STIGQter STIGQter: STIG Summary: MS SQL Server 2016 Instance Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

SQL Server must limit privileges to change software modules and links to software external to SQL Server.

DISA Rule

SV-213950r617437_rule

Vulnerability Number

V-213950

Group Title

SRG-APP-000133-DB-000179

Rule Version

SQL6-D0-006500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change the ownership of all shared software libraries on disk to the authorized account. Remove any modify permissions granted to unauthorized users or groups.

Check Contents

Review Server documentation to determine the authorized owner and users or groups with modify rights for this SQL instance's binary files. Additionally check the owner and users or groups with modify rights for shared software library paths on disk.

If any unauthorized users are granted modify rights or the owner is incorrect, this is a finding.

To determine the location for these instance-specific binaries, Launch SQL Server Management Studio (SSMS) >> Connect to the instance to be reviewed >> Right-click server name in Object Explorer >> Click Facets >> Select the Server facet >> Record the value for the "RootDirectory" facet property.

Navigate to the folder above, and review the "Binn" subdirectory.

Vulnerability Number

V-213950

Documentable

False

Rule Version

SQL6-D0-006500

Severity Override Guidance

Review Server documentation to determine the authorized owner and users or groups with modify rights for this SQL instance's binary files. Additionally check the owner and users or groups with modify rights for shared software library paths on disk.

If any unauthorized users are granted modify rights or the owner is incorrect, this is a finding.

To determine the location for these instance-specific binaries, Launch SQL Server Management Studio (SSMS) >> Connect to the instance to be reviewed >> Right-click server name in Object Explorer >> Click Facets >> Select the Server facet >> Record the value for the "RootDirectory" facet property.

Navigate to the folder above, and review the "Binn" subdirectory.

Check Content Reference

M

Target Key

3993

Comments