Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-17561 | DTOO181 | SV-52718r2_rule | Medium |
Description |
---|
Office files can save graphic files in Portable Network Graphics (PNG) format to improve the quality of the graphics when documents are saved as web pages. The PNG graphic file format (.png) is used for a wide range of graphics, from small images (such as bullets and banners) to complex images (such as photographs), and can offer better image fidelity and smaller file sizes than some other formats. However, PNG graphics cannot be displayed by many earlier web browsers, such as Microsoft Internet Explorer version 5 or earlier. Office applications do not save graphics in the PNG format by default but can be configured to save in PNG format by explicitly enabling this setting. By disabling this setting, future zero-day attacks that target PNG files will be thwarted. |
STIG | Date |
---|---|
Microsoft Office System 2013 STIG | 2017-01-04 |
Check Text ( C-47046r4_chk ) |
---|
Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2013 >> Tools >> Options >> General >> Web Options >> Browsers "Allow PNG as an output format" is set to "Disabled". Use the Windows Registry Editor to navigate to the following hive: HKEY_Users For every users profile hive under HKEY_Users, navigate to the following key: \Software\Policies\Microsoft\Office\15.0\common\internet If the value “AllowPNG” is REG_DWORD = 0 for every user profile hive, this is not a finding. |
Fix Text (F-45643r1_fix) |
---|
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2013 -> Tools \ Options \ General \ Web Options -> Browsers "Allow PNG as an output format" to "Disabled". |