WA000-WI100 IIS6 - The File System Object component, if not required, must be disabled. - 'Scripting.FileSystemObject Check'

Information

Some COM components are not required for most applications and should be removed if possible. Most notably, consider disabling the File System Object component; however, this will also remove the Dictionary object. Be aware some programs may require components that are being disabled, so it is highly recommended this be tested completely before implementing on your production Web servers.

Solution

Unregister the File System Object using the following command: regsvr32 scrrun.dll /u.

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CAT|II, Rule-ID|SV-38151r2_rule, STIG-ID|WA000-WI100_IIS6, Vuln-ID|V-13700

Plugin: Windows

Control ID: fc59baf7e57a3bb1d2e95067645e6723f99c83bba90f5a011d8fd63c3debd87f