Check: EMG2-863 Exch2K3
Microsoft Exchange Server 2003:
EMG2-863 Exch2K3
(in version v1 r5)
Title
Mailbox access control mechanisms are not audited for changes. (Cat II impact)
Discussion
Unauthorized or malicious data changes can compromise the integrity and usefulness of the data, Automated attacks or malicious users with elevated privileges have the ability to affect change using the same mechanisms as E-mail administrators. Auditing changes to access mechanisms supports accountability and non-repudiation for those authorized to define the environment but also enables investigation of changes made by others who may not be authorized.
Check Content
Exchange System Manager >> Administrative Groups >> [administrative group] >> Servers >> [server] >> [storage group] >> Mailbox Store >> Properties >> Security tab >> Advanced button >> Audit tab All listed items must be selected for “change permissions”, “take ownership”, “add/remove self”, and “write properties”. Criteria: If all items are selected for “change permissions”, “take ownership”, “add/remove self”, and “write properties”, this is not a finding.
Fix Text
Ensure that access control mechanisms are audited. Procedure: Exchange System Manager >> Administrative Groups >> [administrative group] >> Servers >> [server] >> [storage group] >> Mailbox Store >> Properties >> Security tab >> Advanced button >> Audit tab Select “change permissions”, “take ownership”, “add/remove self”, and “write properties”.
Additional Identifiers
Rule ID: SV-21025r1_rule
Vulnerability ID: V-19186
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |