Microsoft Windows Server 2019

Windows Server 2019 must not have the Microsoft FTP service installed unless required by the organization

STIG ID: WN19-00-000330 | SRG: SRG-OS-000096-GPOS-00050 | Severity: Medium | CCI: CCI-000382 | Vulnerability ID: V-205697

Description

Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption.

Check

C-5962r355009_chk

If the server has the role of an FTP server, this is NA.Open "PowerShell".Enter "Get-WindowsFeature | Where Name -eq Web-Ftp-Service".If "Installed State" is "Installed", this is a finding.An Installed State of "Available" or "Removed" is not a finding.If the system has the role of an FTP server, this must be documented with the ISSO.

Fix

F-5962r355010_fix

Uninstall the "FTP Server" role.Start "Server Manager".Select the server with the role.Scroll down to "ROLES AND FEATURES" in the right pane.Select "Remove Roles and Features" from the drop-down "TASKS" list.Select the appropriate server on the "Server Selection" page and click "Next".Deselect "FTP Server" under "Web Server (IIS)" on the "Roles" page.Click "Next" and "Remove" as prompted.