Check: 3.087
Windows XP STIG:
3.087
(in versions v6 r1.32 through v1 r0)
Title
The system is configured to allow installation of printers using kernel-mode drivers. (Cat II impact)
Discussion
Kernel-mode drivers are drivers that operate in kernel mode. Kernel mode allows virtually unlimited access to hardware and memory. A poorly written kernel driver may cause system instability and data corruption. Malicious code inserted in a kernel-mode driver has almost no limit on what it may do. Most modern printers do not require kernel-mode drivers.
Check Content
The policy value for Computer Configuration -> Administrative Templates -> System -> Printers “Disallow Installation of Printers Using Kernel-mode Drivers” will be set to “Enabled”. If the following registry value doesn’t exist or its value is not set to 1, then this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Windows NT\Printers\ Value Name: KMPrintersAreBlocked Type: REG_DWORD Value: 1 Note: This setting will prevent some applications from installing PDF print drivers.
Fix Text
Configure the system to prevent it from allowing the installation of kernel-mode drivers by setting the policy value for Computer Configuration -> Administrative Templates -> Printers “Disallow Installation of Printers Using Kernel-mode Drivers” to “Enabled”.
Additional Identifiers
Rule ID: SV-3478r1_rule
Vulnerability ID: V-3478
Group Title: Printers - Disallow Installation of Drivers
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |