Guest account in non-default group

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: Guest in Group

Platforms: Windows NT
Description:

The Guest user has been detected in a group other than Guests or Domain Guests. This membership could result in granting higher access to the Guest user than desired.

Remedy:

Verify that guest should be a member of this group, and ensure that membership could not lead to higher access:

  1. Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
  2. Select the group that includes the Guest account as a member.
  3. From the User menu, select Properties to display the User Properties dialog box.
  4. Select Guest, and click Remove.
  5. Click OK.
References:

X-Force Logo
Know Your Risks