{"id":19369,"date":"2023-04-24T12:39:15","date_gmt":"2023-04-24T16:39:15","guid":{"rendered":"https:\/\/kevinjustin.com\/blog\/?p=19369"},"modified":"2023-04-24T12:39:15","modified_gmt":"2023-04-24T16:39:15","slug":"resolve-hsts-vulnerability-cves-on-iis10","status":"publish","type":"post","link":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/","title":{"rendered":"Resolve HSTS vulnerability CVEs on IIS10"},"content":{"rendered":"<figure id=\"attachment_19370\" aria-describedby=\"caption-attachment-19370\" style=\"width: 1004px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19370\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500.png\" alt=\"\" width=\"1004\" height=\"308\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500.png 1004w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500-300x92.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500-768x236.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><figcaption id=\"caption-attachment-19370\" class=\"wp-caption-text\">IIS Error 500 &#8211; Don&#8217;t let a vulnerability cause downtime with your SCOM web console<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>This article will help resolve security HSTS vulnerability CVEs on IIS10.\u00a0 The steps apply to Windows Server 2016+, to help resolve multiple vulnerabilities, including CVE-2023-23915 CVE-2023-23914 CVE-2017-7789.\u00a0 \u00a0There are a few ways to configure IIS, and the blog post will show how to set up HTTP response, and HTTP redirect for the SCOM web console role&#8217;d server(s).<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Setting HSTS on IIS10 to resolve with Server2016 1609<\/strong><\/h2>\n<p>Open PowerShell window as Admin<br \/>\n<span style=\"color: #3366ff;\">cd c:\\windows\\winsxs<\/span><br \/>\n<span style=\"color: #3366ff;\">gci wow64_microsoft-windows-iis-shared* | ft Name<\/span><\/p>\n<p>Example aim for latest directory<br \/>\nNOTE bottom entry based on software versioning<\/p>\n<p>Example output<br \/>\nPS C:\\windows\\winsxs&gt; gci wow64_microsoft-windows-iis-shared* | ft Name<\/p>\n<p>Name<br \/>\n&#8212;-<br \/>\nwow64_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_10.0.14393.0_none_48b28891ffe5bdae<br \/>\nwow64_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_10.0.14393.1613_none_90c5a57843ef1621<br \/>\nwow64_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_10.0.14393.5246_none_90f3a94643cc33e1<\/p>\n<p><strong># AppCMD lines<\/strong><br \/>\n<span style=\"color: #3366ff;\">.\\appcmd.exe set config -section:system.applicationHost\/sites &#8220;\/[name=&#8217;Default Web Site&#8217;].hsts.enabled:True&#8221; \/commit:apphost<\/span><br \/>\n<span style=\"color: #3366ff;\">.\\appcmd.exe set config -section:system.applicationHost\/sites &#8220;\/[name=&#8217;Default Web Site&#8217;].hsts.max-age:31536000&#8221; \/commit:apphost<\/span><br \/>\n<span style=\"color: #3366ff;\">.\\appcmd.exe set config -section:system.applicationHost\/sites &#8220;\/[name=&#8217;Default Web Site&#8217;].hsts.includeSubDomains:True&#8221; \/commit:apphost<\/span><br \/>\n<span style=\"color: #3366ff;\">.\\appcmd.exe set config -section:system.applicationHost\/sites &#8220;\/[name=&#8217;Default Web Site&#8217;].hsts.redirectHttpToHttps:True&#8221; \/commit:apphost<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>For Server2016 1709 and greater<\/strong><\/h2>\n<p>To add the HSTS Header, follow the steps below:<\/p>\n<p>Open IIS manager.<br \/>\nSelect your site.<br \/>\nOpen HTTP Response Headers option.<br \/>\nClick on Add in the Actions section.<br \/>\nIn the Add Custom HTTP Response Header dialog, add the following values:<br \/>\nName: Strict-Transport-Security<br \/>\nValue: max-age=31536000; includeSubDomains; preload<br \/>\nOr directly in web.config as below under system.webServer:<\/p>\n<p>&lt;httpProtocol&gt;<br \/>\n&lt;customHeaders&gt;<br \/>\n&lt;add name=&#8221;Strict-Transport-Security&#8221; value=&#8221;max-age=31536000; includeSubDomains; preload&#8221; \/&gt;<br \/>\n&lt;\/customHeaders&gt;<br \/>\n&lt;\/httpProtocol&gt;<\/p>\n<p><span style=\"color: #ff0000;\">NOTE iisreset may be required to restart IIS and apply settings<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1><strong>Verify HTTP Response Headers<\/strong><\/h1>\n<p>From IIS10 (IIS Manager) &gt; click on &#8216;Default Web Site&#8217; &gt; HTTP Response Headers<\/p>\n<p>Verify Strict-Transport-Security blurb matches<\/p>\n<figure id=\"attachment_19372\" aria-describedby=\"caption-attachment-19372\" style=\"width: 738px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-ResponseHeaders.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19372\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-ResponseHeaders.png\" alt=\"\" width=\"738\" height=\"281\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-ResponseHeaders.png 738w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-ResponseHeaders-300x114.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-19372\" class=\"wp-caption-text\">HSTS IIS10 HTTP Response Headers screenshot verifying settings applied<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1><strong>Set HTTP Redirect<\/strong><\/h1>\n<p>Now to set the HTTP redirect, to prevent denial of service (DoS) attacks.<\/p>\n<p>From IIS10 (IIS Manager) &gt; Expand &#8216;Default Web Site&#8217; &gt; HTTP Redirect<\/p>\n<p>Screenshot<\/p>\n<figure id=\"attachment_19373\" aria-describedby=\"caption-attachment-19373\" style=\"width: 822px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-Redirect.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19373\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-Redirect.png\" alt=\"\" width=\"822\" height=\"460\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-Redirect.png 822w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-Redirect-300x168.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-Redirect-768x430.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-19373\" class=\"wp-caption-text\">Default Web Site HTTP Redirect to SCOM web console URL<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>From IIS10 (IIS Manager) &gt; Expand &#8216;Default Web Site&#8217; &gt;\u00a0go through each Application to set HTTP redirect<\/p>\n<p>Screenshot<\/p>\n<figure id=\"attachment_19375\" aria-describedby=\"caption-attachment-19375\" style=\"width: 829px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-Redirect-OtherApplications-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-19375 size-full\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-Redirect-OtherApplications-1.png\" alt=\"Set HSTS HTTP Redirect on other web applications\" width=\"829\" height=\"386\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-Redirect-OtherApplications-1.png 829w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-Redirect-OtherApplications-1-300x140.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/HSTS-HTTP-Redirect-OtherApplications-1-768x358.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-19375\" class=\"wp-caption-text\">Set HSTS HTTP Redirect on other web applications<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>Test your web console URL to verify components<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>References<\/strong><\/p>\n<p>NIST <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-23915\" target=\"_blank\" rel=\"noopener\">CVE-2023-23915<\/a> <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-23914\" target=\"_blank\" rel=\"noopener\">CVE-2023-23914<\/a><\/p>\n<p>Mitre <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-7789\">CVE-2017-7789<\/a><\/p>\n<p>Blog link <a href=\"https:\/\/inthetechpit.com\/2019\/07\/17\/add-strict-transport-security-hsts-response-header-to-iis-hosted-site\/\" target=\"_blank\" rel=\"noopener\">https:\/\/inthetechpit.com\/2019\/07\/17\/add-strict-transport-security-hsts-response-header-to-iis-hosted-site\/<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; This article will help resolve security HSTS vulnerability CVEs on IIS10.\u00a0 The steps apply to Windows Server 2016+, to help resolve multiple vulnerabilities, including CVE-2023-23915 CVE-2023-23914 CVE-2017-7789.\u00a0 \u00a0There are a few ways to configure IIS, and the blog post will show how to set up HTTP response, and HTTP redirect for the SCOM web &hellip; <a href=\"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Resolve HSTS vulnerability CVEs on IIS10&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,530,11],"tags":[616,615,614,613,611,610,349,497,617,601,364,505,560,612],"class_list":["post-19369","post","type-post","status-publish","format-standard","hentry","category-administration","category-scom","category-troubleshooting","tag-cve-2017-7789","tag-cve-2023-23914","tag-cve-2023-23915","tag-hsts","tag-iis","tag-iis10","tag-scom-2016","tag-scom-2019","tag-scom-2022","tag-scom-web-console","tag-scom2016","tag-scom2019","tag-scom2022","tag-windows-server"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Resolve HSTS vulnerability CVEs on IIS10 - Kevin Justin&#039;s Blog<\/title>\n<meta name=\"description\" content=\"Resolve HSTS vulnerabilities from IIS10 on Windows Server 2016+ CVE-2023-23915 CVE-2023-23914 CVE-2017-7789\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Resolve HSTS vulnerability CVEs on IIS10 - Kevin Justin&#039;s Blog\" \/>\n<meta property=\"og:description\" content=\"Resolve HSTS vulnerabilities from IIS10 on Windows Server 2016+ CVE-2023-23915 CVE-2023-23914 CVE-2017-7789\" \/>\n<meta property=\"og:url\" content=\"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/\" \/>\n<meta property=\"og:site_name\" content=\"Kevin Justin&#039;s Blog\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-24T16:39:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500.png\" \/>\n<meta name=\"author\" content=\"WordPress Administrator\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"WordPress Administrator\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/\"},\"author\":{\"name\":\"WordPress Administrator\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\"},\"headline\":\"Resolve HSTS vulnerability CVEs on IIS10\",\"datePublished\":\"2023-04-24T16:39:15+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/\"},\"wordCount\":480,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/IISError500.png\",\"keywords\":[\"CVE-2017-7789\",\"CVE-2023-23914\",\"CVE-2023-23915\",\"HSTS\",\"IIS\",\"IIS10\",\"scom 2016\",\"scom 2019\",\"scom 2022\",\"SCOM Web console\",\"scom2016\",\"scom2019\",\"SCOM2022\",\"WIndows Server\"],\"articleSection\":[\"Administration\",\"SCOM\",\"Troubleshooting\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/\",\"name\":\"Resolve HSTS vulnerability CVEs on IIS10 - Kevin Justin&#039;s Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/IISError500.png\",\"datePublished\":\"2023-04-24T16:39:15+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\"},\"description\":\"Resolve HSTS vulnerabilities from IIS10 on Windows Server 2016+ CVE-2023-23915 CVE-2023-23914 CVE-2017-7789\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/#primaryimage\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/IISError500.png\",\"contentUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/IISError500.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/04\\\/24\\\/resolve-hsts-vulnerability-cves-on-iis10\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Resolve HSTS vulnerability CVEs on IIS10\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/\",\"name\":\"Kevin Justin&#039;s Blog\",\"description\":\"Operational monitoring tools including System Center, Azure Monitor\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\",\"name\":\"WordPress Administrator\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"caption\":\"WordPress Administrator\"},\"sameAs\":[\"https:\\\/\\\/kevinjustin.com\"],\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/author\\\/wordpress_admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Resolve HSTS vulnerability CVEs on IIS10 - Kevin Justin&#039;s Blog","description":"Resolve HSTS vulnerabilities from IIS10 on Windows Server 2016+ CVE-2023-23915 CVE-2023-23914 CVE-2017-7789","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/","og_locale":"en_US","og_type":"article","og_title":"Resolve HSTS vulnerability CVEs on IIS10 - Kevin Justin&#039;s Blog","og_description":"Resolve HSTS vulnerabilities from IIS10 on Windows Server 2016+ CVE-2023-23915 CVE-2023-23914 CVE-2017-7789","og_url":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/","og_site_name":"Kevin Justin&#039;s Blog","article_published_time":"2023-04-24T16:39:15+00:00","og_image":[{"url":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500.png","type":"","width":"","height":""}],"author":"WordPress Administrator","twitter_card":"summary_large_image","twitter_misc":{"Written by":"WordPress Administrator","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/#article","isPartOf":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/"},"author":{"name":"WordPress Administrator","@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508"},"headline":"Resolve HSTS vulnerability CVEs on IIS10","datePublished":"2023-04-24T16:39:15+00:00","mainEntityOfPage":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/"},"wordCount":480,"commentCount":0,"image":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/#primaryimage"},"thumbnailUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500.png","keywords":["CVE-2017-7789","CVE-2023-23914","CVE-2023-23915","HSTS","IIS","IIS10","scom 2016","scom 2019","scom 2022","SCOM Web console","scom2016","scom2019","SCOM2022","WIndows Server"],"articleSection":["Administration","SCOM","Troubleshooting"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/","url":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/","name":"Resolve HSTS vulnerability CVEs on IIS10 - Kevin Justin&#039;s Blog","isPartOf":{"@id":"https:\/\/kevinjustin.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/#primaryimage"},"image":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/#primaryimage"},"thumbnailUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500.png","datePublished":"2023-04-24T16:39:15+00:00","author":{"@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508"},"description":"Resolve HSTS vulnerabilities from IIS10 on Windows Server 2016+ CVE-2023-23915 CVE-2023-23914 CVE-2017-7789","breadcrumb":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/#primaryimage","url":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500.png","contentUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/04\/IISError500.png"},{"@type":"BreadcrumbList","@id":"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/kevinjustin.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Resolve HSTS vulnerability CVEs on IIS10"}]},{"@type":"WebSite","@id":"https:\/\/kevinjustin.com\/blog\/#website","url":"https:\/\/kevinjustin.com\/blog\/","name":"Kevin Justin&#039;s Blog","description":"Operational monitoring tools including System Center, Azure Monitor","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/kevinjustin.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508","name":"WordPress Administrator","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","caption":"WordPress Administrator"},"sameAs":["https:\/\/kevinjustin.com"],"url":"https:\/\/kevinjustin.com\/blog\/author\/wordpress_admin\/"}]}},"_links":{"self":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/19369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/comments?post=19369"}],"version-history":[{"count":3,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/19369\/revisions"}],"predecessor-version":[{"id":19377,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/19369\/revisions\/19377"}],"wp:attachment":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/media?parent=19369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/categories?post=19369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/tags?post=19369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}