3.029 - Print driver installation privilege is not restricted to administrators.

Information

By default, the print spooler allows any user to add and to delete printer drivers on the local system. This capability should be restricted to authorized personnel.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Devices: Prevent users from installing printer drivers' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_DC_V6R47_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10), CAT|III, CCI|CCI-001812, CSCv6|5.1, Rule-ID|SV-29010r1_rule, STIG-ID|3.029, Vuln-ID|V-1151

Plugin: Windows

Control ID: ed4e8a000d3121bb2daaa3d97c00b6a2ed9341cb0000e695a59eba6ebed08851