Microsoft FTP Service (FTPSVC)ID: oval:org.secpod.oval:def:80602 | Date: (C)2022-06-02 (M)2023-12-13 |
Class: COMPLIANCE | Family: windows |
Enables the server to be a File Transfer Protocol (FTP) server
Note: This service is not installed by default. It is supplied with Windows, but is installed
by enabling an optional Windows feature (Internet Information Services - FTP Server).
Hosting an FTP server (especially a non-secure FTP server) from a workstation is an
increased security risk, as the attack surface of that workstation is then greatly increased.
Note: This security concern applies to any FTP server application installed on a
workstation, not just IIS.
Default: Not Installed (Automatic when installed)
Counter Measure:
The recommended state for this setting is Disabled or Not Installed.
Potential Impact:
The computer will not function as an FTP server.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft FTP Service
(2) REG: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTPSVC!Start
Platform: |
Microsoft Windows 10 |