2.5.4.1 (L1) Ensure 'Do not allow Home Page URL to be set in folder Properties' is set to 'Enabled'

Information

Users can set a URL to be used as the Home Page for a folder by entering the URL on the Home Page tab on the folder's Properties dialog box.

The recommended state for this setting is: Enabled

In CVE-2017-11774, a client-side Outlook attack exists that involves modifying victims' Outlook client homepages for code execution and persistence. While this has been patched by Microsoft, security researchers such as FireEye have noticed the bypassing of this patch through registry manipulation.

Implementing this recommendation alongside CIS recommendation Ensure 'Do not allow folders in non-default stores to be set as folder home pages' is set to 'Enabled' will help prevent the removal of protections against CVE-2017-11774.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Outlook 2016\Folder Home Pages for Outlook Special Folders\Do not allow Home Page URL to be set in folder Properties

Impact:

Users will be unable to configure this option.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: b1fb381dcfc3aa8f00edff48f5275521de74f253904fb7aa14d33a53ad8f11be