UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The ability to run unsecure Office apps must be disabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-228526 DTOO412 SV-228526r508020_rule Medium
Description
Unsecure apps for Office, which are apps that have web page or catalog locations that are not SSL-secured (https://), and/or are not in users' Internet zones may allow data to be transmitted/accessed via clear text to outside sources. By configuring this policy to be disabled, users will be prevented from transmitting/accessing data in a nonsecure manner.
STIG Date
Microsoft Office System 2013 Security Technical Implementation Guide 2020-09-25

Details

Check Text ( C-30759r498856_chk )
Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2013 >> Security Settings >> Trust Center >> Trusted Catalogs "Allow Unsecure Apps and Catalogs" is set to "Disabled".

Procedure: Use the Windows Registry Editor to navigate to the following hive:

HKCU\Software\Policies\Microsoft\Office\15.0\wef\trustedcatalogs

If the value 'requireserververification' is REG_DWORD = 1, this is not a finding.
Fix Text (F-30744r498857_fix)
Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2013 >> Security Settings >> Trust Center >> Trusted Catalogs "Allow Unsecure Apps and Catalogs" to "Disabled".