[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-99335-2

Platform: cpe:/o:microsoft:windows_11Date: (C)2023-01-13   (M)2023-07-04



Title: Internet Information System (IIS) or its subcomponents must not be installed on a workstation. Description: Installation of Internet Information System (IIS) may allow unauthorized internet services to be hosted. Websites must only be hosted on servers that have been designed for that purpose and can be adequately secured. Check Text: IIS is not installed by default. Verify it has not been installed on the system. Run "Programs and Features". Select "Turn Windows features on or off". If the entries for "Internet Information Services" or "Internet Information Services Hostable Web Core" are selected, this is a finding. If an application requires IIS or a subset to be installed to function, this needs be documented with the ISSO. In addition, any applicable requirements from the IIS STIG must be addressed. Fix: Uninstall "Internet Information Services" or "Internet Information Services Hostable Web Core" from the system.


Parameter:

[yes/no]


Technical Mechanism:

Uninstall "Internet Information Services" or "Internet Information Services Hostable Web Core" from the system.

CCSS Severity:CCSS Metrics:
CCSS Score : 7.8Attack Vector: LOCAL
Exploit Score: 1.8Attack Complexity: LOW
Impact Score: 5.9Privileges Required: LOW
Severity: HIGHUser Interaction: NONE
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:86887


OVAL    1
oval:org.secpod.oval:def:86887
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_11

© SecPod Technologies