Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator.
An XCCDF Rule
Description
Windows Scripting Host (WSH) is installed under either a Typical or Custom installation option of a Microsoft Network Server. This technology permits the execution of powerful script files from the Windows NT command line. This technology is also classified as a Category I Mobile Code. If the access to these files is not tightly controlled, a malicious user could readily compromise the server by using a form to send input to these scripting engines.
Property | Value |
---|---|
Responsibility | System Administrator |
- ID
- SV-33095r1_rule
- Version
- WG470 W22
- Severity
- Medium
- Updated
Remediation Templates
A Manual Procedure
Remove Wscript.exe and Cscript.exe files from the server, or restrict access to these files to the SA, the web administrator, and the system account.