Check: DTOO304
Microsoft Access 2013 STIG:
DTOO304
(in versions v1 r7 through v1 r4)
Title
Trust access for VBA must be disallowed. (Cat II impact)
Discussion
VSTO projects require access to the Visual Basic for Applications project system in Excel, PowerPoint, and Word, even though the projects do not use Visual Basic for Applications. Design-time support of controls in both Visual Basic and C# projects depends on the Visual Basic for Applications project system in Word and Excel. By default, Excel, Word, and PowerPoint do not allow automation clients to have programmatic access to VBA projects. Users can enable this by selecting the Trust access to the VBA project object model in the Macro Settings section of the Trust Center. However, doing so allows macros in any documents the user opens to access the core Visual Basic objects, methods, and properties, which represents a potential security hazard.
Check Content
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Access 2013 -> Application Settings -> Security -> Trust Center -> "VBA macro Notification Settings" is set to "Enabled: Disable all with notification". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\software\policies\Microsoft\office\15.0\access\security Criteria: If the value vbawarnings is REG_DWORD = 2, this is not a finding.
Fix Text
Set policy value for User Configuration -> Administrative Templates -> Microsoft Access 2013 -> Application Settings -> Security -> Trust Center -> "VBA macro Notification Settings" must be set to "Enabled: Disable all with notification".
Additional Identifiers
Rule ID: SV-242328r960963_rule
Vulnerability ID: V-242328
Group Title: SRG-APP-000141
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
Configure the system to provide only organization-defined mission essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |