1.9.4.2.3 Ensure 'Plain Text Options' is set to Disabled

Information

This policy setting allows you to control how plain text messages are formatted when they are sent from Outlook.
If you enable this policy setting, text is automatically wrapped in Internet e-mail messages and attachments are encoded in UUENCODE format.
If you disable this policy setting, Outlook uses the standard MIME format to encode attachments in plain text Outlook messages. Users will not be able to change this configuration.
If you do not configure this policy setting, the behavior is the equivalent of setting the policy to Disabled, but users can modify plain text options in Outlook when required by clicking Tools, clicking Options, clicking the Mail Format tab, clicking Internet Format, and changing the values under 'Plain text options'. The recommended state for this setting is: Disabled.

Rationale:

If outgoing mail is formatted in certain ways, for example if attachments are encoded in UUENCODE format, attackers might manipulate the messages for their own purposes. If UUENCODE formatting is used, an attacker could manipulate the encoded attachment to bypass content filtering software.
By default, Outlook automatically wraps plain text messages at 76 characters and uses the standard MIME format to encode attachments in plain text messages. However, these settings can be altered to allow e-mail to be read in plain text e-mail programs that use a non-standard line length or that cannot process MIME attachments.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Disabled.

User Configuration\Administrative Templates\Microsoft Outlook 2016\Outlook Options\Mail Format\Internet Formatting\Plain text options\: Encode attachments in UUENCODE format

Impact:

If this setting is not configured, users can modify plain text options in Outlook when required by clicking Tools, clicking Options, clicking the Mail Format tab, clicking Internet Format, and changing the values under Plain text options. If you enable this policy setting, text is automatically wrapped in Internet e-mail messages and attachments are encoded in UUENCODE format.

See Also

https://workbench.cisecurity.org/files/553

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 7bd29a5803b403d8fed4f50e04606d653a06c23063ef7607fbb74e41c453b243