SV-224880r569186_rule
V-224880
SRG-OS-000257-GPOS-00098
WN16-AU-000060
CAT II
10
Configure the permissions on the "Eventvwr.exe" file to prevent modification by any groups or accounts other than TrustedInstaller. The default permissions listed below satisfy this requirement:
TrustedInstaller - Full Control
Administrators, SYSTEM, Users, ALL APPLICATION PACKAGES, ALL RESTRICTED APPLICATION PACKAGES - Read & Execute
The default location is the "%SystemRoot%\ System32" folder.
Navigate to "%SystemRoot%\System32".
View the permissions on "Eventvwr.exe".
If any groups or accounts other than TrustedInstaller have "Full control" or "Modify" permissions, this is a finding.
The default permissions below satisfy this requirement:
TrustedInstaller - Full Control
Administrators, SYSTEM, Users, ALL APPLICATION PACKAGES, ALL RESTRICTED APPLICATION PACKAGES - Read & Execute
V-224880
False
WN16-AU-000060
Navigate to "%SystemRoot%\System32".
View the permissions on "Eventvwr.exe".
If any groups or accounts other than TrustedInstaller have "Full control" or "Modify" permissions, this is a finding.
The default permissions below satisfy this requirement:
TrustedInstaller - Full Control
Administrators, SYSTEM, Users, ALL APPLICATION PACKAGES, ALL RESTRICTED APPLICATION PACKAGES - Read & Execute
M
4205