[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-34810-2

Platform: win8.1Date: (C)2015-10-14   (M)2022-10-10



Do not preserve zone information in file attachments This policy setting allows you to manage whether Windows marks file attachments from Internet Explorer or Microsoft Outlook? Express with information about their zone of origin (such as restricted, Internet, intranet, or local). This policy setting requires that files be downloaded to NTFS disk partitions to function correctly. If zone information is not preserved, Windows cannot make proper risk assessments based on the zone where the attachment came from. If the Do not preserve zone information in file attachments setting is enabled, file attachments are not marked with their zone information. If this policy setting is disabled, Windows is forced to store file attachments with their zone information. Because dangerous attachments are often downloaded from untrusted Internet Explorer zones such as the Internet zone, Microsoft recommends that you configure this policy setting to Disabled to help ensure that as much security information as possible is preserved with each file.


Parameter:


Technical Mechanism:

(1) GPO: User Configuration\Administrative Templates\Windows Components\Attachment Manager!Do not preserve zone information in file attachments (2) REG: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments!SaveZoneInformation

CCSS Severity:CCSS Metrics:
CCSS Score : Attack Vector:
Exploit Score: Attack Complexity:
Impact Score: Privileges Required:
Severity: User Interaction:
Vector: Scope:
 Confidentiality:
 Integrity:
 Availability:
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:29577
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:29577
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:29577
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:29577


OVAL    1
oval:org.secpod.oval:def:29577

© SecPod Technologies