DTOO248 - Base - Set Control Item property prompt for data, to automatically deny.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

When a control on a custom Outlook 2007 form is bound directly to any of the Address Information fields, the form code can indirectly retrieve the value of the Address Information field by obtaining the Value property of the control. If the custom form was created by a malicious or inexperienced user, sensitive information could be exposed to unauthorized parties.
By default, Outlook prompts users when they bind a control to an Address Information field.

Solution

The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Custom Form Security 'Set control ItemProperty prompt' will be set to 'Enabled (Automatically Deny)'.

See Also

http://iase.disa.mil/stigs/app_security/office_auto/u_microsoft_office2007_v4r9_stig_20121026.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, Rule-ID|SV-19028r2_rule, STIG-ID|DTOO248, Vuln-ID|V-17801

Plugin: Windows

Control ID: e514d4cbebf18388a08ebda0c17d838a9f8237265162d898504ce796608e40a8