180701.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180621.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180611.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180402.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180313.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180303.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180221.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180211.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180201.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20180122.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20171103.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20171024.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20171014.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20171004.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170924.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170914.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170904.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170616.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170606.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170527.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170517.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170507.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170427.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170417.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170117.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20170107.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20161228.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20161218.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20161208.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20161128.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20161118.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20161108.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160810.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160731.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160721.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160711.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160701.xls
- D:\WebPortal_LKPNETIN\SMSEmailSend\FinalEmailBlank20160620.xls
- D:\WebPortal_LKPNETIN\MF\Fund Tracker 8-jul.xls
- D:\WebPortal_LKPNETIN\CTCL_Certificates\EQTU09052025_3.xls
- D:\172.17.100.60\d$\FileUpload\Compliance\24409-PNL.xlsx
- D:\Backup\01042024_0952\Frontend\New\wwwroot\Files\RMSAllocation\CNC_DDMMYYYY_1.xlsx
- D:\Backup\01042024_0952\Frontend\New\wwwroot\Files\RMSAllocation\WebAllocation_DDMMYYYY_1.xlsx
- D:\Backup\01042024_0952\Frontend\Old\publish\wwwroot\Files\RMSAllocation\CNC_DDMMYYYY_1.xlsx
- D:\Backup\02022024_1709\Frontend\Old\wwwroot\Files\RMSAllocation\CNC_DDMMYYYY_1.xlsx
- D:\Backup\02022024_1709\Frontend\Old\wwwroot\Files\RMSAllocation\WebAllocation_DDMMYYYY_1.xlsx
- D:\Backup\02072024_1807\Frontend\New\wwwroot\Files\KRA\KRA_FORMAT.xlsx
- D:\Backup\02072024_1807\Frontend\New\wwwroot\Files\RMSAllocation\CNC_DDMMYYYY_1.xlsx
- D:\Backup\02072024_1807\Frontend\New\wwwroot\Files\RMSAllocation\WebAllocation_DDMMYYYY_1.xlsx
- D:\Backup\02072024_1807\Frontend\Old\publish\wwwroot\Files\RMSAllocation\CNC_DDMMYYYY_1.xlsx
- D:\Backup\02072024_1807\Frontend\Old\publish\wwwroot\Files\RMSAllocation\WebAllocation_DDMMYYYY_1.xlsx
- D:\Backup\02072024_1807\Frontend\Old\wwwroot\Files\RMSAllocation\CNC_DDMMYYYY_1.xlsx
- D:\Backup\02092024_1214\Frontend\New\wwwroot\Files\RMSAllocation\WebAllocation_DDMMYYYY_1.xlsx
- D:\Backup\02092024_1214\Frontend\Old\publish\wwwroot\Files\RMSAllocation\CNC_DDMMYYYY_1.xlsx


Note that Nessus has limited the report to 255 files although there
may be more.
11777 - Microsoft Windows SMB Share Hosting Possibly Copyrighted Material
-
Synopsis
The remote host may contain material (movies/audio) infringing copyright.
Description
This plugin displays a list of media files (such as .mp3, .ogg, .mpg, .avi) which have been found on the remote SMB shares.

Some of these files may contain copyrighted materials, such as commercial movies or music files, that are being shared without the owner's permission.

If any of these files actually contain copyrighted material, and if they are freely swapped around, your organization might be held liable for copyright infringement by associations such as the RIAA or the MPAA.
Solution
Delete the files infringing copyright.
Risk Factor
None
Plugin Information
Published: 2003/06/26, Modified: 2012/11/29
Plugin Output

tcp/445/cifs


Here is a list of files which have been found on the remote SMB shares.
Some of these files may contain copyrighted materials, such as commercial
movies or music files.

+ D$ :

D:\WebPortal_LKPNETIN\E-Induction-1\story_content\5apG7H0OuNF_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-1\story_content\5lzKavyaxIu_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-1\story_content\5rmUUFFz1QU_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-1\story_content\6jsJFCYkRyN_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-1\story_content\6L3S7C9mE6c_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-1\story_content\6mM8qE8qt09_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-1\story_content\6pCw0SkdFFt_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-1\story_content\6Ppha0dYxHM_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-1\story_content\6R6ki2eMv1k_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-1\story_content\6UaRwuZXFFq_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5a4ERUcXpse_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5byOTpITHUx_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5ccxYfqRVlW_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5cDcxChvoSI_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5cJBv9ZIAe6_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5cniqlZq42V_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5cNuKXAzMBD_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5dgLWeOZExm_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5dMlfpqms7A_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5fU2Ofbf7wm_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5ghbJx1nK0Y_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5gprBQwtAiX_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5hTVZWcheNi_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5hu4D5F5bTG_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5iaL5V6vBV7_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5iThslz1bjC_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5iZnjBzUO5J_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5kNraA0qt3M_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5kSMh9zuryQ_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5kuVqEmdx91_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5kzXblq0hla_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5lbcWlExWl9_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5lfvKs0Bd4C_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5lHlEynAxrI_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5lIrt91atUG_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5nqkM6rYRrn_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5nw7QVTQNA2_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5oNkFcSg3OG_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5opl9lkPKg1_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5osINuAB9XE_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5pDoY0ov0Ve_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5pR6ZwuX2QS_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5qF5Y3WyPOp_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5sJgHTNVnuz_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5sYkPTpaXNp_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5tTEU6VAH7L_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5tYm69UjdKH_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5v09cthpTDW_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5v4NiiMcuSd_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5V8YdYjn7kn_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5VbMIfhZ0oI_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5x7tW72zO17_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5xB65GshlZK_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5xBvJiTQXmh_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5XIO4R91Xff_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5XiOruSY7DE_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5xNuNtYTqSC_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5xStaITYnpv_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5YlxovlezlE_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5YmPzwHPQg7_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5YNd49uXUUU_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5zB0TbxxPkD_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5ZfHGYvp0n7_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5zJNy1JS4Bp_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5ZvGu5rlhpP_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\63hCDawRTHY_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\63OdFjgUAeB_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\63pqnkL66GN_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\63Q3TGiktEN_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\63VQNaKnhda_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\63YPEoEQiL2_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\647ertNAttI_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\686JRqdxgjd_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\68CVoX1xVRo_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\68MiCmGXLwc_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\68WbRplooE5_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\69hX9sOVys7_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\69iVgIEDc6b_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\69kB2qJ7geG_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6aTdYYFF15b_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6azGeyb3h0j_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6b2XKu14vpF_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6B60mqza121_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6B94uBNI8IU_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6BC22SqySeE_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6bfyN5Sm4iR_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6cZADsqEzbh_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6d0NxaTrzBS_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6D0rx3Lx4aB_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6dbffjnQ1Sk_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6DDiwWPIDUk_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6DEzGeqz6IK_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Dh2pw5TnHs_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6dx2UHxnhKW_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6E2hIkwWT2y_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6EJmiulxb62_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6EmjVllH3vP_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6EPKz5Yx8Bh_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6eWHvLvFoa2_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Exd2KKYL5f_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6fg6ftqXCQ5_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6fhX8tchv71_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6fIfvrzGf4K_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6fM0DDpEIlB_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6FNYjS1SNEM_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6gtfQIauUfi_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6H4m0i51eY5_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6h6hmckYxkx_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6H8knyMttSL_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6H9MPYd9K8W_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6HyzNMeZA6X_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6IR4bnQNkWP_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6iRTVpdZOqg_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6IVL6lfTGuP_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6IXhFaAYEQw_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6KdEt1JBVSF_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6KdwGYvxv6Q_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6kGA8ogx1aQ_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6kGPR9CICee_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6ki0ZbFNTkk_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6KyfAyTcwle_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6L0pGd8ST8o_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6L1inWGP139_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6L4vw319UfV_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6LgNPPfOqdE_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6mhdCT4OLPE_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6mkngyhougK_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6mL2TzbBK5t_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Mpjkpe8ddW_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6MsrFkIT0Gc_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6n1DxFI7okC_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6N6gOKIJcR9_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6NbyiIDtn72_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6NJpxYCkeVv_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6noJpbLMfmH_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6onhkYDjkyK_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6oOH4mFckpE_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6oTxXzIqTjf_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6p73SBng7az_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6pfyGavrqpc_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6QuFxkgRZKX_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6qW6W7hxdzz_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6R2oEop3RS9_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6r5BOELGn8F_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6r6dQ8sj7zH_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6rRBqQCHarV_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6RxhB2ZRKZd_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6SKxWZzsBjz_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6SnyPliwyI8_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6SsNnI29AuP_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6VpaqSrLCiI_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6VqcS42Eh94_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6VVKsjcsyGG_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6WaKTLmfsYW_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6WNebdY2m0O_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6WxpXUQAV7L_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6ZuvBBHI4xu_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Ztoy0volso_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Yw34YIaLrY_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6YCS8ZoGrpI_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6XuouTQO1Y2_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6VMfA4f2wWV_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6UKhH6DNjm4_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6UJvSFkj2hm_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6UErHXXIq1E_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Ub36fVDsw8_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6TjEmT89syR_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6RhMEhvdhWC_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6rdl6j60nLV_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6rCqATukJZy_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6rcotPoMDEf_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6RbJQbiuqBt_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6qrl7druwQD_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Pz68T6JU2v_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Pwk6wMKX27_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Pj33zLdqK7_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6pHUE6guztI_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6oInga8hdQN_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6OhIE6NQDXg_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6oF27S6YGcw_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6oAgKEyUUj5_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6nrGbebCaYt_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6N0Ol8rQi31_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6mzHO8jMWkl_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6mxrVHGGPBw_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6mWMj6cKGbi_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6mSuzz6ChqE_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6mExbuPg837_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6LxT8I2Xtgf_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6LSMqTELr1U_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6LKiTOZpoik_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6LgtKiaNB5W_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6KvxQelJo90_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6kuNd5iBDjT_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6kucWwfc3C6_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6KsYFuJv0R7_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6KirY7ofYYD_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6JZdRkcQK3B_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6JT3mqYtZ8r_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6JHcJj7UXBY_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6jdMviQOXlh_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6iZ0pPgqbB5_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6huNVsBCQkJ_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6hSviz6AwP1_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6hP3CrlJ2br_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6HKkVRrlFq8_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6hc94uPYVWR_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6GkjBzctbmO_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6gjpO1djh3v_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6geHTRQtKRs_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6FZk7TDA44e_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6FVnCx0eV2A_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6fFzwM0Ohdv_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6FdU4kCDLlN_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6FCiBWPCv5o_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6F5GWYs6s7b_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6f0AEX8pGl2_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Duco1ngdbG_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6dtG296apf2_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Ds0eURMDZa_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6DnoJLacp9A_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6dNcf9Rxpvv_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Dlin5SHhaU_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6DIfznFCWIX_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6cRgn7YtsOC_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6cNrteS4oDo_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6Cg3FIDcPfk_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6ccHFUlEctz_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6bwEciaqlEw_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6BJCfJE61Hz_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6BIZ27WGvcO_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6ArJ1ACxfHF_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6aRHaYyFzmd_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6aoh9F84VDY_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\6aOCEpIx3kq_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\69ZmA65Uer7_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\69XkYgfXDrU_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\69okx4OEDe2_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\67INM36LeZG_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\67IMGOIZCjI_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\66B2IvZHIDC_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\667gtpEWJqV_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\65qsXTbJ21y_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\65mqzvlSMol_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\64OGdku9DjG_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\63GPe3CH7lJ_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\62NBrABnzbq_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\62eJk7ZuRrB_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\62BXM7t5M9S_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\61JBUZFUUg9_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\60MeMbleLFi_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\60E4AKTAXpd_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5yEPDkQbTCC_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5YEDqF01lK3_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5YBtWjBPfUt_22050_64.mp3
D:\WebPortal_LKPNETIN\E-Induction-2\story_content\5y8GBap1o4l_22050_64.mp3

10396 - Microsoft Windows SMB Shares Access
-
Synopsis
It is possible to access a network share.
Description
The remote has one or more Windows shares that can be accessed through the network with the given credentials.

Depending on the share rights, it may allow an attacker to read / write confidential data.
Solution
To restrict access under Windows, open Explorer, do a right click on each share, go to the 'sharing' tab, and click on 'permissions'.
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following shares can be accessed as tidua :

- E$ - (readable,writable)
+ Content of this share :
Database Backup
System Volume Information

- D$ - (readable,writable)
+ Content of this share :
172.17.100.60
172.17.100.60d$WebPortalIntranet_NewFilesVendorMasterTDS
Backup
Build
CheckAPIAccessibility
FileUpload
IPO_RemarkStatus_Update
IPO_WEBSITE
Lkp Api Engine
LKP IVR FrontEnd
LKPSOFT
LKP_IVR_Frontend_Commodity
LKP_Middleware_API_Dubbeging
Logs
Mf Backups
MF WebAPI Live Backup
MFSinglePaymentFiles
MFWebAPI
MFWebAPI-LIVE
MFWebAPI-LIVE - Copy
middleware
middleware - Copy
Middleware API 15052025
Middleware API Backup
middleware deployment command.txt
MiddlewareAPI_backup
Middleware_Api
Middleware_Api Backup.rar
Middleware_Api_01122025.rar
Middleware_Api_05122025.rar
Middleware_Api_08012026.rar
Middleware_Api_10112025.rar
Middleware_Api_10122025.rar
Middleware_Api_12112025.rar
Middleware_Api_12122025.rar
Middleware_Api_14112025.rar
Middleware_Api_26112025.rar
Middleware_Api_27102025_01.rar
Middleware_Api_28112025.rar
Middleware_Api_30102025.rar
Middleware_Api_UAT
Middleware_Frontend
Middleware_Frontend - 06052025
New folder
New folder (2)
New folder (3)
PennyPalBackup
PennyPalContest

- C$ - (readable,writable)
+ Content of this share :
digio-ckyc
Documents and Settings
inetpub
Java CAPS
Logs
MSOCache
pagefile.sys
PerfLogs
Program Files
Program Files (x86)
ProgramData
Recovery
System Volume Information
Users
Windows

- ADMIN$ - (readable,writable)
+ Content of this share :
..
ADFS
appcompat
apppatch
AppReadiness
assembly
bcastdvr
bfsvc.exe
Boot
bootstat.dat
Branding
CbsTemp
Containers
CSC
Cursors
debug
DfsrAdmin.exe
DfsrAdmin.exe.config
diagnostics
DigitalLocker
Downloaded Program Files
drivers
DtcInstall.log
ELAMBKUP
en-US
explorer.exe
Fonts
Globalization
Help
HelpPane.exe
hh.exe
IdentityCRL
iis.log
IME
ImmersiveControlPanel
INF
InputMethod
Installer
L2Schemas
LiveKernelReports
Logs
lsasetup.log
media
mib.bin
Microsoft.NET
Migration
ModemLogs
notepad.exe
OCR
Offline Web Pages
Panther
PCHEALTH
Performance
PFRO.log
PLA
PolicyDefinitions
Prefetch
PrintDialog
Provisioning
regedit.exe
Registration
RemotePackages
rescache
Resources
SchCache
schemas
security
ServerDataCenter.xml
ServiceProfiles
ServiceState
servicing
Setup
setuperr.log
ShellComponents
ShellExperiences
SKB
SoftwareDistribution
Speech
Speech_OneCore
splwow64.exe
System
system.ini
System32
SystemApps
SystemResources
SystemTemp
SysWOW64
TAPI
Tasks
Temp
TextInput
tracing
twain_32
twain_32.dll
Vss
WaaS
10395 - Microsoft Windows SMB Shares Enumeration
-
Synopsis
It is possible to enumerate remote network shares.
Description
By connecting to the remote host, Nessus was able to enumerate the network share names.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Here are the SMB shares available on the remote host when logged in as tidua:

- ADMIN$
- C$
- D$
- E$
- IPC$
100871 - Microsoft Windows SMB Versions Supported (remote check)
-
Synopsis
It was possible to obtain information about the version of SMB running on the remote host.
Description
Nessus was able to obtain the version of SMB running on the remote host by sending an authentication request to port 139 or 445.

Note that this plugin is a remote check and does not work on agents.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/06/19, Modified: 2019/11/22
Plugin Output

tcp/445/cifs


The remote host supports the following versions of SMB :
SMBv2
106716 - Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)
-
Synopsis
It was possible to obtain information about the dialects of SMB2 and SMB3 available on the remote host.
Description
Nessus was able to obtain the set of SMB2 and SMB3 dialects running on the remote host by sending an authentication request to port 139 or 445.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/09, Modified: 2020/03/11
Plugin Output

tcp/445/cifs


The remote host supports the following SMB dialects :
_version_ _introduced in windows version_
2.0.2 Windows 2008
2.1 Windows 7
3.0 Windows 8
3.0.2 Windows 8.1
3.1.1 Windows 10

The remote host does NOT support the following SMB dialects :
_version_ _introduced in windows version_
2.2.2 Windows 8 Beta
2.2.4 Windows 8 Beta
3.1 Windows 10

92368 - Microsoft Windows Scripting Host Settings
-
Synopsis
Nessus was able to collect and report the Windows scripting host settings from the remote host.
Description
Nessus was able to collect system and user level Windows scripting host settings from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\activedebugging : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\activedebugging : 1

Windows scripting host configuration attached.

200493 - Microsoft Windows Start Menu Software Version Enumeration
-
Synopsis
Enumerates Start Menu software versions.
Description
This plugin enumerates the installed software version by interrogating information obtained from various registry entries and files on disk. This plugin provides a best guess at the software version and a confidence level for that version.

Note that the versions detected here do not necessarily indicate the actual installed version nor do they necessarily mean that the application is actually installed on the remote host. In some cases there may be artifacts left behind by uninstallers on the system.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2024/06/13, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following software information is available on the remote host :

- Blend for Visual Studio 2022.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Blend for Visual Studio 2022.lnk
Target : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\Blend.exe
Version : 17.8.34330.188

- Google Chrome.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Google Chrome.lnk
Target : C:\Program Files\Google\Chrome\Application\chrome.exe
Version : 143.0.7499.193

- Immersive Control Panel.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Immersive Control Panel.lnk
Target : C:\Windows\System32\Control.exe
Version : 10.0.17763.2300

- Server Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Server Manager.lnk
Target : C:\Windows\system32\ServerManager.exe
Version : 10.0.17763.168

- Visual Studio 2017.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Visual Studio 2017.lnk
Target : C:\Program Files (x86)\Microsoft Visual Studio\2017\Professional\Common7\IDE\devenv.exe
Version : 15.0.26730.8

- Visual Studio 2022.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Visual Studio 2022.lnk
Target : C:\Program Files\Microsoft Visual Studio\2022\Professional\Common7\IDE\devenv.exe
Version : 17.8.34330.188

- Visual Studio Installer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Visual Studio Installer.lnk
Target : C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe
Version : 3.8.2112.61926

- Speech Recognition.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessibility\Speech Recognition.lnk
Target : C:\Windows\Speech\Common\sapisvr.exe
Version : 5.3.22514.0

- Calculator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Calculator.lnk
Target : C:\Windows\system32\win32calc.exe
Version : 10.0.17763.4377

- Math Input Panel.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Math Input Panel.lnk
Target : C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe
Version : 10.0.17763.1697

- Paint.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Paint.lnk
Target : C:\Windows\system32\mspaint.exe
Version : 10.0.17763.1697

- Remote Desktop Connection.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Remote Desktop Connection.lnk
Target : C:\Windows\system32\mstsc.exe
Version : 10.0.17763.2867

- Snipping Tool.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Snipping Tool.lnk
Target : C:\Windows\system32\SnippingTool.exe
Version : 10.0.17763.1697

- Steps Recorder.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Steps Recorder.lnk
Target : C:\Windows\system32\psr.exe
Version : 10.0.17763.1697

- Windows Media Player.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Windows Media Player.lnk
Target : C:\Program Files (x86)\Windows Media Player\wmplayer.exe
Version : 12.0.17763.1

- Wordpad.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Wordpad.lnk
Target : C:\Program Files\Windows NT\Accessories\wordpad.exe
Version : 10.0.17763.2989

- XPS Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\XPS Viewer.lnk
Target : C:\Windows\system32\xpsrchvw.exe
Version : 10.0.17763.4492

- Character Map.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\System Tools\Character Map.lnk
Target : C:\Windows\system32\charmap.exe
Version : 5.2.3668.0

- Windows Server Backup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\System Tools\Windows Server Backup.lnk
Target : C:\Windows\system32\wbadmin.msc
Version : unknown

- Acronis Cyber Protect Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Acronis\Acronis Cyber Protect Monitor.lnk
Target : C:\Program Files\BackupClient\TrayMonitor\MmsMonitor.exe
Version : 23.9.883.0

- Component Services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Component Services.lnk
Target : C:\Windows\system32\comexp.msc
Version : unknown

- Computer Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Computer Management.lnk
Target : C:\Windows\system32\compmgmt.msc
Version : unknown

- dfrgui.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\dfrgui.lnk
Target : C:\Windows\system32\dfrgui.exe
Version : 10.0.17763.1697

- Disk Cleanup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Disk Cleanup.lnk
Target : C:\Windows\system32\cleanmgr.exe
Version : 10.0.17763.1

- Event Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Event Viewer.lnk
Target : C:\Windows\system32\eventvwr.msc
Version : unknown

- IIS Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\IIS Manager.lnk
Target : C:\Windows\system32\inetsrv\InetMgr.exe
Version : 10.0.17763.4492

- IIS6 Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\IIS6 Manager.lnk
Target : C:\Windows\system32\inetsrv\InetMgr6.exe
Version : 10.0.17763.1

- iSCSI Initiator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\iSCSI Initiator.lnk
Target : C:\Windows\system32\iscsicpl.exe
Version : 10.0.17763.1

- Memory Diagnostics Tool.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Memory Diagnostics Tool.lnk
Target : C:\Windows\system32\MdSched.exe
Version : 10.0.17763.1

- Microsoft Azure services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Microsoft Azure services.lnk
Target : C:\Windows\explorer.exe
Version : 10.0.17763.3887

- ODBC Data Sources (32-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\ODBC Data Sources (32-bit).lnk
Target : C:\Windows\syswow64\odbcad32.exe
Version : 10.0.17763.1

- ODBC Data Sources (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\ODBC Data Sources (64-bit).lnk
Target : C:\Windows\system32\odbcad32.exe
Version : 10.0.17763.1

- Performance Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Performance Monitor.lnk
Target : C:\Windows\system32\perfmon.msc
Version : unknown

- Print Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Print Management.lnk
Target : C:\Windows\system32\printmanagement.msc
Version : unknown

- RecoveryDrive.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\RecoveryDrive.lnk
Target : C:\Windows\system32\RecoveryDrive.exe
Version : 10.0.17763.2183

- Registry Editor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Registry Editor.lnk
Target : C:\Windows\regedit.exe
Version : 10.0.17763.1697

- Resource Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Resource Monitor.lnk
Target : C:\Windows\system32\perfmon.exe
Version : 10.0.17763.1

- Security Configuration Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Security Configuration Management.lnk
Target : C:\Windows\system32\secpol.msc
Version : unknown

- Server Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Server Manager.lnk
Target : C:\Windows\system32\ServerManager.exe
Version : 10.0.17763.168

- services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\services.lnk
Target : C:\Windows\system32\services.msc
Version : unknown

- System Configuration.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\System Configuration.lnk
Target : C:\Windows\system32\msconfig.exe
Version : 10.0.17763.2061

- System Information.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\System Information.lnk
Target : C:\Windows\system32\msinfo32.exe
Version : 10.0.17763.2145

- Task Scheduler.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Task Scheduler.lnk
Target : C:\Windows\system32\taskschd.msc
Version : unknown

- Windows Defender Firewall with Advanced Security.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk
Target : C:\Windows\system32\WF.msc
Version : unknown

- Windows Server Backup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Windows Server Backup.lnk
Target : C:\Windows\system32\wbadmin.msc
Version : unknown

- Azure Data Studio.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Azure Data Studio\Azure Data Studio.lnk
Target : C:\Program Files\Azure Data Studio\azuredatastudio.exe
Version : 1.44.0.0

- Kaspersky Endpoint Security for Windows.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Kaspersky Endpoint Security for Windows\Kaspersky Endpoint Security for Windows.lnk
Target : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpui.exe
Version : 21.15.8.493

- Microsoft Azure Compute Emulator - v2.9.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Azure\Emulator\Microsoft Azure Compute Emulator - v2.9.lnk
Target : C:\Windows\Installer\{BB44C8F9-C555-45CF-B6DA-80131B139165}\DFIcon.exe
Version : unknown

- Documentation.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Azure\Microsoft Azure SDK for .NET\v2.9\Documentation.lnk
Target : C:\Windows\Installer\{086C537B-DE1A-4A11-8441-6AAF076174B8}\HLPIcon.exe
Version : unknown

- Microsoft Azure Command Prompt - v2.9.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Azure\Microsoft Azure SDK for .NET\v2.9\Microsoft Azure Command Prompt - v2.9.lnk
Target : C:\Windows\System32\cmd.exe
Version : 10.0.17763.1697

- Microsoft Azure HPC Scheduler SDK Content.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Azure\Microsoft Azure SDK for .NET\v2.9\Microsoft Azure HPC Scheduler SDK Content.lnk
Target : C:\Windows\Installer\{086C537B-DE1A-4A11-8441-6AAF076174B8}\WAIcon.exe
Version : unknown

- Release Notes.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Azure\Microsoft Azure SDK for .NET\v2.9\Release Notes.lnk
Target : C:\Windows\Installer\{086C537B-DE1A-4A11-8441-6AAF076174B8}\RELNIcon.exe
Version : unknown

- Samples.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Azure\Microsoft Azure SDK for .NET\v2.9\Samples.lnk
Target : C:\Windows\Installer\{086C537B-DE1A-4A11-8441-6AAF076174B8}\WAIcon.exe
Version : unknown

- Microsoft Azure Storage Emulator - v5.1.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Azure\Storage Emulator\Microsoft Azure Storage Emulator - v5.1.lnk
Target : C:\Windows\Installer\{B3C44E2A-BC4A-48D9-9AEF-6223C8775B7C}\AzureStorageEmulator.exe
Version : 5.1.17060.1722

- Microsoft Excel 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Excel 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\xlicons.exe
Version : 14.0.6009.1000

- Microsoft Outlook 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Outlook 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\outicon.exe
Version : 14.0.6009.1000

- Microsoft Publisher 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Publisher 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\pubs.exe
Version : 14.0.6009.1000

- Microsoft Word 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Word 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\wordicon.exe
Version : 14.0.6009.1000

- Digital Certificate for VBA Projects.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Digital Certificate for VBA Projects.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\misc.exe
Version : 14.0.6009.1000

- Microsoft Clip Organizer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Clip Organizer.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\cagicon.exe
Version : 14.0.6009.1000

- Microsoft Office 2010 Language Preferences.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office 2010 Language Preferences.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\misc.exe
Version : 14.0.6009.1000

- Microsoft Office 2010 Upload Center.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office 2010 Upload Center.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\msouc.exe
Version : 14.0.6009.1000

- Microsoft Office Picture Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office Picture Manager.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\oisicon.exe
Version : 14.0.6009.1000

- SQL Server 2019 Import and Export Data (32-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\SQL Server 2019 Import and Export Data (32-bit).lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\DTSWizard.exe
Version : 15.0.2000.5

- SQL Server 2019 Import and Export Data (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\SQL Server 2019 Import and Export Data (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\150\DTS\Binn\DTSWizard.exe
Version : 15.0.2000.5

- SQL Server 2019 Configuration Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Configuration Manager.lnk
Target : C:\Windows\SysWOW64\mmc.exe
Version : 10.0.17763.1697

- SQL Server 2019 Error and Usage Reporting.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Error and Usage Reporting.lnk
Target : C:\Program Files\Microsoft SQL Server\150\Shared\SqlWtsn.exe
Version : 15.0.2000.5

- SQL Server 2019 Installation Center (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Installation Center (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\LandingPage.exe
Version : 15.0.2000.5

- SQL Server 2019 Data Quality Client.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Data Quality Services\SQL Server 2019 Data Quality Client.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\DQ\DataQualityServices.exe
Version : 15.0.2000.5

- SQL Server 2019 Data Quality Server Installer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Data Quality Services\SQL Server 2019 Data Quality Server Installer.lnk
Target : C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\DQSInstaller.exe
Version : 15.0.2000.5

- Analysis Services Deployment Wizard 19.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 19\Analysis Services Deployment Wizard 19.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 19\Common7\IDE\Microsoft.AnalysisServices.Deployment.exe
Version : 16.0.20010.0

- SQL Server Management Studio Management Studio 19.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 19\SQL Server Management Studio Management Studio 19.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 19\Common7\IDE\Ssms.exe
Version : 19.1.56.0

- Database Engine Tuning Advisor 19.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 19\Performance Tools\Database Engine Tuning Advisor 19.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 19\Common7\DTASHELL.EXE
Version : 19.1.56.0

- SQL Server Profiler 19.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 19\Performance Tools\SQL Server Profiler 19.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 19\Common7\PROFILER.EXE
Version : 2022.160.4001.1

- Install Additional Tools for Node.js.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Node.js\Install Additional Tools for Node.js.lnk
Target : C:\Windows\SysWOW64\cmd.exe
Version : 10.0.17763.1697

- Node.js command prompt.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Node.js\Node.js command prompt.lnk
Target : C:\Windows\SysWOW64\cmd.exe
Version : 10.0.17763.1697

- Node.js.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Node.js\Node.js.lnk
Target : C:\Program Files (x86)\nodejs\node.exe
Version : 18.16.1.0

- Uninstall Node.js.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Node.js\Uninstall Node.js.lnk
Target : C:\Windows\SysWOW64\msiexec.exe
Version : 5.0.17763.4644

- VNC Address Book.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\VNC Address Book.lnk
Target : C:\Program Files\RealVNC\VNC4\vncaddrbook.exe
Version : 4.6.1.54321

- VNC Server.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\VNC Server.lnk
Target : C:\Program Files\RealVNC\VNC4\winvnc4.exe
Version : 4.6.1.54321

- VNC Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\VNC Viewer.lnk
Target : C:\Program Files\RealVNC\VNC4\vncviewer.exe
Version : 4.6.1.54321

- Enter VNC Server License Key.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\Advanced\Enter VNC Server License Key.lnk
Target : C:\Program Files\RealVNC\VNC4\vncconfig.exe
Version : 4.6.1.54321

- Start Listening VNC Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\Advanced\Start Listening VNC Viewer.lnk
Target : C:\Program Files\RealVNC\VNC4\vncviewer.exe
Version : 4.6.1.54321

- VNC Server (User Mode).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\Advanced\VNC Server (User Mode).lnk
Target : C:\Program Files\RealVNC\VNC4\winvnc4.exe
Version : 4.6.1.54321

- Task Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\System Tools\Task Manager.lnk
Target : C:\Windows\system32\taskmgr.exe
Version : 10.0.17763.2989

- Debuggable Package Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Visual Studio 2017\Visual Studio Tools\Debuggable Package Manager.lnk
Target : C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Version : 10.0.17763.1

- Developer Command Prompt for VS 2017.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Visual Studio 2017\Visual Studio Tools\Developer Command Prompt for VS 2017.lnk
Target : C:\Windows\System32\cmd.exe
Version : 10.0.17763.1697

- Debuggable Package Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Visual Studio 2022\Visual Studio Tools\Debuggable Package Manager.lnk
Target : C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Version : 10.0.17763.1

- Developer Command Prompt for VS 2022.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Visual Studio 2022\Visual Studio Tools\Developer Command Prompt for VS 2022.lnk
Target : C:\Windows\System32\cmd.exe
Version : 10.0.17763.1697

- Developer PowerShell for VS 2022.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Visual Studio 2022\Visual Studio Tools\Developer PowerShell for VS 2022.lnk
Target : C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Version : 10.0.17763.1

- start VM Statistics Logging.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\VMware\VMware Tools\start VM Statistics Logging.lnk
Target : C:\Windows\System32\perfmon.msc
Version : unknown

- Console RAR manual.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\Console RAR manual.lnk
Target : C:\Program Files\WinRAR\Rar.txt
Version : unknown

- What is new in the latest version.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\What is new in the latest version.lnk
Target : C:\Program Files\WinRAR\WhatsNew.txt
Version : unknown

- WinRAR help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\WinRAR help.lnk
Target : C:\Program Files\WinRAR\WinRAR.chm
Version : unknown

- WinRAR.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\WinRAR.lnk
Target : C:\Program Files\WinRAR\WinRAR.exe
Version : 5.90.0.0
58452 - Microsoft Windows Startup Software Enumeration
-
Synopsis
It is possible to enumerate startup software.
Description
This plugin lists software that is configured to run on system startup by crawling the registry entries in :

- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersi on\Run
Solution
Review the list of applications and remove any that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/03/23, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following startup item was found :

Acronis Scheduler2 Service - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
AcronisTibMounterMonitor - C:\Program Files (x86)\Common Files\Acronis\TibMounter\tib_mounter_monitor.exe
MmsMonitor.exe - C:\Program Files\BackupClient\TrayMonitor\MmsMonitor.exe
SecurityHealth - %windir%\system32\SecurityHealthSystray.exe
VMware User Process - C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
38153 - Microsoft Windows Summary of Missing Patches
-
Synopsis
The remote host is missing several Microsoft security patches.
Description
This plugin summarizes updates for Microsoft Security Bulletins or Knowledge Base (KB) security updates that have not been installed on the remote Windows host based on the results of either a credentialed check using the supplied credentials or a check done using a supported third-party patch management tool.

Note the results of missing patches also include superseded patches.

Review the summary and apply any missing updates in order to be up to date.
Solution
Run Windows Update on the remote host or use a patch management solution.
Risk Factor
None
Plugin Information
Published: 2009/04/24, Modified: 2019/06/13
Plugin Output

tcp/445/cifs

The patches for the following bulletins or KBs are missing on the remote host :

- MS11-073 ( http://technet.microsoft.com/en-us/security/bulletin/ms11-073 )
- MS11-089 ( http://technet.microsoft.com/en-us/security/bulletin/ms11-089 )
- MS12-027 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-027 )
- MS12-057 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-057 )
- MS12-060 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-060 )
- MS12-064 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-064 )
- MS12-079 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-079 )
- MS13-072 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-072 )
- MS13-074 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-074 )
- MS13-106 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-106 )
- MS14-001 ( http://technet.microsoft.com/en-us/security/bulletin/ms14-001 )
- MS14-017 ( http://technet.microsoft.com/en-us/security/bulletin/ms14-017 )
- MS14-024 ( http://technet.microsoft.com/en-us/security/bulletin/ms14-024 )
- KB4552930 ( https://support.microsoft.com/en-us/help/4552930 )
- KB4565632 ( https://support.microsoft.com/en-us/help/4565632 )
- KB4569750 ( https://support.microsoft.com/en-us/help/4569750 )
- KB4576483 ( https://support.microsoft.com/en-us/help/4576483 )
- KB4578973 ( https://support.microsoft.com/en-us/help/4578973 )
- KB4601055 ( https://support.microsoft.com/en-us/help/4601055 )
- KB5008878 ( https://support.microsoft.com/en-us/help/5008878 )
- KB5012119 ( https://support.microsoft.com/en-us/help/5012119 )
- KB5013626 ( https://support.microsoft.com/en-us/help/5013626 )
- KB5020615 ( https://support.microsoft.com/en-us/help/5020615 )
- KB5020874 ( https://support.microsoft.com/en-us/help/5020874 )
- KB5022504 ( https://support.microsoft.com/en-us/help/5022504 )
- KB5027124 ( https://support.microsoft.com/en-us/help/5027124 )
- KB5028953 ( https://support.microsoft.com/en-us/help/5028953 )
- KB5029925 ( https://support.microsoft.com/en-us/help/5029925 )
- KB5030214 ( https://support.microsoft.com/en-us/help/5030214 )
- KB5031361 ( https://support.microsoft.com/en-us/help/5031361 )
- KB5031990 ( https://support.microsoft.com/en-us/help/5031990 )
- KB5032196 ( https://support.microsoft.com/en-us/help/5032196 )
- KB5033371 ( https://support.microsoft.com/en-us/help/5033371 )
- KB5033911 ( https://support.microsoft.com/en-us/help/5033911 )
- KB5034127 ( https://support.microsoft.com/en-us/help/5034127 )
- KB5034768 ( https://support.microsoft.com/en-us/help/5034768 )
- KB5035849 ( https://support.microsoft.com/en-us/help/5035849 )
- KB5036610 ( https://support.microsoft.com/en-us/help/5036610 )
- KB5036896 ( https://support.microsoft.com/en-us/help/5036896 )
- KB5037765 ( https://support.microsoft.com/en-us/help/5037765 )
- KB5039705 ( https://support.microsoft.com/en-us/help/5039705 )
- KB5039217 ( https://support.microsoft.com/en-us/help/5039217 )
- KB5039886 ( https://support.microsoft.com/en-us/help/5039886 )
- KB5040430 ( https://support.microsoft.com/en-us/help/5040430 )
- KB5041578 ( https://support.microsoft.com/en-us/help/5041578 )
- KB5043050 ( https://support.microsoft.com/en-us/help/5043050 )
- KB5044022 ( https://support.microsoft.com/en-us/help/5044022 )
- KB5044277 ( https://support.microsoft.com/en-us/help/5044277 )
- KB5046615 ( https://support.microsoft.com/en-us/help/5046615 )
- KB5048661 ( https://support.microsoft.com/en-us/help/5048661 )
- KB5049615 ( https://support.microsoft.com/en-us/help/5049615 )
- KB5050008 ( https://support.microsoft.com/en-us/help/5050008 )
- KB5052000 ( https://support.microsoft.com/en-us/help/5052000 )
- KB5053596 ( https://support.microsoft.com/en-us/help/5053596 )
- KB5055519 ( https://support.microsoft.com/en-us/help/5055519 )
- KB5058392 ( https://support.microsoft.com/en-us/help/5058392 )
- KB5060531 ( https://support.microsoft.com/en-us/help/5060531 )
- KB5062557 ( https://support.microsoft.com/en-us/help/5062557 )
- KB5063877 ( https://support.microsoft.com/en-us/help/5063877 )
- KB5065428 ( https://support.microsoft.com/en-us/help/5065428 )
- KB5066586 ( https://support.microsoft.com/en-us/help/5066586 )
- KB5068791 ( https://support.microsoft.com/en-us/help/5068791 )
- KB5071544 ( https://support.microsoft.com/en-us/help/5071544 )

92369 - Microsoft Windows Time Zone Information
-
Synopsis
Nessus was able to collect and report time zone information from the remote host.
Description
Nessus was able to collect time zone information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2023/06/06
Plugin Output

tcp/0

HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\TimeZoneKeyName : India Standard Time
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardName : @tzres.dll,-492
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightName : @tzres.dll,-491
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DynamicDaylightTimeDisabled : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardBias : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightBias : 0xFFFFFFC4
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\Bias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\ActiveTimeBias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightStart : 00000000000000000000000000000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardStart : 00000000000000000000000000000000
19506 - Nessus Scan Information
-
Synopsis
This plugin displays information about the Nessus scan.
Description
This plugin displays, for each tested host, information about the scan itself :

- The version of the plugin set.
- The type of scanner (Nessus or Nessus Home).
- The version of the Nessus Engine.
- The port scanner(s) used.
- The port range scanned.
- The ping round trip time
- Whether credentialed or third-party patch management checks are possible.
- Whether the display of superseded patches is enabled
- The date of the scan.
- The duration of the scan.
- The number of hosts scanned in parallel.
- The number of checks done in parallel.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/08/26, Modified: 2025/10/29
Plugin Output

tcp/0

Information about this scan :

Nessus version : 10.11.1
Nessus build : 20021
Plugin feed version : 202601041845
Scanner edition used : Nessus
Scanner OS : WINDOWS
Scanner distribution : win-x86-64
Scan type : Normal
Scan name : Server 2
Scan policy used : Server
Scanner IP : 172.17.100.38
Port scanner(s) : wmi_netstat
Port range : 1-65535
Ping RTT : Unavailable
Thorough tests : no
Experimental tests : no
Scan for Unpatched Vulnerabilities : yes
Plugin debugging enabled : yes (at debugging level 4)
Paranoia level : 0
Report verbosity : 2
Safe checks : yes
Optimize the test : yes
Credentialed checks : yes, as '172.17.100.112\tidua' via SMB
Patch management checks : None
Display superseded patches : yes (supersedence plugin did not launch)
CGI scanning : disabled
Web application tests : disabled
Max hosts : 2
Max checks : 2
Recv timeout : 5
Backports : None
Allow post-scan editing : Yes
Nessus Plugin Signature Checking : Enabled
Audit File Signature Checking : Disabled
Scan Start Date : 2026/1/12 17:58 India Standard Time (UTC +05:30)
Scan duration : 2276 sec
Scan for malware : no
58651 - Netstat Active Connections
-
Synopsis
Active connections are enumerated via the 'netstat' command.
Description
This plugin runs 'netstat' on the remote machine to enumerate all active 'ESTABLISHED' or 'LISTENING' tcp/udp connections.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/04/10, Modified: 2021/06/29
Plugin Output

tcp/0


Netstat output :

Active Connections

Proto Local Address Foreign Address State PID
TCP 0.0.0.0:80 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1128
TCP 0.0.0.0:443 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:1433 0.0.0.0:0 LISTENING 5680
TCP 0.0.0.0:2383 0.0.0.0:0 LISTENING 6080
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING 1348
TCP 0.0.0.0:5357 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:5800 0.0.0.0:0 LISTENING 4592
TCP 0.0.0.0:5900 0.0.0.0:0 LISTENING 4592
TCP 0.0.0.0:5985 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:6111 0.0.0.0:0 LISTENING 7336
TCP 0.0.0.0:18018 0.0.0.0:0 LISTENING 6316
TCP 0.0.0.0:47001 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING 920
TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING 1480
TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING 1948
TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING 2820
TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING 3288
TCP 0.0.0.0:49669 0.0.0.0:0 LISTENING 3080
TCP 0.0.0.0:49742 0.0.0.0:0 LISTENING 220
TCP 0.0.0.0:49833 0.0.0.0:0 LISTENING 180
TCP 0.0.0.0:57281 0.0.0.0:0 LISTENING 3540
TCP 127.0.0.1:1434 0.0.0.0:0 LISTENING 5680
TCP 127.0.0.1:1550 0.0.0.0:0 LISTENING 3676
TCP 127.0.0.1:1551 0.0.0.0:0 LISTENING 3676
TCP 127.0.0.1:6109 0.0.0.0:0 LISTENING 5272
TCP 127.0.0.1:6111 127.0.0.1:59567 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59568 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59572 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59573 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59576 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59577 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59582 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59584 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59588 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59590 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59597 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59598 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59600 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59606 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59609 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59611 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59612 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59615 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59617 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59619 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59621 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59623 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59624 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59628 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59629 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59631 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59634 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59639 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59641 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59643 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59645 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59647 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59648 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59650 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59660 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59663 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59665 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59666 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59670 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59672 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59674 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59676 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59678 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59680 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59683 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59684 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59686 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59687 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59690 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59692 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59694 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59696 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59698 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59699 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59703 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59709 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59712 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59714 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59715 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59723 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59725 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59727 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59730 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59732 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59734 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59737 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59738 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59740 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59741 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59746 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59747 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59749 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59751 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59753 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59754 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59756 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59762 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59764 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59766 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59767 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59771 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59772 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59774 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:59781 TIME_WAIT 0
TCP 127.0.0.1:6888 0.0.0.0:0 LISTENING 6316
TCP 127.0.0.1:9771 0.0.0.0:0 LISTENING 7000
TCP 127.0.0.1:9771 127.0.0.1:49686 ESTABLISHED 7000
TCP 127.0.0.1:9850 0.0.0.0:0 LISTENING 1448
TCP 127.0.0.1:30523 0.0.0.0:0 LISTENING 3676
TCP 127.0.0.1:43234 0.0.0.0:0 LISTENING 1448
TCP 127.0.0.1:49394 127.0.0.1:49670 ESTABLISHED 7000
TCP 127.0.0.1:49670 0.0.0.0:0 LISTENING 3476
TCP 127.0.0.1:49670 127.0.0.1:49394 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:49691 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:49693 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:49696 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:49709 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:49710 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:49719 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:49938 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:49952 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:49989 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:50032 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:50033 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:50170 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:50172 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:50173 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:50174 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:50177 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:50178 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:50182 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:51268 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:52703 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:52704 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:52705 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:52707 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:52711 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:54415 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:54768 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:54961 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:56139 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:58159 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:58421 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:58849 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:59250 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:59571 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59602 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59627 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59636 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59675 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59682 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59701 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:59702 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:59717 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59728 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59736 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59743 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59750 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59758 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59769 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59775 TIME_WAIT 0
TCP 127.0.0.1:49670 127.0.0.1:59776 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:59777 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:59778 ESTABLISHED 3476
TCP 127.0.0.1:49670 127.0.0.1:63084 ESTABLISHED 3476
TCP 127.0.0.1:49673 0.0.0.0:0 LISTENING 7036
TCP 127.0.0.1:49673 127.0.0.1:49678 ESTABLISHED 7036
TCP 127.0.0.1:49678 127.0.0.1:49673 ESTABLISHED 3476
TCP 127.0.0.1:49679 0.0.0.0:0 LISTENING 7448
TCP 127.0.0.1:49679 127.0.0.1:49763 ESTABLISHED 7448
TCP 127.0.0.1:49684 0.0.0.0:0 LISTENING 6972
TCP 127.0.0.1:49684 127.0.0.1:49692 ESTABLISHED 6972
TCP 127.0.0.1:49686 127.0.0.1:9771 ESTABLISHED 3476
TCP 127.0.0.1:49691 127.0.0.1:49670 ESTABLISHED 6316
TCP 127.0.0.1:49692 127.0.0.1:49684 ESTABLISHED 3476
TCP 127.0.0.1:49693 127.0.0.1:49670 ESTABLISHED 6316
TCP 127.0.0.1:49696 127.0.0.1:49670 ESTABLISHED 7252
TCP 127.0.0.1:49697 0.0.0.0:0 LISTENING 7252
TCP 127.0.0.1:49697 127.0.0.1:49708 ESTABLISHED 7252
TCP 127.0.0.1:49698 0.0.0.0:0 LISTENING 7152
TCP 127.0.0.1:49698 127.0.0.1:58837 ESTABLISHED 7152
TCP 127.0.0.1:49698 127.0.0.1:59046 ESTABLISHED 7152
TCP 127.0.0.1:49698 127.0.0.1:59399 ESTABLISHED 7152
TCP 127.0.0.1:49698 127.0.0.1:59729 ESTABLISHED 7152
TCP 127.0.0.1:49698 127.0.0.1:59744 ESTABLISHED 7152
TCP 127.0.0.1:49698 127.0.0.1:59779 ESTABLISHED 7152
TCP 127.0.0.1:49698 127.0.0.1:59780 ESTABLISHED 7152
TCP 127.0.0.1:49702 0.0.0.0:0 LISTENING 6316
TCP 127.0.0.1:49708 127.0.0.1:49697 ESTABLISHED 3476
TCP 127.0.0.1:49709 127.0.0.1:49670 ESTABLISHED 7152
TCP 127.0.0.1:49710 127.0.0.1:49670 ESTABLISHED 7152
TCP 127.0.0.1:49717 0.0.0.0:0 LISTENING 7212
TCP 127.0.0.1:49719 127.0.0.1:49670 ESTABLISHED 5272
TCP 127.0.0.1:49720 0.0.0.0:0 LISTENING 7104
TCP 127.0.0.1:49720 127.0.0.1:49724 ESTABLISHED 7104
TCP 127.0.0.1:49721 127.0.0.1:49722 ESTABLISHED 6316
TCP 127.0.0.1:49722 127.0.0.1:49721 ESTABLISHED 6316
TCP 127.0.0.1:49724 127.0.0.1:49720 ESTABLISHED 3476
TCP 127.0.0.1:49728 0.0.0.0:0 LISTENING 7488
TCP 127.0.0.1:49735 0.0.0.0:0 LISTENING 5680
TCP 127.0.0.1:49763 127.0.0.1:49679 ESTABLISHED 3476
TCP 127.0.0.1:49809 0.0.0.0:0 LISTENING 3684
TCP 127.0.0.1:49934 0.0.0.0:0 LISTENING 3396
TCP 127.0.0.1:49938 127.0.0.1:49670 ESTABLISHED 6312
TCP 127.0.0.1:49939 127.0.0.1:49940 ESTABLISHED 6312
TCP 127.0.0.1:49940 127.0.0.1:49939 ESTABLISHED 6312
TCP 127.0.0.1:49941 127.0.0.1:49942 ESTABLISHED 6312
TCP 127.0.0.1:49942 127.0.0.1:49941 ESTABLISHED 6312
TCP 127.0.0.1:49943 127.0.0.1:49944 ESTABLISHED 6312
TCP 127.0.0.1:49944 127.0.0.1:49943 ESTABLISHED 6312
TCP 127.0.0.1:49945 127.0.0.1:49946 ESTABLISHED 6312
TCP 127.0.0.1:49946 127.0.0.1:49945 ESTABLISHED 6312
TCP 127.0.0.1:49947 127.0.0.1:49948 ESTABLISHED 6312
TCP 127.0.0.1:49948 127.0.0.1:49947 ESTABLISHED 6312
TCP 127.0.0.1:49949 127.0.0.1:49950 ESTABLISHED 6312
TCP 127.0.0.1:49950 127.0.0.1:49949 ESTABLISHED 6312
TCP 127.0.0.1:49951 0.0.0.0:0 LISTENING 6312
TCP 127.0.0.1:49952 127.0.0.1:49670 ESTABLISHED 6312
TCP 127.0.0.1:49956 0.0.0.0:0 LISTENING 3676
TCP 127.0.0.1:49979 127.0.0.1:49980 ESTABLISHED 3904
TCP 127.0.0.1:49980 127.0.0.1:49979 ESTABLISHED 3904
TCP 127.0.0.1:49981 127.0.0.1:49982 ESTABLISHED 1448
TCP 127.0.0.1:49982 127.0.0.1:49981 ESTABLISHED 1448
TCP 127.0.0.1:49983 127.0.0.1:49984 ESTABLISHED 1448
TCP 127.0.0.1:49984 127.0.0.1:49983 ESTABLISHED 1448
TCP 127.0.0.1:49985 127.0.0.1:49986 ESTABLISHED 1448
TCP 127.0.0.1:49986 127.0.0.1:49985 ESTABLISHED 1448
TCP 127.0.0.1:49987 127.0.0.1:49988 ESTABLISHED 1448
TCP 127.0.0.1:49988 127.0.0.1:49987 ESTABLISHED 1448
TCP 127.0.0.1:49989 127.0.0.1:49670 ESTABLISHED 1448
TCP 127.0.0.1:50002 127.0.0.1:50003 ESTABLISHED 1448
TCP 127.0.0.1:50003 127.0.0.1:50002 ESTABLISHED 1448
TCP 127.0.0.1:50004 127.0.0.1:50005 ESTABLISHED 1448
TCP 127.0.0.1:50005 127.0.0.1:50004 ESTABLISHED 1448
TCP 127.0.0.1:50006 127.0.0.1:50007 ESTABLISHED 1448
TCP 127.0.0.1:50007 127.0.0.1:50006 ESTABLISHED 1448
TCP 127.0.0.1:50008 127.0.0.1:50009 ESTABLISHED 1448
TCP 127.0.0.1:50009 127.0.0.1:50008 ESTABLISHED 1448
TCP 127.0.0.1:50010 127.0.0.1:50011 ESTABLISHED 1448
TCP 127.0.0.1:50011 127.0.0.1:50010 ESTABLISHED 1448
TCP 127.0.0.1:50012 127.0.0.1:50013 ESTABLISHED 1448
TCP 127.0.0.1:50013 127.0.0.1:50012 ESTABLISHED 1448
TCP 127.0.0.1:50014 127.0.0.1:50015 ESTABLISHED 1448
TCP 127.0.0.1:50015 127.0.0.1:50014 ESTABLISHED 1448
TCP 127.0.0.1:50016 127.0.0.1:50017 ESTABLISHED 1448
TCP 127.0.0.1:50017 127.0.0.1:50016 ESTABLISHED 1448
TCP 127.0.0.1:50018 127.0.0.1:50019 ESTABLISHED 1448
TCP 127.0.0.1:50019 127.0.0.1:50018 ESTABLISHED 1448
TCP 127.0.0.1:50020 127.0.0.1:50021 ESTABLISHED 1448
TCP 127.0.0.1:50021 127.0.0.1:50020 ESTABLISHED 1448
TCP 127.0.0.1:50022 127.0.0.1:50023 ESTABLISHED 1448
TCP 127.0.0.1:50023 127.0.0.1:50022 ESTABLISHED 1448
TCP 127.0.0.1:50024 127.0.0.1:50025 ESTABLISHED 1448
TCP 127.0.0.1:50025 127.0.0.1:50024 ESTABLISHED 1448
TCP 127.0.0.1:50026 127.0.0.1:50027 ESTABLISHED 1448
TCP 127.0.0.1:50027 127.0.0.1:50026 ESTABLISHED 1448
TCP 127.0.0.1:50028 127.0.0.1:50029 ESTABLISHED 1448
TCP 127.0.0.1:50029 127.0.0.1:50028 ESTABLISHED 1448
TCP 127.0.0.1:50030 127.0.0.1:50031 ESTABLISHED 1448
TCP 127.0.0.1:50031 127.0.0.1:50030 ESTABLISHED 1448
TCP 127.0.0.1:50032 127.0.0.1:49670 ESTABLISHED 1448
TCP 127.0.0.1:50033 127.0.0.1:49670 ESTABLISHED 1448
TCP 127.0.0.1:50170 127.0.0.1:49670 ESTABLISHED 18808
TCP 127.0.0.1:50172 127.0.0.1:49670 ESTABLISHED 22208
TCP 127.0.0.1:50173 127.0.0.1:49670 ESTABLISHED 22208
TCP 127.0.0.1:50174 127.0.0.1:49670 ESTABLISHED 22208
TCP 127.0.0.1:50177 127.0.0.1:49670 ESTABLISHED 22208
TCP 127.0.0.1:50178 127.0.0.1:49670 ESTABLISHED 1448
TCP 127.0.0.1:50182 127.0.0.1:49670 ESTABLISHED 22208
TCP 127.0.0.1:51268 127.0.0.1:49670 ESTABLISHED 14796
TCP 127.0.0.1:52703 127.0.0.1:49670 ESTABLISHED 14796
TCP 127.0.0.1:52704 127.0.0.1:49670 ESTABLISHED 14796
TCP 127.0.0.1:52705 127.0.0.1:49670 ESTABLISHED 14796
TCP 127.0.0.1:52707 127.0.0.1:49670 ESTABLISHED 14796
TCP 127.0.0.1:52711 127.0.0.1:49670 ESTABLISHED 14796
TCP 127.0.0.1:54268 0.0.0.0:0 LISTENING 6516
TCP 127.0.0.1:54268 127.0.0.1:59625 TIME_WAIT 0
TCP 127.0.0.1:54268 127.0.0.1:59679 TIME_WAIT 0
TCP 127.0.0.1:54268 127.0.0.1:59733 TIME_WAIT 0
TCP 127.0.0.1:54415 127.0.0.1:49670 ESTABLISHED 7104
TCP 127.0.0.1:54768 127.0.0.1:49670 ESTABLISHED 7212
TCP 127.0.0.1:54961 127.0.0.1:49670 ESTABLISHED 3396
TCP 127.0.0.1:56139 127.0.0.1:49670 ESTABLISHED 1448
TCP 127.0.0.1:58159 127.0.0.1:49670 ESTABLISHED 15472
TCP 127.0.0.1:58170 127.0.0.1:49698 TIME_WAIT 0
TCP 127.0.0.1:58421 127.0.0.1:49670 ESTABLISHED 7336
TCP 127.0.0.1:58837 127.0.0.1:49698 ESTABLISHED 3476
TCP 127.0.0.1:58849 127.0.0.1:49670 ESTABLISHED 7104
TCP 127.0.0.1:59046 127.0.0.1:49698 ESTABLISHED 3476
TCP 127.0.0.1:59250 127.0.0.1:49670 ESTABLISHED 1448
TCP 127.0.0.1:59399 127.0.0.1:49698 ESTABLISHED 3476
TCP 127.0.0.1:59489 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59490 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59569 127.0.0.1:54268 TIME_WAIT 0
TCP 127.0.0.1:59570 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59574 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59578 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59579 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59583 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59587 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59589 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59596 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59599 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59601 127.0.0.1:49717 TIME_WAIT 0
TCP 127.0.0.1:59604 127.0.0.1:6109 TIME_WAIT 0
TCP 127.0.0.1:59605 127.0.0.1:49728 TIME_WAIT 0
TCP 127.0.0.1:59607 127.0.0.1:49702 TIME_WAIT 0
TCP 127.0.0.1:59608 127.0.0.1:49934 TIME_WAIT 0
TCP 127.0.0.1:59610 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59613 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59614 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59616 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59618 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59620 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59622 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59626 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59630 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59635 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59640 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59642 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59644 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59646 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59649 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59651 127.0.0.1:49717 TIME_WAIT 0
TCP 127.0.0.1:59652 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59653 127.0.0.1:6109 TIME_WAIT 0
TCP 127.0.0.1:59654 127.0.0.1:49728 TIME_WAIT 0
TCP 127.0.0.1:59661 127.0.0.1:49702 TIME_WAIT 0
TCP 127.0.0.1:59662 127.0.0.1:49934 TIME_WAIT 0
TCP 127.0.0.1:59664 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59667 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59668 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59671 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59673 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59675 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59677 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59679 127.0.0.1:54268 TIME_WAIT 0
TCP 127.0.0.1:59681 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59685 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59688 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59689 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59691 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59693 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59695 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59697 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59700 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59701 127.0.0.1:49670 ESTABLISHED 6516
TCP 127.0.0.1:59702 127.0.0.1:49670 ESTABLISHED 6516
TCP 127.0.0.1:59703 127.0.0.1:6111 TIME_WAIT 0
TCP 127.0.0.1:59704 127.0.0.1:49717 TIME_WAIT 0
TCP 127.0.0.1:59705 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59706 127.0.0.1:6109 TIME_WAIT 0
TCP 127.0.0.1:59707 127.0.0.1:49728 TIME_WAIT 0
TCP 127.0.0.1:59708 127.0.0.1:49702 TIME_WAIT 0
TCP 127.0.0.1:59711 127.0.0.1:49934 TIME_WAIT 0
TCP 127.0.0.1:59713 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59716 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59724 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59726 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59728 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59729 127.0.0.1:49698 ESTABLISHED 3476
TCP 127.0.0.1:59731 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59735 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59736 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59739 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59742 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59744 127.0.0.1:49698 ESTABLISHED 3476
TCP 127.0.0.1:59745 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59748 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59752 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59755 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59757 127.0.0.1:49717 TIME_WAIT 0
TCP 127.0.0.1:59759 127.0.0.1:6109 TIME_WAIT 0
TCP 127.0.0.1:59760 127.0.0.1:49728 TIME_WAIT 0
TCP 127.0.0.1:59761 127.0.0.1:49702 TIME_WAIT 0
TCP 127.0.0.1:59763 127.0.0.1:49934 TIME_WAIT 0
TCP 127.0.0.1:59765 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59768 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59770 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59773 127.0.0.1:49670 TIME_WAIT 0
TCP 127.0.0.1:59776 127.0.0.1:49670 ESTABLISHED 7036
TCP 127.0.0.1:59777 127.0.0.1:49670 ESTABLISHED 7036
TCP 127.0.0.1:59778 127.0.0.1:49670 ESTABLISHED 7036
TCP 127.0.0.1:59779 127.0.0.1:49698 ESTABLISHED 3476
TCP 127.0.0.1:59780 127.0.0.1:49698 ESTABLISHED 3476
TCP 127.0.0.1:63084 127.0.0.1:49670 ESTABLISHED 14796
TCP 172.17.100.112:135 172.17.100.38:57543 ESTABLISHED 1128
TCP 172.17.100.112:139 0.0.0.0:0 LISTENING 4
TCP 172.17.100.112:443 51.162.176.206:9319 ESTABLISHED 4
TCP 172.17.100.112:443 103.71.113.10:50297 ESTABLISHED 4
TCP 172.17.100.112:445 172.17.100.38:57542 ESTABLISHED 4
TCP 172.17.100.112:6888 0.0.0.0:0 LISTENING 6316
TCP 172.17.100.112:52404 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52405 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52406 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52407 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52408 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52409 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52410 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52411 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52412 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52413 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52414 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52415 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52416 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52417 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52418 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52419 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52420 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52421 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52422 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52423 172.17.100.60:1433 ESTABLISHED 12652
TCP 172.17.100.112:52451 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52452 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52453 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52454 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52455 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52456 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52457 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52458 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52459 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52460 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52461 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52462 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52463 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52464 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52465 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52466 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52467 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52468 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52469 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52470 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52473 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52474 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52475 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52476 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52477 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52478 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52479 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52480 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52481 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52482 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52483 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52484 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52485 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52486 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52487 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52488 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52489 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52490 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52491 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52492 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52493 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52494 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52495 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52496 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52497 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52498 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52499 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52500 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52501 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52502 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52503 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52504 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52505 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52506 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52507 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52508 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52509 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52510 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52511 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52512 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52900 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52901 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52902 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52903 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52904 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52905 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52906 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52907 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52908 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52909 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52910 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52911 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52912 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52913 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52914 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52915 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52916 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52917 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52918 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:52919 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54595 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54596 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54597 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54598 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54599 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54600 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54601 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54602 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54603 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54604 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54605 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54606 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54607 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54608 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54609 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54610 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54611 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54612 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54613 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:54614 172.17.100.60:1433 ESTABLISHED 13820
TCP 172.17.100.112:57281 172.17.100.38:57544 ESTABLISHED 3540
TCP 172.17.100.112:60214 192.168.150.60:445 ESTABLISHED 4
TCP 172.17.100.112:61276 172.17.100.60:445 ESTABLISHED 4
TCP [::]:80 [::]:0 LISTENING 4
TCP [::]:135 [::]:0 LISTENING 1128
TCP [::]:443 [::]:0 LISTENING 4
TCP [::]:445 [::]:0 LISTENING 4
TCP [::]:1433 [::]:0 LISTENING 5680
TCP [::]:2383 [::]:0 LISTENING 6080
TCP [::]:3389 [::]:0 LISTENING 1348
TCP [::]:5357 [::]:0 LISTENING 4
TCP [::]:5800 [::]:0 LISTENING 4592
TCP [::]:5900 [::]:0 LISTENING 4592
TCP [::]:5985 [::]:0 LISTENING 4
TCP [::]:47001 [::]:0 LISTENING 4
TCP [::]:49664 [::]:0 LISTENING 920
TCP [::]:49665 [::]:0 LISTENING 1480
TCP [::]:49666 [::]:0 LISTENING 1948
TCP [::]:49667 [::]:0 LISTENING 2820
TCP [::]:49668 [::]:0 LISTENING 3288
TCP [::]:49669 [::]:0 LISTENING 3080
TCP [::]:49742 [::]:0 LISTENING 220
TCP [::]:49833 [::]:0 LISTENING 180
TCP [::]:57281 [::]:0 LISTENING 3540
TCP [::1]:1434 [::]:0 LISTENING 5680
TCP [::1]:1550 [::]:0 LISTENING 3676
TCP [::1]:1551 [::]:0 LISTENING 3676
TCP [::1]:9850 [::]:0 LISTENING 1448
TCP [::1]:30523 [::]:0 LISTENING 3676
TCP [::1]:49735 [::]:0 LISTENING 5680
TCP [::1]:49956 [::]:0 LISTENING 3676
UDP 0.0.0.0:123 *:* 3852
UDP 0.0.0.0:500 *:* 3040
UDP 0.0.0.0:3389 *:* 1348
UDP 0.0.0.0:3702 *:* 11284
UDP 0.0.0.0:3702 *:* 11284
UDP 0.0.0.0:4500 *:* 3040
UDP 0.0.0.0:5353 *:* 2424
UDP 0.0.0.0:5355 *:* 2424
UDP 0.0.0.0:6771 *:* 6316
UDP 0.0.0.0:6771 *:* 6316
UDP 0.0.0.0:15000 *:* 3676
UDP 0.0.0.0:52702 *:* 3904
UDP 0.0.0.0:59033 *:* 11284
UDP 127.0.0.1:6888 *:* 6316
UDP 127.0.0.1:24100 *:* 1448
UDP 127.0.0.1:24101 *:* 1448
UDP 127.0.0.1:24102 *:* 1448
UDP 127.0.0.1:60626 *:* 4148
UDP 172.17.100.112:137 *:* 4
UDP 172.17.100.112:138 *:* 4
UDP 172.17.100.112:6888 *:* 6316
UDP [::]:123 *:* 3852
UDP [::]:500 *:* 3040
UDP [::]:3389 *:* 1348
UDP [::]:3702 *:* 11284
UDP [::]:3702 *:* 11284
UDP [::]:4500 *:* 3040
UDP [::]:15000 *:* 3676
UDP [::]:59034 *:* 11284
64582 - Netstat Connection Information
-
Synopsis
Nessus was able to parse the results of the 'netstat' command on the remote host.
Description
The remote host has listening ports or established connections that Nessus was able to extract from the results of the 'netstat' command.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/13, Modified: 2023/05/23
Plugin Output

tcp/0

tcp4 (listen)
src: [host=0.0.0.0, port=80]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=135]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=443]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=445]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=1433]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=2383]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=3389]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5357]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5800]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5900]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5985]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=6111]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=18018]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=47001]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49664]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49665]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49666]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49667]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49668]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49669]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49742]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49833]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=57281]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=1434]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=1550]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=1551]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=6109]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59567]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59568]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59572]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59573]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59576]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59577]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59582]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59584]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59588]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59590]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59597]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59598]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59600]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59606]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59609]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59611]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59612]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59615]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59617]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59619]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59621]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59623]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59624]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59628]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59629]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59631]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59634]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59639]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59641]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59643]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59645]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59647]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59648]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59650]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59660]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59663]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59665]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59666]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59670]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59672]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59674]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59676]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59678]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59680]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59683]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59684]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59686]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59687]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59690]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59692]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59694]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59696]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59698]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59699]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59703]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59709]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59712]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59714]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59715]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59723]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59725]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59727]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59730]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59732]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59734]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59737]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59738]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59740]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59741]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59746]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59747]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59749]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59751]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59753]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59754]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59756]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59762]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59764]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59766]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59767]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59771]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59772]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59774]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=59781]

tcp4 (listen)
src: [host=127.0.0.1, port=6888]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=9771]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=9771]
dst: [host=127.0.0.1, port=49686]

tcp4 (listen)
src: [host=127.0.0.1, port=9850]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=30523]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=43234]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49394]
dst: [host=127.0.0.1, port=49670]

tcp4 (listen)
src: [host=127.0.0.1, port=49670]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=49394]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=49691]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=49693]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=49696]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=49709]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=49710]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=49719]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=49938]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=49952]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=49989]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=50032]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=50033]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=50170]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=50172]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=50173]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=50174]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=50177]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=50178]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=50182]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=51268]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=52703]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=52704]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=52705]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=52707]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=52711]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=54415]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=54768]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=54961]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=56139]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=58159]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=58421]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=58849]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59250]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59571]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59602]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59627]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59636]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59675]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59682]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59701]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59702]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59717]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59728]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59736]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59743]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59750]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59758]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59769]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59775]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59776]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59777]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=59778]

tcp4 (established)
src: [host=127.0.0.1, port=49670]
dst: [host=127.0.0.1, port=63084]

tcp4 (listen)
src: [host=127.0.0.1, port=49673]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49673]
dst: [host=127.0.0.1, port=49678]

tcp4 (established)
src: [host=127.0.0.1, port=49678]
dst: [host=127.0.0.1, port=49673]

tcp4 (listen)
src: [host=127.0.0.1, port=49679]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49679]
dst: [host=127.0.0.1, port=49763]

tcp4 (listen)
src: [host=127.0.0.1, port=49684]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49684]
dst: [host=127.0.0.1, port=49692]

tcp4 (established)
src: [host=127.0.0.1, port=49686]
dst: [host=127.0.0.1, port=9771]

tcp4 (established)
src: [host=127.0.0.1, port=49691]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=49692]
dst: [host=127.0.0.1, port=49684]

tcp4 (established)
src: [host=127.0.0.1, port=49693]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=49696]
dst: [host=127.0.0.1, port=49670]

tcp4 (listen)
src: [host=127.0.0.1, port=49697]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49697]
dst: [host=127.0.0.1, port=49708]

tcp4 (listen)
src: [host=127.0.0.1, port=49698]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49698]
dst: [host=127.0.0.1, port=58837]

tcp4 (established)
src: [host=127.0.0.1, port=49698]
dst: [host=127.0.0.1, port=59046]

tcp4 (established)
src: [host=127.0.0.1, port=49698]
dst: [host=127.0.0.1, port=59399]

tcp4 (established)
src: [host=127.0.0.1, port=49698]
dst: [host=127.0.0.1, port=59729]

tcp4 (established)
src: [host=127.0.0.1, port=49698]
dst: [host=127.0.0.1, port=59744]

tcp4 (established)
src: [host=127.0.0.1, port=49698]
dst: [host=127.0.0.1, port=59779]

tcp4 (established)
src: [host=127.0.0.1, port=49698]
dst: [host=127.0.0.1, port=59780]

tcp4 (listen)
src: [host=127.0.0.1, port=49702]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49708]
dst: [host=127.0.0.1, port=49697]

tcp4 (established)
src: [host=127.0.0.1, port=49709]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=49710]
dst: [host=127.0.0.1, port=49670]

tcp4 (listen)
src: [host=127.0.0.1, port=49717]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49719]
dst: [host=127.0.0.1, port=49670]

tcp4 (listen)
src: [host=127.0.0.1, port=49720]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49720]
dst: [host=127.0.0.1, port=49724]

tcp4 (established)
src: [host=127.0.0.1, port=49721]
dst: [host=127.0.0.1, port=49722]

tcp4 (established)
src: [host=127.0.0.1, port=49722]
dst: [host=127.0.0.1, port=49721]

tcp4 (established)
src: [host=127.0.0.1, port=49724]
dst: [host=127.0.0.1, port=49720]

tcp4 (listen)
src: [host=127.0.0.1, port=49728]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=49735]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49763]
dst: [host=127.0.0.1, port=49679]

tcp4 (listen)
src: [host=127.0.0.1, port=49809]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=49934]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49938]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=49939]
dst: [host=127.0.0.1, port=49940]

tcp4 (established)
src: [host=127.0.0.1, port=49940]
dst: [host=127.0.0.1, port=49939]

tcp4 (established)
src: [host=127.0.0.1, port=49941]
dst: [host=127.0.0.1, port=49942]

tcp4 (established)
src: [host=127.0.0.1, port=49942]
dst: [host=127.0.0.1, port=49941]

tcp4 (established)
src: [host=127.0.0.1, port=49943]
dst: [host=127.0.0.1, port=49944]

tcp4 (established)
src: [host=127.0.0.1, port=49944]
dst: [host=127.0.0.1, port=49943]

tcp4 (established)
src: [host=127.0.0.1, port=49945]
dst: [host=127.0.0.1, port=49946]

tcp4 (established)
src: [host=127.0.0.1, port=49946]
dst: [host=127.0.0.1, port=49945]

tcp4 (established)
src: [host=127.0.0.1, port=49947]
dst: [host=127.0.0.1, port=49948]

tcp4 (established)
src: [host=127.0.0.1, port=49948]
dst: [host=127.0.0.1, port=49947]

tcp4 (established)
src: [host=127.0.0.1, port=49949]
dst: [host=127.0.0.1, port=49950]

tcp4 (established)
src: [host=127.0.0.1, port=49950]
dst: [host=127.0.0.1, port=49949]

tcp4 (listen)
src: [host=127.0.0.1, port=49951]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49952]
dst: [host=127.0.0.1, port=49670]

tcp4 (listen)
src: [host=127.0.0.1, port=49956]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49979]
dst: [host=127.0.0.1, port=49980]

tcp4 (established)
src: [host=127.0.0.1, port=49980]
dst: [host=127.0.0.1, port=49979]

tcp4 (established)
src: [host=127.0.0.1, port=49981]
dst: [host=127.0.0.1, port=49982]

tcp4 (established)
src: [host=127.0.0.1, port=49982]
dst: [host=127.0.0.1, port=49981]

tcp4 (established)
src: [host=127.0.0.1, port=49983]
dst: [host=127.0.0.1, port=49984]

tcp4 (established)
src: [host=127.0.0.1, port=49984]
dst: [host=127.0.0.1, port=49983]

tcp4 (established)
src: [host=127.0.0.1, port=49985]
dst: [host=127.0.0.1, port=49986]

tcp4 (established)
src: [host=127.0.0.1, port=49986]
dst: [host=127.0.0.1, port=49985]

tcp4 (established)
src: [host=127.0.0.1, port=49987]
dst: [host=127.0.0.1, port=49988]

tcp4 (established)
src: [host=127.0.0.1, port=49988]
dst: [host=127.0.0.1, port=49987]

tcp4 (established)
src: [host=127.0.0.1, port=49989]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=50002]
dst: [host=127.0.0.1, port=50003]

tcp4 (established)
src: [host=127.0.0.1, port=50003]
dst: [host=127.0.0.1, port=50002]

tcp4 (established)
src: [host=127.0.0.1, port=50004]
dst: [host=127.0.0.1, port=50005]

tcp4 (established)
src: [host=127.0.0.1, port=50005]
dst: [host=127.0.0.1, port=50004]

tcp4 (established)
src: [host=127.0.0.1, port=50006]
dst: [host=127.0.0.1, port=50007]

tcp4 (established)
src: [host=127.0.0.1, port=50007]
dst: [host=127.0.0.1, port=50006]

tcp4 (established)
src: [host=127.0.0.1, port=50008]
dst: [host=127.0.0.1, port=50009]

tcp4 (established)
src: [host=127.0.0.1, port=50009]
dst: [host=127.0.0.1, port=50008]

tcp4 (established)
src: [host=127.0.0.1, port=50010]
dst: [host=127.0.0.1, port=50011]

tcp4 (established)
src: [host=127.0.0.1, port=50011]
dst: [host=127.0.0.1, port=50010]

tcp4 (established)
src: [host=127.0.0.1, port=50012]
dst: [host=127.0.0.1, port=50013]

tcp4 (established)
src: [host=127.0.0.1, port=50013]
dst: [host=127.0.0.1, port=50012]

tcp4 (established)
src: [host=127.0.0.1, port=50014]
dst: [host=127.0.0.1, port=50015]

tcp4 (established)
src: [host=127.0.0.1, port=50015]
dst: [host=127.0.0.1, port=50014]

tcp4 (established)
src: [host=127.0.0.1, port=50016]
dst: [host=127.0.0.1, port=50017]

tcp4 (established)
src: [host=127.0.0.1, port=50017]
dst: [host=127.0.0.1, port=50016]

tcp4 (established)
src: [host=127.0.0.1, port=50018]
dst: [host=127.0.0.1, port=50019]

tcp4 (established)
src: [host=127.0.0.1, port=50019]
dst: [host=127.0.0.1, port=50018]

tcp4 (established)
src: [host=127.0.0.1, port=50020]
dst: [host=127.0.0.1, port=50021]

tcp4 (established)
src: [host=127.0.0.1, port=50021]
dst: [host=127.0.0.1, port=50020]

tcp4 (established)
src: [host=127.0.0.1, port=50022]
dst: [host=127.0.0.1, port=50023]

tcp4 (established)
src: [host=127.0.0.1, port=50023]
dst: [host=127.0.0.1, port=50022]

tcp4 (established)
src: [host=127.0.0.1, port=50024]
dst: [host=127.0.0.1, port=50025]

tcp4 (established)
src: [host=127.0.0.1, port=50025]
dst: [host=127.0.0.1, port=50024]

tcp4 (established)
src: [host=127.0.0.1, port=50026]
dst: [host=127.0.0.1, port=50027]

tcp4 (established)
src: [host=127.0.0.1, port=50027]
dst: [host=127.0.0.1, port=50026]

tcp4 (established)
src: [host=127.0.0.1, port=50028]
dst: [host=127.0.0.1, port=50029]

tcp4 (established)
src: [host=127.0.0.1, port=50029]
dst: [host=127.0.0.1, port=50028]

tcp4 (established)
src: [host=127.0.0.1, port=50030]
dst: [host=127.0.0.1, port=50031]

tcp4 (established)
src: [host=127.0.0.1, port=50031]
dst: [host=127.0.0.1, port=50030]

tcp4 (established)
src: [host=127.0.0.1, port=50032]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=50033]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=50170]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=50172]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=50173]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=50174]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=50177]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=50178]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=50182]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=51268]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=52703]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=52704]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=52705]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=52707]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=52711]
dst: [host=127.0.0.1, port=49670]

tcp4 (listen)
src: [host=127.0.0.1, port=54268]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=54268]
dst: [host=127.0.0.1, port=59625]

tcp4 (established)
src: [host=127.0.0.1, port=54268]
dst: [host=127.0.0.1, port=59679]

tcp4 (established)
src: [host=127.0.0.1, port=54268]
dst: [host=127.0.0.1, port=59733]

tcp4 (established)
src: [host=127.0.0.1, port=54415]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=54768]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=54961]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=56139]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=58159]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=58170]
dst: [host=127.0.0.1, port=49698]

tcp4 (established)
src: [host=127.0.0.1, port=58421]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=58837]
dst: [host=127.0.0.1, port=49698]

tcp4 (established)
src: [host=127.0.0.1, port=58849]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59046]
dst: [host=127.0.0.1, port=49698]

tcp4 (established)
src: [host=127.0.0.1, port=59250]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59399]
dst: [host=127.0.0.1, port=49698]

tcp4 (established)
src: [host=127.0.0.1, port=59489]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59490]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59569]
dst: [host=127.0.0.1, port=54268]

tcp4 (established)
src: [host=127.0.0.1, port=59570]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59574]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59578]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59579]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59583]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59587]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59589]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59596]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59599]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59601]
dst: [host=127.0.0.1, port=49717]

tcp4 (established)
src: [host=127.0.0.1, port=59604]
dst: [host=127.0.0.1, port=6109]

tcp4 (established)
src: [host=127.0.0.1, port=59605]
dst: [host=127.0.0.1, port=49728]

tcp4 (established)
src: [host=127.0.0.1, port=59607]
dst: [host=127.0.0.1, port=49702]

tcp4 (established)
src: [host=127.0.0.1, port=59608]
dst: [host=127.0.0.1, port=49934]

tcp4 (established)
src: [host=127.0.0.1, port=59610]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59613]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59614]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59616]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59618]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59620]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59622]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59626]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59630]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59635]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59640]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59642]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59644]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59646]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59649]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59651]
dst: [host=127.0.0.1, port=49717]

tcp4 (established)
src: [host=127.0.0.1, port=59652]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59653]
dst: [host=127.0.0.1, port=6109]

tcp4 (established)
src: [host=127.0.0.1, port=59654]
dst: [host=127.0.0.1, port=49728]

tcp4 (established)
src: [host=127.0.0.1, port=59661]
dst: [host=127.0.0.1, port=49702]

tcp4 (established)
src: [host=127.0.0.1, port=59662]
dst: [host=127.0.0.1, port=49934]

tcp4 (established)
src: [host=127.0.0.1, port=59664]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59667]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59668]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59671]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59673]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59675]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59677]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59679]
dst: [host=127.0.0.1, port=54268]

tcp4 (established)
src: [host=127.0.0.1, port=59681]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59685]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59688]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59689]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59691]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59693]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59695]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59697]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59700]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59701]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59702]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59703]
dst: [host=127.0.0.1, port=6111]

tcp4 (established)
src: [host=127.0.0.1, port=59704]
dst: [host=127.0.0.1, port=49717]

tcp4 (established)
src: [host=127.0.0.1, port=59705]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59706]
dst: [host=127.0.0.1, port=6109]

tcp4 (established)
src: [host=127.0.0.1, port=59707]
dst: [host=127.0.0.1, port=49728]

tcp4 (established)
src: [host=127.0.0.1, port=59708]
dst: [host=127.0.0.1, port=49702]

tcp4 (established)
src: [host=127.0.0.1, port=59711]
dst: [host=127.0.0.1, port=49934]

tcp4 (established)
src: [host=127.0.0.1, port=59713]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59716]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59724]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59726]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59728]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59729]
dst: [host=127.0.0.1, port=49698]

tcp4 (established)
src: [host=127.0.0.1, port=59731]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59735]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59736]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59739]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59742]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59744]
dst: [host=127.0.0.1, port=49698]

tcp4 (established)
src: [host=127.0.0.1, port=59745]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59748]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59752]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59755]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59757]
dst: [host=127.0.0.1, port=49717]

tcp4 (established)
src: [host=127.0.0.1, port=59759]
dst: [host=127.0.0.1, port=6109]

tcp4 (established)
src: [host=127.0.0.1, port=59760]
dst: [host=127.0.0.1, port=49728]

tcp4 (established)
src: [host=127.0.0.1, port=59761]
dst: [host=127.0.0.1, port=49702]

tcp4 (established)
src: [host=127.0.0.1, port=59763]
dst: [host=127.0.0.1, port=49934]

tcp4 (established)
src: [host=127.0.0.1, port=59765]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59768]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59770]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59773]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59776]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59777]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59778]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=127.0.0.1, port=59779]
dst: [host=127.0.0.1, port=49698]

tcp4 (established)
src: [host=127.0.0.1, port=59780]
dst: [host=127.0.0.1, port=49698]

tcp4 (established)
src: [host=127.0.0.1, port=63084]
dst: [host=127.0.0.1, port=49670]

tcp4 (established)
src: [host=172.17.100.112, port=135]
dst: [host=172.17.100.38, port=57543]

tcp4 (listen)
src: [host=172.17.100.112, port=139]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=172.17.100.112, port=443]
dst: [host=51.162.176.206, port=9319]

tcp4 (established)
src: [host=172.17.100.112, port=443]
dst: [host=103.71.113.10, port=50297]

tcp4 (established)
src: [host=172.17.100.112, port=445]
dst: [host=172.17.100.38, port=57542]

tcp4 (listen)
src: [host=172.17.100.112, port=6888]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=172.17.100.112, port=52404]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52405]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52406]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52407]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52408]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52409]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52410]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52411]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52412]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52413]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52414]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52415]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52416]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52417]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52418]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52419]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52420]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52421]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52422]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52423]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52451]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52452]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52453]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52454]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52455]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52456]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52457]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52458]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52459]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52460]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52461]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52462]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52463]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52464]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52465]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52466]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52467]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52468]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52469]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52470]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52473]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52474]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52475]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52476]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52477]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52478]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52479]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52480]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52481]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52482]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52483]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52484]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52485]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52486]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52487]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52488]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52489]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52490]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52491]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52492]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52493]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52494]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52495]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52496]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52497]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52498]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52499]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52500]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52501]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52502]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52503]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52504]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52505]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52506]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52507]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52508]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52509]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52510]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52511]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52512]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52900]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52901]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52902]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52903]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52904]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52905]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52906]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52907]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52908]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52909]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52910]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52911]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52912]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52913]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52914]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52915]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52916]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52917]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52918]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=52919]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54595]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54596]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54597]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54598]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54599]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54600]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54601]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54602]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54603]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54604]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54605]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54606]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54607]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54608]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54609]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54610]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54611]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54612]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54613]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=54614]
dst: [host=172.17.100.60, port=1433]

tcp4 (established)
src: [host=172.17.100.112, port=57281]
dst: [host=172.17.100.38, port=57544]

tcp4 (established)
src: [host=172.17.100.112, port=60214]
dst: [host=192.168.150.60, port=445]

tcp4 (established)
src: [host=172.17.100.112, port=61276]
dst: [host=172.17.100.60, port=445]

tcp6 (listen)
src: [host=[::], port=80]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=135]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=443]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=445]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=1433]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=2383]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=3389]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5357]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5800]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5900]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5985]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=47001]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49664]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49665]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49666]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49667]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49668]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49669]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49742]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49833]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=57281]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=1434]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=1550]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=1551]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=9850]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=30523]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=49735]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=49956]
dst: [host=[::], port=0]

udp4 (listen)
src: [host=0.0.0.0, port=123]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3389]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=4500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5353]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5355]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=6771]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=6771]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=15000]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=52702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=59033]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=6888]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=24100]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=24101]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=24102]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=60626]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.112, port=137]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.112, port=138]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.112, port=6888]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=123]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=500]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3389]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3702]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3702]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=4500]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=15000]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=59034]
dst: [host=*, port=*]
174736 - Netstat Ingress Connections
-
Synopsis
External connections are enumerated via the 'netstat' command.
Description
This plugin runs 'netstat' to enumerate any non-private connections to the scan target.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/25, Modified: 2025/12/15
Plugin Output

tcp/0

Netstat output indicated the following connections from non-private IP addresses:

51.162.176.206 connected to port 443 on the scan target.
103.71.113.10 connected to port 443 on the scan target.

NOTE: This list may be truncated depending on the scan verbosity settings.
34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus was able to find 41 open ports.

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/80/www

Port 80/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/123

Port 123/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Port 135/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/137/netbios-ns

Port 137/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/138

Port 138/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/139/smb

Port 139/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/443/www

Port 443/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

Port 445/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/500

Port 500/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/1433/mssql

Port 1433/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/2383

Port 2383/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/3389/msrdp

Port 3389/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/3389

Port 3389/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/3702

Port 3702/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/4500

Port 4500/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5353

Port 5353/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5355/llmnr

Port 5355/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5357/www

Port 5357/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5800/www

Port 5800/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5900/vnc

Port 5900/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5985/www

Port 5985/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/6111

Port 6111/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/6771

Port 6771/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/6888

Port 6888/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/6888

Port 6888/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/15000

Port 15000/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/18018/www

Port 18018/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/47001/www

Port 47001/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49664/dce-rpc

Port 49664/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49665/dce-rpc

Port 49665/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49666/dce-rpc

Port 49666/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49667/dce-rpc

Port 49667/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49668/dce-rpc

Port 49668/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49669/dce-rpc

Port 49669/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49742/dce-rpc

Port 49742/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49833/dce-rpc

Port 49833/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/52702

Port 52702/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/57281

Port 57281/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/59033

Port 59033/udp was found to be open

24272 - Network Interfaces Enumeration (WMI)
-
Synopsis
Nessus was able to obtain the list of network interfaces on the remote host.
Description
Nessus was able, via WMI queries, to extract a list of network interfaces on the remote host and the IP addresses attached to them.
Note that this plugin only enumerates IPv6 addresses for systems running Windows Vista or later.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/0

+ Network Interface Information :

- Network Interface = [00000001] Intel(R) 82574L Gigabit Network Connection
- MAC Address = 00:50:56:BC:7D:2B
- IPAddress/IPSubnet = 172.17.100.112/255.255.255.0


+ Routing Information :

Destination Netmask Gateway
----------- ------- -------
0.0.0.0 0.0.0.0 172.17.100.10
127.0.0.0 255.0.0.0 0.0.0.0
127.0.0.1 255.255.255.255 0.0.0.0
127.255.255.255 255.255.255.255 0.0.0.0
172.17.100.0 255.255.255.0 0.0.0.0
172.17.100.112 255.255.255.255 0.0.0.0
172.17.100.255 255.255.255.255 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0

110839 - Node.js Installed (Windows)
-
Synopsis
Node.js is installed on the remote Windows host.
Description
Node.js is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/07/03, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\nodejs\
Version : 18.16.1
Full Version : 18.16.1

200172 - Node.js Modules Installed (Windows)
-
Synopsis
Nessus was able to enumerate one or more Node.js modules installed on the remote Windows host.
Description
Nessus was able to enumerate one or more Node.js modules installed on the remote Windows host.
Note that 'Perform thorough tests' may be required for an in-depth search of all Node.js modules.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/06/06, Modified: 2025/12/15
Plugin Output

tcp/0


Installed top-level Node.js modules :

name: corepack
version: 0.17.0
path: C:\Program Files (x86)\nodejs\node_modules\corepack\package.json

name: npm
version: 9.5.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\package.json


Installed dependency Node.js modules :

name: @gar/promisify
version: 1.1.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@gar\promisify\package.json

name: @isaacs/string-locale-compare
version: 1.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@isaacs\string-locale-compare\package.json

name: @npmcli/arborist
version: 6.2.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\arborist\package.json

name: @npmcli/config
version: 6.1.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\config\package.json

name: @npmcli/disparity-colors
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\disparity-colors\package.json

name: @npmcli/fs
version: 3.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\fs\package.json

name: @npmcli/git
version: 4.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\git\package.json

name: @npmcli/installed-package-contents
version: 2.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\installed-package-contents\package.json

name: @npmcli/map-workspaces
version: 3.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\map-workspaces\package.json

name: @npmcli/metavuln-calculator
version: 5.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\metavuln-calculator\package.json

name: @npmcli/move-file
version: 2.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\move-file\package.json

name: @npmcli/name-from-folder
version: 2.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\name-from-folder\package.json

name: @npmcli/node-gyp
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\node-gyp\package.json

name: @npmcli/package-json
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\package-json\package.json

name: @npmcli/promise-spawn
version: 6.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\promise-spawn\package.json

name: @npmcli/query
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\query\package.json

name: @npmcli/run-script
version: 6.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@npmcli\run-script\package.json

name: @tootallnate/once
version: 2.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\@tootallnate\once\package.json

name: abbrev
version: 2.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\abbrev\package.json

name: abort-controller
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\abort-controller\package.json

name: agent-base
version: 6.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\agent-base\package.json

name: agentkeepalive
version: 4.2.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\agentkeepalive\package.json

name: aggregate-error
version: 3.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\aggregate-error\package.json

name: ansi-regex
version: 5.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\ansi-regex\package.json

name: ansi-styles
version: 4.3.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\ansi-styles\package.json

name: aproba
version: 2.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\aproba\package.json

name: are-we-there-yet
version: 4.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\are-we-there-yet\package.json

name: balanced-match
version: 1.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\balanced-match\package.json

name: base64-js
version: 1.5.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\base64-js\package.json

name: bin-links
version: 4.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\bin-links\package.json

name: binary-extensions
version: 2.2.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\binary-extensions\package.json

name: brace-expansion
version: 2.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\brace-expansion\package.json

name: buffer
version: 6.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\buffer\package.json

name: builtins
version: 5.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\builtins\package.json

name: cacache
version: 17.0.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\cacache\package.json

name: chalk
version: 4.1.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\chalk\package.json

name: chownr
version: 2.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\chownr\package.json

name: ci-info
version: 3.8.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\ci-info\package.json

name: cidr-regex
version: 3.1.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\cidr-regex\package.json

name: clean-stack
version: 2.2.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\clean-stack\package.json

name: cli-columns
version: 4.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\cli-columns\package.json

name: cli-table3
version: 0.6.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\cli-table3\package.json

name: clone
version: 1.0.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\clone\package.json

name: cmd-shim
version: 6.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\cmd-shim\package.json

name: color-convert
version: 2.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\color-convert\package.json

name: color-name
version: 1.1.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\color-name\package.json

name: color-support
version: 1.1.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\color-support\package.json

name: columnify
version: 1.6.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\columnify\package.json

name: common-ancestor-path
version: 1.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\common-ancestor-path\package.json

name: console-control-strings
version: 1.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\console-control-strings\package.json

name: cssesc
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\cssesc\package.json

name: debug
version: 4.3.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\debug\package.json

name: ms
version: 2.1.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\debug\node_modules\ms\package.json

name: defaults
version: 1.0.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\defaults\package.json

name: delegates
version: 1.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\delegates\package.json

name: depd
version: 1.1.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\depd\package.json

name: diff
version: 5.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\diff\package.json

name: emoji-regex
version: 8.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\emoji-regex\package.json

name: env-paths
version: 2.2.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\env-paths\package.json

name: err-code
version: 2.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\err-code\package.json

name: event-target-shim
version: 5.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\event-target-shim\package.json

name: events
version: 3.3.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\events\package.json

name: fastest-levenshtein
version: 1.0.16
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\fastest-levenshtein\package.json

name: fs-minipass
version: 3.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\fs-minipass\package.json

name: fs.realpath
version: 1.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\fs.realpath\package.json

name: function-bind
version: 1.1.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\function-bind\package.json

name: gauge
version: 5.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\gauge\package.json

name: glob
version: 8.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\glob\package.json

name: minimatch
version: 5.1.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\glob\node_modules\minimatch\package.json

name: graceful-fs
version: 4.2.10
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\graceful-fs\package.json

name: has
version: 1.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\has\package.json

name: has-flag
version: 4.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\has-flag\package.json

name: has-unicode
version: 2.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\has-unicode\package.json

name: hosted-git-info
version: 6.1.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\hosted-git-info\package.json

name: http-proxy-agent
version: 5.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\http-proxy-agent\package.json

name: https-proxy-agent
version: 5.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\https-proxy-agent\package.json

name: humanize-ms
version: 1.2.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\humanize-ms\package.json

name: ieee754
version: 1.2.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\ieee754\package.json

name: ignore-walk
version: 6.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\ignore-walk\package.json

name: imurmurhash
version: 0.1.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\imurmurhash\package.json

name: indent-string
version: 4.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\indent-string\package.json

name: infer-owner
version: 1.0.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\infer-owner\package.json

name: inflight
version: 1.0.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\inflight\package.json

name: inherits
version: 2.0.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\inherits\package.json

name: ini
version: 3.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\ini\package.json

name: init-package-json
version: 5.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\init-package-json\package.json

name: ip
version: 2.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\ip\package.json

name: ip-regex
version: 4.3.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\ip-regex\package.json

name: is-cidr
version: 4.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\is-cidr\package.json

name: is-core-module
version: 2.11.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\is-core-module\package.json

name: is-fullwidth-code-point
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\is-fullwidth-code-point\package.json

name: is-lambda
version: 1.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\is-lambda\package.json

name: isexe
version: 2.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\isexe\package.json

name: json-parse-even-better-errors
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\json-parse-even-better-errors\package.json

name: json-stringify-nice
version: 1.1.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\json-stringify-nice\package.json

name: jsonparse
version: 1.3.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\jsonparse\package.json

name: just-diff
version: 5.2.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\just-diff\package.json

name: just-diff-apply
version: 5.5.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\just-diff-apply\package.json

name: libnpmaccess
version: 7.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmaccess\package.json

name: libnpmdiff
version: 5.0.11
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmdiff\package.json

name: libnpmexec
version: 5.0.11
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmexec\package.json

name: libnpmfund
version: 4.0.11
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmfund\package.json

name: libnpmhook
version: 9.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmhook\package.json

name: libnpmorg
version: 5.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmorg\package.json

name: libnpmpack
version: 5.0.11
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmpack\package.json

name: libnpmpublish
version: 7.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmpublish\package.json

name: libnpmsearch
version: 6.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmsearch\package.json

name: libnpmteam
version: 5.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmteam\package.json

name: libnpmversion
version: 4.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\libnpmversion\package.json

name: lru-cache
version: 7.16.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\lru-cache\package.json

name: make-fetch-happen
version: 11.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\make-fetch-happen\package.json

name: minimatch
version: 6.2.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minimatch\package.json

name: minipass
version: 4.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass\package.json

name: minipass-collect
version: 1.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-collect\package.json

name: minipass
version: 3.3.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-collect\node_modules\minipass\package.json

name: minipass-fetch
version: 3.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-fetch\package.json

name: minipass-flush
version: 1.0.5
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-flush\package.json

name: minipass
version: 3.3.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-flush\node_modules\minipass\package.json

name: minipass-json-stream
version: 1.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-json-stream\package.json

name: minipass
version: 3.3.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-json-stream\node_modules\minipass\package.json

name: minipass-pipeline
version: 1.2.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-pipeline\package.json

name: minipass
version: 3.3.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-pipeline\node_modules\minipass\package.json

name: minipass-sized
version: 1.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-sized\package.json

name: minipass
version: 3.3.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minipass-sized\node_modules\minipass\package.json

name: minizlib
version: 2.1.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minizlib\package.json

name: minipass
version: 3.3.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\minizlib\node_modules\minipass\package.json

name: mkdirp
version: 1.0.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\mkdirp\package.json

name: ms
version: 2.1.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\ms\package.json

name: mute-stream
version: 1.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\mute-stream\package.json

name: negotiator
version: 0.6.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\negotiator\package.json

name: node-gyp
version: 9.3.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\package.json

name: @npmcli/fs
version: 2.1.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\@npmcli\fs\package.json

name: abbrev
version: 1.1.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\abbrev\package.json

name: are-we-there-yet
version: 3.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\are-we-there-yet\package.json

name: brace-expansion
version: 1.1.11
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\brace-expansion\package.json

name: cacache
version: 16.1.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\cacache\package.json

name: brace-expansion
version: 2.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\cacache\node_modules\brace-expansion\package.json

name: glob
version: 8.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\cacache\node_modules\glob\package.json

name: minimatch
version: 5.1.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\cacache\node_modules\minimatch\package.json

name: fs-minipass
version: 2.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\fs-minipass\package.json

name: gauge
version: 4.0.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\gauge\package.json

name: glob
version: 7.2.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\glob\package.json

name: make-fetch-happen
version: 10.2.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\make-fetch-happen\package.json

name: minimatch
version: 3.1.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\minimatch\package.json

name: minipass
version: 3.3.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\minipass\package.json

name: minipass-fetch
version: 2.1.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\minipass-fetch\package.json

name: nopt
version: 6.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\nopt\package.json

name: npmlog
version: 6.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\npmlog\package.json

name: readable-stream
version: 3.6.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\readable-stream\package.json

name: ssri
version: 9.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\ssri\package.json

name: unique-filename
version: 2.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\unique-filename\package.json

name: unique-slug
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\unique-slug\package.json

name: which
version: 2.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\node-gyp\node_modules\which\package.json

name: nopt
version: 7.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\nopt\package.json

name: normalize-package-data
version: 5.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\normalize-package-data\package.json

name: npm-audit-report
version: 4.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npm-audit-report\package.json

name: npm-bundled
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npm-bundled\package.json

name: npm-install-checks
version: 6.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npm-install-checks\package.json

name: npm-normalize-package-bin
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npm-normalize-package-bin\package.json

name: npm-package-arg
version: 10.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npm-package-arg\package.json

name: npm-packlist
version: 7.0.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npm-packlist\package.json

name: npm-pick-manifest
version: 8.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npm-pick-manifest\package.json

name: npm-profile
version: 7.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npm-profile\package.json

name: npm-registry-fetch
version: 14.0.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npm-registry-fetch\package.json

name: npm-user-validate
version: 2.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npm-user-validate\package.json

name: npmlog
version: 7.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\npmlog\package.json

name: once
version: 1.4.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\once\package.json

name: p-map
version: 4.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\p-map\package.json

name: pacote
version: 15.1.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\pacote\package.json

name: parse-conflict-json
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\parse-conflict-json\package.json

name: path-is-absolute
version: 1.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\path-is-absolute\package.json

name: postcss-selector-parser
version: 6.0.11
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\postcss-selector-parser\package.json

name: proc-log
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\proc-log\package.json

name: process
version: 0.11.10
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\process\package.json

name: promise-all-reject-late
version: 1.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\promise-all-reject-late\package.json

name: promise-call-limit
version: 1.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\promise-call-limit\package.json

name: promise-inflight
version: 1.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\promise-inflight\package.json

name: promise-retry
version: 2.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\promise-retry\package.json

name: promzard
version: 1.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\promzard\package.json

name: qrcode-terminal
version: unknown
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\qrcode-terminal\package.json

name: read
version: 2.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\read\package.json

name: read-cmd-shim
version: 4.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\read-cmd-shim\package.json

name: read-package-json
version: 6.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\read-package-json\package.json

name: read-package-json-fast
version: 3.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\read-package-json-fast\package.json

name: readable-stream
version: 4.3.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\readable-stream\package.json

name: retry
version: 0.12.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\retry\package.json

name: rimraf
version: 3.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\rimraf\package.json

name: brace-expansion
version: 1.1.11
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\rimraf\node_modules\brace-expansion\package.json

name: glob
version: 7.2.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\rimraf\node_modules\glob\package.json

name: minimatch
version: 3.1.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\rimraf\node_modules\minimatch\package.json

name: safe-buffer
version: 5.1.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\safe-buffer\package.json

name: safer-buffer
version: 2.1.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\safer-buffer\package.json

name: semver
version: 7.3.8
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\semver\package.json

name: lru-cache
version: 6.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\semver\node_modules\lru-cache\package.json

name: set-blocking
version: 2.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\set-blocking\package.json

name: signal-exit
version: 3.0.7
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\signal-exit\package.json

name: sigstore
version: 1.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\sigstore\package.json

name: smart-buffer
version: 4.2.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\smart-buffer\package.json

name: socks
version: 2.7.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\socks\package.json

name: socks-proxy-agent
version: 7.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\socks-proxy-agent\package.json

name: spdx-correct
version: 3.1.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\spdx-correct\package.json

name: spdx-exceptions
version: 2.3.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\spdx-exceptions\package.json

name: spdx-expression-parse
version: 3.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\spdx-expression-parse\package.json

name: spdx-license-ids
version: 3.0.12
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\spdx-license-ids\package.json

name: ssri
version: 10.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\ssri\package.json

name: string-width
version: 4.2.3
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\string-width\package.json

name: string_decoder
version: 1.1.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\string_decoder\package.json

name: strip-ansi
version: 6.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\strip-ansi\package.json

name: supports-color
version: 7.2.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\supports-color\package.json

name: tar
version: 6.1.13
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\tar\package.json

name: fs-minipass
version: 2.1.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\tar\node_modules\fs-minipass\package.json

name: minipass
version: 3.3.6
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\tar\node_modules\fs-minipass\node_modules\minipass\package.json

name: tiny-relative-date
version: 1.3.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\tiny-relative-date\package.json

name: treeverse
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\treeverse\package.json

name: tuf-js
version: 1.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\tuf-js\package.json

name: unique-filename
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\unique-filename\package.json

name: unique-slug
version: 4.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\unique-slug\package.json

name: util-deprecate
version: 1.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\util-deprecate\package.json

name: validate-npm-package-license
version: 3.0.4
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\validate-npm-package-license\package.json

name: validate-npm-package-name
version: 5.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\validate-npm-package-name\package.json

name: walk-up-path
version: 1.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\walk-up-path\package.json

name: wcwidth
version: 1.0.1
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\wcwidth\package.json

name: which
version: 3.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\which\package.json

name: wide-align
version: 1.1.5
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\wide-align\package.json

name: wrappy
version: 1.0.2
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\wrappy\package.json

name: write-file-atomic
version: 5.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\write-file-atomic\package.json

name: yallist
version: 4.0.0
path: C:\Program Files (x86)\nodejs\node_modules\npm\node_modules\yallist\package.json
209654 - OS Fingerprints Detected
-
Synopsis
Multiple OS fingerprints were detected.
Description
Using a combination of remote probes (TCP/IP, SMB, HTTP, NTP, SNMP, etc), it was possible to gather one or more fingerprints from the remote system. While the highest-confidence result was reported in plugin 11936, “OS Identification”, the complete set of fingerprints detected are reported here.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/02/26, Modified: 2025/03/03
Plugin Output

tcp/0


Following OS Fingerprints were found

Remote operating system : Microsoft Windows Server 2019
Confidence level : 56
Method : MLSinFP
Type : unknown
Fingerprint : unknown

Remote operating system : Windows
Confidence level : 50
Method : Misc
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 100
Method : SMB_OS
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 70
Method : HTTP
Type : general-purpose
Fingerprint : HTTP:Server: Microsoft-HTTPAPI/2.0


Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 70
Method : SinFP
Type : general-purpose
Fingerprint : SinFP:
P1:B11113:F0x12:W65392:O0204ffff:M1460:
P2:B11113:F0x12:W65535:O0204ffff0103030801010402:M1460:
P3:B00000:F0x00:W0:O0:M0
P4:191601_7_p=49667

Following fingerprints could not be used to determine OS :
SSLcert:!:i/CN:GlobalSign RSA OV SSL CA 2018i/O:GlobalSign nv-sas/CN:www.lkp.net.ins/O:LKP SECURITIES LIMITED
f66174c5d8d4f20ea993126eca563ea908172c9b
i/CN:MiddlewareAPIs/CN:MiddlewareAPI
8a3ad3b8b91bd8638c2fc1963f652eec236218e3
i/CN:SSL_Self_Signed_Fallbacks/CN:SSL_Self_Signed_Fallback
dddfedbe63a1d96a6731b083bff2b91cae0d8dfe
11936 - OS Identification
-
Synopsis
It is possible to guess the remote operating system.
Description
Using a combination of remote probes (e.g., TCP/IP, SMB, HTTP, NTP, SNMP, etc.), it is possible to guess the name of the remote operating system in use. It is also possible sometimes to guess the version of the operating system.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2003/12/09, Modified: 2025/06/03
Plugin Output

tcp/0


Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 100
Method : SMB_OS


The remote host is running Microsoft Windows Server 2019 Datacenter Build 17763

117887 - OS Security Patch Assessment Available
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials and enumerate OS security patch levels.
Description
Nessus was able to determine OS security patch levels by logging into the remote host and running commands to determine the version of the operating system and its components. The remote host was identified as an operating system or device that Nessus supports for patch and update assessment. The necessary information was obtained to perform these checks.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0516
Plugin Information
Published: 2018/10/02, Modified: 2021/07/12
Plugin Output

tcp/445/cifs

OS Security Patch Assessment is available.

Account : 172.17.100.112\tidua
Protocol : SMB

92426 - OpenSaveMRU History
-
Synopsis
Nessus was able to enumerate opened and saved files on the remote host.
Description
Nessus was able to generate a report on files that were opened using the shell dialog box or saved using the shell dialog box. This is the box that appears when you attempt to save a document or open a document in Windows Explorer.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Open / Save report attached.

71462 - Oracle Java JRE Premier Support and Extended Support Version Detection
-
Synopsis
The remote host contains one or more versions of the Oracle Java JRE that require long-term support.
Description
According to its version, there is at least one install of Oracle (formerly Sun) Java JRE that is potentially under either Premier Support or Extended Support.

Note that both support programs require vendor contracts. Premier Support provides upgrades and security fixes for five years after the general availability (GA) date. Extended Support provides upgrades and security fixes for three years after Premier Support ends.
See Also
Solution
To continue receiving updates and security fixes, contact the vendor regarding Premier Support or Extended Support contracts.
Risk Factor
None
Plugin Information
Published: 2013/12/16, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following Java JRE installs are in Premier Support status :

Path : C:\Program Files\Java\jdk-17
Version : 17.0.12
Support dates : 2026-09-01 (end of Premier Support) / 2029-09-01 (end of Extended Support)

33545 - Oracle Java Runtime Environment (JRE) Detection
-
Synopsis
There is a Java runtime environment installed on the remote Windows host.
Description
One or more instances of Oracle's (formerly Sun's) Java Runtime Environment (JRE) is installed on the remote host. This may include private JREs bundled with the Java Development Kit (JDK).

- Additional instances of Java may be discovered if thorough tests are enabled.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0690
Plugin Information
Published: 2008/07/18, Modified: 2022/10/10
Plugin Output

tcp/0


Path : C:\Program Files\Java\jdk-17\
Version : 17.0.12
Binary Location : C:\Program Files\Java\jdk-17\bin\java.exe
66334 - Patch Report
-
Synopsis
The remote host is missing several patches.
Description
The remote host is missing one or more security patches. This plugin lists the newest version of each patch to install to make sure the remote host is up-to-date.

Note: Because the 'Show missing patches that have been superseded' setting in your scan policy depends on this plugin, it will always run and cannot be disabled.
Solution
Install the patches listed below.
Risk Factor
None
Plugin Information
Published: 2013/07/08, Modified: 2025/12/15
Plugin Output

tcp/0



. You need to take the following 42 actions :

+ Install the following Microsoft patches :
- KB5071544 (29 vulnerabilities)The following KBs would be covered:
KB5063877, KB5065428, KB5066586, KB5055519, KB5052000,
KB5058392, KB5060531, KB5048661, KB5050008, KB5068791,
KB5062557, KB5053596, KB5041578, KB5043050, KB5044277,
KB5036896, KB5037765, KB5034768, KB5039705, KB5039217,
KB5033371, KB5034127, KB5046615, KB5040430, KB5035849,
KB5029247, KB5030214, KB5031361, KB5032196
- KB5049615
- KB5044022
- KB5039886
- KB5036610
- KB5033911
- KB5031990
- KB5029925
- KB5028953
- KB5027124
- KB5022504
- KB5020874
- KB5020615
- KB5013626
- KB5012119
- KB5008878
- KB4601055
- KB4578973
- KB4576483
- KB4569750
- KB4565632
- KB4552930
- KB2850016

[ Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104) (156103) ]

+ Action to take : Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life.

Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions.


[ Curl 7.84 <= 8.2.1 Header DoS (CVE-2023-38039) (181409) ]

+ Action to take : Upgrade Curl to version 8.3.0 or later


[ MS13-074: Vulnerabilities in Microsoft Access Could Allow Remote Code Execution (2848637) (69834) ]

+ Action to take : Microsoft has released a set of patches for Microsoft Office 2007, 2010, and 2013.

+ Impact : Taking this action will resolve the following 3 different vulnerabilities :
CVE-2013-3157, CVE-2013-3156, CVE-2013-3155


[ Microsoft ASP.NET Core Security Feature Bypass (October 2025) (270707) ]

+ Action to take : Update .NET Core to version 8.0.21, 9.0.10, 10.0.0-rc.2.25502.107 or later.

+ Impact : Taking this action will resolve the following 4 different vulnerabilities :
CVE-2025-55315, CVE-2024-21386, CVE-2023-44487, CVE-2023-36558


[ Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203) (192147) ]

+ Action to take : Upgrade to Microsoft Azure Data Studio version 1.48.0 or later.


[ Node.js 18.x < 18.20.6 / 20.x < 20.18.2 / 22.x < 22.13.1 / 23.x < 23.6.1 Multiple Vulnerabilities (Tuesday, January 21, 2025 Security Releases). (214404) ]

+ Action to take : Upgrade to Node.js version 18.20.6 / 20.18.2 / 22.13.1 / 23.6.1 or later.

+ Impact : Taking this action will resolve the following 29 different vulnerabilities :
CVE-2025-23085, CVE-2025-23083, CVE-2024-37372, CVE-2024-36137, CVE-2024-27983
CVE-2024-27982, CVE-2024-27980, CVE-2024-22020, CVE-2024-22019, CVE-2024-22018
CVE-2024-22017, CVE-2024-21896, CVE-2024-21892, CVE-2024-21891, CVE-2024-21890
CVE-2023-46809, CVE-2023-45143, CVE-2023-44487, CVE-2023-39333, CVE-2023-39332
CVE-2023-39331, CVE-2023-38552, CVE-2023-32559, CVE-2023-32558, CVE-2023-32006
CVE-2023-32005, CVE-2023-32004, CVE-2023-32003, CVE-2023-32002


[ Node.js 18.x < 18.20.6 / 20.x < 20.18.2 / 22.x < 22.13.1 / 23.x < 23.6.1 Multiple Vulnerabilities (Tuesday, January 21, 2025 Security Releases). (243568) ]

+ Action to take : Upgrade to Node.js version 18.20.6 / 20.18.2 / 22.13.1 / 23.6.1 or later.

+ Impact : Taking this action will resolve the following 28 different vulnerabilities :
CVE-2025-23084, CVE-2024-37372, CVE-2024-36137, CVE-2024-27983, CVE-2024-27982
CVE-2024-27980, CVE-2024-22020, CVE-2024-22019, CVE-2024-22018, CVE-2024-22017
CVE-2024-21896, CVE-2024-21892, CVE-2024-21891, CVE-2024-21890, CVE-2023-46809
CVE-2023-45143, CVE-2023-44487, CVE-2023-39333, CVE-2023-39332, CVE-2023-39331
CVE-2023-38552, CVE-2023-32559, CVE-2023-32558, CVE-2023-32006, CVE-2023-32005
CVE-2023-32004, CVE-2023-32003, CVE-2023-32002


[ Node.js Module node-tar < 6.2.1 DoS (192685) ]

+ Action to take : Upgrade to node-tar version 6.2.1 or later.


[ Oracle Java SE Multiple Vulnerabilities (October 2025 CPU) (271249) ]

+ Action to take : Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory.

+ Impact : Taking this action will resolve the following 74 different vulnerabilities :
CVE-2025-6558, CVE-2025-61748, CVE-2025-53066, CVE-2025-53057, CVE-2025-50106
CVE-2025-50063, CVE-2025-50059, CVE-2025-43265, CVE-2025-43240, CVE-2025-43228
CVE-2025-43227, CVE-2025-43216, CVE-2025-43212, CVE-2025-43211, CVE-2025-32415
CVE-2025-32414, CVE-2025-31278, CVE-2025-31273, CVE-2025-31257, CVE-2025-30761
CVE-2025-30754, CVE-2025-30752, CVE-2025-30749, CVE-2025-30698, CVE-2025-30691
CVE-2025-27113, CVE-2025-24928, CVE-2025-24855, CVE-2025-24189, CVE-2025-24162
CVE-2025-24158, CVE-2025-24150, CVE-2025-24143, CVE-2025-23085, CVE-2025-23084
CVE-2025-23083, CVE-2025-21587, CVE-2025-21502, CVE-2025-0509, CVE-2024-56171
CVE-2024-55549, CVE-2024-54543, CVE-2024-54534, CVE-2024-54508, CVE-2024-54505
CVE-2024-54502, CVE-2024-54479, CVE-2024-47778, CVE-2024-47777, CVE-2024-47776
CVE-2024-47775, CVE-2024-47606, CVE-2024-47597, CVE-2024-47596, CVE-2024-47546
CVE-2024-47545, CVE-2024-47544, CVE-2024-44309, CVE-2024-44308, CVE-2024-44296
CVE-2024-44244, CVE-2024-44187, CVE-2024-44185, CVE-2024-40896, CVE-2024-40866
CVE-2024-36138, CVE-2024-27856, CVE-2024-25062, CVE-2024-22020, CVE-2024-21235
CVE-2024-21217, CVE-2024-21211, CVE-2024-21210, CVE-2024-21208


[ RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088) (248462) ]

+ Action to take : Upgrade to RARLAB WinRAR version 7.13 or later.

+ Impact : Taking this action will resolve the following 7 different vulnerabilities :
CVE-2025-8088, CVE-2025-6218, CVE-2025-31334, CVE-2024-36052, CVE-2024-30370
CVE-2023-40477, CVE-2023-38831


[ Security Update for Microsoft .NET Core (October 2025) (270711) ]

+ Action to take : Update .NET Core, remove vulnerable packages and refer to vendor advisory.

+ Impact : Taking this action will resolve the following 38 different vulnerabilities :
CVE-2025-55248, CVE-2025-30399, CVE-2025-26682, CVE-2025-26646, CVE-2025-24070
CVE-2025-21176, CVE-2025-21173, CVE-2025-21172, CVE-2024-43485, CVE-2024-43484
CVE-2024-43483, CVE-2024-38229, CVE-2024-38168, CVE-2024-38167, CVE-2024-38095
CVE-2024-38081, CVE-2024-35264, CVE-2024-30105, CVE-2024-30045, CVE-2024-21409
CVE-2024-21404, CVE-2024-21392, CVE-2024-20672, CVE-2024-0057, CVE-2023-44487
CVE-2023-38171, CVE-2023-36796, CVE-2023-36794, CVE-2023-36793, CVE-2023-36792
CVE-2023-36558, CVE-2023-36435, CVE-2019-0982, CVE-2019-0981, CVE-2019-0980
CVE-2019-0820, CVE-2019-0757, CVE-2019-0657


[ Security Update for Microsoft Visual Studio Code (November 2025) (275467) ]

+ Action to take : Update to Microsoft Visual Studio Code 1.105.1 or later.

+ Impact : Taking this action will resolve the following 11 different vulnerabilities :
CVE-2025-62453, CVE-2025-55319, CVE-2025-26631, CVE-2025-24042, CVE-2025-24039
CVE-2025-21264, CVE-2025-20570, CVE-2024-26165, CVE-2023-39956, CVE-2023-36742
CVE-2023-33144


[ Security Updates for Microsoft .NET Framework (January 2025) (214274) ]

+ Action to take : Microsoft has released security updates for Microsoft .NET Framework.

+ Impact : Taking this action will resolve the following 40 different vulnerabilities :
CVE-2025-21176, CVE-2024-43484, CVE-2024-43483, CVE-2024-38081, CVE-2024-29059
CVE-2024-21409, CVE-2024-21312, CVE-2024-0057, CVE-2024-0056, CVE-2023-36899
CVE-2023-36873, CVE-2023-36796, CVE-2023-36794, CVE-2023-36793, CVE-2023-36792
CVE-2023-36788, CVE-2023-36560, CVE-2023-36049, CVE-2023-36042, CVE-2023-32030
CVE-2023-29331, CVE-2023-29330, CVE-2023-29326, CVE-2023-24936, CVE-2023-24897
CVE-2023-24895, CVE-2023-21808, CVE-2023-21722, CVE-2022-41089, CVE-2022-41064
CVE-2022-30130, CVE-2022-26832, CVE-2022-21911, CVE-2021-24111, CVE-2020-16937
CVE-2020-1476, CVE-2020-1147, CVE-2020-1108, CVE-2020-1066, CVE-2020-1046



[ Security Updates for Microsoft Office Products (March 2021) (147218) ]

+ Action to take : Microsoft has released the following security updates to address this issue:
-KB4493228
-KB4493203
-KB4504703
-KB4493225
-KB4493200
-KB4493214

+ Impact : Taking this action will resolve the following 35 different vulnerabilities :
CVE-2021-27059, CVE-2021-27057, CVE-2021-27054, CVE-2021-24108, CVE-2014-4117
CVE-2014-1809, CVE-2014-1761, CVE-2014-1758, CVE-2014-1757, CVE-2014-0260
CVE-2014-0259, CVE-2014-0258, CVE-2013-5057, CVE-2013-3858, CVE-2013-3857
CVE-2013-3856, CVE-2013-3855, CVE-2013-3854, CVE-2013-3853, CVE-2013-3852
CVE-2013-3851, CVE-2013-3850, CVE-2013-3849, CVE-2013-3848, CVE-2013-3847
CVE-2013-3160, CVE-2012-2539, CVE-2012-2528, CVE-2012-2524, CVE-2012-1856
CVE-2012-0182, CVE-2012-0158, CVE-2011-1983, CVE-2011-1982, CVE-2011-1980



[ Security Updates for Microsoft SQL Server (November 2025) (275459) ]

+ Action to take : Microsoft has released security updates for Microsoft SQL Server.

+ Impact : Taking this action will resolve the following 122 different vulnerabilities :
CVE-2025-59499, CVE-2025-55227, CVE-2025-53727, CVE-2025-49719, CVE-2025-49718
CVE-2025-49717, CVE-2025-47997, CVE-2024-49043, CVE-2024-49021, CVE-2024-49018
CVE-2024-49017, CVE-2024-49016, CVE-2024-49015, CVE-2024-49014, CVE-2024-49013
CVE-2024-49012, CVE-2024-49011, CVE-2024-49010, CVE-2024-49009, CVE-2024-49008
CVE-2024-49007, CVE-2024-49006, CVE-2024-49005, CVE-2024-49004, CVE-2024-49003
CVE-2024-49002, CVE-2024-49001, CVE-2024-49000, CVE-2024-48999, CVE-2024-48998
CVE-2024-48997, CVE-2024-48996, CVE-2024-48995, CVE-2024-48994, CVE-2024-48993
CVE-2024-43474, CVE-2024-43462, CVE-2024-43459, CVE-2024-38255, CVE-2024-38088
CVE-2024-38087, CVE-2024-37980, CVE-2024-37966, CVE-2024-37965, CVE-2024-37342
CVE-2024-37341, CVE-2024-37340, CVE-2024-37339, CVE-2024-37338, CVE-2024-37337
CVE-2024-37336, CVE-2024-37335, CVE-2024-37334, CVE-2024-37333, CVE-2024-37332
CVE-2024-37331, CVE-2024-37330, CVE-2024-37329, CVE-2024-37328, CVE-2024-37327
CVE-2024-37326, CVE-2024-37324, CVE-2024-37323, CVE-2024-37322, CVE-2024-37321
CVE-2024-37320, CVE-2024-37319, CVE-2024-37318, CVE-2024-35272, CVE-2024-35271
CVE-2024-35256, CVE-2024-29043, CVE-2024-28943, CVE-2024-28941, CVE-2024-28938
CVE-2024-28937, CVE-2024-28936, CVE-2024-28935, CVE-2024-28934, CVE-2024-28933
CVE-2024-28932, CVE-2024-28931, CVE-2024-28930, CVE-2024-28929, CVE-2024-28928
CVE-2024-26191, CVE-2024-26186, CVE-2024-21907, CVE-2024-21449, CVE-2024-21428
CVE-2024-21425, CVE-2024-21415, CVE-2024-21414, CVE-2024-21398, CVE-2024-21373
CVE-2024-21335, CVE-2024-21333, CVE-2024-21332, CVE-2024-21331, CVE-2024-21317
CVE-2024-21308, CVE-2024-21303, CVE-2024-20701, CVE-2023-36785, CVE-2023-36730
CVE-2023-36728, CVE-2023-36420, CVE-2023-36417, CVE-2023-32027, CVE-2023-32026
CVE-2023-32025, CVE-2023-29356, CVE-2023-29349, CVE-2023-23384, CVE-2023-21718
CVE-2023-21713, CVE-2023-21705, CVE-2023-21704, CVE-2023-21568, CVE-2023-21528
CVE-2022-29143, CVE-2021-1636


[ Security Updates for Microsoft SQL Server OLE DB Driver (July 2024) (205300) ]

+ Action to take : Microsoft has released security updates for the Microsoft SQL OLE DB Driver.

+ Impact : Taking this action will resolve the following 31 different vulnerabilities :
CVE-2024-37334, CVE-2024-29985, CVE-2024-29984, CVE-2024-29983, CVE-2024-29982
CVE-2024-29048, CVE-2024-29047, CVE-2024-29046, CVE-2024-29045, CVE-2024-29044
CVE-2024-28945, CVE-2024-28944, CVE-2024-28942, CVE-2024-28940, CVE-2024-28939
CVE-2024-28927, CVE-2024-28926, CVE-2024-28915, CVE-2024-28914, CVE-2024-28913
CVE-2024-28912, CVE-2024-28911, CVE-2024-28910, CVE-2024-28909, CVE-2024-28908
CVE-2024-28906, CVE-2023-38169, CVE-2023-36728, CVE-2023-36417, CVE-2023-32028
CVE-2023-29349


[ Security Updates for Microsoft Visual Studio Products (July 2025) (241959) ]

+ Action to take : Microsoft has released the following security updates to address this issue:
- Update 17.14.8 for Visual Studio 2022
- Update 17.12.10 for Visual Studio 2022
- Update 17.10.17 for Visual Studio 2022
- Update 17.8.23 for Visual Studio 2022
- Update 16.11.49 for Visual Studio 2019
- Update 15.9.75 for Visual Studio 2017

+ Impact : Taking this action will resolve the following 172 different vulnerabilities :
CVE-2025-49739, CVE-2025-48386, CVE-2025-48385, CVE-2025-48384, CVE-2025-47959
CVE-2025-46835, CVE-2025-46334, CVE-2025-32703, CVE-2025-32702, CVE-2025-30399
CVE-2025-29804, CVE-2025-29802, CVE-2025-27614, CVE-2025-27613, CVE-2025-26646
CVE-2025-25003, CVE-2025-24998, CVE-2025-24070, CVE-2025-21206, CVE-2025-21178
CVE-2025-21176, CVE-2025-21173, CVE-2025-21172, CVE-2025-21171, CVE-2024-50338
CVE-2024-49050, CVE-2024-49049, CVE-2024-49044, CVE-2024-43603, CVE-2024-43590
CVE-2024-43499, CVE-2024-43498, CVE-2024-43485, CVE-2024-43484, CVE-2024-43483
CVE-2024-38168, CVE-2024-38167, CVE-2024-38095, CVE-2024-38081, CVE-2024-35264
CVE-2024-32004, CVE-2024-32002, CVE-2024-30105, CVE-2024-30052, CVE-2024-30046
CVE-2024-30045, CVE-2024-29187, CVE-2024-29060, CVE-2024-28938, CVE-2024-28937
CVE-2024-28936, CVE-2024-28935, CVE-2024-28934, CVE-2024-28933, CVE-2024-28932
CVE-2024-28931, CVE-2024-28930, CVE-2024-28929, CVE-2024-26190, CVE-2024-21409
CVE-2024-21404, CVE-2024-21392, CVE-2024-21386, CVE-2024-21319, CVE-2024-20656
CVE-2024-0057, CVE-2024-0056, CVE-2023-36897, CVE-2023-33139, CVE-2023-33135
CVE-2023-33128, CVE-2023-33126, CVE-2023-33032, CVE-2023-32028, CVE-2023-32027
CVE-2023-32026, CVE-2023-32025, CVE-2023-29356, CVE-2023-29349, CVE-2023-29331
CVE-2023-29012, CVE-2023-29011, CVE-2023-29007, CVE-2023-28299, CVE-2023-28296
CVE-2023-28263, CVE-2023-28262, CVE-2023-28260, CVE-2023-27911, CVE-2023-27910
CVE-2023-27909, CVE-2023-25815, CVE-2023-25652, CVE-2023-24936, CVE-2023-24897
CVE-2023-24895, CVE-2023-23946, CVE-2023-23618, CVE-2023-23381, CVE-2023-22743
CVE-2023-22490, CVE-2023-21815, CVE-2023-21808, CVE-2021-42319, CVE-2021-42277
CVE-2021-41355, CVE-2021-36952, CVE-2021-34532, CVE-2021-3450, CVE-2021-3449
CVE-2021-34485, CVE-2021-31204, CVE-2021-28322, CVE-2021-28321, CVE-2021-28313
CVE-2021-27068, CVE-2021-27064, CVE-2021-26434, CVE-2021-26423, CVE-2021-21300
CVE-2021-1971, CVE-2021-1723, CVE-2021-1721, CVE-2021-1680, CVE-2021-1651
CVE-2021-1639, CVE-2020-26870, CVE-2020-1971, CVE-2020-17156, CVE-2020-17100
CVE-2020-16874, CVE-2020-16856, CVE-2020-1597, CVE-2020-1416, CVE-2020-1393
CVE-2020-1293, CVE-2020-1278, CVE-2020-1257, CVE-2020-1203, CVE-2020-1202
CVE-2020-1161, CVE-2020-1147, CVE-2020-1133, CVE-2020-1130, CVE-2020-1108
CVE-2020-0900, CVE-2020-0899, CVE-2020-0884, CVE-2020-0810, CVE-2020-0793
CVE-2020-0789, CVE-2019-1486, CVE-2019-1425, CVE-2019-1387, CVE-2019-1354
CVE-2019-1352, CVE-2019-1351, CVE-2019-1350, CVE-2019-1349, CVE-2019-1301
CVE-2019-1232, CVE-2019-1211, CVE-2019-1113, CVE-2019-1079, CVE-2019-1077
CVE-2019-0809, CVE-2019-0727, CVE-2019-0657, CVE-2019-0613, CVE-2019-0546
CVE-2019-0537, CVE-2018-8599


[ VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015) (266420) ]

+ Action to take : Upgrade to VMware Tools version 12.5.4, 13.0.5 or later.

+ Impact : Taking this action will resolve the following 5 different vulnerabilities :
CVE-2025-41246, CVE-2025-41244, CVE-2025-41239, CVE-2025-22247, CVE-2025-22230



[ Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803) (276819) ]

+ Action to take : Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later.

206777 - Postman Installed (Windows)
-
Synopsis
Postman is installed on the remote Windows host.
Description
Postman is installed on the remote Windows host.

Note. To detect the software, customers need to use an account that is used to install the software, or one that has the administrative privileges on the target.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/09/09, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Users\Administrator\AppData\Local\Postman
Version : 9.22.2

122422 - RARLAB WinRAR Installed (Windows)
-
Synopsis
An archive manager is installed on the remote Windows host.
Description
RARLAB WinRaR, an archive manager, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0706
Plugin Information
Published: 2019/02/26, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Version : 5.90.0.0

92428 - Recent File History
-
Synopsis
Nessus was able to enumerate recently opened files on the remote host.
Description
Nessus was able to gather evidence of files opened by file type from the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\Users\tidua\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini

Recent files found in registry and appdata attached.
92429 - Recycle Bin Files
-
Synopsis
Nessus was able to enumerate files in the recycle bin on the remote host.
Description
Nessus was able to generate a list of all files found in $Recycle.Bin subdirectories.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\$Recycle.Bin\\.
C:\\$Recycle.Bin\\..
C:\\$Recycle.Bin\\S-1-5-21-1687551350-3880216100-4069998428-1009
C:\\$Recycle.Bin\\S-1-5-21-1687551350-3880216100-4069998428-500
C:\\$Recycle.Bin\\S-1-5-21-1687551350-3880216100-4069998428-1009\.
C:\\$Recycle.Bin\\S-1-5-21-1687551350-3880216100-4069998428-1009\..
C:\\$Recycle.Bin\\S-1-5-21-1687551350-3880216100-4069998428-1009\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-1687551350-3880216100-4069998428-500\.
C:\\$Recycle.Bin\\S-1-5-21-1687551350-3880216100-4069998428-500\..
C:\\$Recycle.Bin\\S-1-5-21-1687551350-3880216100-4069998428-500\desktop.ini
92430 - Registry Editor Last Accessed
-
Synopsis
Nessus was able to find the last key accessed by the Registry Editor when it was closed on the remote host.
Description
Nessus was able to find evidence of the last key that was opened when the Registry Editor was closed for each user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

production
- Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

10940 - Remote Desktop Protocol Service Detection
-
Synopsis
The remote host has an remote desktop protocol service enabled.
Description
The Remote Desktop Protocol allows a user to remotely obtain a graphical login (and therefore act as a local user on the remote host).

If an attacker gains a valid login and password, this service could be used to gain further access on the remote host. An attacker may also use this service to mount a dictionary attack against the remote host to try to log in remotely.

Note that RDP (the Remote Desktop Protocol) is vulnerable to Man-in-the-middle attacks, making it easy for attackers to steal the credentials of legitimate users by impersonating the Windows server.
Solution
Disable the service if you do not use it, and do not allow this service to run across the Internet.
Risk Factor
None
Plugin Information
Published: 2002/04/20, Modified: 2023/08/21
Plugin Output

tcp/3389/msrdp

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/443/www

The target TLS server offers no post-quantum ciphers.

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/1433/mssql

The target TLS server offers no post-quantum ciphers.

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/3389/msrdp

The target TLS server offers no post-quantum ciphers.

62042 - SMB QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote host has quick-fix engineering updates installed.
Description
By connecting to the host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/09/11, Modified: 2022/02/01
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

KB4486153, Installed on: 2023/12/27
KB4502496, Installed on: 2021/12/07
KB4535680, Installed on: 2021/12/07
KB4535684, Installed on: 2021/12/07
KB4535685, Installed on: 2021/12/07
KB4558997, Installed on: 2020/07/11
KB4558998, Installed on: 2020/07/11
KB4565625
KB4587735, Installed on: 2020/12/06
KB4589208, Installed on: 2021/12/07
KB5006754, Installed on: 2021/12/07
KB5008539, Installed on: 2021/12/08
KB5009642, Installed on: 2022/03/24
KB5011574, Installed on: 2022/05/04
KB5012128
KB5028316, Installed on: 2023/08/11
KB5029247, Installed on: 2023/08/11
42897 - SMB Registry : Start the Registry Service during the scan (WMI)
-
Synopsis
The registry service was enabled for the duration of the scan.
Description
To perform a full credentialed scan, Nessus needs the ability to connect to the remote registry service (RemoteRegistry). If the service is down, this plugin will attempt to start for the duration of the scan.

For this plugin to work, you need to select the option 'Start the Remote Registry service during the scan' on the credentials page when you add your Windows credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/25, Modified: 2025/12/15
Plugin Output

tcp/0


The registry service was successfully started for the duration of the scan.
42898 - SMB Registry : Stop the Registry Service after the scan (WMI)
-
Synopsis
The registry service was stopped after the scan.
Description
To perform a full credentialed scan, Nessus needs the ability to connect to the remote registry service (RemoteRegistry). If the service is down and if Nessus automatically enabled the registry for the duration of the scan, this plugins will stop it afterwards.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/25, Modified: 2025/12/15
Plugin Output

tcp/0


The registry service was successfully stopped after the scan.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/443/www


This port supports TLSv1.2.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/1433/mssql


This port supports TLSv1.2.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


This port supports TLSv1.2.

45410 - SSL Certificate 'commonName' Mismatch
-
Synopsis
The 'commonName' (CN) attribute in the SSL certificate does not match the hostname.
Description
The service running on the remote host presents an SSL certificate for which the 'commonName' (CN) attribute does not match the hostname on which the service listens.
Solution
If the machine has several names, make sure that users connect to the service through the DNS hostname that matches the common name in the certificate.
Risk Factor
None
Plugin Information
Published: 2010/04/03, Modified: 2021/03/09
Plugin Output

tcp/443/www


The host name known by Nessus is :

middlewareapi

The Common Name in the certificate is :

www.lkp.net.in

The Subject Alternate Names in the certificate are :

admin.pennypal.in
aims.lkp.net.in
allocation.lkp.net.in
api.lkp.net.in
backoffice.lkp.net.in
bo.lkp.net.in
demo.pennypal.in
devtrade.lkp.net.in
devtradekyc.lkp.net.in
druat.pennypal.in
ekyc.lkp.net.in
ekyc.lkponline.com
ekyc.pennypal.in
ekycuat.lkp.net.in
getsetgrow.lkponline.com
hrms.lkp.net.in
ia.lkp.net.in
ipo.lkp.net.in
lkp.net.in
lkpconnect.net.in
lkpsec.com
lms.lkp.net.in
middleware.lkp.net.in
middlewareapi.lkp.net.in
notification.lkponline.com
notification.pennypal.in
pay.lkp.net.in
pennypal.in
ra.lkp.net.in
referral.pennypal.in
rekyc.pennypal.in
spip.lkp.net.in
spip.lkponline.com
trading.lkponline.com
trading.pennypal.in
trilogy.lkp.net.in
uat.lkp.net.in
uat.lkpsec.com
uat.pennypal.in
uatbackoffice.lkp.net.in
uatekyc.lkponline.com
uatgetsetgrow.lkponline.com
uatspip.lkponline.com
uattrading.lkponline.com
uatweb.pennypal.in
wealth.lkp.net.in
welcome.lkp.net.in
www.lkp.net.in
www.lkpfinance.com
www.lkpsec.com

45410 - SSL Certificate 'commonName' Mismatch
-
Synopsis
The 'commonName' (CN) attribute in the SSL certificate does not match the hostname.
Description
The service running on the remote host presents an SSL certificate for which the 'commonName' (CN) attribute does not match the hostname on which the service listens.
Solution
If the machine has several names, make sure that users connect to the service through the DNS hostname that matches the common name in the certificate.
Risk Factor
None
Plugin Information
Published: 2010/04/03, Modified: 2021/03/09
Plugin Output

tcp/1433/mssql


The host name known by Nessus is :

middlewareapi

The Common Name in the certificate is :

ssl_self_signed_fallback

83298 - SSL Certificate Chain Contains Certificates Expiring Soon
-
Synopsis
The remote host has an SSL certificate chain with one or more certificates that are going to expire soon.
Description
The remote host has an SSL certificate chain with one or more SSL certificates that are going to expire soon. Failure to renew these certificates before the expiration date may result in denial of service for users.
Solution
Renew any soon to expire SSL certificates.
Risk Factor
None
Plugin Information
Published: 2015/05/08, Modified: 2015/05/08
Plugin Output

tcp/3389/msrdp


The following soon to expire certificate was part of the certificate
chain sent by the remote host :

|-Subject : CN=MiddlewareAPI
|-Not After : Mar 06 07:26:52 2026 GMT
42981 - SSL Certificate Expiry - Future Expiry
-
Synopsis
The SSL certificate associated with the remote service will expire soon.
Description
The SSL certificate associated with the remote service will expire soon.
Solution
Purchase or generate a new SSL certificate in the near future to replace the existing one.
Risk Factor
None
Plugin Information
Published: 2009/12/02, Modified: 2020/09/04
Plugin Output

tcp/3389/msrdp


The SSL certificate will expire within 60 days, at
Mar 6 07:26:52 2026 GMT :

Subject : CN=MiddlewareAPI
Issuer : CN=MiddlewareAPI
Not valid before : Sep 4 07:26:52 2025 GMT
Not valid after : Mar 6 07:26:52 2026 GMT

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/443/www

Subject Name:

Country: IN
State/Province: Maharashtra
Locality: Mumbai
Organization: LKP SECURITIES LIMITED
Common Name: www.lkp.net.in

Issuer Name:

Country: BE
Organization: GlobalSign nv-sa
Common Name: GlobalSign RSA OV SSL CA 2018

Serial Number: 19 A0 03 FE 47 ED 49 8F 58 AA 19 0A

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Apr 21 10:26:13 2025 GMT
Not Valid After: May 23 10:26:12 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 BF AD CA E4 8E 7F CA 0A 53 22 21 11 61 2F 16 AB A2 1E E1
8C F4 D4 F3 FE BF 71 33 7F E4 DA 14 0C D4 1A 94 23 D5 D8 84
8C F3 88 52 5B E9 16 F0 11 2A 6A 1D C1 04 EE AA 58 0B 41 03
0E 5E E7 E3 7D 19 BF 94 72 12 36 70 3C F8 70 C8 64 98 2E 2D
18 00 93 7E 42 10 0F 11 5A F3 B0 73 8A E6 D2 9B 42 1E 0A A8
25 3B 7E 3D D6 D0 80 D7 47 2D 35 1F BA D1 D0 9A 6E 77 AC BD
95 49 5C 70 61 9A 77 20 EB 41 1B 0E 37 24 59 10 00 FA B7 EF
16 31 13 78 86 6E 73 7B 4C 5F C6 A0 71 97 25 90 24 B2 87 4B
45 E7 D9 5D C7 17 59 01 D8 94 F2 5A 95 BC 3F 3D EC 48 9E 23
B2 B3 7C 71 FB 50 E6 7B 59 F2 3C 02 FB 0C 54 7E 05 05 A8 97
57 69 05 BB 6B DF 05 15 4D EC 4A DC 99 05 A0 64 C5 76 54 7A
C4 31 92 0E 43 D1 53 88 2A ED 81 CD 44 A6 DA 1F 80 55 11 84
EF 92 27 43 DB E2 D4 71 A6 B4 95 1F 35 15 EB 61 8B
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 70 EA 52 F8 6C 82 4B 72 5D FA 42 2E A6 FF 47 33 0B 5E 2F
BF 71 9E 0F C7 F6 17 B4 5C 29 2C BB 72 26 53 6C 4A EA E7 EF
C0 31 95 6A 51 D6 2A A5 9C 99 0C 7B 8E BE 4B 10 4C B6 20 65
91 36 C7 FE 70 7B 31 11 11 A3 02 CD 2D DA 59 46 FA 32 23 73
9D BF AE 3C 9A A0 ED E8 40 EE 96 FB 64 9C 94 03 16 58 C2 21
69 2E 74 44 3F 05 BC 2D A4 E1 A1 11 77 17 10 FC 8A E2 E6 18
E1 25 E4 43 A3 78 38 EB D0 96 85 2C 8D 72 ED 68 15 7F 90 C1
62 DF A9 F1 5C DD 87 84 9C 33 23 1C F2 51 08 C2 AC 17 84 85
F8 F7 93 AB 17 6E 32 D0 DF 2B 69 4A 32 68 6A 53 27 AF C3 5F
4B 7A F0 31 3E CB 4F 48 20 3E 06 D2 3B 0C 65 B4 63 3B D2 7B
45 DC 5B 33 40 97 33 CC 31 99 24 80 E3 C1 F6 C4 5F C6 B0 DC
54 82 A8 01 E7 4F AD 58 5A 1D B1 25 01 1A C3 84 19 EB 32 E7
20 79 07 E6 06 DD EE 28 DC 63 03 7D 2A 90 2C 6E C7

Extension: Key Usage(2.5.29.15)
Critical: 1
Key Usage: Digital Signature, Key Encipherment


Extension: Basic Constraints(2.5.29.19)
Critical: 1


Extension: Authority Information Access(1.3.6.1.5.5.7.1.1)
Critical: 0
Method#1: Certificate Authority Issuers
URI: http://secure.globalsign.com/cacert/gsrsaovsslca2018.crt
Method#2: Online Certificate Status Protocol
URI: http://ocsp.globalsign.com/gsrsaovsslca2018


Extension: Policies(2.5.29.32)
Critical: 0
Policy ID #1: 1.3.6.1.4.1.4146.1.20
Qualifier ID #1: Certification Practice Statement(1.3.6.1.5.5.7.2.1)
CPS URI: https://www.globalsign.com/repository/
Policy ID #2: 2.23.140.1.2.2


Extension: Subject Alternative Name(2.5.29.17)
Critical: 0
DNS: www.lkp.net.in
DNS: www.lkpfinance.com
DNS: uattrading.lkponline.com
DNS: www.lkpsec.com
DNS: trading.lkponline.com
DNS: ekyc.lkponline.com
DNS: lkpsec.com
DNS: uatekyc.lkponline.com
DNS: uat.lkpsec.com
DNS: trading.pennypal.in
DNS: ekyc.pennypal.in
DNS: rekyc.pennypal.in
DNS: uat.pennypal.in
DNS: uatweb.pennypal.in
DNS: pennypal.in
DNS: demo.pennypal.in
DNS: referral.pennypal.in
DNS: notification.lkponline.com
DNS: notification.pennypal.in
DNS: admin.pennypal.in
DNS: uatspip.lkponline.com
DNS: spip.lkponline.com
DNS: druat.pennypal.in
DNS: uatgetsetgrow.lkponline.com
DNS: getsetgrow.lkponline.com
DNS: lkpconnect.net.in
DNS: pay.lkp.net.in
DNS: ekyc.lkp.net.in
DNS: bo.lkp.net.in
DNS: lms.lkp.net.in
DNS: ia.lkp.net.in
DNS: welcome.lkp.net.in
DNS: hrms.lkp.net.in
DNS: devtrade.lkp.net.in
DNS: api.lkp.net.in
DNS: aims.lkp.net.in
DNS: backoffice.lkp.net.in
DNS: devtradekyc.lkp.net.in
DNS: spip.lkp.net.in
DNS: ekycuat.lkp.net.in
DNS: uatbackoffice.lkp.net.in
DNS: wealth.lkp.net.in
DNS: middleware.lkp.net.in
DNS: middlewareapi.lkp.net.in
DNS: ra.lkp.net.in
DNS: ipo.lkp.net.in
DNS: uat.lkp.net.in
DNS: allocation.lkp.net.in
DNS: trilogy.lkp.net.in
DNS: lkp.net.in


Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)
Purpose#2: Web Client Authentication (1.3.6.1.5.5.7.3.2)


Extension: Authority Key Identifier(2.5.29.35)
Critical: 0
Key Identifier: F8 EF 7F F2 CD 78 67 A8 DE 6F 8F 24 8D 88 F1 87 03 02 B3 EB


Extension: Subject Key Identifier(2.5.29.14)
Critical: 0
Subject Key Identifier: 2E 3D 70 B7 04 25 4A 71 43 B6 6A 6E 85 CA 4F 2C 22 95 28 A3


Extension: 1.3.6.1.4.1.11129.2.4.2
Critical: 0
Data: 04 82 01 69 01 67 00 77 00 64 11 C4 6C A4 12 EC A7 89 1C A2
02 2E 00 BC AB 4F 28 07 D4 1E 35 27 AB EA FE D5 03 C9 7D CD
F0 00 00 01 96 57 E2 69 18 00 00 04 03 00 48 30 46 02 21 00
96 52 8C B8 51 AA B8 D9 42 47 DA 1B FE 27 35 66 2E 2F F8 E8
5F DC 5C C5 C9 80 52 A6 E0 0D E2 84 02 21 00 A1 D6 C8 6D 7C
91 4E EA 19 E7 3D 42 7C 00 6E 97 16 76 1A 20 DB 3A 9A 4B D3
E5 D0 87 00 78 3A 4A 00 75 00 CB 38 F7 15 89 7C 84 A1 44 5F
5B C1 DD FB C9 6E F2 9A 59 CD 47 0A 69 05 85 B0 CB 14 C3 14
58 E7 00 00 01 96 57 E2 67 BA 00 00 04 03 00 46 30 44 02 20
5A 27 C8 01 9F C7 B0 9C D6 52 AB 0C 14 AF 20 CF 47 3B 13 05
66 9C 9C 76 64 D8 63 D2 B2 B2 21 9C 02 20 70 82 E8 32 4F 4C
7E 13 8E EB 91 4E 72 A3 56 7A B3 4F DC E4 F6 24 76 97 97 48
28 ED 03 B4 32 70 00 75 00 25 2F 94 C2 2B 29 E9 6E 9F 41 1A
72 07 2B 69 5C 5B 52 FF 97 A9 0D 25 40 BB FC DC 51 EC 4D EE
0B 00 00 01 96 57 E2 69 53 00 00 04 03 00 46 30 44 02 20 61
5F F2 11 43 94 22 D8 EF 61 0C 44 F3 DE 58 50 0D D1 77 D4 45
F8 61 0A B0 3E 5C EA 8D 8C 25 B4 02 20 50 92 96 1B 3F 90 B7
23 1E 26 ED 3F 40 B4 C4 D7 5B 31 4E D7 B7 8B 1E 05 6D DC 51
65 50 91 04 E4


Fingerprints :

SHA-256 Fingerprint: 19 95 B4 E0 56 30 03 B7 44 C1 47 DE DF 5F 1D 04 45 F1 E6 34
1C 37 B0 18 DE 2B 36 C0 83 16 2F F1
SHA-1 Fingerprint: F6 61 74 C5 D8 D4 F2 0E A9 93 12 6E CA 56 3E A9 08 17 2C 9B
MD5 Fingerprint: 76 94 5C 1D 4F B6 7A 66 12 A9 03 D7 C5 41 35 8A


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIKFTCCCP2gAwIBAgIMGaAD/kftSY9YqhkKMA0GCSqGSIb3DQEBCwUAMFAxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMSYwJAYDVQQDEx1HbG9iYWxTaWduIFJTQSBPViBTU0wgQ0EgMjAxODAeFw0yNTA0MjExMDI2MTNaFw0yNjA1MjMxMDI2MTJaMG4xCzAJBgNVBAYTAklOMRQwEgYDVQQIEwtNYWhhcmFzaHRyYTEPMA0GA1UEBxMGTXVtYmFpMR8wHQYDVQQKExZMS1AgU0VDVVJJVElFUyBMSU1JVEVEMRcwFQYDVQQDEw53d3cubGtwLm5ldC5pbjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL+tyuSOf8oKUyIhEWEvFquiHuGM9NTz/r9xM3/k2hQM1BqUI9XYhIzziFJb6RbwESpqHcEE7qpYC0EDDl7n430Zv5RyEjZwPPhwyGSYLi0YAJN+QhAPEVrzsHOK5tKbQh4KqCU7fj3W0IDXRy01H7rR0Jpud6y9lUlccGGadyDrQRsONyRZEAD6t+8WMRN4hm5ze0xfxqBxlyWQJLKHS0Xn2V3HF1kB2JTyWpW8Pz3sSJ4jsrN8cftQ5ntZ8jwC+wxUfgUFqJdXaQW7a98FFU3sStyZBaBkxXZUesQxkg5D0VOIKu2BzUSm2h+AVRGE75InQ9vi1HGmtJUfNRXrYYsCAwEAAaOCBs8wggbLMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMIGOBggrBgEFBQcBAQSBgTB/MEQGCCsGAQUFBzAChjhodHRwOi8vc2VjdXJlLmdsb2JhbHNpZ24uY29tL2NhY2VydC9nc3JzYW92c3NsY2EyMDE4LmNydDA3BggrBgEFBQcwAYYraHR0cDovL29jc3AuZ2xvYmFsc2lnbi5jb20vZ3Nyc2FvdnNzbGNhMjAxODBWBgNVHSAETzBNMEEGCSsGAQQBoDIBFDA0MDIGCCsGAQUFBwIBFiZodHRwczovL3d3dy5nbG9iYWxzaWduLmNvbS9yZXBvc2l0b3J5LzAIBgZngQwBAgIwggPgBgNVHREEggPXMIID04IOd3d3LmxrcC5uZXQuaW6CEnd3dy5sa3BmaW5hbmNlLmNvbYIYdWF0dHJhZGluZy5sa3BvbmxpbmUuY29tgg53d3cubGtwc2VjLmNvbYIVdHJhZGluZy5sa3BvbmxpbmUuY29tghJla3ljLmxrcG9ubGluZS5jb22CCmxrcHNlYy5jb22CFXVhdGVreWMubGtwb25saW5lLmNvbYIOdWF0LmxrcHNlYy5jb22CE3RyYWRpbmcucGVubnlwYWwuaW6CEGVreWMucGVubnlwYWwuaW6CEXJla3ljLnBlbm55cGFsLmlugg91YXQucGVubnlwYWwuaW6CEnVhdHdlYi5wZW5ueXBhbC5pboILcGVubnlwYWwuaW6CEGRlbW8ucGVubnlwYWwuaW6CFHJlZmVycmFsLnBlbm55cGFsLmlughpub3RpZmljYXRpb24ubGtwb25saW5lLmNvbYIYbm90aWZpY2F0aW9uLnBlbm55cGFsLmlughFhZG1pbi5wZW5ueXBhbC5pboIVdWF0c3BpcC5sa3BvbmxpbmUuY29tghJzcGlwLmxrcG9ubGluZS5jb22CEWRydWF0LnBlbm55cGFsLmlught1YXRnZXRzZXRncm93LmxrcG9ubGluZS5jb22CGGdldHNldGdyb3cubGtwb25saW5lLmNvbYIRbGtwY29ubmVjdC5uZXQuaW6CDnBheS5sa3AubmV0Lmlugg9la3ljLmxrcC5uZXQuaW6CDWJvLmxrcC5uZXQuaW6CDmxtcy5sa3AubmV0Lmlugg1pYS5sa3AubmV0LmlughJ3ZWxjb21lLmxrcC5uZXQuaW6CD2hybXMubGtwLm5ldC5pboITZGV2dHJhZGUubGtwLm5ldC5pboIOYXBpLmxrcC5uZXQuaW6CD2FpbXMubGtwLm5ldC5pboIVYmFja29mZmljZS5sa3AubmV0LmlughZkZXZ0cmFkZWt5Yy5sa3AubmV0Lmlugg9zcGlwLmxrcC5uZXQuaW6CEmVreWN1YXQubGtwLm5ldC5pboIYdWF0YmFja29mZmljZS5sa3AubmV0LmlughF3ZWFsdGgubGtwLm5ldC5pboIVbWlkZGxld2FyZS5sa3AubmV0LmlughhtaWRkbGV3YXJlYXBpLmxrcC5uZXQuaW6CDXJhLmxrcC5uZXQuaW6CDmlwby5sa3AubmV0Lmlugg51YXQubGtwLm5ldC5pboIVYWxsb2NhdGlvbi5sa3AubmV0LmlughJ0cmlsb2d5LmxrcC5uZXQuaW6CCmxrcC5uZXQuaW4wHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB8GA1UdIwQYMBaAFPjvf/LNeGeo3m+PJI2I8YcDArPrMB0GA1UdDgQWBBQuPXC3BCVKcUO2am6Fyk8sIpUoozCCAX0GCisGAQQB1nkCBAIEggFtBIIBaQFnAHcAZBHEbKQS7KeJHKICLgC8q08oB9QeNSer6v7VA8l9zfAAAAGWV+JpGAAABAMASDBGAiEAllKMuFGquNlCR9ob/ic1Zi4v+Ohf3FzFyYBSpuAN4oQCIQCh1shtfJFO6hnnPUJ8AG6XFnYaINs6mkvT5dCHAHg6SgB1AMs49xWJfIShRF9bwd37yW7ymlnNRwppBYWwyxTDFFjnAAABllfiZ7oAAAQDAEYwRAIgWifIAZ/HsJzWUqsMFK8gz0c7EwVmnJx2ZNhj0rKyIZwCIHCC6DJPTH4TjuuRTnKjVnqzT9zk9iR2l5dIKO0DtDJwAHUAJS+Uwisp6W6fQRpyBytpXFtS/5epDSVAu/zcUexN7gsAAAGWV+JpUwAABAMARjBEAiBhX/IRQ5Qi2O9hDETz3lhQDdF31EX4YQqwPlzqjYwltAIgUJKWGz+QtyMeJu0/QLTE11sxTte3ix4FbdxRZVCRBOQwDQYJKoZIhvcNAQELBQADggEBAHDqUvhsgktyXfpCLqb/RzMLXi+/cZ4Px/YXtFwpLLtyJlNsSurn78AxlWpR1iqlnJkMe46+SxBMtiBlkTbH/nB7MRERowLNLdpZRvoyI3Odv648mqDt6EDulvtknJQDFljCIWkudEQ/BbwtpOGhEXcXEPyK4uYY4SXkQ6N4OOvQloUsjXLtaBV/kMFi36nxXN2HhJwzIxzyUQjCrBeEhfj3k6sXbjLQ3ytpSjJoalMnr8NfS3rwMT7LT0ggPgbSOwxltGM70ntF3FszQJczzDGZJIDjwfbEX8aw3FSCqAHnT61YWh2xJQEaw4QZ6zLnIHkH5gbd7ijcYwN9KpAsbsc=
-----END CERTIFICATE-----

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/1433/mssql

Subject Name:

Common Name: SSL_Self_Signed_Fallback

Issuer Name:

Common Name: SSL_Self_Signed_Fallback

Serial Number: 6A 1A 0F A8 C0 4A B4 A9 42 18 5C 32 2A 89 A4 56

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Jan 01 03:49:40 2026 GMT
Not Valid After: Jan 01 03:49:40 2056 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 E4 5C 13 19 70 6E 0C 87 B5 36 F5 41 DA 2D 43 E1 5D 39 13
78 12 00 DD C1 08 0F 73 71 51 8D 17 8D 8E 76 25 0A CF 7A A4
4D 79 78 8A F6 C8 F6 DD 0C 7E 1C 0A BA BE D3 C6 00 3F BD EF
4F F7 2D 12 D4 29 E8 48 0F A1 59 9A 3C 86 CF 51 DD 4A 73 F2
E8 F3 D5 3C 83 3E 68 14 88 06 8A DC 69 E6 05 93 15 B0 2E D4
9A 68 59 DF 0D B4 37 2A E6 2E 87 10 96 68 13 15 99 10 4D DE
10 A4 C7 B2 F8 38 5C 7F 77 7A C7 DE 55 2F 30 26 C3 8A 78 C0
C2 DE B5 A7 B6 C3 74 4E 88 2A 26 A4 F7 34 8D 45 19 27 FB FA
A4 C1 A1 43 A9 D2 5F 56 DD E9 E2 01 0E 1D D6 DC 51 8A A7 C1
CB 3C 5B D2 69 C8 FD 5E CE 88 AD 4B 90 34 20 23 21 A2 C6 DE
20 D7 21 F1 27 26 3C DD 83 87 29 D2 F8 4E 67 D7 22 4F CB AE
13 24 D6 C0 50 33 23 62 2D 2D F0 F0 DC DE E8 1B 83 CD 27 A1
22 70 31 1C 2F D0 72 DC 16 7D 62 E3 F3 B1 69 61 B1
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 43 DF D8 EF 41 4A 4D 0C F5 88 43 09 43 B9 C2 6C 55 5F EE
FB 7D 1D 15 06 00 56 A3 34 D8 71 B6 49 45 D3 31 49 7D 2B 78
95 4A CA 04 CA 4B 5E CF 32 B5 B1 B4 6F 17 39 CE 94 B6 17 98
00 CC D7 D0 F3 1B 5B 73 DC D5 2B 68 CF ED 20 C4 FC A1 82 D8
DA 06 FE 58 53 68 E2 E0 1C ED A1 98 99 5B 1D F0 D9 0F 5A 37
A8 5F DA 04 F0 03 AD D2 BF 81 F6 21 C6 EA 85 5D 86 4C 21 08
CE F1 0E BB 98 E0 5A 0B 77 44 EB A7 67 F9 21 EC 6D 31 4A E3
D0 00 EB 06 81 4D 80 CE 74 C6 15 CE 23 BA 7C B6 A0 39 43 36
B3 5C D1 DE E4 9B 5F 46 F9 3A 2A EA 4B 43 CF 36 45 45 3B 6C
BD 24 6D B4 89 E8 FC F6 E6 22 B6 38 AE 60 DD 02 83 D5 A7 6C
78 D8 10 A2 3C AF A9 FD 37 DE 86 41 18 04 07 4F 2D 59 D2 CE
8B 6C FA D0 53 FB AA BA 59 22 BB 65 9F 0C 8F D4 42 E9 1D 3D
B9 10 89 CA DC E4 F8 9D 27 3C B7 AB 79 A3 43 C5 AF

Fingerprints :

SHA-256 Fingerprint: 27 4C C5 13 98 EC D3 66 9A FC 0E 98 15 0D 57 BF AB 30 6C AC
B2 07 88 D9 DD A3 9A EB 25 09 05 BC
SHA-1 Fingerprint: DD DF ED BE 63 A1 D9 6A 67 31 B0 83 BF F2 B9 1C AE 0D 8D FE
MD5 Fingerprint: FF 49 89 15 8C 3E 23 21 B5 72 32 36 D9 85 5D 06


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIDADCCAeigAwIBAgIQahoPqMBKtKlCGFwyKomkVjANBgkqhkiG9w0BAQsFADA7MTkwNwYDVQQDHjAAUwBTAEwAXwBTAGUAbABmAF8AUwBpAGcAbgBlAGQAXwBGAGEAbABsAGIAYQBjAGswIBcNMjYwMTAxMDM0OTQwWhgPMjA1NjAxMDEwMzQ5NDBaMDsxOTA3BgNVBAMeMABTAFMATABfAFMAZQBsAGYAXwBTAGkAZwBuAGUAZABfAEYAYQBsAGwAYgBhAGMAazCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAORcExlwbgyHtTb1QdotQ+FdORN4EgDdwQgPc3FRjReNjnYlCs96pE15eIr2yPbdDH4cCrq+08YAP73vT/ctEtQp6EgPoVmaPIbPUd1Kc/Lo89U8gz5oFIgGitxp5gWTFbAu1JpoWd8NtDcq5i6HEJZoExWZEE3eEKTHsvg4XH93esfeVS8wJsOKeMDC3rWntsN0TogqJqT3NI1FGSf7+qTBoUOp0l9W3eniAQ4d1txRiqfByzxb0mnI/V7OiK1LkDQgIyGixt4g1yHxJyY83YOHKdL4TmfXIk/LrhMk1sBQMyNiLS3w8Nze6BuDzSehInAxHC/QctwWfWLj87FpYbECAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAQ9/Y70FKTQz1iEMJQ7nCbFVf7vt9HRUGAFajNNhxtklF0zFJfSt4lUrKBMpLXs8ytbG0bxc5zpS2F5gAzNfQ8xtbc9zVK2jP7SDE/KGC2NoG/lhTaOLgHO2hmJlbHfDZD1o3qF/aBPADrdK/gfYhxuqFXYZMIQjO8Q67mOBaC3dE66dn+SHsbTFK49AA6waBTYDOdMYVziO6fLagOUM2s1zR3uSbX0b5OirqS0PPNkVFO2y9JG20iej89uYitjiuYN0Cg9WnbHjYEKI8r6n9N96GQRgEB08tWdLOi2z60FP7qrpZIrtlnwyP1ELpHT25EInK3OT4nSc8t6t5o0PFrw==
-----END CERTIFICATE-----

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: MiddlewareAPI

Issuer Name:

Common Name: MiddlewareAPI

Serial Number: 17 D5 AD 7C A8 B2 04 81 4F 42 FB C1 A5 37 6F EC

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Sep 04 07:26:52 2025 GMT
Not Valid After: Mar 06 07:26:52 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 B2 2A 44 0B B5 5C 2E 65 20 CC F9 2B 25 E0 80 EB 3D C5 07
95 29 3E 44 AB 88 1A E2 7E 9E E7 F0 73 58 4F BA DC 06 89 69
2A 34 9E 97 E4 76 83 BD 9B 83 97 40 FE 62 C6 54 50 1E 92 08
3F 5F 97 49 5C FE 2B 84 AD FD 5C DB 24 65 A7 02 27 09 90 2F
44 F2 41 0C AC 86 6E ED 30 B2 2D 86 54 71 0D DC 75 A9 20 D1
3B FC EC A7 F9 CE A1 FF 43 A2 74 22 55 C0 6F 57 9E 62 6C B7
4D 9A 9F A5 A3 1B C3 81 F2 5C 81 08 D3 41 B0 80 9F 66 C3 70
B7 F7 32 18 F3 DE E3 87 75 CC 6F 9D A9 A1 89 2C 8C 5F 0D A9
22 08 D9 EE 17 1F F3 47 E3 7B E6 82 DE 8D 69 F4 54 9C 03 3D
21 87 10 51 18 FA 51 EE A2 45 70 49 B9 1B F1 7C F7 7A BE B0
3F 00 DD 0A 6F 5A 30 CA 5C 9A BC 5C 14 FD 51 B0 2D 9A 04 A1
68 8B A5 69 8A 1D 96 05 89 79 22 52 09 F4 90 BB 4D 7F 13 9C
F5 E4 10 1E 62 8D E3 8F 33 99 9A CF 03 A9 A8 42 29
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 38 53 31 70 14 E8 7E 4B BE 9F FD C5 E1 53 C9 36 6C 8F 2A
7E 78 67 83 72 0D 04 41 5D E3 E9 C0 F7 7F D2 69 FC 3A B5 5A
FE CC A8 47 89 C8 64 9E CD FC 98 0A D2 60 BA 22 00 2A 23 B8
31 AB 29 7D D4 28 44 CB 43 B5 9D 8C D7 58 28 C5 43 E7 68 FA
35 71 E4 89 CD 2B AD EB D4 9B F7 E8 06 68 7E B9 5B EB 14 67
0E 41 4E B4 10 AC 4D 9E D0 9A FF C2 09 AE AD 42 DD 01 46 67
12 5B AB 4B 75 D7 40 90 89 A3 FD A5 4C E2 D9 56 85 F6 64 CA
FD FD 86 1A 30 54 FD 72 3E D0 C0 0B 2F C4 4E 67 34 2B 7F 04
88 38 4A 4F B4 54 6C 5F 25 23 18 47 C0 88 46 2E 3B 35 7E 33
8E FE 8A CD 40 8A 86 E6 27 88 A3 A0 20 D0 EC A0 C6 82 46 8A
C4 75 71 AB 02 12 10 E8 66 D1 C3 0D 43 E6 81 5B 01 51 8B BA
18 36 86 41 1D 31 3F A4 E2 2F 6D 3D 97 6E 83 5B 09 19 EC 63
78 3C 4A 86 B1 6D F0 C2 32 1B DC 16 6A 05 22 24 B9

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment


Fingerprints :

SHA-256 Fingerprint: 64 59 72 75 6A 64 3D CE 52 43 96 DD A4 1F 82 41 F4 0B E7 34
3D FE 9C 75 8A EE CA 1D 6D 07 FC 80
SHA-1 Fingerprint: 8A 3A D3 B8 B9 1B D8 63 8C 2F C1 96 3F 65 2E EC 23 62 18 E3
MD5 Fingerprint: 10 83 F1 88 D4 D1 C3 75 C7 0F B7 DE AA 6B 1A A7


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIC3jCCAcagAwIBAgIQF9WtfKiyBIFPQvvBpTdv7DANBgkqhkiG9w0BAQsFADAYMRYwFAYDVQQDEw1NaWRkbGV3YXJlQVBJMB4XDTI1MDkwNDA3MjY1MloXDTI2MDMwNjA3MjY1MlowGDEWMBQGA1UEAxMNTWlkZGxld2FyZUFQSTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALIqRAu1XC5lIMz5KyXggOs9xQeVKT5Eq4ga4n6e5/BzWE+63AaJaSo0npfkdoO9m4OXQP5ixlRQHpIIP1+XSVz+K4St/VzbJGWnAicJkC9E8kEMrIZu7TCyLYZUcQ3cdakg0Tv87Kf5zqH/Q6J0IlXAb1eeYmy3TZqfpaMbw4HyXIEI00GwgJ9mw3C39zIY897jh3XMb52poYksjF8NqSII2e4XH/NH43vmgt6NafRUnAM9IYcQURj6Ue6iRXBJuRvxfPd6vrA/AN0Kb1owylyavFwU/VGwLZoEoWiLpWmKHZYFiXkiUgn0kLtNfxOc9eQQHmKN448zmZrPA6moQikCAwEAAaMkMCIwEwYDVR0lBAwwCgYIKwYBBQUHAwEwCwYDVR0PBAQDAgQwMA0GCSqGSIb3DQEBCwUAA4IBAQA4UzFwFOh+S76f/cXhU8k2bI8qfnhng3INBEFd4+nA93/Safw6tVr+zKhHichkns38mArSYLoiACojuDGrKX3UKETLQ7WdjNdYKMVD52j6NXHkic0rrevUm/foBmh+uVvrFGcOQU60EKxNntCa/8IJrq1C3QFGZxJbq0t110CQiaP9pUzi2VaF9mTK/f2GGjBU/XI+0MALL8ROZzQrfwSIOEpPtFRsXyUjGEfAiEYuOzV+M47+is1AiobmJ4ijoCDQ7KDGgkaKxHVxqwISEOhm0cMNQ+aBWwFRi7oYNoZBHTE/pOIvbT2XboNbCRnsY3g8SoaxbfDCMhvcFmoFIiS5
-----END CERTIFICATE-----

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/443/www


Here is the list of SSL CBC ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/1433/mssql


Here is the list of SSL CBC ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp


Here is the list of SSL CBC ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/443/www


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/1433/mssql


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/3389/msrdp


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.

57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/443/www


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/1433/mssql


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/3389/msrdp


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

94761 - SSL Root Certification Authority Certificate Information
-
Synopsis
A root Certification Authority certificate was found at the top of the certificate chain.
Description
The remote service uses an SSL certificate chain that contains a self-signed root Certification Authority certificate at the top of the chain.
See Also
Solution
Ensure that use of this root Certification Authority certificate complies with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2016/11/14, Modified: 2018/11/15
Plugin Output

tcp/443/www


The following root Certification Authority certificate was found :

|-Subject : OU=GlobalSign Root CA - R3/O=GlobalSign/CN=GlobalSign
|-Issuer : OU=GlobalSign Root CA - R3/O=GlobalSign/CN=GlobalSign
|-Valid From : Mar 18 10:00:00 2009 GMT
|-Valid To : Mar 18 10:00:00 2029 GMT
|-Signature Algorithm : SHA-256 With RSA Encryption
156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/443/www

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/1433/mssql

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/3389/msrdp

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

160486 - Server Message Block (SMB) Protocol Version Detection
-
Synopsis
Verify the version of SMB on the remote host.
Description
The Server Message Block (SMB) Protocol provides shared access to files and printers across nodes on a network.
See Also
Solution
Disable SMB version 1 and block all versions of SMB at the network boundary by blocking TCP port 445 with related protocols on UDP ports 137-138 and TCP port 139, for all boundary devices.
Risk Factor
None
Plugin Information
Published: 2022/05/04, Modified: 2022/05/04
Plugin Output

tcp/445/cifs

- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB2 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB3 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB1 : Key not found.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/80/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/443/www

A TLSv1.2 server answered on this port.

tcp/443/www

A web server is running on this port through TLSv1.2.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5357/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5800/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5900/vnc

A vnc server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5985/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/6888

The service closed the connection without sending any data.
It might be protected by some sort of TCP wrapper.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/18018/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/47001/www

A web server is running on this port.

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/80/www


URL : http://172.17.100.112/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/443/www


URL : https://172.17.100.112/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/5985/www


URL : http://172.17.100.112:5985/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/18018/www


URL : http://172.17.100.112:18018/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/47001/www


URL : http://172.17.100.112:47001/cgi-bin/meteobridge
Version : unknown
Authenticated : False

161455 - Supersedence Data Builder
-
Synopsis
Supersedence data.
Description
Collects and stores supersedence patch data for various patch types.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/24, Modified: 2025/07/14
Plugin Output

tcp/0

Supersedence patch data summary :
- MSKB : 82


Plugin debug log has been attached.

84821 - TLS ALPN Supported Protocol Enumeration
-
Synopsis
The remote host supports the TLS ALPN extension.
Description
The remote host supports the TLS ALPN extension. This plugin enumerates the protocols the extension supports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/07/17, Modified: 2024/09/11
Plugin Output

tcp/443/www


http/1.1
h2
136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/443/www

TLSv1.2 is enabled and the server supports at least one cipher.

136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/1433/mssql

TLSv1.2 is enabled and the server supports at least one cipher.

136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/3389/msrdp

TLSv1.2 is enabled and the server supports at least one cipher.

110095 - Target Credential Issues by Authentication Protocol - No Issues Found
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials. No issues were reported with access, privilege, or intermittent failure.
Description
Valid credentials were provided for an authentication protocol on the remote target and Nessus did not log any subsequent errors or failures for the authentication protocol.

When possible, Nessus tracks errors or failures related to otherwise valid credentials in order to highlight issues that may result in incomplete scan results or limited scan coverage. The types of issues that are tracked include errors that indicate that the account used for scanning did not have sufficient permissions for a particular check, intermittent protocol failures which are unexpected after the protocol has been negotiated successfully earlier in the scan, and intermittent authentication failures which are unexpected after a credential set has been accepted as valid earlier in the scan. This plugin reports when none of the above issues have been logged during the course of the scan for at least one authenticated protocol. See plugin output for details, including protocol, port, and account.

Please note the following :

- This plugin reports per protocol, so it is possible for issues to be encountered for one protocol and not another.
For example, authentication to the SSH service on the remote target may have consistently succeeded with no privilege errors encountered, while connections to the SMB service on the remote target may have failed intermittently.

- Resolving logged issues for all available authentication protocols may improve scan coverage, but the value of resolving each issue for a particular protocol may vary from target to target depending upon what data (if any) is gathered from the target via that protocol and what particular check failed. For example, consistently successful checks via SSH are more critical for Linux targets than for Windows targets, and likewise consistently successful checks via SMB are more critical for Windows targets than for Linux targets.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0520
Plugin Information
Published: 2018/05/24, Modified: 2025/08/28
Plugin Output

tcp/445/cifs


Nessus was able to log into the remote host with no privilege or access
problems via the following :

User: '172.17.100.112\tidua'
Port: 445
Proto: SMB
Method: password
141118 - Target Credential Status by Authentication Protocol - Valid Credentials Provided
-
Synopsis
Valid credentials were provided for an available authentication protocol.
Description
Nessus was able to determine that valid credentials were provided for an authentication protocol available on the remote target because it was able to successfully authenticate directly to the remote target using that authentication protocol at least once. Authentication was successful because the authentication protocol service was available remotely, the service was able to be identified, the authentication protocol was able to be negotiated successfully, and a set of credentials provided in the scan policy for that authentication protocol was accepted by the remote service. See plugin output for details, including protocol, port, and account.

Please note the following :

- This plugin reports per protocol, so it is possible for valid credentials to be provided for one protocol and not another. For example, authentication may succeed via SSH but fail via SMB, while no credentials were provided for an available SNMP service.

- Providing valid credentials for all available authentication protocols may improve scan coverage, but the value of successful authentication for a given protocol may vary from target to target depending upon what data (if any) is gathered from the target via that protocol. For example, successful authentication via SSH is more valuable for Linux targets than for Windows targets, and likewise successful authentication via SMB is more valuable for Windows targets than for Linux targets.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/10/15, Modified: 2024/03/25
Plugin Output

tcp/445/cifs


Nessus was able to log in to the remote host via the following :

User: '172.17.100.112\tidua'
Port: 445
Proto: SMB
Method: password

64814 - Terminal Services Use SSL/TLS
-
Synopsis
The remote Terminal Services use SSL/TLS.
Description
The remote Terminal Services is configured to use SSL/TLS.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/22, Modified: 2023/07/10
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: MiddlewareAPI

Issuer Name:

Common Name: MiddlewareAPI

Serial Number: 17 D5 AD 7C A8 B2 04 81 4F 42 FB C1 A5 37 6F EC

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Sep 04 07:26:52 2025 GMT
Not Valid After: Mar 06 07:26:52 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 B2 2A 44 0B B5 5C 2E 65 20 CC F9 2B 25 E0 80 EB 3D C5 07
95 29 3E 44 AB 88 1A E2 7E 9E E7 F0 73 58 4F BA DC 06 89 69
2A 34 9E 97 E4 76 83 BD 9B 83 97 40 FE 62 C6 54 50 1E 92 08
3F 5F 97 49 5C FE 2B 84 AD FD 5C DB 24 65 A7 02 27 09 90 2F
44 F2 41 0C AC 86 6E ED 30 B2 2D 86 54 71 0D DC 75 A9 20 D1
3B FC EC A7 F9 CE A1 FF 43 A2 74 22 55 C0 6F 57 9E 62 6C B7
4D 9A 9F A5 A3 1B C3 81 F2 5C 81 08 D3 41 B0 80 9F 66 C3 70
B7 F7 32 18 F3 DE E3 87 75 CC 6F 9D A9 A1 89 2C 8C 5F 0D A9
22 08 D9 EE 17 1F F3 47 E3 7B E6 82 DE 8D 69 F4 54 9C 03 3D
21 87 10 51 18 FA 51 EE A2 45 70 49 B9 1B F1 7C F7 7A BE B0
3F 00 DD 0A 6F 5A 30 CA 5C 9A BC 5C 14 FD 51 B0 2D 9A 04 A1
68 8B A5 69 8A 1D 96 05 89 79 22 52 09 F4 90 BB 4D 7F 13 9C
F5 E4 10 1E 62 8D E3 8F 33 99 9A CF 03 A9 A8 42 29
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 38 53 31 70 14 E8 7E 4B BE 9F FD C5 E1 53 C9 36 6C 8F 2A
7E 78 67 83 72 0D 04 41 5D E3 E9 C0 F7 7F D2 69 FC 3A B5 5A
FE CC A8 47 89 C8 64 9E CD FC 98 0A D2 60 BA 22 00 2A 23 B8
31 AB 29 7D D4 28 44 CB 43 B5 9D 8C D7 58 28 C5 43 E7 68 FA
35 71 E4 89 CD 2B AD EB D4 9B F7 E8 06 68 7E B9 5B EB 14 67
0E 41 4E B4 10 AC 4D 9E D0 9A FF C2 09 AE AD 42 DD 01 46 67
12 5B AB 4B 75 D7 40 90 89 A3 FD A5 4C E2 D9 56 85 F6 64 CA
FD FD 86 1A 30 54 FD 72 3E D0 C0 0B 2F C4 4E 67 34 2B 7F 04
88 38 4A 4F B4 54 6C 5F 25 23 18 47 C0 88 46 2E 3B 35 7E 33
8E FE 8A CD 40 8A 86 E6 27 88 A3 A0 20 D0 EC A0 C6 82 46 8A
C4 75 71 AB 02 12 10 E8 66 D1 C3 0D 43 E6 81 5B 01 51 8B BA
18 36 86 41 1D 31 3F A4 E2 2F 6D 3D 97 6E 83 5B 09 19 EC 63
78 3C 4A 86 B1 6D F0 C2 32 1B DC 16 6A 05 22 24 B9

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment

161691 - The Microsoft Windows Support Diagnostic Tool (MSDT) RCE Workaround Detection (CVE-2022-30190)
-
Synopsis
Checks for the HKEY_CLASSES_ROOT\ms-msdt registry key.
Description
The remote host has the HKEY_CLASSES_ROOT\ms-msdt registry key. This is a known exposure for CVE-2022-30190.

Note that Nessus has not tested for CVE-2022-30190. It is only checking if the registry key exists. The recommendation is to apply the latest patch.
See Also
Solution
Apply the latest Cumulative Update.
Risk Factor
None
Plugin Information
Published: 2022/05/31, Modified: 2022/07/28
Plugin Output

tcp/445/cifs

The HKEY_CLASSES_ROOT\ms-msdt registry key exists on the target. This may indicate that the target is vulnerable to CVE-2022-30190, if the vendor patch is not applied.

56468 - Time of Last System Startup
-
Synopsis
The system has been started.
Description
Using the supplied credentials, Nessus was able to determine when the host was last started.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/10/12, Modified: 2018/06/19
Plugin Output

tcp/0


20260101091933.500000+330

10287 - Traceroute Information
-
Synopsis
It was possible to obtain traceroute information.
Description
Makes a traceroute to the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/11/27, Modified: 2023/12/04
Plugin Output

udp/0

For your information, here is the traceroute from 172.17.100.38 to 172.17.100.112 :
172.17.100.38
172.17.100.112

Hop Count: 1

92434 - User Download Folder Files
-
Synopsis
Nessus was able to enumerate downloaded files on the remote host.
Description
Nessus was able to generate a report of all files listed in the default user download folder.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

C:\\Users\Administrator\Downloads\desktop.ini
C:\\Users\Public\Downloads\desktop.ini
C:\\Users\tidua\Downloads\desktop.ini

Download folder content report attached.
92431 - User Shell Folders Settings
-
Synopsis
Nessus was able to find the folder paths for user folders on the remote host.
Description
Nessus was able to gather a list of settings from the target system that store common user folder locations. A few of the more common locations are listed below :

- Administrative Tools
- AppData
- Cache
- CD Burning
- Cookies
- Desktop
- Favorites
- Fonts
- History
- Local AppData
- My Music
- My Pictures
- My Video
- NetHood
- Personal
- PrintHood
- Programs
- Recent
- SendTo
- Start Menu
- Startup
- Templates
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

tidua
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\tidua\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\tidua\Downloads
- recent : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\tidua\Videos
- my music : C:\Users\tidua\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\tidua\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\tidua\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\tidua\AppData\LocalLow
- sendto : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\tidua\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\tidua\Documents
- administrative tools : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- nethood : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- history : C:\Users\tidua\AppData\Local\Microsoft\Windows\History
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\tidua\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\tidua\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\tidua\AppData\Local
- my pictures : C:\Users\tidua\Pictures
- templates : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\tidua\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\tidua\Desktop
- programs : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\Windows\Fonts
- cd burning : C:\Users\tidua\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\tidua\Favorites
- appdata : C:\Users\tidua\AppData\Roaming

production
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\Administrator\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\Administrator\Downloads
- recent : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\Administrator\Videos
- my music : C:\Users\Administrator\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\Administrator\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\Administrator\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\Administrator\AppData\LocalLow
- sendto : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\Administrator\Documents
- administrative tools : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- nethood : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- history : C:\Users\Administrator\AppData\Local\Microsoft\Windows\History
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\Administrator\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\Administrator\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\Administrator\AppData\Local
- my pictures : C:\Users\Administrator\Pictures
- templates : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\Administrator\Desktop
- programs : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\Windows\Fonts
- cd burning : C:\Users\Administrator\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\Administrator\Favorites
- appdata : C:\Users\Administrator\AppData\Roaming
92435 - UserAssist Execution History
-
Synopsis
Nessus was able to enumerate program execution history on the remote host.
Description
Nessus was able to gather evidence from the UserAssist registry key that has a list of programs that have been executed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/11/12
Plugin Output

tcp/0

{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
microsoft.windows.shell.rundialog
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\paint.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
ueme_ctlcuacount:ctor
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\notepad.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mspaint.exe
ueme_ctlsession
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\servermanager.exe
microsoft.autogenerated.{21a0406e-7390-4dba-8e06-a6804c6dd1c9}
e:\x64\scenarioengine.exe
d:\middleware api\lkp_middleware.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\realvnc\advanced\vnc server (user mode).lnk
d:\backup\.folderstructure.bat
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\google chrome.lnk
e:\setup.exe
ueme_ctlsession
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
d:\lkpsoft\kes av_12.0.0.465 +netagent_14.2.0.26967\installer.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\rundll32.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\remote desktop connection.lnk
visualstudio.48a6ba8a
\\192.168.150.152\d$\lkpsoft\vs2017_professional\vs_setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msdt.exe
kasperskylab.kis.ui.toasts
c:\users\administrator\appdata\local\temp\~nsu1.tmp\un.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\services.lnk
c:\programdata\package cache\{f3fbabb4-bcfb-45eb-8fff-9b784fd68c38}\vsta_setup.exe
microsoft.internetexplorer.default
d:\schedulers\mfclientregistration\mfclientregister.exe
d:\lkpsoft\digio setup\jdk-17.0.12_windows-x64_bin.exe
microsoft.autogenerated.{226eceae-b45f-0609-6b17-752995609757}
microsoft.autogenerated.{2c18cdd1-cf26-19b4-988a-862fc5db076a}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mmc.exe
{6d809377-6af0-444b-8957-a3773f02200e}\nodejs\node.exe
d:\setup64.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\internet explorer.lnk
d:\lkpsoft\sql\ssms-setup-enu.exe
visualstudio.645b951f
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\task scheduler.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\visual studio 2022.lnk
d:\lkpsoft\dotnet-hosting-7.0.10-win.exe
d:\lkpsoft\dotnet-sdk-7.0.400-win-x64.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\cmd.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\iis manager.lnk
d:\backup\06082023\lkp_middleware.exe
microsoft.autogenerated.{923dd477-5846-686b-a659-0fccd73851a8}
c:\users\administrator\desktop\postman-win64-9.24.2-setup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\task manager.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\shutdown.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\paint.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
com.squirrel.postman.postman
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\internet explorer.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiescomputername.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\temp\{0190f599-fb99-40d6-a189-2fc5e346cf3f}\.cr\ssms-setup-enu.exe
c:\users\administrator\desktop\github desktop.lnk
microsoft.windows.explorer
ueme_ctlcuacount:ctor
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msiexec.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\visual studio 2017.lnk
microsoft.autogenerated.{40815e86-5702-c2c8-a620-1ed06b4da7ee}
microsoft.visualstudio.installer
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\file explorer.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesadvanced.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\iis manager.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dcomcnfg.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\regedit.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\visual studio code\visual studio code.lnk
d:\lkpsoft\dotnet-sdk-8.0.303-win-x64.exe
microsoft.windows.controlpanel
chrome.chromeuserdatabfc9e8e87.default
com.squirrel.githubdesktop.githubdesktop
e:\x64\landingpage.exe
d:\lkpsoft\sanernow_lkp_window_cm_windows_x86_6.3\sanernow_windows_x86_6.3.exe
d:\middleware_api\lkp_middleware_3_1.exe
microsoft.autogenerated.{bd3f924e-55fb-a1ba-9de6-b50f9f2460ac}
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\control panel.lnk
d:\scriptdbtoaws\bin\debug\net6.0\scriptdbtoaws.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\winver.exe
d:\checkapiaccessibility\checkapi.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wscript.exe
{6d809377-6af0-444b-8957-a3773f02200e}\winrar\winrar.exe
d:\lkpsoft\office2010\setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 19\common7\ide\ssms.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\visual studio installer.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\computer management.lnk
microsoft.windows.windowsinstaller
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\github, inc\github desktop.lnk
microsoft.autogenerated.{bb044bfd-25b7-2faa-22a8-6371a93e0456}
d:\lkpsoft\digio setup\win64openssl-3_4_0.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesremote.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\temp\{6aa23977-6cf8-47aa-b960-229251c7206b}\.cr\dotnet-hosting-7.0.10-win.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\command prompt.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft visual studio\2022\professional\common7\ide\commonextensions\platform\debugger\vsdebugconsole.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mspaint.exe
d:\middleware_api\lkp_middleware.exe
microsoft.visualstudiocode
c:\users\administrator\appdata\local\temp\2\170f619051262861183020699fd8b028\vs_bootstrapper_d15\vs_setup_bootstrapper.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\event viewer.lnk
microsoft.windows.computer
{6d809377-6af0-444b-8957-a3773f02200e}\realvnc\vnc4\vncconfig.exe
microsoft.windows.remotedesktop
c:\users\administrator\desktop\sql server management studio management studio 19.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\iisreset.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft visual studio\installer\vs_installershell.exe
microsoft.windows.cortana_cw5n1h2txyewy!cortanaui
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\node.js\node.js command prompt.lnk
microsoft.autogenerated.{499ee7ca-7ed5-ebc9-ab09-80dc143d7b90}
d:\lkpsoft\iiscrypto (1).exe
d:\lkpsoft\acroniscyberprotect_agentforwindows_web.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\server manager.lnk
c:\users\public\desktop\google chrome.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\node.js\node.js.lnk
microsoft.autogenerated.{8abd94fb-e7d6-84a6-a997-c918edde0ae5}
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\common files\microsoft shared\msenv\vslauncher.exe
{6d809377-6af0-444b-8957-a3773f02200e}\dotnet\dotnet.exe
microsoft.windows.shell.rundialog
d:\pennypalbackup\swiftbackup.bat
c:\users\administrator\desktop\jdk-17.0.12_windows-x64_bin.exe
microsoft.windows.shellexperiencehost_cw5n1h2txyewy!app
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\notepad.exe
windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
{f38bf404-1d43-42f2-9305-67de0b28fc23}\temp\{5090adfa-1df3-4428-8cff-60368a7e4e6b}\.cr\dotnet-sdk-8.0.303-win-x64.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\temp\{903cd4e2-17d1-4c4f-b2af-48600965e15e}\.cr\dotnet-sdk-7.0.400-win-x64.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\servermanager.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cmd.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\inetsrv\inetmgr.exe
c:\users\administrator\desktop\postman.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\kaspersky lab\networkagent\klshwmsg.exe
microsoft.autogenerated.{c1c6f8ac-40a3-0f5c-146f-65a9dc70bbb4}
c:\users\administrator\desktop\winrar-x64-590.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\openwith.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\postman\postman.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\kaspersky lab\networkagent\klcsngtgui.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
c:\programdata\microsoft\visualstudio\packages\_bootstrapper\vs_bootstrapper.exe
\\192.168.150.235\lkpsoft\software\real vnc 4.6.1 enterprise edition\vnc-e4_6_1-x86_x64_win32.exe
chrome
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\notepad.lnk
c:\users\administrator\appdata\local\temp\28207943484fe2d9f3\vs_bootstrapper_d15\vs_setup_bootstrapper.exe
d:\liquiloans_trial\liquiloans_trial\bin\debug\net8.0\liquiloans_trial.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell.lnk

Extended userassist report attached.

105793 - VMware Tools Detection
-
Synopsis
A virtual machine management application is installed on the remote host.
Description
VMware Tools, a suite of utilities that enhances the performance of the virtual machines guest operating system is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0738
Plugin Information
Published: 2018/01/13, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Version : 12.3.5.46049

20094 - VMware Virtual Machine Detection
-
Synopsis
The remote host is a VMware virtual machine.
Description
According to the MAC address of its network adapter, the remote host is a VMware virtual machine.
Solution
Since it is physically accessible through the network, ensure that its configuration matches your organization's security policy.
Risk Factor
None
Plugin Information
Published: 2005/10/27, Modified: 2019/12/11
Plugin Output

tcp/0


The remote host is a VMware virtual machine.

10758 - VNC HTTP Server Detection
-
Synopsis
The remote host is running a remote display software (VNC).
Description
The remote host is running VNC (Virtual Network Computing), which uses the RFB (Remote Framebuffer) protocol to provide remote access to graphical user interfaces and thus permits a console on the remote host to be displayed on another.
See Also
Solution
Make sure use of this software is done in accordance with your organization's security policy and filter incoming traffic to this port.
Risk Factor
None
Plugin Information
Published: 2001/09/14, Modified: 2020/06/12
Plugin Output

tcp/5800/www

19288 - VNC Server Security Type Detection
-
Synopsis
A VNC server is running on the remote host.
Description
This script checks the remote VNC server protocol version and the available 'security types'.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/07/22, Modified: 2021/07/13
Plugin Output

tcp/5900/vnc


The remote VNC server supports the following security types :\n\n 5 (RA2)
129
10342 - VNC Software Detection
-
Synopsis
The remote host is running a remote display software (VNC).
Description
The remote host is running VNC (Virtual Network Computing), which uses the RFB (Remote Framebuffer) protocol to provide remote access to graphical user interfaces and thus permits a console on the remote host to be displayed on another.
See Also
Solution
Make sure use of this software is done in accordance with your organization's security policy and filter incoming traffic to this port.
Risk Factor
None
Plugin Information
Published: 2000/03/07, Modified: 2017/06/12
Plugin Output

tcp/5900/vnc


The highest RFB protocol version supported by the server is :

4.1

24269 - WMI Available
-
Synopsis
WMI queries can be made against the remote host.
Description
The supplied credentials can be used to make WMI (Windows Management Instrumentation) requests against the remote host over DCOM.

These requests can be used to gather information about the remote host, such as its current state, network interface configuration, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The remote host returned the following caption from Win32_OperatingSystem:

Microsoft Windows Server 2019 Datacenter

52001 - WMI QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote Windows host has quick-fix engineering updates installed.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/02/16, Modified: 2025/12/15
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

+ KB5012128
- Description : Update
- InstalledOn : 5/4/2022
- SystemName : MIDDLEWAREAPI
- InstalledBy : MIDDLEWAREAPI\production
- Caption : http://support.microsoft.com/?kbid=5012128

+ KB4486153
- Description : Update
- InstalledOn : 12/27/2023
- SystemName : MIDDLEWAREAPI
- InstalledBy : MIDDLEWAREAPI\production
- Caption : http://support.microsoft.com/?kbid=4486153

+ KB4535680
- Description : Security Update
- InstalledOn : 12/7/2021
- SystemName : MIDDLEWAREAPI
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=4535680

+ KB4558997
- Description : Security Update
- InstalledOn : 7/10/2020
- SystemName : MIDDLEWAREAPI
- Caption : http://support.microsoft.com/?kbid=4558997

+ KB4587735
- Description : Security Update
- InstalledOn : 12/6/2020
- SystemName : MIDDLEWAREAPI
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/4587735

+ KB4589208
- Description : Update
- InstalledOn : 12/7/2021
- SystemName : MIDDLEWAREAPI
- InstalledBy : MIDDLEWAREAPI\production
- Caption : https://support.microsoft.com/help/4589208

+ KB5029247
- Description : Security Update
- InstalledOn : 8/11/2023
- SystemName : MIDDLEWAREAPI
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5029247

+ KB5006754
- Description : Update
- InstalledOn : 12/7/2021
- SystemName : MIDDLEWAREAPI
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5008539
- Description : Update
- InstalledOn : 12/8/2021
- SystemName : MIDDLEWAREAPI
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5009642
- Description : Update
- InstalledOn : 3/24/2022
- SystemName : MIDDLEWAREAPI
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5011574
- Description : Update
- InstalledOn : 5/4/2022
- SystemName : MIDDLEWAREAPI
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5028316
- Description : Security Update
- InstalledOn : 8/11/2023
- SystemName : MIDDLEWAREAPI
- InstalledBy : NT AUTHORITY\SYSTEM
44871 - WMI Windows Feature Enumeration
-
Synopsis
It is possible to enumerate Windows features using WMI.
Description
Nessus was able to enumerate the server features of the remote host by querying the 'Win32_ServerFeature' class of the '\Root\cimv2' WMI namespace for Windows Server versions or the 'Win32_OptionalFeature' class of the '\Root\cimv2' WMI namespace for Windows Desktop versions.

Note that Features can only be enumerated for Windows 7 and later for desktop versions.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0754
Plugin Information
Published: 2010/02/24, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus enumerated the following Windows features :

- .NET Extensibility 4.7
- .NET Framework 4.7
- .NET Framework 4.7 Features
- ASP.NET 4.7
- ASP.NET 4.7
- Application Development
- Application Initialization
- Basic Authentication
- CGI
- Centralized SSL Certificate Support
- Client Certificate Mapping Authentication
- Common HTTP Features
- Configuration APIs
- Custom Logging
- Default Document
- Digest Authentication
- Directory Browsing
- Dynamic Content Compression
- File and Storage Services
- HTTP Activation
- HTTP Errors
- HTTP Logging
- HTTP Redirection
- Health and Diagnostics
- IIS 6 Management Compatibility
- IIS 6 Management Console
- IIS 6 Metabase Compatibility
- IIS 6 Scripting Tools
- IIS 6 WMI Compatibility
- IIS Client Certificate Mapping Authentication
- IIS Management Console
- IIS Management Scripts and Tools
- IP and Domain Restrictions
- ISAPI Extensions
- ISAPI Filters
- Logging Tools
- Management Service
- Management Tools
- Named Pipe Activation
- ODBC Logging
- Performance
- Process Model
- Request Filtering
- Request Monitor
- Security
- Server Side Includes
- Static Content
- Static Content Compression
- Storage Services
- System Data Archiver
- TCP Activation
- TCP Port Sharing
- Telnet Client
- Tracing
- URL Authorization
- WCF Services
- Web Server
- Web Server (IIS)
- WebDAV Publishing
- WebSocket Protocol
- Windows Authentication
- Windows PowerShell
- Windows PowerShell 5.1
- Windows PowerShell ISE
- Windows Process Activation Service
- WoW64 Support
- XPS Viewer

33139 - WS-Management Server Detection
-
Synopsis
The remote web server is used for remote management.
Description
The remote web server supports the Web Services for Management (WS-Management) specification, a general web services protocol based on SOAP for managing systems, applications, and other such entities.
See Also
Solution
Limit incoming traffic to this port if desired.
Risk Factor
None
Plugin Information
Published: 2008/06/11, Modified: 2021/05/19
Plugin Output

tcp/5985/www


Here is some information about the WS-Management Server :

Product Vendor : Microsoft Corporation
Product Version : OS: 0.0.0 SP: 0.0 Stack: 3.0

10386 - Web Server No 404 Error Code Check
-
Synopsis
The remote web server does not return 404 error codes.
Description
The remote web server is configured such that it does not return '404 Not Found' error codes when a nonexistent file is requested, perhaps returning instead a site map, search page or authentication page.

Nessus has enabled some counter measures for this. However, they might be insufficient. If a great number of security holes are produced for this port, they might not all be accurate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/04/28, Modified: 2022/06/17
Plugin Output

tcp/80/www


Unfortunately, Nessus has been unable to find a way to recognize this
page so some CGI-related checks have been disabled.

92436 - WinRAR History
-
Synopsis
Nessus was able to enumerate files opened with WinRAR on the remote host.
Description
Nessus was able to gather evidence of compressed files that were opened by WinRAR. Note that only compressed files that were opened and not extracted through the explorer shortcut or command line interface were reported.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

D:\Middleware_Api Backup.rar

WinRAR report attached.

162174 - Windows Always Installed Elevated Status
-
Synopsis
Windows AlwaysInstallElevated policy status was found on the remote Windows host
Description
Windows AlwaysInstallElevated policy status was found on the remote Windows host.
You can use the AlwaysInstallElevated policy to install a Windows Installer package with elevated (system) privileges This option is equivalent to granting full administrative rights, which can pose a massive security risk. Microsoft strongly discourages the use of this setting.
Solution
If enabled, disable AlwaysInstallElevated policy per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/06/14, Modified: 2022/06/14
Plugin Output

tcp/445/cifs

AlwaysInstallElevated policy is not enabled under HKEY_LOCAL_MACHINE.
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-1687551350-3880216100-4069998428-1009
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-1687551350-3880216100-4069998428-500

48337 - Windows ComputerSystemProduct Enumeration (WMI)
-
Synopsis
It is possible to obtain product information from the remote host using WMI.
Description
By querying the WMI class 'Win32_ComputerSystemProduct', it is possible to extract product information about the computer system such as UUID, IdentifyingNumber, vendor, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/16, Modified: 2025/12/15
Plugin Output

tcp/0


+ Computer System Product
- IdentifyingNumber : VMware-56 4d 78 ae ff 06 22 fe-1e ab f6 43 74 cc b0 00
- Description : Computer System Product
- Vendor : VMware, Inc.
- Name : VMware Virtual Platform
- UUID : AE784D56-06FF-FE22-1EAB-F64374CCB000
- Version : None

159817 - Windows Credential Guard Status
-
Synopsis
Retrieves the status of Windows Credential Guard.
Description
Retrieves the status of Windows Credential Guard.
Credential Guard prevents attacks such as such as Pass-the-Hash or Pass-The-Ticket by protecting NTLM password hashes, Kerberos Ticket Granting Tickets, and credentials stored by applications as domain credentials.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/04/18, Modified: 2023/08/25
Plugin Output

tcp/445/cifs


Windows Credential Guard is not fully enabled.
The following registry keys have not been set :
- System\CurrentControlSet\Control\DeviceGuard\RequirePlatformSecurityFeatures : Key not found.
- System\CurrentControlSet\Control\LSA\LsaCfgFlags : Key not found.
- System\CurrentControlSet\Control\DeviceGuard\EnableVirtualizationBasedSecurity : Key not found.
58181 - Windows DNS Server Enumeration
-
Synopsis
Nessus enumerated the DNS servers being used by the remote Windows host.
Description
Nessus was able to enumerate the DNS servers configured on the remote Windows host by looking in the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/03/01, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Nessus enumerated DNS servers for the following interfaces :

Interface: {da0c869a-9291-4d69-8682-6a0c842db79b}
Network Connection : LAN
NameServer: 8.8.8.8,4.2.2.2
164690 - Windows Disabled Command Prompt Enumeration
-
Synopsis
This plugin determines if the DisableCMD policy is enabled or disabled on the remote host for each local user.
Description
The remote host may employ the DisableCMD policy on a per user basis. Enumerated local users may have the following registry key:
'HKLM\Software\Policies\Microsoft\Windows\System\DisableCMD'

- Unset or 0: The command prompt is enabled normally.
- 1: The command promt is disabled.
- 2: The command prompt is disabled however windows batch processing is allowed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/09/06, Modified: 2022/10/05
Plugin Output

tcp/445/cifs


Username: tidua
SID: S-1-5-21-1687551350-3880216100-4069998428-1009
DisableCMD: Unset

Username: DefaultAccount
SID: S-1-5-21-1687551350-3880216100-4069998428-503
DisableCMD: Unset

Username: CommonProduction
SID: S-1-5-21-1687551350-3880216100-4069998428-1007
DisableCMD: Unset

Username: commoniis
SID: S-1-5-21-1687551350-3880216100-4069998428-1008
DisableCMD: Unset

Username: production
SID: S-1-5-21-1687551350-3880216100-4069998428-500
DisableCMD: Unset

Username: WDAGUtilityAccount
SID: S-1-5-21-1687551350-3880216100-4069998428-504
DisableCMD: Unset

Username: Lkpadmin
SID: S-1-5-21-1687551350-3880216100-4069998428-1000
DisableCMD: Unset

Username: Guest
SID: S-1-5-21-1687551350-3880216100-4069998428-501
DisableCMD: Unset

72482 - Windows Display Driver Enumeration
-
Synopsis
Nessus was able to enumerate one or more of the display drivers on the remote host.
Description
Nessus was able to enumerate one or more of the display drivers on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0756
Plugin Information
Published: 2014/02/06, Modified: 2025/12/15
Plugin Output

tcp/0


Device Name : VMware SVGA 3D
Driver File Version : 9.17.6.5
Driver Date : 08/25/2023
Video Processor : VMware Virtual SVGA 3D Graphics Adapter
171956 - Windows Enumerate Accounts
-
Synopsis
Enumerate Windows accounts.
Description
Enumerate Windows accounts.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/28, Modified: 2025/12/15
Plugin Output

tcp/0

Windows accounts enumerated. Results output to DB.
User data gathered in scan starting at : 2026/1/12 17:58 India Standard Time
92423 - Windows Explorer Recently Executed Programs
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to find evidence of program execution using Windows Explorer registry logs and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/08/15
Plugin Output

tcp/0

WinRAR.exePO :i+00/D:\1Z\Middleware_Api Backup\Z\Z\.;Middleware_Api Backup$
notepad.exePO :i+00:.:,LB)A&&mU?!@+g)K
SanerNow_Windows_x86_6.3.exePO :i+00/D:\V1YLKPSOFT@W' Y.$bLKPSOFT1YSanerNow_LKP_Window_CM_Windows_x86_6.3~YY.|=,!SanerNow_LKP_Window_CM_Windows_x86_6.36
InetMgr.exePO :i+00/D:\V1ZjnLKPSOFT@W' Zjn.$%LKPSOFT
IISCrypto (1).exePO :i+00/D:\V1SWBLKPSOFT@W' SWB.$eLKPSOFT
devenv.exePO :i+00/D:\x1I[6WebPortal_LKPNETINVpWPI[6.\nWWebPortal_LKPNETIN"
mmc.exePO :i+00/D:\`1C[0SchedulersFYIC[F.=Schedulers~1C[!FMFClientRegistrationZC[0C[!F.'MFClientRegistration$
GitHubDesktop.exePO :i+00/D:\
a
services.msc\1
dcomcnfg\1
\\172.17.100.60\f$\1
\\192.168.150.67\d$\1
\\172.17.100.120\7PicksFile\\1
taskschd.msc\1
%temp%\1
\\192.168.150.67\1
\\172.17.100.60\d$\1
\\172.17.100.60\1
\\192.168.150.60\d$\1
cmd\1
winver\1
\\192.168.150.164\1
drivers\1
\\192.168.150.154\d$\1
inetmgr\1
d:\1
secpol.msc\1
\\172.17.100.120\7PicksFile\1
\\192.168.150.152\d$\1
mfcjkebsqploirvuhagyndzxwt
services.msc\1
\\192.168.150.67\ucc_match\1
appwiz.cpl\1
regedit\1
notepad\1
wmimgmt.msc\1
notepad.exe<3:
SanerNow_Windows_x86_6.3.exe/]
devenv.exe^
InetMgr.exed{\rc
WinRAR.exe4Nj
IISCrypto (1).exeirP
mmc.exenitm
regedit.exe.%aIj
GitHubDesktop.exe""v
X\r,!PCsg<
x@_dP/N

MRU programs details in attached report.
92418 - Windows Explorer Typed Paths
-
Synopsis
Nessus was able to enumerate the directory paths that users visited by typing the full directory path into Windows Explorer.
Description
Nessus was able to enumerate the directory paths that users visited by manually typing the full directory path into Windows Explorer. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Z:\
D:\Middleware_Api
\\192.168.150.154\d$\Meet\Middleware_API\LKP_Middleware\LKP_Middleware\bin\Release\net7.0\publish
\\192.168.150.67\d$
\\192.168.150.154
D:\
D:\UAT_Middleware_Api
D:\Schedulers\Release\net8.0
\\192.168.150.60\d$
C:\Users\Administrator\.ssh\id_ed25519.pub
D:\Backup\10072024_2126\API\New
\\192.168.150.154\d$\Meet\MutualFund\Publish-LIVE
\\192.168.150.154\d$\Meet
Z:\FileUpload\Accounts
\\172.17.100.60\d$
\\192.168.150.154\d$\Middleware_Api
Y:\IVR\PushClientInfo
D:\FileUpload\PreTrade
D:\Middleware_Api\Logs\10112025
Y:\Accounts\TP_Invoice

Extended explorer typed paths report attached.

159929 - Windows LSA Protection Status
-
Synopsis
Windows LSA Protection is disabled on the remote Windows host.
Description
The LSA Protection validates users for local and remote sign-ins and enforces local security policies to prevent reading memory and code injection by non-protected processes. This provides added security for the credentials that the LSA stores and manages. This protects against Pass-the-Hash or Mimikatz-style attacks.
Solution
Enable LSA Protection per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/04/20, Modified: 2025/06/16
Plugin Output

tcp/445/cifs


LSA Protection Key \SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL not found.

148541 - Windows Language Settings Detection
-
Synopsis
This plugin enumerates language files on a windows host.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates language IDs listed on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/04/14, Modified: 2022/02/01
Plugin Output

tcp/0

Default Install Language Code: 1033

Default Active Language Code: 1033

Other common microsoft Language packs may be scanned as well.
92422 - Windows Mapped Network Drives
-
Synopsis
Nessus was able to enumerate mapped network drives on the remote host.
Description
Nessus was able to generate a report of mapped network drives on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

b : \\172.17.100.60\FileUpload
mrulist : ba
a : \\172.17.100.60\D$


Extended mapped network drive report attached.

10150 - Windows NetBIOS / SMB Remote Host Information Disclosure
-
Synopsis
It was possible to obtain the network name of the remote host.
Description
The remote host is listening on UDP port 137 or TCP port 445, and replies to NetBIOS nbtscan or SMB requests.

Note that this plugin gathers information to be used in other plugins, but does not itself generate a report.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2021/02/10
Plugin Output

udp/137/netbios-ns

The following 3 NetBIOS names have been gathered :

MIDDLEWAREAPI = File Server Service
MIDDLEWAREAPI = Computer name
WORKGROUP = Workgroup / Domain name

The remote host has the following MAC address on its adapter :

00:50:56:bc:7d:2b

155963 - Windows Printer Driver Enumeration
-
Synopsis
Nessus was able to enumerate one or more of the printer drivers on the remote host.
Description
Nessus was able to enumerate one or more of the printer drivers on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/12/09, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


--- Microsoft XPS Document Writer v4 ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_2121e11a60e09843\Amd64\mxdwdrv.dll
Version : 10.0.17763.1
Supported Platform : Windows x64

--- Microsoft Software Printer Driver ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_2121e11a60e09843\Amd64\mxdwdrv.dll
Version : 10.0.17763.1192
Supported Platform : Windows x64

--- Microsoft enhanced Point and Print compatibility driver ---

Nessus detected 2 installs of Microsoft enhanced Point and Print compatibility driver:

Path : C:\Windows\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 10.0.17763.3532
Supported Platform : Windows x64

Path : C:\Windows\system32\spool\DRIVERS\W32X86\3\mxdwdrv.dll
Version : 10.0.17763.3532
Supported Platform : Windows NT x86

--- Microsoft Print To PDF ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_2121e11a60e09843\Amd64\mxdwdrv.dll
Version : 10.0.17763.1
Supported Platform : Windows x64

--- Microsoft Shared Fax Driver ---

Path : C:\Windows\system32\spool\DRIVERS\x64\3\FXSDRV.DLL
Version : 10.0.17763.4720
Supported Platform : Windows x64

--- Microsoft IPP Class Driver ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_2121e11a60e09843\Amd64\mxdwdrv.dll
Version : 10.0.17763.1
Supported Platform : Windows x64

--- Remote Desktop Easy Print ---

Path : C:\Windows\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 10.0.17763.973
Supported Platform : Windows x64
63620 - Windows Product Key Retrieval
-
Synopsis
This plugin retrieves the Windows Product key of the remote Windows host.
Description
Using the supplied credentials, Nessus was able to obtain the retrieve the Windows host's partial product key'.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/01/18, Modified: 2013/01/18
Plugin Output

tcp/445/cifs


Product key : XXXXX-XXXXX-XXXXX-XXXXX-BWT4H

Note that all but the final portion of the key has been obfuscated.
160576 - Windows Services Registry ACL
-
Synopsis
Checks Windows Registry for Service ACLs
Description
Checks Windows Registry for Service ACLs.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/05, Modified: 2024/01/15
Plugin Output

tcp/445/cifs

report output too big - ending list here

85736 - Windows Store Application Enumeration
-
Synopsis
It is possible to obtain the list of applications installed from the Windows Store.
Description
This plugin connects to the remote Windows host with the supplied credentials and uses WMI and Powershell to enumerate applications installed on the host from the Windows Store.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/09/02, Modified: 2025/12/15
Plugin Output

tcp/0


-1527c705-839a-4832-9118-54d4Bd6a0c89
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FilePicker_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-c5e2524a-ea46-4f67-841f-6a9465d9d515
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FileExplorer_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-E2A4F912-2574-4A75-9BB0-0D023378592B
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppResolverUX_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AddSuggestedFoldersToLibraryDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-InputApp
Version : 1000.17763.1.0
InstallLocation : C:\Windows\SystemApps\InputApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AAD.BrokerPlugin
Version : 1000.17763.1.0
InstallLocation : C:\Windows\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AccountsControl
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AsyncTextService
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.AsyncTextService_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.BioEnrollment
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.BioEnrollment_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.CredDialogHost
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\microsoft.creddialoghost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.ECApp
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.ECApp_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.LockApp
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Win32WebViewHost
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Win32WebViewHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Apprep.ChxApp
Version : 1000.17763.1.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CapturePicker
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CapturePicker_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CloudExperienceHost
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Cortana
Version : 1.11.6.17763
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.NarratorQuickStart
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\microsoft.windows.narratorquickstart_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.OOBENetworkCaptivePortal
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.OOBENetworkConnectionFlow
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.PeopleExperienceHost
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.PinningConfirmationDialog
Version : 1000.17763.1.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ShellExperienceHost
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.XGpuEjectDialog
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.CBSPreview
Version : 10.0.17763.1
InstallLocation : C:\Windows\SystemApps\Windows.CBSPreview_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-windows.immersivecontrolpanel
Version : 10.0.2.1000
InstallLocation : C:\Windows\ImmersiveControlPanel
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.PrintDialog
Version : 6.2.1.0
InstallLocation : C:\Windows\PrintDialog
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecHealthUI
Version : 10.0.17763.3232
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
204960 - Windows System Driver Enumeration (Windows)
-
Synopsis
One or more kernel or file system drivers were enumerated on the remote Windows host.
Description
One or more kernel or file system drivers were enumerated on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/08/01, Modified: 2025/12/15
Plugin Output

tcp/0


Total : 366

Name : 1394ohci
Path : C:\Windows\system32\drivers\1394ohci.sys
Service Type : Kernel Driver
Description : 1394 OHCI Compliant Host Controller
State : Stopped

Name : 3ware
Path : C:\Windows\system32\drivers\3ware.sys
Service Type : Kernel Driver
Description : 3ware
State : Stopped

Name : ACPI
Path : C:\Windows\system32\drivers\ACPI.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Driver
State : Running

Name : AcpiDev
Path : C:\Windows\system32\drivers\AcpiDev.sys
Service Type : Kernel Driver
Description : ACPI Devices driver
State : Stopped

Name : acpiex
Path : C:\Windows\system32\Drivers\acpiex.sys
Service Type : Kernel Driver
Description : Microsoft ACPIEx Driver
State : Running

Name : acpipagr
Path : C:\Windows\system32\drivers\acpipagr.sys
Service Type : Kernel Driver
Description : ACPI Processor Aggregator Driver
State : Stopped

Name : AcpiPmi
Path : C:\Windows\system32\drivers\acpipmi.sys
Service Type : Kernel Driver
Description : ACPI Power Meter Driver
State : Stopped

Name : acpitime
Path : C:\Windows\system32\drivers\acpitime.sys
Service Type : Kernel Driver
Description : ACPI Wake Alarm Driver
State : Stopped

Name : ADP80XX
Path : C:\Windows\system32\drivers\ADP80XX.SYS
Service Type : Kernel Driver
Description : ADP80XX
State : Stopped

Name : AFD
Path : C:\Windows\system32\drivers\afd.sys
Service Type : Kernel Driver
Description : Ancillary Function Driver for Winsock
State : Running

Name : afunix
Path : C:\Windows\system32\drivers\afunix.sys
Service Type : Kernel Driver
Description : afunix
State : Running

Name : ahcache
Path : C:\Windows\system32\DRIVERS\ahcache.sys
Service Type : Kernel Driver
Description : Application Compatibility Cache
State : Running

Name : AmdK8
Path : C:\Windows\system32\drivers\amdk8.sys
Service Type : Kernel Driver
Description : AMD K8 Processor Driver
State : Stopped

Name : AmdPPM
Path : C:\Windows\system32\drivers\amdppm.sys
Service Type : Kernel Driver
Description : AMD Processor Driver
State : Stopped

Name : amdsata
Path : C:\Windows\system32\drivers\amdsata.sys
Service Type : Kernel Driver
Description : amdsata
State : Stopped

Name : amdsbs
Path : C:\Windows\system32\drivers\amdsbs.sys
Service Type : Kernel Driver
Description : amdsbs
State : Stopped

Name : amdxata
Path : C:\Windows\system32\drivers\amdxata.sys
Service Type : Kernel Driver
Description : amdxata
State : Stopped

Name : AppID
Path : C:\Windows\system32\drivers\appid.sys
Service Type : Kernel Driver
Description : AppID Driver
State : Stopped

Name : applockerfltr
Path : C:\Windows\system32\drivers\applockerfltr.sys
Service Type : Kernel Driver
Description : Smartlocker Filter Driver
State : Stopped

Name : AppvStrm
Path : C:\Windows\system32\drivers\AppvStrm.sys
Service Type : File System Driver
Description : AppvStrm
State : Stopped

Name : AppvVemgr
Path : C:\Windows\system32\drivers\AppvVemgr.sys
Service Type : File System Driver
Description : AppvVemgr
State : Stopped

Name : AppvVfs
Path : C:\Windows\system32\drivers\AppvVfs.sys
Service Type : File System Driver
Description : AppvVfs
State : Stopped

Name : arcsas
Path : C:\Windows\system32\drivers\arcsas.sys
Service Type : Kernel Driver
Description : Adaptec SAS/SATA-II RAID Storport's Miniport Driver
State : Stopped

Name : AsyncMac
Path : C:\Windows\system32\drivers\asyncmac.sys
Service Type : Kernel Driver
Description : RAS Asynchronous Media Driver
State : Stopped

Name : atapi
Path : C:\Windows\system32\drivers\atapi.sys
Service Type : Kernel Driver
Description : IDE Channel
State : Running

Name : b06bdrv
Path : C:\Windows\system32\drivers\bxvbda.sys
Service Type : Kernel Driver
Description : QLogic Network Adapter VBD
State : Stopped

Name : bam
Path : C:\Windows\system32\drivers\bam.sys
Service Type : Kernel Driver
Description : Background Activity Moderator Driver
State : Running

Name : BasicDisplay
Path : C:\Windows\system32\DriverStore\FileRepository\basicdisplay.inf_amd64_5103ac179273be89\BasicDisplay.sys
Service Type : Kernel Driver
Description : BasicDisplay
State : Running

Name : BasicRender
Path : C:\Windows\system32\DriverStore\FileRepository\basicrender.inf_amd64_efdc64af60c69a6d\BasicRender.sys
Service Type : Kernel Driver
Description : BasicRender
State : Running

Name : bcmfn2
Path : C:\Windows\system32\drivers\bcmfn2.sys
Service Type : Kernel Driver
Description : bcmfn2 Service
State : Stopped

Name : Beep
Path : C:\Windows\system32\drivers\Beep.sys
Service Type : Kernel Driver
Description : Beep
State : Running

Name : bfadfcoei
Path : C:\Windows\system32\drivers\bfadfcoei.sys
Service Type : Kernel Driver
Description : bfadfcoei
State : Stopped

Name : bfadi
Path : C:\Windows\system32\drivers\bfadi.sys
Service Type : Kernel Driver
Description : bfadi
State : Stopped

Name : bindflt
Path : C:\Windows\system32\drivers\bindflt.sys
Service Type : File System Driver
Description : Windows Bind Filter Driver
State : Stopped

Name : bowser
Path : C:\Windows\system32\DRIVERS\bowser.sys
Service Type : File System Driver
Description : Browser
State : Running

Name : BthEnum
Path : C:\Windows\system32\drivers\BthEnum.sys
Service Type : Kernel Driver
Description : Bluetooth Enumerator Service
State : Stopped

Name : BthLEEnum
Path : C:\Windows\system32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys
Service Type : Kernel Driver
Description : Bluetooth Low Energy Driver
State : Stopped

Name : BthMini
Path : C:\Windows\system32\drivers\BTHMINI.sys
Service Type : Kernel Driver
Description : Bluetooth Radio Driver
State : Stopped

Name : BTHPORT
Path : C:\Windows\system32\drivers\BTHport.sys
Service Type : Kernel Driver
Description : Bluetooth Port Driver
State : Stopped

Name : BTHUSB
Path : C:\Windows\system32\drivers\BTHUSB.sys
Service Type : Kernel Driver
Description : Bluetooth Radio USB Driver
State : Stopped

Name : bttflt
Path : C:\Windows\system32\drivers\bttflt.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V VHDPMEM BTT Filter
State : Stopped

Name : buttonconverter
Path : C:\Windows\system32\drivers\buttonconverter.sys
Service Type : Kernel Driver
Description : Service for Portable Device Control devices
State : Stopped

Name : bxfcoe
Path : C:\Windows\system32\drivers\bxfcoe.sys
Service Type : Kernel Driver
Description : QLogic FCoE Offload driver
State : Stopped

Name : bxois
Path : C:\Windows\system32\drivers\bxois.sys
Service Type : Kernel Driver
Description : QLogic Offload iSCSI Driver
State : Stopped

Name : CapImg
Path : C:\Windows\system32\drivers\capimg.sys
Service Type : Kernel Driver
Description : HID driver for CapImg touch screen
State : Stopped

Name : cdfs
Path : C:\Windows\system32\DRIVERS\cdfs.sys
Service Type : File System Driver
Description : CD/DVD File System Reader
State : Stopped

Name : cdrom
Path : C:\Windows\system32\drivers\cdrom.sys
Service Type : Kernel Driver
Description : CD-ROM Driver
State : Running

Name : cht4iscsi
Path : C:\Windows\system32\drivers\cht4sx64.sys
Service Type : Kernel Driver
Description : cht4iscsi
State : Stopped

Name : cht4vbd
Path : C:\Windows\system32\drivers\cht4vx64.sys
Service Type : Kernel Driver
Description : Chelsio Virtual Bus Driver
State : Stopped

Name : CldFlt
Path : C:\Windows\system32\drivers\cldflt.sys
Service Type : File System Driver
Description : Windows Cloud Files Filter Driver
State : Running

Name : CLFS
Path : C:\Windows\system32\drivers\CLFS.sys
Service Type : Kernel Driver
Description : Common Log (CLFS)
State : Running

Name : CmBatt
Path : C:\Windows\system32\drivers\CmBatt.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Control Method Battery Driver
State : Running

Name : CNG
Path : C:\Windows\system32\Drivers\cng.sys
Service Type : Kernel Driver
Description : CNG
State : Running

Name : cnghwassist
Path : C:\Windows\system32\DRIVERS\cnghwassist.sys
Service Type : Kernel Driver
Description : CNG Hardware Assist algorithm provider
State : Stopped

Name : CompositeBus
Path : C:\Windows\system32\DriverStore\FileRepository\compositebus.inf_amd64_e4d35af746093dc3\CompositeBus.sys
Service Type : Kernel Driver
Description : Composite Bus Enumerator Driver
State : Running

Name : condrv
Path : C:\Windows\system32\drivers\condrv.sys
Service Type : Kernel Driver
Description : Console Driver
State : Running

Name : CSC
Path : C:\Windows\system32\drivers\csc.sys
Service Type : Kernel Driver
Description : Offline Files Driver
State : Stopped

Name : dam
Path : C:\Windows\system32\drivers\dam.sys
Service Type : Kernel Driver
Description : Desktop Activity Moderator Driver
State : Stopped

Name : Dfsc
Path : C:\Windows\system32\Drivers\dfsc.sys
Service Type : File System Driver
Description : DFS Namespace Client Driver
State : Running

Name : Disk
Path : C:\Windows\system32\drivers\disk.sys
Service Type : Kernel Driver
Description : Disk Driver
State : Running

Name : dmvsc
Path : C:\Windows\system32\drivers\dmvsc.sys
Service Type : Kernel Driver
Description : dmvsc
State : Stopped

Name : drmkaud
Path : C:\Windows\system32\drivers\drmkaud.sys
Service Type : Kernel Driver
Description : Microsoft Trusted Audio Drivers
State : Stopped

Name : DXGKrnl
Path : C:\Windows\system32\drivers\dxgkrnl.sys
Service Type : Kernel Driver
Description : LDDM Graphics Subsystem
State : Running

Name : e1iexpress
Path : C:\Windows\system32\drivers\e1i63x64.sys
Service Type : Kernel Driver
Description : Intel(R) PRO/1000 PCI Express Network Connection Driver I
State : Running

Name : ebdrv
Path : C:\Windows\system32\drivers\evbda.sys
Service Type : Kernel Driver
Description : QLogic 10 Gigabit Ethernet Adapter VBD
State : Stopped

Name : EhStorClass
Path : C:\Windows\system32\drivers\EhStorClass.sys
Service Type : Kernel Driver
Description : Enhanced Storage Filter Driver
State : Running

Name : EhStorTcgDrv
Path : C:\Windows\system32\drivers\EhStorTcgDrv.sys
Service Type : Kernel Driver
Description : Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols
State : Stopped

Name : elxfcoe
Path : C:\Windows\system32\drivers\elxfcoe.sys
Service Type : Kernel Driver
Description : elxfcoe
State : Stopped

Name : elxstor
Path : C:\Windows\system32\drivers\elxstor.sys
Service Type : Kernel Driver
Description : elxstor
State : Stopped

Name : ErrDev
Path : C:\Windows\system32\drivers\errdev.sys
Service Type : Kernel Driver
Description : Microsoft Hardware Error Device Driver
State : Stopped

Name : exfat
Path : C:\Windows\system32\drivers\exfat.sys
Service Type : File System Driver
Description : exFAT File System Driver
State : Stopped

Name : fastfat
Path : C:\Windows\system32\drivers\fastfat.sys
Service Type : File System Driver
Description : FAT12/16/32 File System Driver
State : Stopped

Name : fcvsc
Path : C:\Windows\system32\drivers\fcvsc.sys
Service Type : Kernel Driver
Description : fcvsc
State : Stopped

Name : fdc
Path : C:\Windows\system32\drivers\fdc.sys
Service Type : Kernel Driver
Description : Floppy Disk Controller Driver
State : Running

Name : FileCrypt
Path : C:\Windows\system32\drivers\filecrypt.sys
Service Type : File System Driver
Description : FileCrypt
State : Running

Name : FileInfo
Path : C:\Windows\system32\drivers\fileinfo.sys
Service Type : File System Driver
Description : File Information FS MiniFilter
State : Stopped

Name : Filetrace
Path : C:\Windows\system32\drivers\filetrace.sys
Service Type : File System Driver
Description : Filetrace
State : Stopped

Name : file_monitor
Path : C:\Windows\system32\DRIVERS\file_monitor.sys
Service Type : File System Driver
Description : file_monitor
State : Running

Name : file_protector
Path : C:\Windows\system32\DRIVERS\file_protector.sys
Service Type : File System Driver
Description : Acronis File Protector Driver
State : Running

Name : flpydisk
Path : C:\Windows\system32\drivers\flpydisk.sys
Service Type : Kernel Driver
Description : Floppy Disk Driver
State : Running

Name : FltMgr
Path : C:\Windows\system32\drivers\fltmgr.sys
Service Type : File System Driver
Description : FltMgr
State : Running

Name : fltsrv
Path : C:\Windows\system32\DRIVERS\fltsrv.sys
Service Type : Kernel Driver
Description : Acronis Storage Filter Management
State : Running

Name : FsDepends
Path : C:\Windows\system32\drivers\FsDepends.sys
Service Type : File System Driver
Description : File System Dependency Minifilter
State : Stopped

Name : gencounter
Path : C:\Windows\system32\drivers\vmgencounter.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Generation Counter
State : Running

Name : genericusbfn
Path : C:\Windows\system32\drivers\genericusbfn.sys
Service Type : Kernel Driver
Description : Generic USB Function Class
State : Stopped

Name : GPIOClx0101
Path : C:\Windows\system32\Drivers\msgpioclx.sys
Service Type : Kernel Driver
Description : Microsoft GPIO Class Extension Driver
State : Stopped

Name : HDAudBus
Path : C:\Windows\system32\drivers\HDAudBus.sys
Service Type : Kernel Driver
Description : Microsoft UAA Bus Driver for High Definition Audio
State : Stopped

Name : HidBatt
Path : C:\Windows\system32\drivers\HidBatt.sys
Service Type : Kernel Driver
Description : HID UPS Battery Driver
State : Stopped

Name : hidinterrupt
Path : C:\Windows\system32\drivers\hidinterrupt.sys
Service Type : Kernel Driver
Description : Common Driver for HID Buttons implemented with interrupts
State : Stopped

Name : HidUsb
Path : C:\Windows\system32\drivers\hidusb.sys
Service Type : Kernel Driver
Description : Microsoft HID Class Driver
State : Stopped

Name : HpSAMD
Path : C:\Windows\system32\drivers\HpSAMD.sys
Service Type : Kernel Driver
Description : HpSAMD
State : Stopped

Name : HTTP
Path : C:\Windows\system32\drivers\HTTP.sys
Service Type : Kernel Driver
Description : HTTP Service
State : Running

Name : hvcrash
Path : C:\Windows\system32\drivers\hvcrash.sys
Service Type : Kernel Driver
Description : hvcrash
State : Stopped

Name : hvservice
Path : C:\Windows\system32\drivers\hvservice.sys
Service Type : Kernel Driver
Description : Hypervisor/Virtual Machine Support Driver
State : Stopped

Name : HwNClx0101
Path : C:\Windows\system32\Drivers\mshwnclx.sys
Service Type : Kernel Driver
Description : Microsoft Hardware Notifications Class Extension Driver
State : Stopped

Name : hwpolicy
Path : C:\Windows\system32\drivers\hwpolicy.sys
Service Type : Kernel Driver
Description : Hardware Policy Driver
State : Stopped

Name : hyperkbd
Path : C:\Windows\system32\drivers\hyperkbd.sys
Service Type : Kernel Driver
Description : hyperkbd
State : Stopped

Name : HyperVideo
Path : C:\Windows\system32\drivers\HyperVideo.sys
Service Type : Kernel Driver
Description : HyperVideo
State : Stopped

Name : i8042prt
Path : C:\Windows\system32\drivers\i8042prt.sys
Service Type : Kernel Driver
Description : PS/2 Keyboard and Mouse Port Driver
State : Running

Name : iaLPSSi_GPIO
Path : C:\Windows\system32\drivers\iaLPSSi_GPIO.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO GPIO Controller Driver
State : Stopped

Name : iaLPSSi_I2C
Path : C:\Windows\system32\drivers\iaLPSSi_I2C.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Controller Driver
State : Stopped

Name : iaStorAVC
Path : C:\Windows\system32\drivers\iaStorAVC.sys
Service Type : Kernel Driver
Description : Intel Chipset SATA RAID Controller
State : Stopped

Name : iaStorV
Path : C:\Windows\system32\drivers\iaStorV.sys
Service Type : Kernel Driver
Description : Intel RAID Controller Windows 7
State : Stopped

Name : ibbus
Path : C:\Windows\system32\drivers\ibbus.sys
Service Type : Kernel Driver
Description : Mellanox InfiniBand Bus/AL (Filter Driver)
State : Stopped

Name : IndirectKmd
Path : C:\Windows\system32\drivers\IndirectKmd.sys
Service Type : Kernel Driver
Description : Indirect Displays Kernel-Mode Driver
State : Stopped

Name : intelide
Path : C:\Windows\system32\drivers\intelide.sys
Service Type : Kernel Driver
Description : intelide
State : Running

Name : intelpep
Path : C:\Windows\system32\drivers\intelpep.sys
Service Type : Kernel Driver
Description : Intel(R) Power Engine Plug-in Driver
State : Running

Name : intelppm
Path : C:\Windows\system32\drivers\intelppm.sys
Service Type : Kernel Driver
Description : Intel Processor Driver
State : Running

Name : IpFilterDriver
Path : C:\Windows\system32\DRIVERS\ipfltdrv.sys
Service Type : Kernel Driver
Description : IP Traffic Filter Driver
State : Stopped

Name : IPMIDRV
Path : C:\Windows\system32\drivers\IPMIDrv.sys
Service Type : Kernel Driver
Description : IPMIDRV
State : Stopped

Name : IPNAT
Path : C:\Windows\system32\drivers\ipnat.sys
Service Type : Kernel Driver
Description : IP Network Address Translator
State : Stopped

Name : IPsecGW
Path : C:\Windows\system32\drivers\ipsecgw.sys
Service Type : Kernel Driver
Description : Windows IPsec Gateway Driver
State : Stopped

Name : IPT
Path : C:\Windows\system32\drivers\ipt.sys
Service Type : Kernel Driver
Description : IPT
State : Stopped

Name : isapnp
Path : C:\Windows\system32\drivers\isapnp.sys
Service Type : Kernel Driver
Description : isapnp
State : Stopped

Name : iScsiPrt
Path : C:\Windows\system32\drivers\msiscsi.sys
Service Type : Kernel Driver
Description : iScsiPort Driver
State : Stopped

Name : ItSas35i
Path : C:\Windows\system32\drivers\ItSas35i.sys
Service Type : Kernel Driver
Description : ItSas35i
State : Stopped

Name : kbdclass
Path : C:\Windows\system32\drivers\kbdclass.sys
Service Type : Kernel Driver
Description : Keyboard Class Driver
State : Running

Name : kbdhid
Path : C:\Windows\system32\drivers\kbdhid.sys
Service Type : Kernel Driver
Description : Keyboard HID Driver
State : Stopped

Name : kdnic
Path : C:\Windows\system32\drivers\kdnic.sys
Service Type : Kernel Driver
Description : Microsoft Kernel Debug Network Miniport (NDIS 6.20)
State : Running

Name : klbackupdisk.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klbackupdisk.sys
Service Type : Kernel Driver
Description : Kaspersky Lab klbackupdisk.KES-21-15
State : Running

Name : klbackupflt.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klbackupflt.sys
Service Type : File System Driver
Description : Kaspersky Lab klbackupflt.KES-21-15
State : Running

Name : klelam
Path : C:\Windows\system32\DRIVERS\klelam.sys
Service Type : Kernel Driver
Description : klelam
State : Stopped

Name : KLFLT.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klflt.sys
Service Type : Kernel Driver
Description : Kaspersky Lab Kernel DLL.KES-21-15
State : Running

Name : klfltdev.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klfltdev.sys
Service Type : Kernel Driver
Description : Kaspersky Lab KLFltDev.KES-21-15
State : Running

Name : klgse.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klgse.sys
Service Type : File System Driver
Description : Kaspersky Lab Security Extender Driver.KES-21-15
State : Running

Name : KLHK.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klhk.sys
Service Type : Kernel Driver
Description : Kaspersky Lab service driver.KES-21-15
State : Running

Name : KLIF.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klif.sys
Service Type : File System Driver
Description : Kaspersky Lab Driver.KES-21-15
State : Running

Name : klim6
Path : C:\Windows\system32\DRIVERS\klim6.sys
Service Type : Kernel Driver
Description : Kaspersky Anti-Virus NDIS 6 Filter
State : Running

Name : klpd.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klpd.sys
Service Type : File System Driver
Description : Kaspersky Lab format recognizer driver.KES-21-15
State : Running

Name : klpnpflt.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klpnpflt.sys
Service Type : Kernel Driver
Description : Kaspersky Lab klpnpflt.KES-21-15
State : Running

Name : klupd_KES-21-15_arkmon
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_arkmon.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_arkmon
State : Running

Name : klupd_KES-21-15_klark
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_klark.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_klark
State : Running

Name : klupd_KES-21-15_klbg
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_klbg.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_klbg
State : Running

Name : klupd_KES-21-15_mark
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_mark.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_mark
State : Running

Name : klwfp
Path : C:\Windows\system32\DRIVERS\klwfp.sys
Service Type : Kernel Driver
Description : klwfp
State : Running

Name : klwtp.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klwtp.sys
Service Type : Kernel Driver
Description : klwtp.KES-21-15
State : Running

Name : kneps.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\kneps.sys
Service Type : Kernel Driver
Description : kneps.KES-21-15
State : Running

Name : KSecDD
Path : C:\Windows\system32\Drivers\ksecdd.sys
Service Type : Kernel Driver
Description : KSecDD
State : Running

Name : KSecPkg
Path : C:\Windows\system32\Drivers\ksecpkg.sys
Service Type : Kernel Driver
Description : KSecPkg
State : Running

Name : ksthunk
Path : C:\Windows\system32\drivers\ksthunk.sys
Service Type : Kernel Driver
Description : Kernel Streaming Thunks
State : Stopped

Name : lltdio
Path : C:\Windows\system32\drivers\lltdio.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Mapper I/O Driver
State : Running

Name : LSI_SAS
Path : C:\Windows\system32\drivers\lsi_sas.sys
Service Type : Kernel Driver
Description : LSI_SAS
State : Running

Name : LSI_SAS2i
Path : C:\Windows\system32\drivers\lsi_sas2i.sys
Service Type : Kernel Driver
Description : LSI_SAS2i
State : Stopped

Name : LSI_SAS3i
Path : C:\Windows\system32\drivers\lsi_sas3i.sys
Service Type : Kernel Driver
Description : LSI_SAS3i
State : Stopped

Name : LSI_SSS
Path : C:\Windows\system32\drivers\lsi_sss.sys
Service Type : Kernel Driver
Description : LSI_SSS
State : Stopped

Name : luafv
Path : C:\Windows\system32\drivers\luafv.sys
Service Type : File System Driver
Description : UAC File Virtualization
State : Running

Name : mausbhost
Path : C:\Windows\system32\drivers\mausbhost.sys
Service Type : Kernel Driver
Description : MA-USB Host Controller Driver
State : Stopped

Name : mausbip
Path : C:\Windows\system32\drivers\mausbip.sys
Service Type : Kernel Driver
Description : MA-USB IP Filter Driver
State : Stopped

Name : megasas
Path : C:\Windows\system32\drivers\megasas.sys
Service Type : Kernel Driver
Description : megasas
State : Stopped

Name : megasas2i
Path : C:\Windows\system32\drivers\MegaSas2i.sys
Service Type : Kernel Driver
Description : megasas2i
State : Stopped

Name : megasas35i
Path : C:\Windows\system32\drivers\megasas35i.sys
Service Type : Kernel Driver
Description : megasas35i
State : Stopped

Name : megasr
Path : C:\Windows\system32\drivers\megasr.sys
Service Type : Kernel Driver
Description : megasr
State : Stopped

Name : Microsoft_Bluetooth_AvrcpTransport
Path : C:\Windows\system32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys
Service Type : Kernel Driver
Description : Microsoft Bluetooth Avrcp Transport Driver
State : Stopped

Name : mlx4_bus
Path : C:\Windows\system32\drivers\mlx4_bus.sys
Service Type : Kernel Driver
Description : Mellanox ConnectX Bus Enumerator
State : Stopped

Name : MMCSS
Path : C:\Windows\system32\drivers\mmcss.sys
Service Type : Kernel Driver
Description : Multimedia Class Scheduler
State : Running

Name : Modem
Path : C:\Windows\system32\drivers\modem.sys
Service Type : Kernel Driver
Description : Modem
State : Stopped

Name : monitor
Path : C:\Windows\system32\drivers\monitor.sys
Service Type : Kernel Driver
Description : Microsoft Monitor Class Function Driver Service
State : Running

Name : mouclass
Path : C:\Windows\system32\drivers\mouclass.sys
Service Type : Kernel Driver
Description : Mouse Class Driver
State : Running

Name : mouhid
Path : C:\Windows\system32\drivers\mouhid.sys
Service Type : Kernel Driver
Description : Mouse HID Driver
State : Stopped

Name : mountmgr
Path : C:\Windows\system32\drivers\mountmgr.sys
Service Type : Kernel Driver
Description : Mount Point Manager
State : Running

Name : mpsdrv
Path : C:\Windows\system32\drivers\mpsdrv.sys
Service Type : Kernel Driver
Description : Windows Defender Firewall Authorization Driver
State : Running

Name : mrxsmb
Path : C:\Windows\system32\DRIVERS\mrxsmb.sys
Service Type : File System Driver
Description : SMB MiniRedirector Wrapper and Engine
State : Running

Name : mrxsmb20
Path : C:\Windows\system32\DRIVERS\mrxsmb20.sys
Service Type : File System Driver
Description : SMB 2.0 MiniRedirector
State : Running

Name : MsBridge
Path : C:\Windows\system32\drivers\bridge.sys
Service Type : Kernel Driver
Description : Microsoft MAC Bridge
State : Stopped

Name : Msfs
Path : C:\Windows\system32\drivers\Msfs.sys
Service Type : File System Driver
Description : Msfs
State : Running

Name : msgpiowin32
Path : C:\Windows\system32\drivers\msgpiowin32.sys
Service Type : Kernel Driver
Description : Common Driver for Buttons, DockMode and Laptop/Slate Indicator
State : Stopped

Name : mshidkmdf
Path : C:\Windows\system32\drivers\mshidkmdf.sys
Service Type : Kernel Driver
Description : Pass-through HID to KMDF Filter Driver
State : Stopped

Name : mshidumdf
Path : C:\Windows\system32\drivers\mshidumdf.sys
Service Type : Kernel Driver
Description : Pass-through HID to UMDF Driver
State : Stopped

Name : msisadrv
Path : C:\Windows\system32\drivers\msisadrv.sys
Service Type : Kernel Driver
Description : msisadrv
State : Running

Name : MSKSSRV
Path : C:\Windows\system32\drivers\MSKSSRV.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Service Proxy
State : Stopped

Name : MsLbfoProvider
Path : C:\Windows\system32\drivers\MsLbfoProvider.sys
Service Type : Kernel Driver
Description : Microsoft Load Balancing/Failover Provider
State : Stopped

Name : MsLldp
Path : C:\Windows\system32\drivers\mslldp.sys
Service Type : Kernel Driver
Description : Microsoft Link-Layer Discovery Protocol
State : Running

Name : MSPCLOCK
Path : C:\Windows\system32\drivers\MSPCLOCK.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Clock Proxy
State : Stopped

Name : MSPQM
Path : C:\Windows\system32\drivers\MSPQM.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Quality Manager Proxy
State : Stopped

Name : MsRPC
Path : C:\Windows\system32\drivers\MsRPC.sys
Service Type : Kernel Driver
Description : MsRPC
State : Stopped

Name : MsSecCore
Path : C:\Windows\system32\drivers\msseccore.sys
Service Type : Kernel Driver
Description : Microsoft Security Core Boot Driver
State : Running

Name : MsSecFlt
Path : C:\Windows\system32\drivers\mssecflt.sys
Service Type : Kernel Driver
Description : Microsoft Security Events Component Minifilter
State : Stopped

Name : MsSecWfp
Path : C:\Windows\system32\drivers\mssecwfp.sys
Service Type : Kernel Driver
Description : Microsoft Security WFP Callout Driver
State : Stopped

Name : mssmbios
Path : C:\Windows\system32\drivers\mssmbios.sys
Service Type : Kernel Driver
Description : Microsoft System Management BIOS Driver
State : Running

Name : MSTEE
Path : C:\Windows\system32\drivers\MSTEE.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Tee/Sink-to-Sink Converter
State : Stopped

Name : MTConfig
Path : C:\Windows\system32\drivers\MTConfig.sys
Service Type : Kernel Driver
Description : Microsoft Input Configuration Driver
State : Stopped

Name : Mup
Path : C:\Windows\system32\Drivers\mup.sys
Service Type : File System Driver
Description : Mup
State : Running

Name : mvumis
Path : C:\Windows\system32\drivers\mvumis.sys
Service Type : Kernel Driver
Description : mvumis
State : Stopped

Name : ndfltr
Path : C:\Windows\system32\drivers\ndfltr.sys
Service Type : Kernel Driver
Description : NetworkDirect Service
State : Stopped

Name : NDIS
Path : C:\Windows\system32\drivers\ndis.sys
Service Type : Kernel Driver
Description : NDIS System Driver
State : Running

Name : NdisCap
Path : C:\Windows\system32\drivers\ndiscap.sys
Service Type : Kernel Driver
Description : Microsoft NDIS Capture
State : Stopped

Name : NdisImPlatform
Path : C:\Windows\system32\drivers\NdisImPlatform.sys
Service Type : Kernel Driver
Description : Microsoft Network Adapter Multiplexor Protocol
State : Stopped

Name : NdisTapi
Path : C:\Windows\system32\DRIVERS\ndistapi.sys
Service Type : Kernel Driver
Description : Remote Access NDIS TAPI Driver
State : Running

Name : Ndisuio
Path : C:\Windows\system32\drivers\ndisuio.sys
Service Type : Kernel Driver
Description : NDIS Usermode I/O Protocol
State : Stopped

Name : NdisVirtualBus
Path : C:\Windows\system32\drivers\NdisVirtualBus.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Network Adapter Enumerator
State : Running

Name : NdisWan
Path : C:\Windows\system32\drivers\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access NDIS WAN Driver
State : Running

Name : ndiswanlegacy
Path : C:\Windows\system32\DRIVERS\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access LEGACY NDIS WAN Driver
State : Stopped

Name : ndproxy
Path : C:\Windows\system32\DRIVERS\NDProxy.sys
Service Type : Kernel Driver
Description : NDIS Proxy Driver
State : Running

Name : NetAdapterCx
Path : C:\Windows\system32\drivers\NetAdapterCx.sys
Service Type : Kernel Driver
Description : Network Adapter Wdf Class Extension Library
State : Stopped

Name : NetBIOS
Path : C:\Windows\system32\drivers\netbios.sys
Service Type : File System Driver
Description : NetBIOS Interface
State : Running

Name : NetBT
Path : C:\Windows\system32\DRIVERS\netbt.sys
Service Type : Kernel Driver
Description : NetBT
State : Running

Name : netvsc
Path : C:\Windows\system32\drivers\netvsc.sys
Service Type : Kernel Driver
Description : netvsc
State : Stopped

Name : ngelam
Path : C:\Windows\system32\drivers\ngelam.sys
Service Type : Kernel Driver
Description : ngelam
State : Stopped

Name : Npfs
Path : C:\Windows\system32\drivers\Npfs.sys
Service Type : File System Driver
Description : Npfs
State : Running

Name : npsvctrig
Path : C:\Windows\system32\drivers\npsvctrig.sys
Service Type : Kernel Driver
Description : Named pipe service trigger provider
State : Running

Name : nsiproxy
Path : C:\Windows\system32\drivers\nsiproxy.sys
Service Type : Kernel Driver
Description : NSI Proxy Service Driver
State : Running

Name : Ntfs
Path : C:\Windows\system32\drivers\Ntfs.sys
Service Type : File System Driver
Description : Ntfs
State : Running

Name : Null
Path : C:\Windows\system32\drivers\Null.sys
Service Type : Kernel Driver
Description : Null
State : Running

Name : nvdimm
Path : C:\Windows\system32\drivers\nvdimm.sys
Service Type : Kernel Driver
Description : Microsoft NVDIMM device driver
State : Stopped

Name : nvraid
Path : C:\Windows\system32\drivers\nvraid.sys
Service Type : Kernel Driver
Description : nvraid
State : Stopped

Name : nvstor
Path : C:\Windows\system32\drivers\nvstor.sys
Service Type : Kernel Driver
Description : nvstor
State : Stopped

Name : Parport
Path : C:\Windows\system32\drivers\parport.sys
Service Type : Kernel Driver
Description : Parallel port driver
State : Stopped

Name : partmgr
Path : C:\Windows\system32\drivers\partmgr.sys
Service Type : Kernel Driver
Description : Partition driver
State : Running

Name : pci
Path : C:\Windows\system32\drivers\pci.sys
Service Type : Kernel Driver
Description : PCI Bus Driver
State : Running

Name : pciide
Path : C:\Windows\system32\drivers\pciide.sys
Service Type : Kernel Driver
Description : pciide
State : Stopped

Name : pcmcia
Path : C:\Windows\system32\drivers\pcmcia.sys
Service Type : Kernel Driver
Description : pcmcia
State : Stopped

Name : pcw
Path : C:\Windows\system32\drivers\pcw.sys
Service Type : Kernel Driver
Description : Performance Counters for Windows Driver
State : Running

Name : pdc
Path : C:\Windows\system32\drivers\pdc.sys
Service Type : Kernel Driver
Description : pdc
State : Running

Name : PEAUTH
Path : C:\Windows\system32\drivers\peauth.sys
Service Type : Kernel Driver
Description : PEAUTH
State : Running

Name : percsas2i
Path : C:\Windows\system32\drivers\percsas2i.sys
Service Type : Kernel Driver
Description : percsas2i
State : Stopped

Name : percsas3i
Path : C:\Windows\system32\drivers\percsas3i.sys
Service Type : Kernel Driver
Description : percsas3i
State : Stopped

Name : PktMon
Path : C:\Windows\system32\drivers\PktMon.sys
Service Type : Kernel Driver
Description : Packet Monitor Driver
State : Stopped

Name : pmem
Path : C:\Windows\system32\drivers\pmem.sys
Service Type : Kernel Driver
Description : Microsoft persistent memory disk driver
State : Stopped

Name : PNPMEM
Path : C:\Windows\system32\drivers\pnpmem.sys
Service Type : Kernel Driver
Description : Microsoft Memory Module Driver
State : Stopped

Name : PptpMiniport
Path : C:\Windows\system32\drivers\raspptp.sys
Service Type : Kernel Driver
Description : WAN Miniport (PPTP)
State : Running

Name : Processor
Path : C:\Windows\system32\drivers\processr.sys
Service Type : Kernel Driver
Description : Processor Driver
State : Stopped

Name : Psched
Path : C:\Windows\system32\drivers\pacer.sys
Service Type : Kernel Driver
Description : QoS Packet Scheduler
State : Running

Name : qebdrv
Path : C:\Windows\system32\drivers\qevbda.sys
Service Type : Kernel Driver
Description : QLogic FastLinQ Ethernet VBD
State : Stopped

Name : qefcoe
Path : C:\Windows\system32\drivers\qefcoe.sys
Service Type : Kernel Driver
Description : QLogic FCoE driver
State : Stopped

Name : qeois
Path : C:\Windows\system32\drivers\qeois.sys
Service Type : Kernel Driver
Description : QLogic 40G iSCSI Driver
State : Stopped

Name : ql2300i
Path : C:\Windows\system32\drivers\ql2300i.sys
Service Type : Kernel Driver
Description : QLogic Fibre Channel STOR Miniport Inbox Driver (wx64)
State : Stopped

Name : ql40xx2i
Path : C:\Windows\system32\drivers\ql40xx2i.sys
Service Type : Kernel Driver
Description : QLogic iSCSI Miniport Inbox Driver
State : Stopped

Name : qlfcoei
Path : C:\Windows\system32\drivers\qlfcoei.sys
Service Type : Kernel Driver
Description : QLogic [FCoE] STOR Miniport Inbox Driver (wx64)
State : Stopped

Name : QWAVEdrv
Path : C:\Windows\system32\drivers\qwavedrv.sys
Service Type : Kernel Driver
Description : QWAVE driver
State : Stopped

Name : Ramdisk
Path : C:\Windows\system32\DRIVERS\ramdisk.sys
Service Type : Kernel Driver
Description : Windows RAM Disk Driver
State : Stopped

Name : RasAcd
Path : C:\Windows\system32\DRIVERS\rasacd.sys
Service Type : Kernel Driver
Description : Remote Access Auto Connection Driver
State : Stopped

Name : RasAgileVpn
Path : C:\Windows\system32\drivers\AgileVpn.sys
Service Type : Kernel Driver
Description : WAN Miniport (IKEv2)
State : Running

Name : RasGre
Path : C:\Windows\system32\drivers\rasgre.sys
Service Type : Kernel Driver
Description : WAN Miniport (GRE)
State : Running

Name : Rasl2tp
Path : C:\Windows\system32\drivers\rasl2tp.sys
Service Type : Kernel Driver
Description : WAN Miniport (L2TP)
State : Running

Name : RasPppoe
Path : C:\Windows\system32\DRIVERS\raspppoe.sys
Service Type : Kernel Driver
Description : Remote Access PPPOE Driver
State : Running

Name : RasSstp
Path : C:\Windows\system32\drivers\rassstp.sys
Service Type : Kernel Driver
Description : WAN Miniport (SSTP)
State : Running

Name : rdbss
Path : C:\Windows\system32\DRIVERS\rdbss.sys
Service Type : File System Driver
Description : Redirected Buffering Sub System
State : Running

Name : rdpbus
Path : C:\Windows\system32\drivers\rdpbus.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Bus Driver
State : Running

Name : RDPDR
Path : C:\Windows\system32\drivers\rdpdr.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Driver
State : Running

Name : RdpVideoMiniport
Path : C:\Windows\system32\drivers\rdpvideominiport.sys
Service Type : Kernel Driver
Description : Remote Desktop Video Miniport Driver
State : Running

Name : ReFS
Path : C:\Windows\system32\drivers\ReFS.sys
Service Type : File System Driver
Description : ReFS
State : Stopped

Name : ReFSv1
Path : C:\Windows\system32\drivers\ReFSv1.sys
Service Type : File System Driver
Description : ReFSv1
State : Stopped

Name : RFCOMM
Path : C:\Windows\system32\drivers\rfcomm.sys
Service Type : Kernel Driver
Description : Bluetooth Device (RFCOMM Protocol TDI)
State : Stopped

Name : rhproxy
Path : C:\Windows\system32\drivers\rhproxy.sys
Service Type : Kernel Driver
Description : Resource Hub proxy driver
State : Stopped

Name : RsFx0600
Path : C:\Windows\system32\DRIVERS\RsFx0600.sys
Service Type : File System Driver
Description : RsFx0600 Driver
State : Stopped

Name : rspndr
Path : C:\Windows\system32\drivers\rspndr.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Responder
State : Running

Name : s3cap
Path : C:\Windows\system32\drivers\vms3cap.sys
Service Type : Kernel Driver
Description : s3cap
State : Stopped

Name : sacdrv
Path : C:\Windows\system32\DRIVERS\sacdrv.sys
Service Type : Kernel Driver
Description : sacdrv
State : Stopped

Name : sbp2port
Path : C:\Windows\system32\drivers\sbp2port.sys
Service Type : Kernel Driver
Description : SBP-2 Transport/Protocol Bus Driver
State : Stopped

Name : scfilter
Path : C:\Windows\system32\DRIVERS\scfilter.sys
Service Type : Kernel Driver
Description : Smart card PnP Class Filter Driver
State : Stopped

Name : scmbus
Path : C:\Windows\system32\drivers\scmbus.sys
Service Type : Kernel Driver
Description : Microsoft Storage Class Memory Bus Driver
State : Stopped

Name : sdbus
Path : C:\Windows\system32\drivers\sdbus.sys
Service Type : Kernel Driver
Description : sdbus
State : Stopped

Name : SDFRd
Path : C:\Windows\system32\drivers\SDFRd.sys
Service Type : Kernel Driver
Description : SDF Reflector
State : Stopped

Name : sdstor
Path : C:\Windows\system32\drivers\sdstor.sys
Service Type : Kernel Driver
Description : SD Storage Port Driver
State : Stopped

Name : SerCx
Path : C:\Windows\system32\drivers\SerCx.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : SerCx2
Path : C:\Windows\system32\drivers\SerCx2.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : Serenum
Path : C:\Windows\system32\drivers\serenum.sys
Service Type : Kernel Driver
Description : Serenum Filter Driver
State : Stopped

Name : Serial
Path : C:\Windows\system32\drivers\serial.sys
Service Type : Kernel Driver
Description : Serial port driver
State : Stopped

Name : sermouse
Path : C:\Windows\system32\drivers\sermouse.sys
Service Type : Kernel Driver
Description : Serial Mouse Driver
State : Stopped

Name : sfloppy
Path : C:\Windows\system32\drivers\sfloppy.sys
Service Type : Kernel Driver
Description : High-Capacity Floppy Disk Drive
State : Stopped

Name : SgrmAgent
Path : C:\Windows\system32\drivers\SgrmAgent.sys
Service Type : Kernel Driver
Description : System Guard Runtime Monitor Agent
State : Running

Name : SiSRaid2
Path : C:\Windows\system32\drivers\SiSRaid2.sys
Service Type : Kernel Driver
Description : SiSRaid2
State : Stopped

Name : SiSRaid4
Path : C:\Windows\system32\drivers\sisraid4.sys
Service Type : Kernel Driver
Description : SiSRaid4
State : Stopped

Name : SmartSAMD
Path : C:\Windows\system32\drivers\SmartSAMD.sys
Service Type : Kernel Driver
Description : SmartSAMD
State : Stopped

Name : smbdirect
Path : C:\Windows\system32\DRIVERS\smbdirect.sys
Service Type : File System Driver
Description : smbdirect
State : Stopped

Name : snapman
Path : C:\Windows\system32\DRIVERS\snapman.sys
Service Type : Kernel Driver
Description : Acronis Snapshots Manager
State : Running

Name : spaceport
Path : C:\Windows\system32\drivers\spaceport.sys
Service Type : Kernel Driver
Description : Storage Spaces Driver
State : Running

Name : SpbCx
Path : C:\Windows\system32\drivers\SpbCx.sys
Service Type : Kernel Driver
Description : Simple Peripheral Bus Support Library
State : Stopped

Name : srv2
Path : C:\Windows\system32\DRIVERS\srv2.sys
Service Type : File System Driver
Description : Server SMB 2.xxx Driver
State : Running

Name : srvnet
Path : C:\Windows\system32\DRIVERS\srvnet.sys
Service Type : File System Driver
Description : srvnet
State : Running

Name : stexstor
Path : C:\Windows\system32\drivers\stexstor.sys
Service Type : Kernel Driver
Description : stexstor
State : Stopped

Name : storahci
Path : C:\Windows\system32\drivers\storahci.sys
Service Type : Kernel Driver
Description : Microsoft Standard SATA AHCI Driver
State : Stopped

Name : storflt
Path : C:\Windows\system32\drivers\vmstorfl.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Storage Accelerator
State : Stopped

Name : stornvme
Path : C:\Windows\system32\drivers\stornvme.sys
Service Type : Kernel Driver
Description : Microsoft Standard NVM Express Driver
State : Stopped

Name : storqosflt
Path : C:\Windows\system32\drivers\storqosflt.sys
Service Type : File System Driver
Description : Storage QoS Filter Driver
State : Running

Name : storufs
Path : C:\Windows\system32\drivers\storufs.sys
Service Type : Kernel Driver
Description : Microsoft Universal Flash Storage (UFS) Driver
State : Stopped

Name : storvsc
Path : C:\Windows\system32\drivers\storvsc.sys
Service Type : Kernel Driver
Description : storvsc
State : Stopped

Name : swenum
Path : C:\Windows\system32\DriverStore\FileRepository\swenum.inf_amd64_31f554b660026323\swenum.sys
Service Type : Kernel Driver
Description : Software Bus Driver
State : Running

Name : Synth3dVsc
Path : C:\Windows\system32\drivers\Synth3dVsc.sys
Service Type : Kernel Driver
Description : Synth3dVsc
State : Stopped

Name : system_monitor
Path : C:\Windows\system32\DRIVERS\system_monitor.sys
Service Type : Kernel Driver
Description : system_monitor
State : Running

Name : Tcpip
Path : C:\Windows\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : TCP/IP Protocol Driver
State : Running

Name : Tcpip6
Path : C:\Windows\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : @todo.dll,-100;Microsoft IPv6 Protocol Driver
State : Stopped

Name : tcpipreg
Path : C:\Windows\system32\drivers\tcpipreg.sys
Service Type : Kernel Driver
Description : TCP/IP Registry Compatibility
State : Running

Name : tdx
Path : C:\Windows\system32\DRIVERS\tdx.sys
Service Type : Kernel Driver
Description : NetIO Legacy TDI Support Driver
State : Running

Name : terminpt
Path : C:\Windows\system32\drivers\terminpt.sys
Service Type : Kernel Driver
Description : Microsoft Remote Desktop Input Driver
State : Running

Name : tib_mounter
Path : C:\Windows\system32\DRIVERS\tib_mounter.sys
Service Type : Kernel Driver
Description : Acronis TIB Mounter
State : Running

Name : TPM
Path : C:\Windows\system32\drivers\tpm.sys
Service Type : Kernel Driver
Description : TPM
State : Stopped

Name : TsUsbFlt
Path : C:\Windows\system32\drivers\tsusbflt.sys
Service Type : Kernel Driver
Description : Remote Desktop USB Hub Class Filter Driver
State : Stopped

Name : TsUsbGD
Path : C:\Windows\system32\drivers\TsUsbGD.sys
Service Type : Kernel Driver
Description : Remote Desktop Generic USB Device
State : Stopped

Name : tsusbhub
Path : C:\Windows\system32\drivers\tsusbhub.sys
Service Type : Kernel Driver
Description : Remote Desktop USB Hub
State : Stopped

Name : tunnel
Path : C:\Windows\system32\drivers\tunnel.sys
Service Type : Kernel Driver
Description : Microsoft Tunnel Miniport Adapter Driver
State : Stopped

Name : UASPStor
Path : C:\Windows\system32\drivers\uaspstor.sys
Service Type : Kernel Driver
Description : USB Attached SCSI (UAS) Driver
State : Stopped

Name : UcmCx0101
Path : C:\Windows\system32\Drivers\UcmCx.sys
Service Type : Kernel Driver
Description : USB Connector Manager KMDF Class Extension
State : Stopped

Name : UcmTcpciCx0101
Path : C:\Windows\system32\Drivers\UcmTcpciCx.sys
Service Type : Kernel Driver
Description : UCM-TCPCI KMDF Class Extension
State : Stopped

Name : UcmUcsi
Path : C:\Windows\system32\drivers\UcmUcsi.sys
Service Type : Kernel Driver
Description : USB Connector Manager UCSI Client
State : Stopped

Name : UcmUcsiAcpiClient
Path : C:\Windows\system32\drivers\UcmUcsiAcpiClient.sys
Service Type : Kernel Driver
Description : UCM-UCSI ACPI Client
State : Stopped

Name : UcmUcsiCx0101
Path : C:\Windows\system32\Drivers\UcmUcsiCx.sys
Service Type : Kernel Driver
Description : UCM-UCSI KMDF Class Extension
State : Stopped

Name : Ucx01000
Path : C:\Windows\system32\drivers\ucx01000.sys
Service Type : Kernel Driver
Description : USB Host Support Library
State : Stopped

Name : UdeCx
Path : C:\Windows\system32\drivers\udecx.sys
Service Type : Kernel Driver
Description : USB Device Emulation Support Library
State : Stopped

Name : udfs
Path : C:\Windows\system32\DRIVERS\udfs.sys
Service Type : File System Driver
Description : udfs
State : Stopped

Name : UEFI
Path : C:\Windows\system32\drivers\UEFI.sys
Service Type : Kernel Driver
Description : Microsoft UEFI Driver
State : Stopped

Name : UevAgentDriver
Path : C:\Windows\system32\drivers\UevAgentDriver.sys
Service Type : File System Driver
Description : UevAgentDriver
State : Stopped

Name : Ufx01000
Path : C:\Windows\system32\drivers\ufx01000.sys
Service Type : Kernel Driver
Description : USB Function Class Extension
State : Stopped

Name : UfxChipidea
Path : C:\Windows\system32\drivers\UfxChipidea.sys
Service Type : Kernel Driver
Description : USB Chipidea Controller
State : Stopped

Name : ufxsynopsys
Path : C:\Windows\system32\drivers\ufxsynopsys.sys
Service Type : Kernel Driver
Description : USB Synopsys Controller
State : Stopped

Name : umbus
Path : C:\Windows\system32\drivers\umbus.sys
Service Type : Kernel Driver
Description : UMBus Enumerator Driver
State : Running

Name : UmPass
Path : C:\Windows\system32\drivers\umpass.sys
Service Type : Kernel Driver
Description : Microsoft UMPass Driver
State : Stopped

Name : UrsChipidea
Path : C:\Windows\system32\drivers\urschipidea.sys
Service Type : Kernel Driver
Description : Chipidea USB Role-Switch Driver
State : Stopped

Name : UrsCx01000
Path : C:\Windows\system32\drivers\urscx01000.sys
Service Type : Kernel Driver
Description : USB Role-Switch Support Library
State : Stopped

Name : UrsSynopsys
Path : C:\Windows\system32\drivers\urssynopsys.sys
Service Type : Kernel Driver
Description : Synopsys USB Role-Switch Driver
State : Stopped

Name : usbccgp
Path : C:\Windows\system32\drivers\usbccgp.sys
Service Type : Kernel Driver
Description : Microsoft USB Generic Parent Driver
State : Stopped

Name : usbehci
Path : C:\Windows\system32\drivers\usbehci.sys
Service Type : Kernel Driver
Description : Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
State : Stopped

Name : usbhub
Path : C:\Windows\system32\drivers\usbhub.sys
Service Type : Kernel Driver
Description : Microsoft USB Standard Hub Driver
State : Stopped

Name : USBHUB3
Path : C:\Windows\system32\drivers\UsbHub3.sys
Service Type : Kernel Driver
Description : SuperSpeed Hub
State : Stopped

Name : usbohci
Path : C:\Windows\system32\drivers\usbohci.sys
Service Type : Kernel Driver
Description : Microsoft USB Open Host Controller Miniport Driver
State : Stopped

Name : usbprint
Path : C:\Windows\system32\drivers\usbprint.sys
Service Type : Kernel Driver
Description : Microsoft USB PRINTER Class
State : Stopped

Name : usbser
Path : C:\Windows\system32\drivers\usbser.sys
Service Type : Kernel Driver
Description : Microsoft USB Serial Driver
State : Stopped

Name : USBSTOR
Path : C:\Windows\system32\drivers\USBSTOR.SYS
Service Type : Kernel Driver
Description : USB Mass Storage Driver
State : Stopped

Name : usbuhci
Path : C:\Windows\system32\drivers\usbuhci.sys
Service Type : Kernel Driver
Description : Microsoft USB Universal Host Controller Miniport Driver
State : Stopped

Name : USBXHCI
Path : C:\Windows\system32\drivers\USBXHCI.SYS
Service Type : Kernel Driver
Description : USB xHCI Compliant Host Controller
State : Stopped

Name : vdrvroot
Path : C:\Windows\system32\drivers\vdrvroot.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Drive Enumerator
State : Running

Name : VerifierExt
Path : C:\Windows\system32\drivers\VerifierExt.sys
Service Type : Kernel Driver
Description : Driver Verifier Extension
State : Stopped

Name : vhdmp
Path : C:\Windows\system32\drivers\vhdmp.sys
Service Type : Kernel Driver
Description : vhdmp
State : Stopped

Name : vhf
Path : C:\Windows\system32\drivers\vhf.sys
Service Type : Kernel Driver
Description : Virtual HID Framework (VHF) Driver
State : Stopped

Name : vm3dmp
Path : C:\Windows\system32\DRIVERS\vm3dmp.sys
Service Type : Kernel Driver
Description : vm3dmp
State : Running

Name : vm3dmp-debug
Path : C:\Windows\system32\DRIVERS\vm3dmp-debug.sys
Service Type : Kernel Driver
Description : vm3dmp-debug
State : Stopped

Name : vm3dmp-stats
Path : C:\Windows\system32\DRIVERS\vm3dmp-stats.sys
Service Type : Kernel Driver
Description : vm3dmp-stats
State : Stopped

Name : vm3dmp_loader
Path : C:\Windows\system32\DRIVERS\vm3dmp_loader.sys
Service Type : Kernel Driver
Description : vm3dmp_loader
State : Running

Name : vmbus
Path : C:\Windows\system32\drivers\vmbus.sys
Service Type : Kernel Driver
Description : Virtual Machine Bus
State : Stopped

Name : VMBusHID
Path : C:\Windows\system32\drivers\VMBusHID.sys
Service Type : Kernel Driver
Description : VMBusHID
State : Stopped

Name : vmci
Path : C:\Windows\system32\drivers\vmci.sys
Service Type : Kernel Driver
Description : VMware VMCI Bus Driver
State : Running

Name : vmgid
Path : C:\Windows\system32\drivers\vmgid.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Guest Infrastructure Driver
State : Stopped

Name : VMMemCtl
Path : C:\Windows\system32\DRIVERS\vmmemctl.sys
Service Type : Kernel Driver
Description : Memory Control Driver
State : Running

Name : vmmouse
Path : C:\Windows\system32\drivers\vmmouse.sys
Service Type : Kernel Driver
Description : VMware Pointing Device
State : Running

Name : volmgr
Path : C:\Windows\system32\drivers\volmgr.sys
Service Type : Kernel Driver
Description : Volume Manager Driver
State : Running

Name : volmgrx
Path : C:\Windows\system32\drivers\volmgrx.sys
Service Type : Kernel Driver
Description : Dynamic Volume Manager
State : Running

Name : volsnap
Path : C:\Windows\system32\drivers\volsnap.sys
Service Type : Kernel Driver
Description : Volume Shadow Copy driver
State : Running

Name : volume
Path : C:\Windows\system32\drivers\volume.sys
Service Type : Kernel Driver
Description : Volume driver
State : Running

Name : volume_tracker
Path : C:\Windows\system32\DRIVERS\volume_tracker.sys
Service Type : Kernel Driver
Description : Acronis Volume Tracker
State : Running

Name : vpci
Path : C:\Windows\system32\drivers\vpci.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Virtual PCI Bus
State : Stopped

Name : vsmraid
Path : C:\Windows\system32\drivers\vsmraid.sys
Service Type : Kernel Driver
Description : vsmraid
State : Stopped

Name : vsock
Path : C:\Windows\system32\DRIVERS\vsock.sys
Service Type : Kernel Driver
Description : vSockets Virtual Machine Communication Interface Sockets driver
State : Running

Name : VSTXRAID
Path : C:\Windows\system32\drivers\vstxraid.sys
Service Type : Kernel Driver
Description : VIA StorX Storage RAID Controller Windows Driver
State : Stopped

Name : WacomPen
Path : C:\Windows\system32\drivers\wacompen.sys
Service Type : Kernel Driver
Description : Wacom Serial Pen HID Driver
State : Stopped

Name : wanarp
Path : C:\Windows\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IP ARP Driver
State : Running

Name : wanarpv6
Path : C:\Windows\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IPv6 ARP Driver
State : Stopped

Name : wcifs
Path : C:\Windows\system32\drivers\wcifs.sys
Service Type : File System Driver
Description : Windows Container Isolation
State : Running

Name : wcnfs
Path : C:\Windows\system32\drivers\wcnfs.sys
Service Type : File System Driver
Description : Windows Container Name Virtualization
State : Stopped

Name : Wdf01000
Path : C:\Windows\system32\drivers\Wdf01000.sys
Service Type : Kernel Driver
Description : Kernel Mode Driver Frameworks service
State : Running

Name : WdmCompanionFilter
Path : C:\Windows\system32\drivers\WdmCompanionFilter.sys
Service Type : Kernel Driver
Description : WdmCompanionFilter
State : Stopped

Name : WFPLWFS
Path : C:\Windows\system32\drivers\wfplwfs.sys
Service Type : Kernel Driver
Description : Microsoft Windows Filtering Platform
State : Running

Name : WIMMount
Path : C:\Windows\system32\drivers\wimmount.sys
Service Type : File System Driver
Description : WIMMount
State : Stopped

Name : WindowsTrustedRT
Path : C:\Windows\system32\drivers\WindowsTrustedRT.sys
Service Type : Kernel Driver
Description : Windows Trusted Execution Environment Class Extension
State : Running

Name : WindowsTrustedRTProxy
Path : C:\Windows\system32\drivers\WindowsTrustedRTProxy.sys
Service Type : Kernel Driver
Description : Microsoft Windows Trusted Runtime Secure Service
State : Running

Name : WinMad
Path : C:\Windows\system32\drivers\winmad.sys
Service Type : Kernel Driver
Description : WinMad Service
State : Stopped

Name : WinNat
Path : C:\Windows\system32\drivers\winnat.sys
Service Type : Kernel Driver
Description : Windows NAT Driver
State : Stopped

Name : WinQuic
Path : C:\Windows\system32\drivers\winquic.sys
Service Type : Kernel Driver
Description : WinQuic
State : Running

Name : WINUSB
Path : C:\Windows\system32\drivers\WinUSB.SYS
Service Type : Kernel Driver
Description : WinUsb Driver
State : Stopped

Name : WinVerbs
Path : C:\Windows\system32\drivers\winverbs.sys
Service Type : Kernel Driver
Description : WinVerbs Service
State : Stopped

Name : WmiAcpi
Path : C:\Windows\system32\drivers\wmiacpi.sys
Service Type : Kernel Driver
Description : Microsoft Windows Management Interface for ACPI
State : Stopped

Name : Wof
Path : C:\Windows\system32\drivers\Wof.sys
Service Type : File System Driver
Description : Windows Overlay File System Filter Driver
State : Running

Name : WpdUpFltr
Path : C:\Windows\system32\drivers\WpdUpFltr.sys
Service Type : Kernel Driver
Description : WPD Upper Class Filter Driver
State : Running

Name : ws2ifsl
Path : C:\Windows\system32\drivers\ws2ifsl.sys
Service Type : Kernel Driver
Description : Windows Socket 2.0 Non-IFS Service Provider Support Environment
State : Running

Name : WudfPf
Path : C:\Windows\system32\drivers\WudfPf.sys
Service Type : Kernel Driver
Description : User Mode Driver Frameworks Platform Driver
State : Stopped

Name : WUDFRd
Path : C:\Windows\system32\drivers\WUDFRd.sys
Service Type : Kernel Driver
Description : Windows Driver Foundation - User-mode Driver Framework Reflector
State : Running

Name : WUDFWpdFs
Path : C:\Windows\system32\DRIVERS\WUDFRd.sys
Service Type : Kernel Driver
Description : WPD File System driver
State : Running
Compliance 'FAILED'
Compliance 'SKIPPED'
Compliance 'PASSED'
Compliance 'INFO', 'WARNING', 'ERROR'
Remediations
Suggested Remediations
Taking the following actions across 6 hosts would resolve 11% of the vulnerabilities on the network.
Action to take Vulns Hosts
Security Updates for Microsoft SQL Server (November 2025): Microsoft has released security updates for Microsoft SQL Server. 306 3
Install KB5071544 270 5
Security Updates for Microsoft Visual Studio Products (July 2025): Microsoft has released the following security updates to address this issue: - Update 17.14.8 for Visual Studio 2022 - Update 17.12.10 for Visual Studio 2022 - Update 17.10.17 for Visual Studio 2022 - Update 17.8.23 for Visual Studio 2022 - Update 16.11.49 for Visual Studio 2019 - Update 15.9.75 for Visual Studio 2017 172 1
Security Updates for Microsoft .NET Framework (January 2025): Microsoft has released security updates for Microsoft .NET Framework. 152 4
Security Updates for Microsoft SQL Server OLE DB Driver (July 2024): Microsoft has released security updates for the Microsoft SQL OLE DB Driver. 78 3
Oracle Java SE Multiple Vulnerabilities (October 2025 CPU): Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory. 74 1
Security Update for Microsoft .NET Core (October 2025): Update .NET Core, remove vulnerable packages and refer to vendor advisory. 38 1
Security Updates for Microsoft Office Products (March 2021): Microsoft has released the following security updates to address this issue: -KB4493228 -KB4493203 -KB4504703 -KB4493225 -KB4493200 -KB4493214 35 1
Node.js 18.x < 18.20.6 / 20.x < 20.18.2 / 22.x < 22.13.1 / 23.x < 23.6.1 Multiple Vulnerabilities (Tuesday, January 21, 2025 Security Releases).: Upgrade to Node.js version 18.20.6 / 20.18.2 / 22.13.1 / 23.6.1 or later. 28 1
VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015): Upgrade to VMware Tools version 12.5.4, 13.0.5 or later. 25 5
Security Updates for Microsoft SQL Server ODBC Driver (April 2024): Microsoft has released security updates for the Microsoft SQL Driver. 23 1
Security Updates for Microsoft .NET Core (December 2022): Update .NET Core Runtime to version 3.1.32 or 6.0.12 or 7.0.1. 16 1
RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088): Upgrade to RARLAB WinRAR version 7.13 or later. 15 5
Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144): Upgrade to Notepad++ 8.8.2 or later. 12 2
Security Update for Microsoft Visual Studio Code (November 2025): Update to Microsoft Visual Studio Code 1.105.1 or later. 11 1
MS09-035: Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706): Microsoft has released a set of patches for Visual Studio .NET 2003, Visual Studio 2005 and 2008, as well as Visual C++ 2005 and 2008. 9 3
Security Update for Microsoft ASP.NET Core (February 2024) (CVE-2024-21386): Update .NET Core, remove vulnerable packages and refer to vendor advisory. 8 1
Microsoft ASP.NET Core Security Feature Bypass (October 2025): Update .NET Core to version 8.0.21, 9.0.10, 10.0.0-rc.2.25502.107 or later. 4 1
MS13-074: Vulnerabilities in Microsoft Access Could Allow Remote Code Execution (2848637): Microsoft has released a set of patches for Microsoft Office 2007, 2010, and 2013. 3 1
Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803): Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later. 3 3
VMware Tools 10.x / 11.x / 12.x < 12.1.5 DoS (VMSA-2022-0029): Upgrade to VMware Tools version 12.1.5 or later. 2 1
Microsoft Teams for Desktop < 25122.1415.3698.6812 Remote Code Execution (August 2025): Upgrade to Microsoft Teams for Desktop version 25122.1415.3698.6812 or later via the Microsoft Store. 2 1
Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104): Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life. Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions. 2 2
Curl Use-After-Free < 7.87 (CVE-2022-43552): Upgrade Curl to version 7.87.0 or later 2 2
Adobe Flash Player <= 32.0.0.433 (APSB20-58): Upgrade to Adobe Flash Player version 32.0.0.445 or later. 1 1
KB4580325: Security update for Adobe Flash Player (October 2020): Microsoft has released KB4580325 to address this issue. 1 1
MS12-021: Vulnerability in Visual Studio Could Allow Elevation of Privilege (2651019): Microsoft has released a set of patches for Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1. 1 1
Security Updates for Windows Malicious Software Removal Tool (January 2023): Microsoft has released version 5.109 to address this issue. 1 1
Curl 7.84 <= 8.2.1 Header DoS (CVE-2023-38039): Upgrade Curl to version 8.3.0 or later 1 1
Node.js Module node-tar < 6.2.1 DoS: Upgrade to node-tar version 6.2.1 or later. 1 1
OpenSSL AES-NI Padding Oracle MitM Information Disclosure: Upgrade to OpenSSL version 1.0.1t / 1.0.2h or later. 1 1
Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203): Upgrade to Microsoft Azure Data Studio version 1.48.0 or later. 0 3
© 2026 Tenable™, Inc. All rights reserved.