1.136 WN19-CC-000430

Information

Windows Server 2019 must disable the Windows Installer Always install with elevated privileges option.

GROUP ID:V-205802
RULE ID:SV-205802r1051079

Standard user accounts must not be granted elevated privileges. Enabling Windows Installer to elevate privileges when installing applications can allow malicious persons and applications to gain full control of a system.

Solution

Configure the policy value for

Computer Configuration >> Administrative Templates >> Windows Components >> Windows Installer >> 'Always install with elevated privileges' to 'Disabled'.

See Also

https://workbench.cisecurity.org/benchmarks/22176