WN12-GE-000007 - Permissions for program file directories must conform to minimum requirements

Information

Changing the system's file and directory permissions allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.

The default permissions are adequate when the Security Option 'Network access: Let everyone permissions apply to anonymous users' is set to 'Disabled' (V-3377).

Solution

Maintain the default permissions for the program file directories and configure the Security Option: 'Network access: Let everyone permissions apply to anonymous users' to 'Disabled' (V-3377).

Default Permissions:
\Program Files and \Program Files (x86)
Type - 'Allow' for all
Inherited from - 'None' for all

Principal - Access - Applies to

TrustedInstaller - Full control - This folder and subfolders
SYSTEM - Modify - This folder only
SYSTEM - Full control - Subfolders and files only
Administrators - Modify - This folder only
Administrators - Full control - Subfolders and files only
Users - Read & execute - This folder, subfolders and files
CREATOR OWNER - Full control - Subfolders and files only
ALL APPLICATION PACKAGES - Read & execute - This folder, subfolders and files

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R7_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-002165, Rule-ID|SV-225421r852235_rule, STIG-ID|WN12-GE-000007, STIG-Legacy|SV-52135, STIG-Legacy|V-40177, Vuln-ID|V-225421

Plugin: Windows

Control ID: 261916f86da35f2710b2f4174c770f67a128ef438744062a6aa8bfd734d1f0ed