WA000-WI6010 - Application pools are not used to isolate Web Applications.

Information

Vulnerability Key: V0013703
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
IIS 6.0 is designed into a new component, the kernel mode driver, HTTP.sys. HTTP.sys receives all
incoming requests and parses these requests to separate application pools for processing. This
architecture allows IIS 6.0 to listen for requests and queue them as needed. HTTP.sys does not load
any application code making it more secure. Applications can be run in independent/isolated
application pools providing for a significant operational isolation boundary. This means that an
application operating in one application pool will not have any operational effect on an application in
another application pool.
NOTE: Review each Web Applications to ensure each utilizes a separate Application Pool.

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-39

Plugin: Windows

Control ID: 9f872f3dd6d4b073ab72793c87051d3284e37190253033c4cff079579335f7cd