7.10 Remove empty crontab files and restrict file permissions, Check if the file permissions for /var/spool/cron/crontabs/* are OK.

Information

The system crontab files are accessed only by the cron daemon (which runs with superuser privileges) and the crontab command (which is set-UID to root). Allowing unprivileged users to read or (even worse) modify system crontab files can create the potential for a local user on the system to gain elevated privileges.

See Also

https://workbench.cisecurity.org/files/633