[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-42262-6

Platform: win10Date: (C)2016-09-23   (M)2022-10-10



Do not preserve zone information in file attachments This policy setting allows you to manage whether Windows marks file attachments from Internet Explorer or Microsoft Outlook Express with information about their zone of origin (such as restricted, Internet, intranet, or local). This policy setting requires that files be downloaded to NTFS disk partitions to function correctly. If zone information is not preserved, Windows cannot make proper risk assessments based on the zone where the attachment came from. If the Do not preserve zone information in file attachments setting is enabled, file attachments are not marked with their zone information. If this policy setting is disabled, Windows is forced to store file attachments with their zone information. Because dangerous attachments are often downloaded from untrusted Internet Explorer zones such as the Internet zone, Microsoft recommends that you configure this policy setting to Disabled to help ensure that as much security information as possible is preserved with each file. Counter Measure: Configure the Do not preserve zone information in file attachments setting to Disabled. Potential Impact: None, this is the default configuration.


Parameter:


Technical Mechanism:

(1) GPO: User Configuration\Administrative Templates\Windows Components\Attachment Manager\Do not preserve zone information in file attachments (2) REG: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\SaveZoneInformation (3) WMI: ###

CCSS Severity:CCSS Metrics:
CCSS Score : Attack Vector:
Exploit Score: Attack Complexity:
Impact Score: Privileges Required:
Severity: User Interaction:
Vector: Scope:
 Confidentiality:
 Integrity:
 Availability:
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:36531
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:36531
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:36531


OVAL    1
oval:org.secpod.oval:def:36531

© SecPod Technologies