SV-205731r569188_rule
V-205731
SRG-OS-000257-GPOS-00098
WN19-AU-000060
CAT II
10
Configure the permissions on the "Eventvwr.exe" file to prevent modification by any groups or accounts other than TrustedInstaller. The default permissions listed below satisfy this requirement:
TrustedInstaller - Full Control
Administrators, SYSTEM, Users, ALL APPLICATION PACKAGES, ALL RESTRICTED APPLICATION PACKAGES - Read & Execute
The default location is the "%SystemRoot%\System32" folder.
Navigate to "%SystemRoot%\System32".
View the permissions on "Eventvwr.exe".
If any groups or accounts other than TrustedInstaller have "Full control" or "Modify" permissions, this is a finding.
The default permissions below satisfy this requirement:
TrustedInstaller - Full Control
Administrators, SYSTEM, Users, ALL APPLICATION PACKAGES, ALL RESTRICTED APPLICATION PACKAGES - Read & Execute
V-205731
False
WN19-AU-000060
Navigate to "%SystemRoot%\System32".
View the permissions on "Eventvwr.exe".
If any groups or accounts other than TrustedInstaller have "Full control" or "Modify" permissions, this is a finding.
The default permissions below satisfy this requirement:
TrustedInstaller - Full Control
Administrators, SYSTEM, Users, ALL APPLICATION PACKAGES, ALL RESTRICTED APPLICATION PACKAGES - Read & Execute
M
2907