WG080 - A compiler will not be installed on a production web server. 'msvc.exe search'

Information

Vulnerability Key: V0002236
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 12.4 CM Process
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 3.3, Web Site Administration Policies & Procedures, With
Amendments and Corrections incorporated in red italics
The presence of a compiler on a production server facilitates the malicious user's task of creating
custom versions of programs and installing Trojan Horses or viruses. For example, the attacker's
code can be uploaded and compiled on the server under attack. Of particular concern are C
compiliers.
NOTE: This check only searches the 'C:' drive, if the system has multiple drives ensure each drive doesn't contain compilers.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Windows

Control ID: 6a25b1e2d732205924f7749609e8d75905d21a688f11a2e9a7fc20a58a8e27f1