2.4 Ensure 'Database Mail XPs' Server Configuration Option is set to '0'

Information

The Database Mail XPs option controls the ability to generate and transmit email messages from SQL Server.

Disabling the Database Mail XPs option reduces the SQL Server surface, eliminates a DOS attack vector and channel to exfiltrate data from the database server to a remote host.

Solution

Run the following T-SQL command:

EXECUTE sp_configure 'show advanced options', 1;
RECONFIGURE;
EXECUTE sp_configure 'Database Mail XPs', 0;
RECONFIGURE;
GO
EXECUTE sp_configure 'show advanced options', 0;
RECONFIGURE;

See Also

https://workbench.cisecurity.org/benchmarks/14058

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: MS_SQLDB

Control ID: 5f27565b68a2d05709da209fa424bfb9d633642cb5d9ba866ddef80f62685fb4