UCF STIG Viewer Logo

The Macro Security Level option in Office 2000, XP (2002), or 2003 applications is not set to Medium, High, or Very High.


Overview

Finding ID Version Rule ID IA Controls Severity
V-6326 DTOO001 SV-6396r1_rule DCMC-1 Medium
Description
The security level controls the action of macros. Macros can be embedded into documents to be executed at the time the document is opened. This can potentially intitiate a malicious action.
STIG Date
Microsoft Excel 2003 2014-10-03

Details

Check Text ( C-620r1_chk )
Procedure: This check must be performed once for each Office 2000 application, once for each Office XP application, and once for each Office 2003 application:

a) Start the MS Word application. On the Tools menu, select the Macro item. On the Macro menu, select the Security… item. On the Security window, select the Security Level tab. On the Security Level tab, determine the value of the Security Level option.
b) Start the MS Excel application. On the Tools menu, select the Macro item. On the Macro menu, select the Security… item. On the Security window, select the Security Level tab. On the Security Level tab, determine the value of the Security Level option.
c) Start the MS PowerPoint application. On the Tools menu, select the Macro item. On the Macro menu, select the Security… item. On the Security window, select the Security Level tab. On the Security Level tab, determine the value of the Security Level option.
d) Start the MS Outlook application. On the Tools menu, select the Macro item. On the Macro menu, select the Security… item. On the Security window, select the Security Level tab. On the Security Level tab, determine the value of the Security Level option.

Criteria: If the Security Level option specifies a value other than Very High, High or Medium in any application, then this is a Finding.
Fix Text (F-5849r1_fix)
For each Office 2000/Office XP/Office2003 application, perform the check once. Start the application and on the Tools menu, select the Macro item. On the Macro menu, select the Security... item. On the Security window, select the Security Level tab. On the Security Level tab, change the value of the Security Level option so that it specifies Very High, High, or Medium.