WG275 W22 - The web server, although started by superuser or privileged account, must run using a non-privileged account.

Information

Running the web server with excessive privileges presents an increased risk to the web server. In the event the web server's services are compromised, the context by which the web server is running will determine the amount of damage that may be caused by the attacker. If the web server is run as an administrator or as an equivalent account, the attacker will gain administrative access through the web server. If, on the other hand, the web server is running with least privilege required to function, the capabilities of the attacker will be greatly decreased.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the web server to run using a non-privileged account.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apache_2-2_WIN_V1R13_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-36607r1_rule, STIG-ID|WG275_W22, Vuln-ID|V-13619

Plugin: Windows

Control ID: 7fc40da4678b793db61b607fff45f040f81143d289587ff1ebba0ac4cf8f2ef2