Check: ARDC-CL-000045
Adobe Acrobat Reader DC Classic Track STIG:
ARDC-CL-000045
(in versions v2 r1 through v1 r1)
Title
Adobe Reader DC must block Flash Content. (Cat II impact)
Discussion
Flash content is commonly hosted on a web page, but it can also be embedded in PDF and other documents. Flash could be used to surreptitious install malware on the end-users computer. Flash Content restricts Adobe Reader DC not to play Flash content within a PDF. Satisfies: SRG-APP-000112, SRG-APP-000206, SRG-APP-000207, SRG-APP-000209, SRG-APP-000210
Check Content
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnableFlash Type: REG_DWORD Value: 0 If the value for bEnableFlash is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix Text
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnableFlash Type: REG_DWORD Value: 0
Additional Identifiers
Rule ID: SV-213148r557349_rule
Vulnerability ID: V-213148
Group Title: SRG-APP-000112
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001166 |
The information system identifies organization-defined unacceptable mobile code. |
CCI-001169 |
The information system prevents the download of organization-defined unacceptable mobile code. |
CCI-001170 |
The information system prevents the automatic execution of mobile code in organization-defined software applications. |
CCI-001662 |
The information system takes organization-defined corrective action when organization-defined unacceptable mobile code is identified. |
CCI-001695 |
The information system prevents the execution of organization-defined unacceptable mobile code. |