STIGQter STIGQter: STIG Summary: Microsoft SQL Server 2022 Instance Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Apr 2026:

Access to xp_cmdshell must be disabled unless specifically required and approved.

DISA Rule

SV-271302r1109113_rule

Vulnerability Number

V-271302

Group Title

SRG-APP-000141-DB-000093

Rule Version

SQLI-22-007200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable use of or remove any external application executable object definitions that are not approved.

To disable the use of xp_cmdshell, from the query prompt:

EXEC SP_CONFIGURE 'show advanced options', 1;
RECONFIGURE WITH OVERRIDE;
EXEC SP_CONFIGURE 'xp_cmdshell', 0;
RECONFIGURE WITH OVERRIDE;
EXEC SP_CONFIGURE 'show advanced options', 0;
RECONFIGURE WITH OVERRIDE;

Check Contents

To determine if [xp_cmdshell] is enabled, execute the following command:

SELECT name, value, value_in_use
FROM sys.configurations
WHERE name = 'xp_cmdshell'

If [value_in_use] is a [1], review the system documentation to determine whether the use of [xp_cmdshell] is approved. If it is not approved, this is a finding.

Vulnerability Number

V-271302

Documentable

False

Rule Version

SQLI-22-007200

Severity Override Guidance

To determine if [xp_cmdshell] is enabled, execute the following command:

SELECT name, value, value_in_use
FROM sys.configurations
WHERE name = 'xp_cmdshell'

If [value_in_use] is a [1], review the system documentation to determine whether the use of [xp_cmdshell] is approved. If it is not approved, this is a finding.

Check Content Reference

M

Target Key

5677