Inappropriate user with Change the System Time privilege

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: Change System Time Privilege

Platforms: Windows NT
Description:

A user has been detected with Change the System Time privileges. This right is normally only granted to Administrators and Power Users.

Remedy:

Verify user rights in User Manager.

To audit and revoke this privilege, follow these steps:

  1. Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
  2. From the Policies menu, select User Rights to display the User Rights Policy dialog box.
  3. From the Right list, select Change the system time.
  4. Verify this right is set in accordance with your security policy.
  5. To remove a user, select the user and click Remove.
References:

X-Force Logo
Know Your Risks