Check: 3.029
Win7 Audit:
3.029
(in version v1 r16)
Title
Print driver installation privilege is not restricted to administrators. (Cat III impact)
Discussion
By default, the print spooler allows any user to add and to delete printer drivers on the local system. This capability should be restricted to privileged groups to ensure only stable, non-malicious drivers are used.
Check Content
Fix Text
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> “Devices: Prevent users from installing printer drivers” to “Enabled”.
Additional Identifiers
Rule ID: SV-25035r1_rule
Vulnerability ID: V-1151
Group Title: Secure Print Driver Installation
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |