STIGQter STIGQter: STIG Summary: Microsoft Windows Server 2012/2012 R2 Member Server Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 04 May 2021:

The Microsoft FTP service must not be installed unless required.

DISA Rule

SV-225529r569185_rule

Vulnerability Number

V-225529

Group Title

SRG-OS-000096-GPOS-00050

Rule Version

WN12-SV-000101

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove or disable the "Microsoft FTP Service" (Service name: FTPSVC).

To remove the "FTP Server" role from a system:
Start "Server Manager"
Select the server with the "FTP Server" role.
Scroll down to "ROLES AND FEATURES" in the left pane.
Select "Remove Roles and Features" from the drop down "TASKS" list.
Select the appropriate server on the "Server Selection" page, click "Next".
De-select "FTP Server" under "Web Server (IIS).
Click "Next" and "Remove" as prompted.

Check Contents

If the server has the role of an FTP server, this is NA.

Run "Services.msc".

If the "Microsoft FTP Service" (Service name: FTPSVC) is installed and not disabled, this is a finding.

Vulnerability Number

V-225529

Documentable

False

Rule Version

WN12-SV-000101

Severity Override Guidance

If the server has the role of an FTP server, this is NA.

Run "Services.msc".

If the "Microsoft FTP Service" (Service name: FTPSVC) is installed and not disabled, this is a finding.

Check Content Reference

M

Target Key

4214

Comments