WG470 - Wscript.exe and Cscript.exe are accessible by users other than the SA and Web Manager. - 'cscript.exe'

Information

Vulnerability Key: V0002264
IA Controls: ECCD-1 Changes to Data, ECCD-2 Changes to Data
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 4.11 Guide to the Secure Configuration and Administration
of Microsoft Internet Information
Windows Scripting Host (WSH) is installed under either a Typical or Custom installation option of a
Microsoft Network Server. This technology permits the execution of powerful script files from the
Windows NT command line. This technology is also classified as a Category I Mobile Code. If the
access to these files is not tightly controlled, a malicious user could readily compromise the server
by using a form to send input to these scripting engines. This is a web related vulnerability which
could exist on any NT / Win 2000 system regardless of the web server software being used on the
platform.
Review the file permissions to ensure that only the SA, System, or Web Manager have Full Control.

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Windows

Control ID: aca42d5ddf38256f970b1606c608c0250d0ff7e7524a931509478ab5a0a08d55