Check: WINER-000018
Windows Vista STIG:
WINER-000018
(in versions v6 r42 through v6 r41)
Title
The system must be configured to permit the default consent levels of Windows Error Reporting to override any other consent policy setting. (Cat II impact)
Discussion
This setting determines the behavior of the "Configure Default Consent" setting in relation to custom consent settings. Enabling this allows the default consent levels of Windows Error Reporting to always override any other consent policy setting.
Check Content
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting\Consent\ Value Name: DefaultOverrideBehavior Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Error Reporting -> Consent -> "Ignore custom consent settings" to "Enabled".
Additional Identifiers
Rule ID: SV-71973r1_rule
Vulnerability ID: V-57479
Group Title: WINER-000018
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001312 |
The information system generates error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |