2.2.34 Ensure 'Load and unload device drivers' is set to 'Administrators'

Information

This policy setting allows users to dynamically load a new device driver on a system. This user right is not required if a signed driver for the new hardware already exists in the Driver.cab file on the system.

The recommended state for this setting is: Administrators.

Note: This user right is considered a 'sensitive privilege' for the purposes of auditing.

Device drivers run as highly privileged code. A user or threat actor who has the Load and unload device drivers user right could unintentionally install malicious code that masquerades as a device driver. Administrators should exercise greater care and install only drivers with verified digital signatures.

Solution

To establish the recommended configuration via GP, set the following UI path to Administrators :

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Load and unload device drivers

Impact:

If the Load and unload device drivers user right is removed from the Print Operators group or other accounts, it could limit the abilities of users who are assigned to specific administrative roles in your environment. Ensure that delegated tasks will not be negatively affected by this setting.

See Also

https://workbench.cisecurity.org/benchmarks/25708