1.15 WN19-00-000150

Information

Windows Server 2019 permissions for program file directories must conform to minimum requirements.

GROUP ID:V-205735
RULE ID:SV-205735r958702

Changing the system's file and directory permissions allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.

The default permissions are adequate when the Security Option 'Network access: Let Everyone permissions apply to anonymous users' is set to 'Disabled' (WN19-SO-000240).

Satisfies: SRG-OS-000312-GPOS-00122, SRG-OS-000312-GPOS-00123, SRG-OS-000312-GPOS-00124

Solution

Maintain the default permissions for the program file directories and configure the Security Option 'Network access: Let Everyone permissions apply to anonymous users' to 'Disabled' (WN19-SO-000240).

Default permissions:\Program Files and \Program Files (x86)Type - 'Allow' for allInherited from - 'None' for all

Principal - Access - Applies to

- TrustedInstaller - Full control - This folder and subfolders
- SYSTEM - Modify - This folder only
- SYSTEM - Full control - Subfolders and files only
- Administrators - Modify - This folder only
- Administrators - Full control - Subfolders and files only
- Users - Read & execute - This folder, subfolders, and files
- CREATOR OWNER - Full control - Subfolders and files only
- ALL APPLICATION PACKAGES - Read & execute - This folder, subfolders, and files
- ALL RESTRICTED APPLICATION PACKAGES - Read & execute - This folder, subfolders, and files

See Also

https://workbench.cisecurity.org/benchmarks/22176