Check: WINER-000103
Windows 2003 MS STIG:
WINER-000103
(in version v6 r37)
Title
The system must be configured to prevent the display of any error dialog links to any website. (Cat III impact)
Discussion
Windows Error Reporting information can be used to help diagnose day-to-day software issues, as well as help discover malicious code and possibly zero-day attacks on systems. This setting controls whether to display links to any Microsoft provided web sites.
Check Content
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\DW\ Value Name: DWNoExternalURL Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Error Reporting -> "Configure Error Reporting" to "Enabled" with "Do not display links to any Microsoft provided 'more information' web sites" selected.
Additional Identifiers
Rule ID: SV-70809r1_rule
Vulnerability ID: V-56549
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
Configure the system to provide only organization-defined mission essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |