STIGQter STIGQter: STIG Summary: Windows 2008 Member Server Security Technical Implementation Guide Version: 6 Release: 43 Benchmark Date: 26 Jul 2019: Preserve Zone information when saving attachments.

DISA Rule

SV-29754r1_rule

Vulnerability Number

V-14268

Group Title

Attachment Mgr - Preserve Zone Info

Rule Version

5.134

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the policy value for User Configuration -> Administrative Templates -> Windows Components -> Attachment Manager -> “Do not preserve zone information in file attachments” to “Disabled”.

Check Contents

If the following registry value doesn’t exist or is not configured as specified, this is a finding:

Registry Hive: HKEY_Current_User
Subkey: \Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\

Value Name: SaveZoneInformation

Type: REG_DWORD
Value: 2

Vulnerability Number

V-14268

Documentable

False

Rule Version

5.134

Severity Override Guidance

If the following registry value doesn’t exist or is not configured as specified, this is a finding:

Registry Hive: HKEY_Current_User
Subkey: \Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\

Value Name: SaveZoneInformation

Type: REG_DWORD
Value: 2

Check Content Reference

M

Responsibility

System Administrator

Target Key

1340

Comments