WA000-WI6040 - A non-privileged account is not used to run Worker Process Identities. - 'AppPoolIdentityType Check'

Information

Vulnerability Key: V0013713
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
The Worker Process Identity is the user defined to run an application pool. In previous versions of IIS,
the worker processes ran as the LocalSystem account. Because the LocalSystem account has access
to almost all resources on the operating system, this had serious security implications. IIS 6.0 worker
processes, by default, run under the new built-in Network Service account. You have the option of
using one of three predefined accounts Network Service, Local Service, or Local System, or creating
your own account.
NOTE: Review each website's AppPoolIdentityType to ensure it is a non-privileged account.
NOTE: AppPoolIdentityType values: 0 - NT AUTHORITY\SYSTEM, 1 - NT AUTHORITY\LOCAL SERVICE, 2 - NT AUTHORITY\NETWORK SERVICE
3 - Specific user account defined by the WAMUserName.

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: 07d883c3fd9991256fc9a7a91bdcdf45c8b0425a846eeee6a805193280db80e4