35
Manage auditing and security log
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators Not
Defined Not Defined
Administrators
The
Manage auditing and security log
privilege allows a user to specify object access auditing options
for individual resources such as files, Active Directory objects, and registry keys. The right to manage
the security event log is a powerful user privilege that should be closely guarded. Anyone with this
user right can clear the security log, possibly erasing important evidence of unauthorized activity. The
default security groups for this user right are sufficient for the Legacy Client and Enterprise Client
environments. However, this user right is configured to enforce the default
Administrators
in the High
Security environment.
Modify firmware environment values
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators Not
Defined Not Defined
Administrators
The
Modify firmware environment values
user right allows modification of system environment
variables either by a process through an API, or by a user through
System Properties.
Anyone with
this privilege could configure the settings of a hardware component to cause it to fail, which could
lead to data corruption or a DoS condition. The default security groups for this user right are sufficient
for the Legacy Client and Enterprise Client environments. However, this user right is configured to
enforce the default
Administrators
group in the High Security environment.
Perform volume maintenance tasks
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators Not
Defined Not Defined
Administrators
The
Perform volume maintenance tasks
user right allows a non-administrative or remote user to
manage volumes or disks. A user with this privilege could delete a volume, leading to the loss of data
or a DoS condition. The default security groups for this user right are sufficient for the Legacy Client
and Enterprise Client environments. However, this user right is configured to enforce the default
Administrators
group in the High Security environment.
Profile single process
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators and
Power
Users
Not Defined
Not Defined Administrators
The
Profile single process
user right determines which users can use performance monitoring tools to
monitor the performance of non-system processes. This is a moderate vulnerability; an attacker with
this privilege could monitor a computer’s performance to help identify critical processes that he or she
might want to attack directly. The attacker may also be able to determine what processes are running
on the system so that he or she could identify countermeasures to avoid-such as antivirus software, an
intrusion-detection system, or other users logged onto a system. To better secure an environment,
remove
Power Users
from this user right in the High Security environment.