1.18 WN16-00-000200

Information

Non-administrative accounts or groups must only have print permissions on printer shares.

GROUP ID:V-224836
RULE ID:SV-224836r958472

Windows shares are a means by which files, folders, printers, and other resources can be published for network users to access. Improper configuration can permit access to devices and data beyond a user's need.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the permissions on shared printers to restrict standard users to only have Print permissions.

See Also

https://workbench.cisecurity.org/benchmarks/23093