3.027 - Printer share permissions must be restricted to Print for non administrators.

Information

Improperly configured share permissions on printers can permit the addition of unauthorized print devices on the network. Windows shares are a means by which files, folders, printers, and other resources can be published for network users to remotely access.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the permissions on locally shared printers to ensure non administrators only have 'Print'.

Open 'Devices and Printers' in Control Panel.

Right-click on a locally attached printer.
Select 'Printer Properties'.
Select the 'Sharing' tab.

For each printer that has the 'Share this printer' selected:
Select the Security tab.

Assign any non-administrative user accounts or groups 'Print' permission only.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_7_V1R32_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000213, Rule-ID|SV-25007r2_rule, STIG-ID|3.027, Vuln-ID|V-1135

Plugin: Windows

Control ID: db343af26875649fe6186b9e464e0bf7c9ebbd1ff69cb744dd90993092cae2a1