STIGQter STIGQter: STIG Summary: Microsoft IIS 8.5 Server Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

All IIS 8.5 web server sample code, example applications, and tutorials must be removed from a production IIS 8.5 server.

DISA Rule

SV-214410r508658_rule

Vulnerability Number

V-214410

Group Title

SRG-APP-000141-WSR-000077

Rule Version

IISW-SV-000120

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Remove any executable sample code, example applications, or tutorials which are not explicitly used by a production website.

Check Contents

Navigate to the following folders:

inetpub\
Program Files\Common Files\System\msadc
Program Files (x86)\Common Files\System\msadc

If the folder or sub-folders contain any executable sample code, example applications, or tutorials which are not explicitly used by a production website, this is a finding.

Vulnerability Number

V-214410

Documentable

False

Rule Version

IISW-SV-000120

Severity Override Guidance

Navigate to the following folders:

inetpub\
Program Files\Common Files\System\msadc
Program Files (x86)\Common Files\System\msadc

If the folder or sub-folders contain any executable sample code, example applications, or tutorials which are not explicitly used by a production website, this is a finding.

Check Content Reference

M

Target Key

4000

Comments