STIGQter STIGQter: STIG Summary: Microsoft IIS 8.5 Server Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

IIS 8.5 web server system files must conform to minimum file permission requirements.

DISA Rule

SV-214429r508658_rule

Vulnerability Number

V-214429

Group Title

SRG-APP-000340-WSR-000029

Rule Version

IISW-SV-000144

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Open Explorer and navigate to the inetpub directory.
Right-click "inetpub" and select "Properties".
Click the "Security" tab.
Set the following permissions:

SYSTEM: Full control
Administrators: Full control
TrustedInstaller: Full control
ALL APPLICATION PACKAGES (built-in security group): Read and execute
Users: Read and execute, list folder contents
CREATOR OWNER: special permissions to subkeys

Check Contents

Open Explorer and navigate to the inetpub directory.
Right-click "inetpub" and select "Properties".
Click the "Security" tab.
Verify the permissions for the following users:

System: Full control
Administrators: Full control
TrustedInstaller: Full control
ALL APPLICATION PACKAGES (built-in security group): Read and execute
ALL RESTRICTED APPLICATION PACKAGES (built-in security group): Read and execute
Users: Read and execute, list folder contents
CREATOR OWNER: Full Control, Subfolders and files only

If the permissions are less restrictive than what is listed, this is a finding.

Vulnerability Number

V-214429

Documentable

False

Rule Version

IISW-SV-000144

Severity Override Guidance

Open Explorer and navigate to the inetpub directory.
Right-click "inetpub" and select "Properties".
Click the "Security" tab.
Verify the permissions for the following users:

System: Full control
Administrators: Full control
TrustedInstaller: Full control
ALL APPLICATION PACKAGES (built-in security group): Read and execute
ALL RESTRICTED APPLICATION PACKAGES (built-in security group): Read and execute
Users: Read and execute, list folder contents
CREATOR OWNER: Full Control, Subfolders and files only

If the permissions are less restrictive than what is listed, this is a finding.

Check Content Reference

M

Target Key

4000

Comments