STIGQter STIGQter: STIG Summary: Microsoft Outlook 2010 STIG Version: 1 Release: 13 Benchmark Date: 27 Apr 2018:

External content and pictures in HTML eMail must be displayed.

DISA Rule

SV-33548r2_rule

Vulnerability Number

V-17672

Group Title

DTOO270 - External Pictures & content

Rule Version

DTOO270 - Outlook

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set the policy value for User Configuration >> Administrative Templates >> Microsoft Outlook 2010 >> Security >> Automatic Picture Download Settings “Display pictures and external content in HTML e-mail” to “Enabled”.

Check Contents

Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2010 >> Security >> Automatic Picture Download Settings “Display pictures and external content in HTML e-mail” is set to “Enable”.

NOTE: When this setting is Enabled, Outlook 2010 blocks automatic download of content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis.

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\14.0\Outlook\Options\Mail

Criteria: If the value BlockExtContent is REG_DWORD = 0, this is not a finding.

Vulnerability Number

V-17672

Documentable

False

Rule Version

DTOO270 - Outlook

Severity Override Guidance

Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2010 >> Security >> Automatic Picture Download Settings “Display pictures and external content in HTML e-mail” is set to “Enable”.

NOTE: When this setting is Enabled, Outlook 2010 blocks automatic download of content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis.

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\14.0\Outlook\Options\Mail

Criteria: If the value BlockExtContent is REG_DWORD = 0, this is not a finding.

Check Content Reference

M

Responsibility

Information Assurance Officer

Target Key

2024

Comments