Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-1155 | 4.025 | SV-29599r1_rule | ECLP-1 | High |
Description |
---|
This is a Category 1 finding because allowing network logins by the built-in guest accounts, which are a member of the Everyone group and Guests group, with all the rights and permissions associated with that group, could provide anonymous access to system resources to unauthorized users. Anonymous Logon and Support_388945a0 are also included in applicable Windows versions. |
STIG | Date |
---|---|
Windows 2008 Domain Controller Security Technical Implementation Guide | 2012-06-29 |
Check Text ( C-421r1_chk ) |
---|
Analyze the system using the Security Configuration and Analysis snap-in. Expand the Security Configuration and Analysis tree view. Navigate to Local Policies -> User Rights Administration. If the following groups/accounts are not listed under the right "Deny access to this computer from the network", then this is a finding. Windows 2000 - Guests Windows 2003 - Guests, Anonymous Logon, Support_388945a0 Windows XP - Guests, Support_388945a0 Vista - Guests Windows 2008 - Guests Note: If an account listed has been deleted from the system such as the Support_388945a0 account, the Gold Disk may incorrectly report the account as a finding. If the account does not exist on a system it would not be a finding. Documentable Explanation: On Exchange Server 2003 supporting OWA, the Guests group should be removed and replaced with “Anonymous Logon”. Document with the IAO |
Fix Text (F-5770r1_fix) |
---|
Configure the system to give the right "Deny access to this computer from the network" to the Accounts/Groups specified in the manual check. |