Check: DTOO284 - Outlook
Microsoft Outlook 2007:
DTOO284 - Outlook
(in versions v4 r16 through v4 r15)
Title
Automatically download Internet Calendar appointment attachments. (Cat II impact)
Discussion
Files attached to Internet Calendar appointments could contain malicious code that could be used to compromise a computer. By default, Outlook 2007 does not download attachments when retrieving Internet Calendar appointments.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Internet Calendars “Automatically download attachments” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\WebCal Criteria: If the value EnableAttachments is REG_DWORD = 0, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Internet Calendars “Automatically download attachments” will be set to “Disabled”.
Additional Identifiers
Rule ID: SV-18918r1_rule
Vulnerability ID: V-17738
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |