Information
Users can set a URL to be used as the Home Page for a folder by entering the URL on the Home Page tab on the folder's Properties dialog box.
The recommended state for this setting is: Enabled.
Rationale:
In CVE-2017-11774, a client-side Outlook attack exists that involves modifying victims' Outlook client homepages for code execution and persistence. While this has been patched by Microsoft, security researchers such as FireEye have noticed the bypassing of this patch through registry manipulation.
Implementing this recommendation alongside CIS recommendation Ensure 'Do not allow folders in non-default stores to be set as folder home pages' is set to 'Enabled' will help prevent the removal of protections against CVE-2017-11774.
Impact:
Users will be unable to configure this option.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled:
User Configuration\Administrative Templates\Microsoft Outlook 2016\Folder Home Pages for Outlook Special Folders\Do not allow Home Page URL to be set in folder Properties
Default Value:
Disabled. (Users can set a URL to be used as the Home Page for a folder.)