DTOO248 - Base - Set Control Item property prompt for data, to automatically deny.


When a control on a custom Outlook 2007 form is bound directly to any of the Address Information fields, the form code can indirectly retrieve the value of the Address Information field by obtaining the Value property of the control. If the custom form was created by a malicious or inexperienced user, sensitive information could be exposed to unauthorized parties.
By default, Outlook prompts users when they bind a control to an Address Information field.


The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Custom Form Security 'Set control ItemProperty prompt' will be set to 'Enabled (Automatically Deny)'.

See Also


Item Details


References: 800-53|CM-6, CAT|II, Rule-ID|SV-19028r2_rule, STIG-ID|DTOO248, Vuln-ID|V-17801

Plugin: Windows

Control ID: e514d4cbebf18388a08ebda0c17d838a9f8237265162d898504ce796608e40a8