UCF STIG Viewer Logo

Hyperlink warnings for Office must be configured for use.


Overview

Finding ID Version Rule ID IA Controls Severity
V-17659 DTOO194 SV-52731r2_rule Medium
Description
Unsafe hyperlinks are links that might pose a security risk if users click them. Clicking an unsafe link could compromise the security of sensitive information or harm the computer. Links that Office considers unsafe include links to executable files, TIFF files, and Microsoft Document Imaging (MDI) files. Other unsafe links are those using protocols considered to be unsafe, including msn, nntp, mms, outlook, and stssync.
STIG Date
Microsoft Office System 2013 STIG 2017-06-20

Details

Check Text ( C-47059r3_chk )
Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2013 >> Security Settings "Suppress hyperlink warnings" is set to "Disabled".
Use the Windows Registry Editor to navigate to the following hive:
HKEY_Users

For every users profile hive under HKEY_Users, navigate to the following key:
\Software\Policies\Microsoft\Office\15.0\common\security

Criteria: If the value “DisableHyperLinkWarning” is REG_DWORD = 0 for all user profile hives, this is not a finding.

Fix Text: Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2013 >> Security Settings "Suppress hyperlink warnings" to "Disabled".
Fix Text (F-45656r1_fix)
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2013 -> Security Settings "Suppress hyperlink warnings" to "Disabled".