UCF STIG Viewer Logo

Automatic actions must be disabled for video DVDs.


Overview

Finding ID Version Rule ID IA Controls Severity
V-58281 AOSX-09-000105 SV-72711r1_rule Medium
Description
Applications should not be configured to launch automatically when a disk is inserted. This potentially circumvents anti-virus software and allows malicious users to craft disks that can exploit user applications. Disabling Automatic Actions for video DVDs mitigates this risk.
STIG Date
Apple OS X 10.9 (Mavericks) Workstation Security Technical Implementation Guide 2017-01-05

Details

Check Text ( C-59107r2_chk )
To check if the system has the correct setting for video DVDs in the configuration profile, run the following command:

system_profiler SPConfigurationProfileDataType | grep -A 2 'com.apple.digihub.dvd.video.appeared'

If this is not defined or 'action' is not set to '1', this is a finding.
Fix Text (F-63597r1_fix)
This setting is enforced using a configuration profile.