Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-26654 | DTOO334 | SV-53591r1_rule | ECSC-1 | Medium |
Description |
---|
This setting specifies whether users can open, view, edit, or save files saved in the specified format. Enabling the editing of the specified format in protected view, it mitigates zero-day security attacks (which are attacks that occur during between the time that a vulnerability becomes publicly known and a software update or service pack is available) by temporarily preventing users from opening specific types of files and to prevent a user from opening files that have been saved in earlier and pre-release (beta) Microsoft Office formats. |
STIG | Date |
---|---|
Microsoft Word 2013 STIG | 2014-12-23 |
Check Text ( C-47737r1_chk ) |
---|
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Word 2013 -> Word Options -> Security -> Trust Center -> File Block Settings "Word 2000 binary documents and templates" is set to "Enabled: Allow editing and open in Protected View". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\word\security\fileblock Criteria: If the value Word2000Files is REG_DWORD = 5, this is not a finding. |
Fix Text (F-46515r1_fix) |
---|
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Word 2013 -> Word Options -> Security -> Trust Center -> File Block Settings "Word 2000 binary documents and templates" to "Enabled: Allow editing and open in Protected View". |