UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The Enhanced Mitigation Experience Toolkit (EMET) Protection Profile for Popular Software must be implemented.


Overview

Finding ID Version Rule ID IA Controls Severity
V-36704 WINEM-000081 SV-50507r5_rule ECVP-1 Medium
Description
Attackers are constantly looking for vulnerabilities in systems and applications. The Enhanced Mitigation Experience Toolkit can enable several mechanisms, such as Data Execution Prevention (DEP) on the system and applications adding additional levels of protection.
STIG Date
Windows 2003 Domain Controller Security Technical Implementation Guide 2015-06-03

Details

Check Text ( C-49488r4_chk )
This is applicable to unclassified systems, for other systems this is NA.

Verify the "Popular Software" Protection Profile has been implemented. This implements mitigations to protect Internet Explorer, Office programs, and numerous third party applications.

If the following registry subkeys do not exist, this is a finding.

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SOFTWARE\Microsoft\EMET\

The subkeys will include the following:
7z.exe
7zfm.exe
7zg.exe
acrobat.exe
acrord32.exe
chrome.exe
communicator.exe
excel.exe
firefox.exe
foxit reader.exe
googletalk.exe
iexplore.exe
infopath.exe
itunes.exe
java.exe
javaw.exe
javaws.exe
lync.exe
mirc.exe
msaccess.exe
mspup.exe
ois.exe
opera.exe
outlook.exe
photoshop.exe
pidgen.exe
plugin-container.exe
powerpnt.exe
pptview.exe
quicktimeplayer.exe
rar.exe
realconverter.exe
realplay.exe
safari.exe
skydrive.exe
skype.exe
thunderbird.exe
unrar.exe
visio.exe
vlc.exe
vpreview.exe
winamp.exe
windowslivewriter.exe
winrar.exe
winword.exe
winzip32.exe
winzip64.exe
wlmail.exe
wlxphotogallery.exe
wmplayer.exe
wordpad.exe

Additional details of the implementation can be viewed with the following.
Open a command prompt.
Navigate to the EMET installation directory, typically \Program Files\EMET.
Execute the following command - "EMET_Conf --list".
Fix Text (F-49712r3_fix)
This is applicable to unclassified systems, for other systems this is NA.

Open a command prompt.
Navigate to the EMET installation directory, typically \Program Files\EMET.
Execute the following command -'EMET_Conf --import "deployment\protection profiles\popular software.xml"'

The Enhanced Mitigation Experience Toolkit must be installed on the system to make this setting available.