Check: WINER-000014
Windows Vista STIG:
WINER-000014
(in versions v6 r42 through v6 r41)
Title
The system must be configured to add all error reports to the queue. (Cat II impact)
Discussion
Error reports are queued for sending to an error reporting site when the queueing behavior is set to Always Queue. This will maintain the reports in the queue until a connection can be made to the collection server.
Check Content
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting\ Value Name: ForceQueue Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Error Reporting -> Advanced Error Reporting Settings -> "Configure Report Queue" to "Enabled" with "Queuing behavior:" to "Always queue".
Additional Identifiers
Rule ID: SV-71933r1_rule
Vulnerability ID: V-57471
Group Title: WINER-000014
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001312 |
The information system generates error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |