Check: ARDC-CN-000030
Adobe Acrobat Reader DC Continuous Track STIG:
ARDC-CN-000030
(in versions v2 r1 through v1 r2)
Title
Adobe Reader DC must block access to Unknown Websites. (Cat II impact)
Discussion
Because Internet access is a potential security risk, clicking any unknown website link to the Internet poses a potential security risk. Malicious websites can transfer harmful content or silently gather data. Satisfies: SRG-APP-000112, SRG-APP-000206, SRG-APP-000207, SRG-APP-000209, SRG-APP-000210
Check Content
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iUnknownURLPerms Type: REG_DWORD Value: 3 If the value for iUnknownURLPerms is not set to “3” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix Text
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iUnknownURLPerms Type: REG_DWORD Value: 3
Additional Identifiers
Rule ID: SV-213173r395811_rule
Vulnerability ID: V-213173
Group Title: SRG-APP-000112
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001166 |
The information system identifies organization-defined unacceptable mobile code. |
CCI-001169 |
The information system prevents the download of organization-defined unacceptable mobile code. |
CCI-001170 |
The information system prevents the automatic execution of mobile code in organization-defined software applications. |
CCI-001662 |
The information system takes organization-defined corrective action when organization-defined unacceptable mobile code is identified. |
CCI-001695 |
The information system prevents the execution of organization-defined unacceptable mobile code. |