1. Home
  2. Security Hardening
  3. DISA STIG Microsoft Outlook 2013 V1R13
  4. DTOO231 – Dragging Unicode email messages to file system must be disallowed.

DTOO231 – Dragging Unicode email messages to file system must be disallowed.

Details

When users drag email messages from Outlook to a Windows Explorer window or to their Desktop, Outlook creates an .msg file using the native character encoding format for the configured locale (the so-called ‘ANSI’ format). If this setting is Enabled, Outlook uses the Unicode character encoding standard to create the message file, which preserves special characters in the message.

However, Unicode text is vulnerable to homograph attacks, in which characters are replaced by different but similar-looking characters. For example, the Cyrillic letter ‘?’ (U+0430) appears identical to the Latin letter ‘a’ (U+0061) in many typefaces, but is actually a different character. Homographs can be used in ‘phishing’ attacks to convince victims to visit fraudulent websites and enter sensitive information.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2013 -> Outlook Options -> Other -> Advanced ‘Use Unicode format when dragging e-mail message to file system’ to ‘Disabled’.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles