Check: DTOO130
Microsoft Access 2013 STIG:
DTOO130
(in versions v1 r6 through v1 r4)
Title
The configuration for enabling of hyperlinks must be enforced. (Cat II impact)
Discussion
Access underlines hyperlinks that appear in tables, queries, forms, and reports. If this configuration is changed, users might click on dangerous hyperlinks without realizing it, which could pose a security risk.
Check Content
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Access 2013-> Application Settings -> Web Options... -> General "Underline Hyperlinks" is set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\access\internet Criteria: If the value DoNotUnderlineHyperlinks is REG_DWORD = 0, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Access 2013 -> Application Settings -> Web Options... -> General "Underline Hyperlinks" to "Enabled".
Additional Identifiers
Rule ID: SV-52768r1_rule
Vulnerability ID: V-17810
Group Title: DTOO130 - Underline hyperlinks
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002460 |
The information system enforces organization-defined actions prior to executing mobile code. |
Controls
Number | Title |
---|---|
SC-18 (4) |
Prevent Automatic Execution |