Check: 3.027
windows 7 iavm:
3.027
(in version v1 r32)
Title
Printer share permissions must be restricted to Print for non administrators. (Cat III impact)
Discussion
Improperly configured share permissions on printers can permit the addition of unauthorized print devices on the network. Windows shares are a means by which files, folders, printers, and other resources can be published for network users to remotely access.
Check Content
Open "Devices and Printers" in Control Panel. If there are no locally attached printers, this is NA. Perform this check for each locally attached printer: Right-click on a locally attached printer. Select "Printer Properties". Select the "Sharing" tab. View whether "Share this printer" is checked. Perform this check on each printer that has the "Share this printer" selected: Select the Security tab. If any non-administrative user accounts or groups have greater than "Print", this is a finding.
Fix Text
Configure the permissions on locally shared printers to ensure non administrators only have "Print". Open "Devices and Printers" in Control Panel. Right-click on a locally attached printer. Select "Printer Properties". Select the "Sharing" tab. For each printer that has the "Share this printer" selected: Select the Security tab. Assign any non-administrative user accounts or groups "Print" permission only.
Additional Identifiers
Rule ID:
Vulnerability ID: V-1135
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000213 |
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
Controls
Number | Title |
---|---|
AC-3 |
Access Enforcement |