Details
The notListedIsapisAllowed attribute is a server-level setting that is located in the ApplicationHost.config file in the
Restricting this attribute to false will help prevent potentially malicious ISAPI extensions from being run.
Solution
To use IIS Manager to set the notListedIsapisAllowed attribute to false:
1. Open IIS Manager as Administrator
2. In the Connections pane on the left, select server to be configured
3. In Features View, select ISAPI and CGI Restrictions; in the Actions pane, select Open Feature
4. In the Actions pane, select Edit Feature Settings
5. In the Edit ISAPI and CGI Restrictions Settings dialog, clear the Allow unspecified ISAPI modules check box, if checked
6. Click OK
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system Windows.