Check: 3.083
Windows XP STIG:
3.083
(in versions v6 r1.32 through v1 r0)
Title
The system is configured to automatically forward error information. (Cat II impact)
Discussion
This setting controls the reporting of errors to Microsoft and, if defined, a corporate error reporting site. This does not interfere with the reporting of errors to the local user. Since the contents of memory are included in this Error Report, sensitive information may be transmitted to Microsoft. This feature should be disabled to prevent the release of such information.
Check Content
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\PCHealth\ErrorReporting\ Value Name: DoReport Type: REG_DWORD Value: 0 Documentable Explanation: This setting may be enabled, if the site has configured the options to send the report to a local error reporting server: Computer Configuration -> Administrative Templates -> System -> Error Reporting ,”Configure Error Reporting”. Document the requirement with the IAO.
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Internet Communication Management -> Internet Communication settings-> “Turn off Windows Error Reporting” to “Enabled”.
Additional Identifiers
Rule ID: SV-3471r1_rule
Vulnerability ID: V-3471
Group Title: Error Reporting - Report Errors
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |