3.029 - Print driver installation privilege is not restricted to administrators.

Information

By default, the print spooler allows any user to add and to delete printer drivers on the local system. This capability should be restricted to authorized personnel.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Devices- Prevent users from installing printer drivers' to 'Enabled'.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-11(2), CAT|III, CCI|CCI-001812, Rule-ID|SV-29009r1_rule, STIG-ID|3.029, Vuln-ID|V-1151

Plugin: Windows

Control ID: 19e7af66a6a15fc842bad2fb5f2b907728a92ef0a9b36b0f3bd608e7a89fcdb1