Information
Users can set a URL to be used as the Home Page for a folder by entering the URL on the Home Page tab on the folder's Properties dialog box.
The recommended state for this setting is: Enabled
In CVE-2017-11774, a client-side Outlook attack exists that involves modifying victims' Outlook client homepages for code execution and persistence. While this has been patched by Microsoft, security researchers such as FireEye have noticed the bypassing of this patch through registry manipulation.
Implementing this recommendation alongside CIS recommendation Ensure 'Do not allow folders in non-default stores to be set as folder home pages' is set to 'Enabled' will help prevent the removal of protections against CVE-2017-11774.
Solution
To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled :
Microsoft Outlook 2016\Folder Home Pages for Outlook Special Folders\Do not allow Home Page URL to be set in folder Properties
Impact:
Users will be unable to configure this option.