Check: DTOO225 - Outlook
Microsoft Outlook 2007:
DTOO225 - Outlook
(in versions v4 r16 through v4 r15)
Title
Configure Outlook Dial-up options to Warn user before allowing switch in dial-up access. (Cat II impact)
Discussion
By default, users can connect to their e-mail servers using dial-up networking if their accounts are configured appropriately. Dial-up connections are often used by mobile users who need to connect to the Internet from remote locations. Remote connections are generally not subject to the same restrictions as enterprise network environments, which can make them more vulnerable to attack.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail Setup “Dial–up options” will be set to “Enabled” and Warn before switching dial-up connection is selected. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail\ Criteria: If the value Warn on Dialup is REG_DWORD = 1, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail Setup “Dial–up options” will be set to “Enabled” and Warn before switching dial-up connection is selected.
Additional Identifiers
Rule ID: SV-18710r1_rule
Vulnerability ID: V-17586
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |