UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Document behavior if file validation fails must be set.


Overview

Finding ID Version Rule ID IA Controls Severity
V-26616 DTOO292 SV-53581r1_rule ECSC-1 Medium
Description
This policy key controls the behavior of how Office documents should be handled when failing file validation. By requiring such documents to be opened in Protected View, any potentially malicious code would be disabled, allowing the user to edit the document and resaved correctly.
STIG Date
Microsoft Word 2013 STIG 2014-01-06

Details

Check Text ( C-47729r1_chk )
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Word 2013 -> Word Options -> Security -> Trust Center -> Protected View "Set document behavior if file validation fails" is set to "Enabled: Open in Protected View" and Unchecked for "Do not allow edit".

Procedure: Use the Windows Registry Editor to navigate to the following keys:

If both
HKCU\Software\Policies\Microsoft\Office\15.0\word\security\filevalidation\OpenInProtectedView is set to REG_DWORD = 1 and HKCU\Software\Policies\Microsoft\Office\15.0\word\security\filevalidation\DisableEditFromPV is set to REG_DWORD = 1, this is not a finding.

If either, or both keys is not set to REG_DWORD = 1, this is a finding.
Fix Text (F-46506r1_fix)
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Word 2013 -> Word Options -> Security -> Trust Center -> Protected View "Set document behavior if file validation fails" to "Enabled: Open in Protected View" and Unchecked for "Do not allow edit".