3.027 - Non-administrative user accounts or groups will only have print permissions of Printer Shares.

Information

Improperly configured share permissions on printers can permit the addition of unauthorized print devices on the network. Windows shares are a means by which files, folders, printers, and other resources can be published for network users to remotely access. Regular users cannot create shares on their local machines; only Administrators and Power Users have that ability.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the permissions on locally-shared printers to meet the minimum requirements.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_R2_MS_V1R33_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000213, Rule-ID|SV-32257r1_rule, STIG-ID|3.027, Vuln-ID|V-1135

Plugin: Windows

Control ID: 70d3d45883263459a0d74b67314cbe4925e72965bce854151527d2ff3db28e78