IISW-SV-000149 - The Internet Printing Protocol (IPP) must be disabled on the IIS 8.5 web server

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The use of Internet Printing Protocol (IPP) on an IIS web server allows client's access to shared printers. This privileged access could allow remote code execution by increasing the web servers attack surface. Additionally, since IPP does not support SSL, it is considered a risk and will not be deployed.

Solution

Click 'Start', then click 'Administrative Tools', and then click 'Server Manager'.

Expand the roles node, then right-click 'Print Services', and then select 'Remove Roles Services'.

If the Internet Printing option is checked, clear the check box, click 'Next', and then click 'Remove' to complete the wizard.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_8-5_Y23M04_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001762, Rule-ID|SV-214433r879756_rule, STIG-ID|IISW-SV-000149, STIG-Legacy|SV-91449, STIG-Legacy|V-76753, Vuln-ID|V-214433

Plugin: Windows

Control ID: df169d9f6dc1ff64da891bc144a8c7c5cd770fab54aa6bf500a1dfc84b3bc69e