Check: WINER-000102
Windows 2003 MS STIG:
WINER-000102
(in version v6 r37)
Title
The system must be configured to collect additional information about the system when error reports are generated. (Cat II impact)
Discussion
Windows Error Reporting information can be used to help diagnose day-to-day software issues, as well as help discover malicious code and possibly zero-day attacks on systems. This setting controls whether to collect and include additional data related to the system's configuration in the error report. This is useful for obtaining contextual information relative to the process that caused the error.
Check Content
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\DW\ Value Name: DWNoSecondLevelCollection Type: REG_DWORD Value: 0
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Error Reporting -> "Configure Error Reporting" to "Enabled" with "Do not collect additional machine data" unchecked.
Additional Identifiers
Rule ID: SV-70807r1_rule
Vulnerability ID: V-56547
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001312 |
Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |