DTOO236 - Outlook - The Add-In Trust Level must be configured.

Information

Under normal circumstances the installed COM add-ins are applications that have been approved and intentionally deployed by the organization and therefore they should not pose a security threat. However, if malware has infected systems it is possible that the malware will use the COM add-in feature to perform unauthorized actions. This setting enforces the default configuration, and therefore is unlikely to cause significant usability issues for most users.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2010 -> Security 'Configure Add-In Trust Level' to 'Enabled (Trust all loaded and installed COM addins)'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Outlook_2010_V1R13_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4), CAT|II, CCI|CCI-001170, Rule-ID|SV-33932r1_rule, STIG-ID|DTOO236, Vuln-ID|V-17566

Plugin: Windows

Control ID: 1fd24af3bd1fce8684aa1e528c265e4beeb4e7c4cfec4d763026d1cce880ed7b