WN12-SV-000101 - The Microsoft FTP service must not be installed unless required.

Information

Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption.

Solution

Remove or disable the 'Microsoft FTP Service' (Service name: FTPSVC).

To remove the 'FTP Server' role from a system:
Start 'Server Manager'
Select the server with the 'FTP Server' role.
Scroll down to 'ROLES AND FEATURES' in the left pane.
Select 'Remove Roles and Features' from the drop down 'TASKS' list.
Select the appropriate server on the 'Server Selection' page, click 'Next'.
De-select 'FTP Server' under 'Web Server (IIS).
Click 'Next' and 'Remove' as prompted.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CAT|II, CCI|CCI-000382, CSCv6|9.1, Rule-ID|SV-225529r569185_rule, STIG-ID|WN12-SV-000101, STIG-Legacy|SV-52237, STIG-Legacy|V-26602, Vuln-ID|V-225529

Plugin: Windows

Control ID: d073e57c4c552e1ac27a9c4e756174bf752eb1dd56b3426c610e7c52f52b7910