1.1.4.1.3 Ensure 'Consistent Mime Handling' is set to 'Enabled' - spdesign.exe

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Internet Explorer uses Multipurpose Internet Mail Extensions (MIME) data to determine file handling procedures for files received through a Web server. This policy setting determines whether Internet Explorer requires that all file-type information provided by Web servers be consistent.

For example, if the MIME type of a file is text/plain but the MIME data indicates that the file is really an executable file, Internet Explorer changes its extension to reflect this executable status. This capability helps ensure that executable code cannot masquerade as other types of trustable data.

The recommended state for this setting is: Enabled: groove.exe, excel.exe, mspub.exe, powerpnt.exe, pptview.exe, visio.exe, winproj.exe, winword.exe, outlook.exe, spDesign.exe, exprwd.exe, msaccess.exe, onent.exe, mse7.exe).

Rationale:

Users can use Internet Explorer to unknowingly download malicious content disguised with an incorrect filename extension or incorrectly marked in the MIME header. Once downloaded, an incorrect handler can run the file, enabling the malicious content to cause damage to the user's system or network.

Impact:

Internet Explorer uses both the extension of the filename and the MIME information to decide how to handle a file. Enabling this setting requires that information in the MIME header matches the file extension provided. Since mismatched files will be blocked by enabling this setting, ensure that any web server under organizational control is set up correctly.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: check all applications:

Computer Configuration\Administrative Templates\Microsoft Office 2016 (Machine)\Security Settings\IE Security\Consistent Mime Handling

Default Value:

Not Configured

See Also

https://workbench.cisecurity.org/files/4234