Check: WINER-000007
Windows Vista STIG:
WINER-000007
(in versions v6 r42 through v6 r41)
Title
The system must be configured to store error reports locally, on the system or in the enclave, and not send them to Microsoft. (Cat II impact)
Discussion
Forwarding error reports to vendors could expose sensitive information. This setting controls the configuration of a local or DOD-wide error reporting site. In order to not send the data to any system at this time, yet create the reports locally on the system, this value needs to be a single blank character. To forward error reports to a collection server, the site's error reporting server name or IP address must be defined.
Check Content
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting\ Value Name: CorporateWerServer Type: REG_SZ Value: " " (A single BLANK character to store the data on the system or the error reporting server name or IP address to forward the data to.)
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Error Reporting -> Advanced Error Reporting Settings -> "Configure Corporate Windows Error Reporting" -> to "Enabled" with "Corporate server name:" defined as a single blank character to store the data on the system or the name or IP address of the local collection server.
Additional Identifiers
Rule ID: SV-71861r1_rule
Vulnerability ID: V-57457
Group Title: WINER-000007
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001312 |
The information system generates error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |